Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
astx_setup.exe

Overview

General Information

Sample Name:astx_setup.exe
Analysis ID:755221
MD5:7dd75b2c2e214c0347df3dc137161b19
SHA1:072a03d9279d3ecbdb5a76c70a862a75fb50d95b
SHA256:06f360d2a25c75619cb769f56ced75d3d92cd339cb3ec2e3aa9c642ba6f3158f
Infos:

Detection

GuLoader
Score:34
Range:0 - 100
Whitelisted:false
Confidence:20%

Compliance

Score:51
Range:0 - 100

Signatures

Yara detected AntiVM3
Yara detected GuLoader
Found driver which could be used to inject code into processes
May modify the system service descriptor table (often done to hook functions)
Writes many files with high entropy
Uses 32bit PE files
Antivirus or Machine Learning detection for unpacked file
Drops PE files to the application program directory (C:\ProgramData)
Drops certificate files (DER)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
Contains functionality to shutdown / reboot the system
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
PE file contains sections with non-standard names
Detected potential crypto function
Found potential string decryption / allocating functions
Contains functionality to launch a process as a different user
Sample execution stops while process was sleeping (likely an evasion)
Found evasive API chain (may stop execution after checking a module file name)
Contains functionality to dynamically determine API calls
Found dropped PE file which has not been started or loaded
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Abnormal high CPU Usage
Sample file is different than original file name gathered from version info
Extensive use of GetProcAddress (often used to hide API calls)
Drops PE files
Tries to load missing DLLs
Uses cacls to modify the permissions of files
Drops PE files to the windows directory (C:\Windows)
Yara detected Keylogger Generic
Creates or modifies windows services
Found large amount of non-executed APIs
Uses Microsoft's Enhanced Cryptographic Provider
Contains functionality to delete services
Creates a process in suspended mode (likely to inject code)

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample has a GUI, but Joe Sandbox has not found any clickable buttons, likely more UI automation may extend behavior
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Sample searches for specific file, try point organization specific fake files to the analysis machine
  • System is w10x64_ra
  • astx_setup.exe (PID: 6348 cmdline: C:\Users\user\Desktop\astx_setup.exe MD5: 7DD75B2C2E214C0347DF3DC137161B19)
    • cmd.exe (PID: 6456 cmdline: C:\Windows\system32\cmd.exe /C "ECHO Y| cacls C:\Users\user\AppData\Local\Temp\asfB6FB.tmp /s:D:PAI(A;;FA;;;BA)" MD5: 4943BA1A9B41D69643F69685E35B2943)
      • conhost.exe (PID: 6464 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
      • cmd.exe (PID: 6512 cmdline: C:\Windows\system32\cmd.exe /S /D /c" ECHO Y" MD5: 4943BA1A9B41D69643F69685E35B2943)
      • cacls.exe (PID: 6524 cmdline: cacls C:\Users\user\AppData\Local\Temp\asfB6FB.tmp /s:D:PAI(A;;FA;;;BA) MD5: B304B0EF47E125F696425BD99096D3E3)
    • V3Medic.exe (PID: 6624 cmdline: "C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exe" MD5: F4116873D9C057697783C2C128708617)
      • SysX64.exe (PID: 7156 cmdline: C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\SysX64.exe MD5: 9005E21833E657558F139A3D3945C97D)
        • conhost.exe (PID: 7164 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
      • SysX64.exe (PID: 6204 cmdline: C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\SysX64.exe MD5: 9005E21833E657558F139A3D3945C97D)
        • conhost.exe (PID: 6180 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
C:\Program Files\AhnLab\Safe Transaction\medvpdrv.sysJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
    C:\Program Files\AhnLab\Safe Transaction\medvpdrv.sysJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
      SourceRuleDescriptionAuthorStrings
      00000000.00000002.2413738502.0000000000768000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_GuLoader_3Yara detected GuLoaderJoe Security
        Process Memory Space: astx_setup.exe PID: 6348JoeSecurity_GuLoader_3Yara detected GuLoaderJoe Security
          Process Memory Space: V3Medic.exe PID: 6624JoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
            No Sigma rule has matched
            No Snort rule has matched

