IOC Report
astx_setup.exe

loading gif

Files

File Path
Type
Category
Malicious
astx_setup.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
initial sample
C:\Program Files\AhnLab\Safe Transaction\DB\defcfg.db
data
dropped
malicious
C:\Program Files\AhnLab\Safe Transaction\MeD\Definition\geo.asd
data
dropped
malicious
C:\Program Files\AhnLab\Safe Transaction\MeD\Definition\gof.dat
data
dropped
malicious
C:\Program Files\AhnLab\Safe Transaction\MeD\Definition\msg.dat
data
dropped
malicious
C:\Program Files\AhnLab\Safe Transaction\NetRule\tnnipsig.rul
data
dropped
malicious
C:\Program Files\AhnLab\Safe Transaction\V3Prtect.dat
data
dropped
malicious
C:\Program Files\AhnLab\Safe Transaction\medvpdrv.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\Engine\med_arm64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\Engine\med_com.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\Engine\med_nt32.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\Engine\med_x64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\ASTX_ARM64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\ASTX_Common.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\ASTX_Install_ARM64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\ASTX_Install_NT32.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\ASTX_Install_X64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\ASTX_NT32.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\ASTX_Res.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\ASTX_X64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Av_ARM64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Av_NT32.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Av_X64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Core_ARM64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Core_NT32.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Core_X64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Fw_ARM64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Fw_NT32.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Fw_X64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Ips_ARM64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Ips_NT32.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Ips_X64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Mdp_ARM64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Mdp_NT32.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Mdp_X64.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\Update.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\asdahc.nz
7-zip archive data, version 0.3
dropped
malicious
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\V3Prtect.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\defcfg.db
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\geo.asd
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\gof.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\msg.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tnnipsig.rul
data
dropped
malicious
C:\Program Files\AhnLab\Safe Transaction\AHAWKE.DLL
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\AHAWKENT.SYS
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\Ark32.dll.ahc
Microsoft Cabinet archive data, single, 172 bytes, 1 file, at 0x44 +AX "Ark32.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\Ark32lgplv2.dll.ahc
Microsoft Cabinet archive data, single, 178 bytes, 1 file, at 0x44 +AX "Ark32lgplv2.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\Ark64.dll.ahc
Microsoft Cabinet archive data, single, 172 bytes, 1 file, at 0x44 +AX "Ark64.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\Ark64a.dll.ahc
Microsoft Cabinet archive data, single, 173 bytes, 1 file, at 0x44 +AX "Ark64a.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\Ark64algplv2.dll.ahc
Microsoft Cabinet archive data, single, 179 bytes, 1 file, at 0x44 +AX "Ark64algplv2.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\Ark64lgplv2.dll.ahc
Microsoft Cabinet archive data, single, 178 bytes, 1 file, at 0x44 +AX "Ark64lgplv2.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\X64\msvcp90.dll.ahc
Microsoft Cabinet archive data, single, 150 bytes, 1 file, at 0x44 +AX "msvcp90.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\X64\msvcr90.dll.ahc
Microsoft Cabinet archive data, single, 150 bytes, 1 file, at 0x44 +AX "msvcr90.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\X86\msvcp90.dll.ahc
Microsoft Cabinet archive data, single, 150 bytes, 1 file, at 0x44 +AX "msvcp90.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\X86\msvcr90.dll.ahc
Microsoft Cabinet archive data, single, 150 bytes, 1 file, at 0x44 +AX "msvcr90.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\asdf.sld.ahc
Microsoft Cabinet archive data, single, 171 bytes, 1 file, at 0x44 +AX "asdf.sld.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\asdsr.dat.ahc
Microsoft Cabinet archive data, single, 172 bytes, 1 file, at 0x44 +AX "asdsr.dat.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\ckwcfg.dat.ahc
Microsoft Cabinet archive data, single, 173 bytes, 1 file, at 0x44 +AX "ckwcfg.dat.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\drvinfo.ini.ahc
Microsoft Cabinet archive data, single, 174 bytes, 1 file, at 0x44 +AX "drvinfo.ini.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AHC\product.dat.ahc
Microsoft Cabinet archive data, single, 150 bytes, 1 file, at 0x44 +AX "product.dat.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\AKDVE.EXE
PE32+ executable (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ALWFCtrl.Dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\AMonLWLH.cat
data
dropped
C:\Program Files\AhnLab\Safe Transaction\AMonLWLH.inf
Windows setup INFormation
dropped
C:\Program Files\AhnLab\Safe Transaction\AMonLWLH.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ASDCli.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ASDCr.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ASDSvc.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ASDUp.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ASDWsc.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ASDi.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ATampt.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ATamptNt.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\AhnCtlKD.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\AhnI2.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Ark64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Ark64lgplv2.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\AtamptU.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\AupASD.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Av.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\BldInfo.ini
ASCII text, with CRLF line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\BtScnCtl.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\CdmAPI.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\CdmCtrl.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\astx.inf
Windows setup INFormation
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\ca.der
