Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
elBAfme5gQ

Overview

General Information

Sample Name:elBAfme5gQ (renamed file extension from none to dll)
Analysis ID:595323
MD5:ca7c6f265e4bc09e6d9d0b2b6234e8b3
SHA1:1720aadb4965df64ee40d32957ee6080500639b2
SHA256:a8f566b8d2d9f9a418211039cb76552d460f83195d519a89313a880ead9bd4a4
Tags:Dridexexe
Infos:

Detection

Dridex
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected Dridex unpacked file
Multi AV Scanner detection for submitted file
Benign windows process drops PE files
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Changes memory attributes in foreign processes to executable or writable
Machine Learning detection for sample
Modifies the prolog of user mode functions (user mode inline hooks)
Queues an APC in another process (thread injection)
Sigma detected: Suspicious Call by Ordinal
Machine Learning detection for dropped file
Uses Atom Bombing / ProGate to inject into other processes
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Contains functionality to execute programs as a different user
PE file contains sections with non-standard names
Queries the installation date of Windows
Detected potential crypto function
Found potential string decryption / allocating functions
Contains functionality to call native functions
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
Contains functionality which may be used to detect a debugger (GetProcessHeap)
PE file contains executable resources (Code or Archives)
Contains functionality for execution timing, often used to detect debuggers
Sample file is different than original file name gathered from version info
PE file contains strange resources
Drops PE files
Tries to load missing DLLs
Found evasive API chain checking for process token information
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Binary contains a suspicious time stamp
PE file contains more sections than normal
Found large amount of non-executed APIs
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

  • System is w10x64
  • loaddll64.exe (PID: 6828 cmdline: loaddll64.exe "C:\Users\user\Desktop\elBAfme5gQ.dll" MD5: 4E8A40CAD6CCC047914E3A7830A2D8AA)
    • cmd.exe (PID: 6836 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1 MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
      • rundll32.exe (PID: 6856 cmdline: rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1 MD5: 73C519F050C20580F8A62C849D49215A)
    • rundll32.exe (PID: 6844 cmdline: rundll32.exe C:\Users\user\Desktop\elBAfme5gQ.dll,CreateXmlReader MD5: 73C519F050C20580F8A62C849D49215A)
      • explorer.exe (PID: 3968 cmdline: C:\Windows\Explorer.EXE MD5: AD5296B280E8F522A8A897C96BAB0E1D)
        • PresentationSettings.exe (PID: 7040 cmdline: C:\Windows\system32\PresentationSettings.exe MD5: 76086DD04B6760277A2B897345A0B457)
        • PresentationSettings.exe (PID: 5432 cmdline: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exe MD5: 76086DD04B6760277A2B897345A0B457)
        • DmNotificationBroker.exe (PID: 5352 cmdline: C:\Windows\system32\DmNotificationBroker.exe MD5: 1643D5735213BC89C0012F0E48253765)
        • DmNotificationBroker.exe (PID: 5876 cmdline: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exe MD5: 1643D5735213BC89C0012F0E48253765)
        • WFS.exe (PID: 4504 cmdline: C:\Windows\system32\WFS.exe MD5: CD6ACF3B997099B6CFB2417D3942F755)
        • WFS.exe (PID: 6212 cmdline: C:\Users\user\AppData\Local\daH0n9\WFS.exe MD5: CD6ACF3B997099B6CFB2417D3942F755)
        • DmNotificationBroker.exe (PID: 6008 cmdline: C:\Windows\system32\DmNotificationBroker.exe MD5: 1643D5735213BC89C0012F0E48253765)
        • DmNotificationBroker.exe (PID: 1804 cmdline: C:\Users\user\AppData\Local\pEcAZnNU3\DmNotificationBroker.exe MD5: 1643D5735213BC89C0012F0E48253765)
        • wusa.exe (PID: 6376 cmdline: C:\Windows\system32\wusa.exe MD5: 04CE745559916B99248F266BBF5F9ED9)
    • rundll32.exe (PID: 6896 cmdline: rundll32.exe C:\Users\user\Desktop\elBAfme5gQ.dll,CreateXmlReaderInputWithEncodingCodePage MD5: 73C519F050C20580F8A62C849D49215A)
    • rundll32.exe (PID: 6928 cmdline: rundll32.exe C:\Users\user\Desktop\elBAfme5gQ.dll,CreateXmlReaderInputWithEncodingName MD5: 73C519F050C20580F8A62C849D49215A)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000015.00000002.455715001.00007FFC66921000.00000020.00000001.01000000.0000000C.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
    00000002.00000002.382683427.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
      0000001F.00000002.529541082.00007FFC67881000.00000020.00000001.01000000.00000010.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
        00000006.00000002.279312817.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
          00000003.00000002.265252224.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
            Click to see the 4 entries
            SourceRuleDescriptionAuthorStrings
            18.2.PresentationSettings.exe.7ffc66970000.3.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
              25.2.WFS.exe.7ffc66970000.3.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                2.2.rundll32.exe.7ffc646c0000.2.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                  31.2.DmNotificationBroker.exe.7ffc67880000.3.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                    5.2.rundll32.exe.7ffc646c0000.2.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                      Click to see the 4 entries

                      System Summary

                      barindex