            Click to jump to signature section

            Show All Signature Results
            Source: 6.3.V3Medic.exe.5b54600.7.unpackAvira: Label: TR/Patched.Ren.Gen
            Source: 6.3.V3Medic.exe.5ab0000.5.unpackAvira: Label: TR/Patched.Ren.Gen7
            Source: 6.3.V3Medic.exe.6065a80.14.unpackAvira: Label: TR/Crypt.XPACK.Gen8
            Source: C:\Users\user\Desktop\astx_setup.exeCode function: 0_2_1007F680 CryptAcquireContextW,CryptGenRandom,CryptReleaseContext,CryptAcquireContextW,CryptGenRandom,CryptReleaseContext,0_2_1007F680

            Compliance

            barindex
            Source: astx_setup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeWindow detected: < BackI AgreeCancelAhnLab Installation System AhnLab Installation SystemLicense AgreementPlease review the license terms before installing AhnLab Safe Transaction.Press Page Down to see the rest of the agreement.AhnLab Software License AgreementIMPORTANT - READ CAREFULLY BEFORE USING AHNLAB SOFTWARE.This Software License Agreement (this Agreement) is a legal agreement by and between you and AhnLab Inc. (AhnLab) with regard to the use of the software as defined below (AhnLab Software). If you do not agree to be bound by this Agreement you shall not install copy or use AhnLab Software. 1. Definitions 1.1 AhnLab Software means the software that AhnLab develops or produces and holds the rights such as copyright ownership right etc. AhnLab Software may include computer software any media printed materials and online or electronic documents including but not limited to any and all executable files additional functions user manual help files and other files accompanying AhnLab Software. 1.2 Computer means information processors such as server computer user computer etc. that can transmit and receive information through connection with communication networks. 1.3 Appliance means products that AhnLab sells to customers as a separate form of products produced by installing AhnLab Software in hardware equipment. 1.4 Use refers to any and all acts of using AhnLab Software such as storing installing or executing AhnLab Software in the main or auxiliary memory of Computer CD-ROM or other storage devices or displaying AhnLab on the screen. 1.5 Supplier means a person such as its distributor or reseller who entered into a business partnership agreement with AhnLab with regard to the sales of AhnLab Software or has been officially authorized by AhnLab to sell AhnLab Software. 1.6 You or Customer refers to you as a group or an individual that has entered into an agreement with AhnLab or the Supplier for the license to use AhnLab Software (the Purchase Agreement). 1.7 Commercial Product refers to AhnLab Software that AhnLab or the Supplier sells with charges. 1.8 Free Product refers to AhnLab Software that AhnLab or the Supplier provides free of charges. 2. Software License2.1 Restricted License: Subject to your consent to the terms and conditions of this Agreement AhnLab grants the non-exclusive and non-transferrable license to use AhnLab Software during the term of the license (in case of Commercial Product the term set forth in Purchase Agreement and in case of Free Product the term during which AhnLab Software is available for free).2.2 Scope of License: If you are a purchaser of Commercial Product you may install and use as many copies of AhnLab Software as you have agreed to use under the license from AhnLab or the Supplier. If you (i) execute the process of configuration or installation of this Software in a physical and/or virtual environment or (ii) make all or part of the existing instance run on a separate memory through for ex
            Source: C:\Users\user\Desktop\astx_setup.exeFile created: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\License_en_US.txtJump to behavior
            Source: C:\Users\user\Desktop\astx_setup.exeFile created: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\License_ko_kr.txtJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeFile created: C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\license.txtJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeFile created: C:\Program Files\AhnLab\Safe Transaction\license.txtJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeFile opened: C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\msvcr90.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLabJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe TransactionJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\DBJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\DefPlyJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\TempJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\ResourceJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\defaultJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\imageJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\tableJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\en_usJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\en_us\imageJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\en_us\tableJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\MUpdate2Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\SDKJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\SDK\AKJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\NetRuleJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\LogJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\CertJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nssJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\AHCJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\AHC\X86Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\AHC\X64Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\SDK\AK\x64Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\QuarantineJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\MUpdate2\ASDTEMPJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\MeDJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\MeD\DefinitionJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\SDK\AK\Microsoft.VC90.CRT.manifestJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\license.txtJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\drvinfo_astx.iniJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\DB\defcfg.dbJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\DB\ipcntry.dbJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\DB\nzcmncfg.dbJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\DB\nzdefcfg.dbJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\AHC\X86\msvcp90.dll.ahcJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\AHC\X64\msvcp90.dll.ahcJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\AHC\X86\msvcr90.dll.ahcJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\AHC\X64\msvcr90.dll.ahcJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\AHC\product.dat.ahcJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\mupdate2.cfgJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Product.datJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\V3Prtect.datJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\ca.derJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\ca2.derJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\astx.infJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\NetRule\tnnipprt.rulJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\NetRule\tnnipsig.rulJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\aos.sldJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\SDK\AK\aspinfo.uiJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\DefPly\extraopn_ply.uiJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\DefPly\netizen_ply_default.uiJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\DefPly\ply_ver.uiJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\DefPly\starter_ply.uiJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\certutil.exeJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\certutil_.exeJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\V3Medic.exeJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\certadm.