Certificate, Version=3, Serial=00d01329e89a358cfe, not-valid-before=2015-06-18 04:03:23 GMT, not-valid-after=2038-06-12 04:03:23 GMT
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\ca2.der
Certificate, Version=3, Serial=009c786262fd7479bd, not-valid-before=2015-06-18 04:03:24 GMT, not-valid-after=2038-06-12 04:03:24 GMT
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\certadm.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\certutil_.exe
PE32 executable (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\certutil.exe
PE32 executable (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\freebl3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\libnspr4.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\libplc4.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\libplds4.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\msvcr100.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\nss3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\nssckbi.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\nssdbm3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\nssutil3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\smime3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\softokn3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\sqlite3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Cert\nss\ssl3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Core.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\DB\ipcntry.db
SQLite 3.x database, last written using SQLite version 3014002, file counter 2, database pages 1127, cookie 0x1, schema 4, UTF-8, version-valid-for 2
dropped
C:\Program Files\AhnLab\Safe Transaction\DB\nzcmncfg.db
data
dropped
C:\Program Files\AhnLab\Safe Transaction\DB\nzdefcfg.db
data
dropped
C:\Program Files\AhnLab\Safe Transaction\DefPly\extraopn_ply.ui
Microsoft Cabinet archive data, single, 90334 bytes, 1 file, at 0x44 +AX "extraopn_ply.html.new", flags 0x4, number 1, extra bytes 20 in head, 3 datablocks, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\DefPly\netizen_ply_default.ui
Microsoft Cabinet archive data, single, 7101 bytes, 1 file, at 0x44 +AX "netizen_ply_default.html.new", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\DefPly\ply_ver.ui
Microsoft Cabinet archive data, single, 137 bytes, 1 file, at 0x44 +AX "ply_ver.html.new", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\DefPly\starter_ply.ui
Microsoft Cabinet archive data, single, 326717 bytes, 1 file, at 0x44 +AX "starter_ply.html.new", flags 0x4, number 1, extra bytes 20 in head, 10 datablocks, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\HsbCtl.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\IAccessible2Proxy.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MFC90CHS.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MFC90CHT.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MFC90DEU.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MFC90ENU.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MFC90ESN.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MFC90ESP.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MFC90FRA.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MFC90ITA.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MFC90JPN.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MFC90KOR.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MUpdate2\Microsoft.VC90.CRT.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1506), with CRLF line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\MUpdate2\msvcp90.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MUpdate2\msvcr90.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MeD\Definition\libcrypto-1_1-x64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\MeD\Definition\mdp.scd
data
dropped
C:\Program Files\AhnLab\Safe Transaction\MeD\Definition\uh.dat
data
dropped
C:\Program Files\AhnLab\Safe Transaction\MeD\Definition\wlist.asd
data
dropped
C:\Program Files\AhnLab\Safe Transaction\Microsoft.VC90.CRT.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1506), with CRLF line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\Microsoft.VC90.MFC.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (2003), with CRLF line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\NetRule\tnnipprt.rul
data
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\AhnI2.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\HsbCtl32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\IAccessible2Proxy32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90CHS.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90CHT.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90DEU.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90ENU.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90ESN.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90ESP.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90FRA.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90ITA.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90JPN.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\MFC90KOR.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\Microsoft.VC90.CRT.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1506), with CRLF line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\Microsoft.VC90.MFC.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (2003), with CRLF line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\NzBrcom32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\NzInst32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\ScrMon32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\StCtl32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\StSdk32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\StSess32.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\aostrust32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\libacm.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\mfc90u.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\msvcp90.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\msvcr90.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Nz32\powapi32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\NzBrcom.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\NzInst.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\NzPlugin.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\PdCfg.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\Product.dat
data
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ASTX10_ico.ico
MS Windows icon resource - 7 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, -128x-128, 32 bits/pixel
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\b_bg_bottom_left.bmp
PC bitmap, Windows 3.x format, 10 x 3 x 24, image size 98, resolution 2834 x 2834 px/m, cbSize 152, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\b_bg_bottom_right.bmp
PC bitmap, Windows 3.x format, 10 x 3 x 24, image size 98, resolution 2834 x 2834 px/m, cbSize 152, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\b_bg_top_left.bmp