                      Source: Process startedAuthor: Florian Roth: Data: Command: rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1, CommandLine: rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1, CommandLine|base64offset|contains: , Image: C:\Windows\System32\rundll32.exe, NewProcessName: C:\Windows\System32\rundll32.exe, OriginalFileName: C:\Windows\System32\rundll32.exe, ParentCommandLine: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 6836, ProcessCommandLine: rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1, ProcessId: 6856
                      Source: File createdAuthor: frack113: Data: EventID: 11, Image: C:\Windows\explorer.exe, ProcessId: 3968, TargetFilename: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exe

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: elBAfme5gQ.dllVirustotal: Detection: 62%Perma Link
                      Source: elBAfme5gQ.dllMetadefender: Detection: 65%Perma Link
                      Source: elBAfme5gQ.dllReversingLabs: Detection: 88%
                      Source: elBAfme5gQ.dllAvira: detected
                      Source: C:\Users\user\AppData\Local\WRsLe\DUI70.dllAvira: detection malicious, Label: TR/Crypt.XPACK.Gen4
                      Source: C:\Users\user\AppData\Local\daH0n9\credui.dllAvira: detection malicious, Label: TR/Crypt.XPACK.Gen7
                      Source: C:\Users\user\AppData\Local\WRsLe\DUI70.dllAvira: detection malicious, Label: TR/Crypt.XPACK.Gen4
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\WINMM.dllAvira: detection malicious, Label: TR/Crypt.ZPACK.Gen
                      Source: elBAfme5gQ.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\WRsLe\DUI70.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\daH0n9\credui.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\WRsLe\DUI70.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\WINMM.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E073F500 CryptProtectData,GetLastError,RegSetValueExW,25_2_00007FF7E073F500
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E073F5C8 RegQueryValueExW,RegQueryValueExW,CryptUnprotectData,GetLastError,LocalFree,25_2_00007FF7E073F5C8
                      Source: elBAfme5gQ.dllStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
                      Source: Binary string: DmNotificationBroker.pdb source: DmNotificationBroker.exe, 00000015.00000000.431514520.00007FF793F65000.00000002.00000001.01000000.0000000B.sdmp, DmNotificationBroker.exe, 00000015.00000002.455649631.00007FF793F65000.00000002.00000001.01000000.0000000B.sdmp, DmNotificationBroker.exe, 0000001F.00000000.502738188.00007FF6DC635000.00000002.00000001.01000000.0000000F.sdmp, DmNotificationBroker.exe, 0000001F.00000002.529497507.00007FF6DC635000.00000002.00000001.01000000.0000000F.sdmp, DmNotificationBroker.exe0.4.dr, DmNotificationBroker.exe.4.dr
                      Source: Binary string: PresentationSettings.pdb source: PresentationSettings.exe, 00000012.00000002.417779681.00007FF7B4466000.00000002.00000001.01000000.00000009.sdmp, PresentationSettings.exe, 00000012.00000000.394587436.00007FF7B4466000.00000002.00000001.01000000.00000009.sdmp, PresentationSettings.exe.4.dr
                      Source: Binary string: DmNotificationBroker.pdbGCTL source: DmNotificationBroker.exe, 00000015.00000000.431514520.00007FF793F65000.00000002.00000001.01000000.0000000B.sdmp, DmNotificationBroker.exe, 00000015.00000002.455649631.00007FF793F65000.00000002.00000001.01000000.0000000B.sdmp, DmNotificationBroker.exe, 0000001F.00000000.502738188.00007FF6DC635000.00000002.00000001.01000000.0000000F.sdmp, DmNotificationBroker.exe, 0000001F.00000002.529497507.00007FF6DC635000.00000002.00000001.01000000.0000000F.sdmp, DmNotificationBroker.exe0.4.dr, DmNotificationBroker.exe.4.dr
                      Source: Binary string: Wfs.pdbGCTL source: WFS.exe, 00000019.00000002.489112517.00007FF7E075C000.00000002.00000001.01000000.0000000D.sdmp, WFS.exe, 00000019.00000000.461037552.00007FF7E075C000.00000002.00000001.01000000.0000000D.sdmp, WFS.exe.4.dr
                      Source: Binary string: Wfs.pdb source: WFS.exe, 00000019.00000002.489112517.00007FF7E075C000.00000002.00000001.01000000.0000000D.sdmp, WFS.exe, 00000019.00000000.461037552.00007FF7E075C000.00000002.00000001.01000000.0000000D.sdmp, WFS.exe.4.dr
                      Source: Binary string: PresentationSettings.pdbGCTL source: PresentationSettings.exe, 00000012.00000002.417779681.00007FF7B4466000.00000002.00000001.01000000.00000009.sdmp, PresentationSettings.exe, 00000012.00000000.394587436.00007FF7B4466000.00000002.00000001.01000000.00000009.sdmp, PresentationSettings.exe.4.dr
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6471ED10 FindFirstFileExW,0_2_00007FFC6471ED10
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B4464518 PathAppendW,FindFirstFileW,PathAppendW,GetLastError,PathFindExtensionW,StrCmpICW,FindNextFileW,FindClose,GetLastError,18_2_00007FF7B4464518
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669CED10 FindFirstFileExW,18_2_00007FFC669CED10
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6697ED10 FindFirstFileExW,21_2_00007FFC6697ED10
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E07071B0 #626,memset,#6887,#1122,#1287,FindFirstFileW,GetLastError,#6886,#1122,#1287,#1287,#624,EnterCriticalSection,LeaveCriticalSection,FindNextFileW,GetLastError,FindClose,#6887,#1040,SendMessageW,25_2_00007FF7E07071B0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E07389BC wcscpy_s,wcscat_s,FindFirstFileW,_wcsicmp,FindNextFileW,GetLastError,FindClose,25_2_00007FF7E07389BC