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\freebl3.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\libnspr4.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\libplc4.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\libplds4.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90CHS.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90CHT.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90DEU.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90ENU.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90ESN.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90ESP.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90FRA.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90ITA.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90JPN.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90KOR.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\SDK\AK\mkd25def.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\SDK\AK\mkd25sdk.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\msvcr100.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\SDK\AK\msvcr90.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\nss3.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\nssckbi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\nssdbm3.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\nssutil3.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\smime3.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\softokn3.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\sqlite3.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Cert\nss\ssl3.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_default.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_disable.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_focus_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_focus_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_focus_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_over.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_press_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_press_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_press_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_default_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_default_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_default_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_disable.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_disable_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_disable_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focused_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focused_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focused_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focus_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focus_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focus_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_over_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_over_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_over_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_press_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_press_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_press_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_close_h.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_close_n.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_close_p.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_focused_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_focused_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_focused_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_normal_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_normal_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_normal_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_over_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_over_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_over_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_press_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_press_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_press_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_help_h.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_help_n.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_help_p.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_minimize_h.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_minimize_n.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_minimize_p.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_next_dafault.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_next_dim.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_next_focus.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_next_over.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_next_pressed.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_pre_dafault.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_pre_dim.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_pre_focus.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_pre_over.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_pre_pressed.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_disable_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_disable_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_disable_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_normal_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_normal_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_normal_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_over_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_over_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_over_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_press_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_press_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_press_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_info_f.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_info_h.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_info_n.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_info_p.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_left_h.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_left_n.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_left_p.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_mid_h.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_mid_n.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_mid_p.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_right_h.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_right_n.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_right_p.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\b_bg_bottom_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\b_bg_bottom_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\b_bg_top_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\b_bg_top_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\checkboxes.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\custom_logo.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\help_btn_focus.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\help_btn_hover.