PC bitmap, Windows 3.x format, 10 x 3 x 24, image size 98, resolution 2834 x 2834 px/m, cbSize 152, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\b_bg_top_right.bmp
PC bitmap, Windows 3.x format, 10 x 3 x 24, image size 98, resolution 2834 x 2834 px/m, cbSize 152, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_default.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_disable.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_focus_left.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_focus_mid.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_focus_right.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_over.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_press_left.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_press_mid.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_b_press_right.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_default_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_default_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_default_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_disable.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_disable_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_disable_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focus_left.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focus_mid.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focus_right.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focused_left.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focused_mid.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_focused_right.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_over_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_over_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_over_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_press_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_press_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_basic_w_press_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_close_h.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_close_n.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_close_p.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_focused_left.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_focused_mid.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_focused_right.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_normal_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_normal_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_normal_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_over_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_over_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_over_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_press_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_press_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_default_press_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_help_h.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_help_n.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_help_p.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_minimize_h.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_minimize_n.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_minimize_p.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_next_dafault.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_next_dim.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_next_focus.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_next_over.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_next_pressed.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_pre_dafault.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_pre_dim.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_pre_focus.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_pre_over.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_pre_pressed.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_disable_left.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_disable_mid.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_disable_right.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_normal_left.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_normal_mid.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_normal_right.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_over_left.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_over_mid.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_over_right.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_press_left.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_press_mid.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_setting_press_right.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_info_f.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_info_h.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_info_n.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_info_p.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_left_h.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_left_n.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_left_p.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_mid_h.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_mid_n.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_mid_p.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_right_h.bmp
PC bitmap, Windows 3.x format, 22 x 33 x 24, image size 2246, resolution 2834 x 2834 px/m, cbSize 2300, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_right_n.bmp
PC bitmap, Windows 3.x format, 22 x 33 x 24, image size 2246, resolution 2834 x 2834 px/m, cbSize 2300, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\btn_web_link_right_p.bmp
PC bitmap, Windows 3.x format, 22 x 33 x 24, image size 2246, resolution 2834 x 2834 px/m, cbSize 2300, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\checkboxes.bmp
PC bitmap, Windows 3.x format, 48 x 16 x 8, image size 768, cbSize 1846, bits offset 1078
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\custom_logo.bmp
PC bitmap, Windows 3.x format, 142 x 21 x 24, image size 8990, resolution 2834 x 2834 px/m, cbSize 9044, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\help_btn_focus.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\help_btn_hover.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\help_btn_normal.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\help_btn_pressed.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_cr_default.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_cr_disable.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_ff_default.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_ff_disable.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_ie_default.bmp
PC bitmap, Windows 3.x format, 26 x 25 x 24, image size 2002, resolution 2834 x 2834 px/m, cbSize 2056, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_browser_ie_disable.bmp