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0705B40 #626,#626,memset,memset,#6887,#620,#1122,#1040,#1287,FindFirstFileW,GetLastError,#6886,#620,#1122,#1040,#1287,#1287,#620,EnterCriticalSection,LeaveCriticalSection,FindNextFileW,GetLastError,FindClose,#6887,#1040,#1040,SendMessageW,25_2_00007FF7E0705B40
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E07230D8 SendMessageW,GetLastError,wcschr,#626,#2846,FindFirstFileW,GetLastError,#1040,#626,memset,GetLastError,ReadFile,GetLastError,CloseHandle,FindNextFileW,GetLastError,FindClose,GetLastError,#1040,CloseHandle,SendMessageW,#4262,#640,#1122,#1040,#6395,#6395,25_2_00007FF7E07230D8
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06FF0AC GetTempPathW,GetLastError,wcsrchr,_wcsnset,GetCurrentProcessId,FindFirstFileW,GetLastError,DeleteFileW,GetLastError,FindNextFileW,GetLastError,GetLastError,FindClose,25_2_00007FF7E06FF0AC

                      E-Banking Fraud

                      barindex
                      Source: Yara matchFile source: 18.2.PresentationSettings.exe.7ffc66970000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 25.2.WFS.exe.7ffc66970000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.rundll32.exe.7ffc646c0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 31.2.DmNotificationBroker.exe.7ffc67880000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.7ffc646c0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.7ffc646c0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll64.exe.7ffc646c0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.rundll32.exe.7ffc646c0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 21.2.DmNotificationBroker.exe.7ffc66920000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000015.00000002.455715001.00007FFC66921000.00000020.00000001.01000000.0000000C.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.382683427.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001F.00000002.529541082.00007FFC67881000.00000020.00000001.01000000.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.279312817.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.265252224.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.285761236.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000019.00000002.489503728.00007FFC66971000.00000020.00000001.01000000.0000000E.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000002.417833376.00007FFC66971000.00000020.00000001.01000000.0000000A.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.271180425.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472D5200_2_00007FFC6472D520
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647276500_2_00007FFC64727650
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6471DDC00_2_00007FFC6471DDC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647097D00_2_00007FFC647097D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F50200_2_00007FFC646F5020
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647131500_2_00007FFC64713150
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E78800_2_00007FFC646E7880
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F59F00_2_00007FFC646F59F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6470CA500_2_00007FFC6470CA50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646FAA700_2_00007FFC646FAA70
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6470A2C00_2_00007FFC6470A2C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F3CF00_2_00007FFC646F3CF0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D3CD00_2_00007FFC646D3CD0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F5CD00_2_00007FFC646F5CD0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EAC800_2_00007FFC646EAC80
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D9D700_2_00007FFC646D9D70
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E48B0_2_00007FFC6472E48B
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472A4900_2_00007FFC6472A490
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E4940_2_00007FFC6472E494
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E49D0_2_00007FFC6472E49D
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64722CA00_2_00007FFC64722CA0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E4A60_2_00007FFC6472E4A6
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E3D500_2_00007FFC646E3D50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646ED5500_2_00007FFC646ED550
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E4AD0_2_00007FFC6472E4AD
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E4B60_2_00007FFC6472E4B6
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F1D300_2_00007FFC646F1D30
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F0D100_2_00007FFC646F0D10
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D65E00_2_00007FFC646D65E0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D95C00_2_00007FFC646D95C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F25C00_2_00007FFC646F25C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647106500_2_00007FFC64710650
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646CC5A00_2_00007FFC646CC5A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D86700_2_00007FFC646D8670
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646CDE200_2_00007FFC646CDE20
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C16200_2_00007FFC646C1620
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E36100_2_00007FFC646E3610
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F2E100_2_00007FFC646F2E10
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64720F300_2_00007FFC64720F30
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EF6B00_2_00007FFC646EF6B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F06A00_2_00007FFC646F06A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647257600_2_00007FFC64725760