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\help_btn_normal.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\help_btn_pressed.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_firewall.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_log_viewer.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_message_complete.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_message_error.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_message_info.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_message_warning.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_on.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_product_tray.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_quarantine.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_scan.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_scan_complete.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_scan_detect.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_setting.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_stx_info.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_tray_alert.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_tray_complete.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_cr_default.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_cr_disable.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_ff_default.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_ff_disable.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_ie_default.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_ie_disable.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_shel_check.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\img_listctrl_header.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\img_popup_titlebar.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\scan_ico_safe.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\scan_ico_warning.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_line.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_normal_bg.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_normal_line.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_over_bg.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_over_line.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_selected_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_selected_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_sel_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_sel_mid.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_sel_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_unselected_left.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_unselected_right.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\title_logo.bmpJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exeDirectory created: C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\title_logo_about.bmpJump to behavior
            Source: astx_setup.exeStatic PE information: certificate valid
            Source: astx_setup.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: Binary string: AhnRghNt.pdb source: V3Medic.exe, 00000006.00000003.2204584934.000000000062D000.00000004.00000020.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.2270494586.0000000006597000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: u:\AhnLab\Common\WinFWMgr\Trunk\Build\X64Release.vc90\WinFWMgr.pdb source: V3Medic.exe, 00000006.00000003.1885537209.00000000039B0000.00000004.00001000.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.1963764220.0000000000629000.00000004.00000020.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.1855415087.0000000006012000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: u:\Product\AOS\SafeTransaction\1.0\Trunk\Build\X64Release\PdCfg.pdb source: V3Medic.exe, 00000006.00000003.1863999407.0000000006332000.00000004.00001000.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.1795673899.0000000000629000.00000004.00000020.00020000.00000000.sdmp
            Source: Binary string: u:\Project\Medicine\Framework\2.5\Trunk\Build\X64Release\Av.pdb source: V3Medic.exe, 00000006.00000003.2039114730.0000000003750000.00000004.00001000.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.2028561930.0000000006AB1000.00000004.00000800.00020000.00000000.sdmp
            Source: Binary string: u:\Product\AOS\SafeTransaction\1.0\Trunk\Build\X64Release\UpEx.pdb source: V3Medic.exe, 00000006.00000003.1838675962.0000000006AB1000.00000004.00000800.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.1848648986.0000000005D70000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: ATamptNt.pdb source: V3Medic.exe, 00000006.00000003.2220560883.0000000006AB1000.00000004.00000800.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.2270494586.0000000006597000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: U:\Build\X64Release.vc60\CdmCtrl.pdb source: V3Medic.exe, 00000006.00000003.2164525785.000000000062D000.00000004.00000020.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.2279453834.00000000067A9000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: d:\Build\Product\AOS\SafeTransaction\1.0\building\build\Product\AOS\SafeTransaction\1.0\Trunk\Src\AkSdk\Trunk\Build\Release\mkd25def.pdb source: V3Medic.exe, 00000006.00000003.1567514805.0000000000620000.00000004.00000020.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.1591414722.0000000005AB0000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: AHAWKENT.pdb source: V3Medic.exe, 00000006.00000003.2203334329.000000000062D000.00000004.00000020.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.2270494586.0000000006597000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: AMonTDLH.pdb source: V3Medic.exe, 00000006.00000003.2212897136.000000000062D000.00000004.00000020.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.2270494586.0000000006597000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: AMonTDnt.pdb source: V3Medic.exe, 00000006.00000003.2216027615.000000000062D000.00000004.00000020.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.2270494586.0000000006597000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: u:\Product\AOS\SafeTransaction\1.0\Trunk\Build\X64Release\StCtl32.pdb source: V3Medic.exe, 00000006.00000003.1872389829.0000000006605000.00000004.00001000.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.1817604204.0000000006AC0000.00000004.00000800.00020000.00000000.sdmp
            Source: Binary string: AMonCDw7.pdb source: V3Medic.exe, 00000006.00000003.2206061085.000000000062D000.00000004.00000020.00020000.00000000.sdmp, V3Medic.exe, 00000006.00000003.2270494586.0000000006597000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: U:\build\X64Release.vc60\AhnCtlKD.pdb source: V3Medic.exe, 00000006.00000003.2118726572.000000000062C000.00000004.00000020.00020000.00000000.sdmp
            Source: Binary string: u:\Product\AOS\SafeTransaction\1.0\Trunk\Build\X64Release\HsbCtl.pdb source: V3Medic.exe, 00000006.00000003.1746313302.0000000003A5E000.00000004.00000800.00020000.00000000.sdmp
            Source: Binary string: u:\Product\AOS\2.1\Trunk\Src\Common\aostrust\Trunk\Build\X64Release\aostrust32.pdb source: V3Medic.exe, 00000006.00000003.1754532060.0000000000627000.00000004.00000020.00020000.00000000.sdmp
            Source: Binary string: msvcm90.i386.pdb source: V3Medic.exe, 00000006.00000003.1941544747.0000000005E6A000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: u:\AhnLab\Common\AhnTrust\3.0\trunk\Build\X64Release.vc90\atstrumt.pdb source: V3Medic.exe, 00000006.00000003.2376704009.0000000006BB0000.00000004.00001000.00020000.00000000.sdmp
            Source: Binary string: u:\Product\AOS\SafeTransactio