PC bitmap, Windows 3.x format, 26 x 25 x 24, image size 2002, resolution 2834 x 2834 px/m, cbSize 2056, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\ico_shel_check.bmp
PC bitmap, Windows 3.x format, 16 x 16 x 24, image size 770, resolution 2834 x 2834 px/m, cbSize 824, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_firewall.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_log_viewer.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_message_complete.bmp
PC bitmap, Windows 3.x format, 36 x 41 x 24, image size 4430, resolution 2834 x 2834 px/m, cbSize 4484, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_message_error.bmp
PC bitmap, Windows 3.x format, 36 x 41 x 24, image size 4430, resolution 2834 x 2834 px/m, cbSize 4484, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_message_info.bmp
PC bitmap, Windows 3.x format, 36 x 41 x 24, image size 4430, resolution 2834 x 2834 px/m, cbSize 4484, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_message_warning.bmp
PC bitmap, Windows 3.x format, 36 x 41 x 24, image size 4430, resolution 2834 x 2834 px/m, cbSize 4484, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_on.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_product_tray.bmp
PC bitmap, Windows 3.x format, 74 x 83 x 32, image size 24570, resolution 2834 x 2834 px/m, cbSize 24624, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_quarantine.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_scan.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_scan_complete.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_scan_detect.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_setting.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_stx_info.bmp
PC bitmap, Windows 3.x format, 44 x 49 x 24, image size 6470, resolution 2834 x 2834 px/m, cbSize 6524, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_tray_alert.bmp
PC bitmap, Windows 3.x format, 25 x 27 x 24, image size 2054, resolution 2834 x 2834 px/m, cbSize 2108, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\icon_tray_complete.bmp
PC bitmap, Windows 3.x format, 25 x 27 x 32, image size 2702, resolution 2834 x 2834 px/m, cbSize 2756, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\img_listctrl_header.bmp
PC bitmap, Windows 3.x format, 1 x 12 x 24, image size 48, resolution 3780 x 3780 px/m, cbSize 102, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\img_popup_titlebar.bmp
PC bitmap, Windows 3.x format, 5 x 22 x 24, image size 354, resolution 2834 x 2834 px/m, cbSize 408, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\scan_ico_safe.bmp
PC bitmap, Windows 3.x format, 24 x 24 x 24, image size 1730, resolution 2834 x 2834 px/m, cbSize 1784, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\scan_ico_warning.bmp
PC bitmap, Windows 3.x format, 24 x 24 x 24, image size 1730, resolution 2834 x 2834 px/m, cbSize 1784, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_line.bmp
PC bitmap, Windows 3.x format, 10 x 28 x 24, image size 898, resolution 2834 x 2834 px/m, cbSize 952, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_normal_bg.bmp
PC bitmap, Windows 3.x format, 20 x 28 x 24, image size 1682, resolution 2834 x 2834 px/m, cbSize 1736, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_normal_line.bmp
PC bitmap, Windows 3.x format, 1 x 28 x 24, image size 114, resolution 2834 x 2834 px/m, cbSize 168, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_over_bg.bmp
PC bitmap, Windows 3.x format, 20 x 28 x 24, image size 1682, resolution 2834 x 2834 px/m, cbSize 1736, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_over_line.bmp
PC bitmap, Windows 3.x format, 1 x 28 x 24, image size 114, resolution 2834 x 2834 px/m, cbSize 168, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_sel_left.bmp
PC bitmap, Windows 3.x format, 20 x 28 x 24, image size 1682, resolution 2834 x 2834 px/m, cbSize 1736, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_sel_mid.bmp
PC bitmap, Windows 3.x format, 20 x 28 x 24, image size 1682, resolution 2834 x 2834 px/m, cbSize 1736, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_sel_right.bmp
PC bitmap, Windows 3.x format, 20 x 28 x 24, image size 1682, resolution 2834 x 2834 px/m, cbSize 1736, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_selected_left.bmp
PC bitmap, Windows 3.x format, 5 x 35 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_selected_right.bmp
PC bitmap, Windows 3.x format, 5 x 35 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_unselected_left.bmp
PC bitmap, Windows 3.x format, 5 x 35 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\tab_unselected_right.bmp
PC bitmap, Windows 3.x format, 5 x 35 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\title_logo.bmp
PC bitmap, Windows 3.x format, 142 x 11 x 24, image size 4710, resolution 2834 x 2834 px/m, cbSize 4764, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\title_logo_about.bmp
PC bitmap, Windows 3.x format, 251 x 16 x 24, image size 12098, resolution 2834 x 2834 px/m, cbSize 12152, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\image\warning_icon.bmp
PC bitmap, Windows 3.x format, 47 x 40 x 24, image size 5762, resolution 2834 x 2834 px/m, cbSize 5816, bits offset 54
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\default\table\V3ISStr.atb
data
dropped
C:\Program Files\AhnLab\Safe Transaction\Resource\en_us\table\V3ISStr.atb
data
dropped
C:\Program Files\AhnLab\Safe Transaction\SCTX.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\Microsoft.VC90.CRT.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1506), with CRLF line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\aspinfo.ui
ASCII text, with no line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\mkd25.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\mkd25def.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\mkd25sdk.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\msvcr90.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\x64\Microsoft.VC90.CRT.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1506), with CRLF line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\x64\mkd25.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\x64\mkd2564.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\x64\mkd25def64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\x64\mkd25sdk64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\x64\msvcr90.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\StCli.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\StCtInst.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\StCtl.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\StSdk.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\StSess.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\StSvr.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\TFFREGNT.SYS
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\TNNetUtil.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\TSFltCtl.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\TSFltDrv.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\UpEx.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\V3Cert.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\V3ElamCt.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\V3Medic.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