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C6E900_2_00007FFC646C6E90
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6473BF6F0_2_00007FFC6473BF6F
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647207700_2_00007FFC64720770
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C7E800_2_00007FFC646C7E80
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646DE7700_2_00007FFC646DE770
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E2F500_2_00007FFC646E2F50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472A6B00_2_00007FFC6472A6B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64727EC00_2_00007FFC64727EC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E872B0_2_00007FFC646E872B
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E6FE00_2_00007FFC646E6FE0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646DA7D00_2_00007FFC646DA7D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D8FC00_2_00007FFC646D8FC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647158400_2_00007FFC64715840
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EE7B00_2_00007FFC646EE7B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C67900_2_00007FFC646C6790
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6470F8700_2_00007FFC6470F870
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472C7800_2_00007FFC6472C780
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6473EF800_2_00007FFC6473EF80
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646FF8700_2_00007FFC646FF870
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6473B7A00_2_00007FFC6473B7A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E50500_2_00007FFC646E5050
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EC0300_2_00007FFC646EC030
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F00200_2_00007FFC646F0020
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C10100_2_00007FFC646C1010
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64734FF00_2_00007FFC64734FF0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E48000_2_00007FFC646E4800
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C18D00_2_00007FFC646C18D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D08B00_2_00007FFC646D08B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647269500_2_00007FFC64726950
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472B9600_2_00007FFC6472B960
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646DD8900_2_00007FFC646DD890
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E41400_2_00007FFC646E4140
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F61300_2_00007FFC646F6130
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646DE1100_2_00007FFC646DE110
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E39100_2_00007FFC646E3910
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646CB1000_2_00007FFC646CB100
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EF1F00_2_00007FFC646EF1F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F91F00_2_00007FFC646F91F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F89F00_2_00007FFC646F89F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F21D00_2_00007FFC646F21D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E69C00_2_00007FFC646E69C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646DE9B00_2_00007FFC646DE9B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E11B00_2_00007FFC646E11B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EE9A00_2_00007FFC646EE9A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472B2600_2_00007FFC6472B260
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F99900_2_00007FFC646F9990
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C29800_2_00007FFC646C2980
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646FB2500_2_00007FFC646FB250
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C7A400_2_00007FFC646C7A40
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E82E00_2_00007FFC646E82E0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646FBAE00_2_00007FFC646FBAE0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E92C00_2_00007FFC646E92C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64725B500_2_00007FFC64725B50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EDAA00_2_00007FFC646EDAA0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F43600_2_00007FFC646F4360
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647282A00_2_00007FFC647282A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472AAA00_2_00007FFC6472AAA0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C53500_2_00007FFC646C5350
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E33400_2_00007FFC646E3340
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D83400_2_00007FFC646D8340
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6471F2C00_2_00007FFC6471F2C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F1B300_2_00007FFC646F1B30
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646CBB200_2_00007FFC646CBB20
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64722AE00_2_00007FFC64722AE0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EA3100_2_00007FFC646EA310
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64727AF00_2_00007FFC64727AF0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F03000_2_00007FFC646F0300
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E4000_2_00007FFC6472E400
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D23F00_2_00007FFC646D23F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647294100_2_00007FFC64729410
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647243900_2_00007FFC64724390
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64714BC00_2_00007FFC64714BC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D54200_2_00007FFC646D5420
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C5C200_2_00007FFC646C5C20
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D74100_2_00007FFC646D7410
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B446437418_2_00007FF7B4464374
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B4452D9018_2_00007FF7B4452D90
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B445327818_2_00007FF7B4453278
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B446303418_2_00007FF7B4463034
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B445441C18_2_00007FF7B445441C
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B446354C18_2_00007FF7B446354C
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B4463CDC18_2_00007FF7B4463CDC
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B44536DC18_2_00007FF7B44536DC
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B445649C18_2_00007FF7B445649C
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B44556A418_2_00007FF7B44556A4
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B44639C818_2_00007FF7B44639C8
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A502018_2_00007FFC669A5020
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669B97D018_2_00007FFC669B97D0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DD52018_2_00007FFC669DD520
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A5CD018_2_00007FFC669A5CD0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D765018_2_00007FFC669D7650
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669CDDC018_2_00007FFC669CDDC0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669ABAE018_2_00007FFC669ABAE0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669BA2C018_2_00007FFC669BA2C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C315018_2_00007FFC669C3150
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699788018_2_00007FFC66997880
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669AAA7018_2_00007FFC669AAA70
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669BCA5018_2_00007FFC669BCA50
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A59F018_2_00007FFC669A59F0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699872B18_2_00007FFC6699872B
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D0F3018_2_00007FFC669D0F30
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D576018_2_00007FFC669D5760
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D077018_2_00007FFC669D0770
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698E77018_2_00007FFC6698E770
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EBF6F18_2_00007FFC669EBF6F
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66992F5018_2_00007FFC66992F50
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A06A018_2_00007FFC669A06A0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DA6B018_2_00007FFC669DA6B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699F6B018_2_00007FFC6699F6B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66977E8018_2_00007FFC66977E80
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66976E9018_2_00007FFC66976E90
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D7EC018_2_00007FFC669D7EC0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669F082018_2_00007FFC669F0820
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A002018_2_00007FFC669A0020
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699C03018_2_00007FFC6699C030
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699480018_2_00007FFC66994800
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697101018_2_00007FFC66971010
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669AF87018_2_00007FFC669AF870
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669BF87018_2_00007FFC669BF870
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C584018_2_00007FFC669C5840
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699505018_2_00007FFC66995050
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EB7A018_2_00007FFC669EB7A0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699E7B018_2_00007FFC6699E7B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DC78018_2_00007FFC669DC780
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EEF8018_2_00007FFC669EEF80
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697679018_2_00007FFC66976790
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66996FE018_2_00007FFC66996FE0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669E4FF018_2_00007FFC669E4FF0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66988FC018_2_00007FFC66988FC0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698A7D018_2_00007FFC6698A7D0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C8D2018_2_00007FFC669C8D20
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A1D3018_2_00007FFC669A1D30
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A0D1018_2_00007FFC669A0D10
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66989D7018_2_00007FFC66989D70
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66993D5018_2_00007FFC66993D50
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699D55018_2_00007FFC6699D550
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE4A618_2_00007FFC669DE4A6
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D2CA018_2_00007FFC669D2CA0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE49D18_2_00007FFC669DE49D