C:\Program Files\AhnLab\Safe Transaction\WinFWMgr.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ahloha.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ambassmt.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\aos.sld
data
dropped
C:\Program Files\AhnLab\Safe Transaction\aostrust.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\arklicense.txt
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\asc_main.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\asdf.sld
data
dropped
C:\Program Files\AhnLab\Safe Transaction\asdsr.dat
data
dropped
C:\Program Files\AhnLab\Safe Transaction\astxverify64.dac
Microsoft Cabinet archive data, single, 4213 bytes, 1 file, at 0x44 +A "astxverify64.daf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Program Files\AhnLab\Safe Transaction\atstrust.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\ckwcfg.dat
data
dropped
C:\Program Files\AhnLab\Safe Transaction\drvinfo_astx.ini
Generic INItialization configuration [CKW]
dropped
C:\Program Files\AhnLab\Safe Transaction\libacm.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\license.txt
ASCII text, with CRLF line terminators
dropped
C:\Program Files\AhnLab\Safe Transaction\medcore.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\medcored.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\medext.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\medvphkd.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\medvphku.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\medvphkuw6.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\mfc90u.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\msvcp90.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\msvcr90.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\mupdate2.cfg
data
dropped
C:\Program Files\AhnLab\Safe Transaction\powapi.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\trueeyesu.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files\AhnLab\Safe Transaction\tsmime.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\ProgramData\AhnLab\AIS\SafeTransaction\AhnI2.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\ProgramData\AhnLab\AIS\SafeTransaction\BldInfo.ini
ASCII text, with CRLF line terminators
dropped
C:\ProgramData\AhnLab\AIS\SafeTransaction\Microsoft.VC90.CRT.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1506), with CRLF line terminators
dropped
C:\ProgramData\AhnLab\AIS\SafeTransaction\Microsoft.VC90.MFC.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (2003), with CRLF line terminators
dropped
C:\ProgramData\AhnLab\AIS\SafeTransaction\NzInst.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\ProgramData\AhnLab\AIS\SafeTransaction\mfc90u.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\ProgramData\AhnLab\AIS\SafeTransaction\msvcm90.dll
PE32+ executable (DLL) (GUI) x86-64 Mono/.Net assembly, for MS Windows
dropped
C:\ProgramData\AhnLab\AIS\SafeTransaction\msvcp90.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\ProgramData\AhnLab\AIS\SafeTransaction\msvcr90.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\AhnSec.dat
data
dropped
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\BldInfo.ini
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\License_en_US.txt
Unicode text, UTF-16, little-endian text, with very long lines (1245), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\License_ko_kr.txt
Unicode text, UTF-16, little-endian text, with very long lines (653), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\astxverify32.dac
Microsoft Cabinet archive data, single, 3382 bytes, 1 file, at 0x44 +A "astxverify32.daf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\astxverify64.dac
Microsoft Cabinet archive data, single, 4213 bytes, 1 file, at 0x44 +A "astxverify64.daf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\_Setup\astxverifyarm64.dac
Microsoft Cabinet archive data, single, 354 bytes, 1 file, at 0x44 +A "astxverifyarm64.daf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
modified
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\AI7z20.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\AIS_PageProgramMaintenance.ini
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\AIS_PageUnConfirm.ini
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\AhnI2t.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\AhnIEx.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\InstallOptions.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\NSIS.cat
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\SysARM64.exe
PE32+ executable (console) Aarch64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\SysX64.exe
PE32+ executable (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\System.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AHAWKE.DLL
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AHAWKENT.SYS
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AKDVE.EXE
PE32+ executable (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ALWFCtrl.Dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AMonCDW7.sys
PE32+ executable (DLL) (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AMonCDW8.sys
PE32+ executable (DLL) (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AMonHKnt.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AMonLWLH.cat
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AMonLWLH.inf
Windows setup INFormation
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AMonLWLH.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AMonTDLH.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AMonTDnt.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ASDCli.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ASDCr.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ASDSvc.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ASDUp.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ASDWsc.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ASDi.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ASTX10_ico.ico
MS Windows icon resource - 7 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, -128x-128, 32 bits/pixel
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ATampt.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ATamptNt.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AhnCtlKD.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AhnI2.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AhnRghNt.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Ark32.dll.ahc
Microsoft Cabinet archive data, single, 172 bytes, 1 file, at 0x44 +AX "Ark32.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Ark32lgplv2.dll.ahc
Microsoft Cabinet archive data, single, 178 bytes, 1 file, at 0x44 +AX "Ark32lgplv2.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Ark64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Ark64.dll.ahc
Microsoft Cabinet archive data, single, 172 bytes, 1 file, at 0x44 +AX "Ark64.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Ark64a.dll.ahc
Microsoft Cabinet archive data, single, 173 bytes, 1 file, at 0x44 +AX "Ark64a.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Ark64algplv2.dll.ahc
Microsoft Cabinet archive data, single, 179 bytes, 1 file, at 0x44 +AX "Ark64algplv2.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Ark64lgplv2.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Ark64lgplv2.dll.ahc
Microsoft Cabinet archive data, single, 178 bytes, 1 file, at 0x44 +AX "Ark64lgplv2.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AtamptU.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\AupASD.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Av.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\BtScnCtl.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Cdm2DrNt.sys
PE32+ executable (DLL) (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\CdmAPI.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\CdmCtrl.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Core.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\HsbCtl.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\HsbCtl32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\HsbDrv64.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\IAccessible2Proxy.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\IAccessible2Proxy32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\MFC90CHS.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\MFC90CHT.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\MFC90DEU.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\MFC90ENU.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\MFC90ESN.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\MFC90ESP.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\MFC90FRA.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\MFC90ITA.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\MFC90JPN.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\MFC90KOR.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Microsoft.VC90.CRT.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1506), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Microsoft.VC90.MFC.manifest
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (2003), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Mkd2Nadr.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Mkd2bthf.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\NzBrcom.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\NzBrcom32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\NzInst.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\NzInst32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\NzPlugin.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\PdCfg.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\Product.dat
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\SCTX.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ScrMon32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\StCli.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\StCtInst.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\StCtl.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\StCtl32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\StSdk.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\StSdk32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\StSess.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\StSess32.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\StSvr.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\TFFREGNT.SYS
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\TNNetUtil.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\TSFltCtl.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\TSFltDrv.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\UpEx.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\V3Cert.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\V3ElamCt.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\V3ElamDr.cat
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\V3ElamDr.inf
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\V3ElamDr.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\V3ISStr.atb
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\V3Medic.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\WinFWMgr.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ahloha.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ambassmt.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\aos.sld
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\aostrust.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\aostrust32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\arklicense.txt
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\asc_main.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\asdf.sld
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\asdf.sld.ahc
Microsoft Cabinet archive data, single, 171 bytes, 1 file, at 0x44 +AX "asdf.sld.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\asdsr.dat
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\asdsr.dat.ahc
Microsoft Cabinet archive data, single, 172 bytes, 1 file, at 0x44 +AX "asdsr.dat.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\aspinfo.ui
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\astx.inf
Windows setup INFormation
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\atstrust.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\b_bg_bottom_left.bmp
PC bitmap, Windows 3.x format, 10 x 3 x 24, image size 98, resolution 2834 x 2834 px/m, cbSize 152, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\b_bg_bottom_right.bmp
PC bitmap, Windows 3.x format, 10 x 3 x 24, image size 98, resolution 2834 x 2834 px/m, cbSize 152, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\b_bg_top_left.bmp
PC bitmap, Windows 3.x format, 10 x 3 x 24, image size 98, resolution 2834 x 2834 px/m, cbSize 152, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\b_bg_top_right.bmp
PC bitmap, Windows 3.x format, 10 x 3 x 24, image size 98, resolution 2834 x 2834 px/m, cbSize 152, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_b_default.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_b_disable.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_b_focus_left.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_b_focus_mid.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_b_focus_right.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_b_over.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_b_press_left.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_b_press_mid.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_b_press_right.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_default_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_default_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_default_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_disable.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_disable_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_disable_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_focus_left.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_focus_mid.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_focus_right.bmp