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE4B618_2_00007FFC669DE4B6
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE4AD18_2_00007FFC669DE4AD
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE48B18_2_00007FFC669DE48B
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699AC8018_2_00007FFC6699AC80
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE49418_2_00007FFC669DE494
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DA49018_2_00007FFC669DA490
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A3CF018_2_00007FFC669A3CF0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66983CD018_2_00007FFC66983CD0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697162018_2_00007FFC66971620
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697DE2018_2_00007FFC6697DE20
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699361018_2_00007FFC66993610
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A2E1018_2_00007FFC669A2E10
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698867018_2_00007FFC66988670
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C065018_2_00007FFC669C0650
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697C5A018_2_00007FFC6697C5A0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EC59018_2_00007FFC669EC590
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669865E018_2_00007FFC669865E0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669895C018_2_00007FFC669895C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A25C018_2_00007FFC669A25C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697BB2018_2_00007FFC6697BB20
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A1B3018_2_00007FFC669A1B30
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A030018_2_00007FFC669A0300
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699A31018_2_00007FFC6699A310
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A436018_2_00007FFC669A4360
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699334018_2_00007FFC66993340
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698834018_2_00007FFC66988340
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697535018_2_00007FFC66975350
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D5B5018_2_00007FFC669D5B50
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D82A018_2_00007FFC669D82A0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DAAA018_2_00007FFC669DAAA0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699DAA018_2_00007FFC6699DAA0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D2AE018_2_00007FFC669D2AE0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669982E018_2_00007FFC669982E0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D7AF018_2_00007FFC669D7AF0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669CF2C018_2_00007FFC669CF2C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669992C018_2_00007FFC669992C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C22C018_2_00007FFC669C22C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66975C2018_2_00007FFC66975C20
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698542018_2_00007FFC66985420
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE40018_2_00007FFC669DE400
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EFC0018_2_00007FFC669EFC00
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698741018_2_00007FFC66987410
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D941018_2_00007FFC669D9410
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D439018_2_00007FFC669D4390
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669823F018_2_00007FFC669823F0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C4BC018_2_00007FFC669C4BC0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A613018_2_00007FFC669A6130
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697B10018_2_00007FFC6697B100
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698E11018_2_00007FFC6698E110
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699391018_2_00007FFC66993910
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DB96018_2_00007FFC669DB960
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699414018_2_00007FFC66994140
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D695018_2_00007FFC669D6950
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669808B018_2_00007FFC669808B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EC8B118_2_00007FFC669EC8B1
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698D89018_2_00007FFC6698D890
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EC0EB18_2_00007FFC669EC0EB
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669718D018_2_00007FFC669718D0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DB26018_2_00007FFC669DB260
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66977A4018_2_00007FFC66977A40
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669AB25018_2_00007FFC669AB250
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699E9A018_2_00007FFC6699E9A0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698E9B018_2_00007FFC6698E9B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669911B018_2_00007FFC669911B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697298018_2_00007FFC66972980
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A999018_2_00007FFC669A9990
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699F1F018_2_00007FFC6699F1F0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A91F018_2_00007FFC669A91F0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A89F018_2_00007FFC669A89F0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669969C018_2_00007FFC669969C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A21D018_2_00007FFC669A21D0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695502021_2_00007FFC66955020
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669697D021_2_00007FFC669697D0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698D52021_2_00007FFC6698D520
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66955CD021_2_00007FFC66955CD0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698765021_2_00007FFC66987650
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6697DDC021_2_00007FFC6697DDC0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695BAE021_2_00007FFC6695BAE0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6696A2C021_2_00007FFC6696A2C0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6697315021_2_00007FFC66973150
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694788021_2_00007FFC66947880
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695AA7021_2_00007FFC6695AA70
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6696CA5021_2_00007FFC6696CA50
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669559F021_2_00007FFC669559F0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694872B21_2_00007FFC6694872B
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66980F3021_2_00007FFC66980F30
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698576021_2_00007FFC66985760
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698077021_2_00007FFC66980770
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6693E77021_2_00007FFC6693E770
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6699BF6F21_2_00007FFC6699BF6F
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66942F5021_2_00007FFC66942F50
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669506A021_2_00007FFC669506A0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694F6B021_2_00007FFC6694F6B0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698A6B021_2_00007FFC6698A6B0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66927E8021_2_00007FFC66927E80
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66926E9021_2_00007FFC66926E90
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66987EC021_2_00007FFC66987EC0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695002021_2_00007FFC66950020
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669A082021_2_00007FFC669A0820
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694C03021_2_00007FFC6694C030
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694480021_2_00007FFC66944800
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6692101021_2_00007FFC66921010
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695F87021_2_00007FFC6695F870
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6696F87021_2_00007FFC6696F870
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6697584021_2_00007FFC66975840
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694505021_2_00007FFC66945050
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6699B7A021_2_00007FFC6699B7A0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694E7B021_2_00007FFC6694E7B0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698C78021_2_00007FFC6698C780
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6699EF8021_2_00007FFC6699EF80
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6692679021_2_00007FFC66926790
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66946FE021_2_00007FFC66946FE0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66994FF021_2_00007FFC66994FF0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66938FC021_2_00007FFC66938FC0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6693A7D021_2_00007FFC6693A7D0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66978D2021_2_00007FFC66978D20
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66951D3021_2_00007FFC66951D30
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66950D1021_2_00007FFC66950D10
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66939D7021_2_00007FFC66939D70
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694D55021_2_00007FFC6694D550
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66943D5021_2_00007FFC66943D50
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E4A621_2_00007FFC6698E4A6
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66982CA021_2_00007FFC66982CA0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E49D21_2_00007FFC6698E49D
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E4B621_2_00007FFC6698E4B6
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E4AD21_2_00007FFC6698E4AD
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694AC8021_2_00007FFC6694AC80
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E48B21_2_00007FFC6698E48B
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E49421_2_00007FFC6698E494
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698A49021_2_00007FFC6698A490
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66953CF021_2_00007FFC66953CF0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66933CD021_2_00007FFC66933CD0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6692162021_2_00007FFC66921620
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6692DE2021_2_00007FFC6692DE20
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66952E1021_2_00007FFC66952E10
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694361021_2_00007FFC66943610
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6693867021_2_00007FFC66938670
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6697065021_2_00007FFC66970650
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.