PC bitmap, Windows 3.x format, 5 x 37 x 24, image size 594, resolution 2834 x 2834 px/m, cbSize 648, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_focused_left.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_focused_mid.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_focused_right.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_over_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_over_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_over_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_press_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_press_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_basic_w_press_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_close_h.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_close_n.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_close_p.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_focused_left.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_focused_mid.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_focused_right.bmp
PC bitmap, Windows 3.x format, 6 x 28 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_normal_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_normal_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_normal_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_over_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_over_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_over_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_press_left.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_press_mid.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_default_press_right.bmp
PC bitmap, Windows 3.x format, 5 x 28 x 24, image size 450, resolution 2834 x 2834 px/m, cbSize 504, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_help_h.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_help_n.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_help_p.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_minimize_h.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_minimize_n.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_minimize_p.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_next_dafault.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_next_dim.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_next_focus.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_next_over.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_next_pressed.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_pre_dafault.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_pre_dim.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_pre_focus.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_pre_over.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_pre_pressed.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_disable_left.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_disable_mid.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_disable_right.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_normal_left.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_normal_mid.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_normal_right.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_over_left.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_over_mid.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_over_right.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_press_left.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_press_mid.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_setting_press_right.bmp
PC bitmap, Windows 3.x format, 15 x 22 x 24, image size 1058, resolution 2834 x 2834 px/m, cbSize 1112, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_info_f.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_info_h.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_info_n.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_info_p.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_left_h.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_left_n.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_left_p.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_mid_h.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_mid_n.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_mid_p.bmp
PC bitmap, Windows 3.x format, 15 x 33 x 24, image size 1586, resolution 2834 x 2834 px/m, cbSize 1640, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_right_h.bmp
PC bitmap, Windows 3.x format, 22 x 33 x 24, image size 2246, resolution 2834 x 2834 px/m, cbSize 2300, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_right_n.bmp
PC bitmap, Windows 3.x format, 22 x 33 x 24, image size 2246, resolution 2834 x 2834 px/m, cbSize 2300, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\btn_web_link_right_p.bmp
PC bitmap, Windows 3.x format, 22 x 33 x 24, image size 2246, resolution 2834 x 2834 px/m, cbSize 2300, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ca.der
Certificate, Version=3, Serial=00d01329e89a358cfe, not-valid-before=2015-06-18 04:03:23 GMT, not-valid-after=2038-06-12 04:03:23 GMT
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ca2.der
Certificate, Version=3, Serial=009c786262fd7479bd, not-valid-before=2015-06-18 04:03:24 GMT, not-valid-after=2038-06-12 04:03:24 GMT
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\certadm.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\certutil.exe
PE32 executable (console) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\certutil_.exe
PE32 executable (console) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\checkboxes.bmp
PC bitmap, Windows 3.x format, 48 x 16 x 8, image size 768, cbSize 1846, bits offset 1078
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ckwcfg.dat
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ckwcfg.dat.ahc
Microsoft Cabinet archive data, single, 173 bytes, 1 file, at 0x44 +AX "ckwcfg.dat.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\custom_logo.bmp
PC bitmap, Windows 3.x format, 142 x 21 x 24, image size 8990, resolution 2834 x 2834 px/m, cbSize 9044, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\drvinfo.ini.ahc
Microsoft Cabinet archive data, single, 174 bytes, 1 file, at 0x44 +AX "drvinfo.ini.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\drvinfo_astx.ini
Generic INItialization configuration [CKW]
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\extraopn_ply.ui
Microsoft Cabinet archive data, single, 90334 bytes, 1 file, at 0x44 +AX "extraopn_ply.html.new", flags 0x4, number 1, extra bytes 20 in head, 3 datablocks, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\freebl3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\help_btn_focus.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\help_btn_hover.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\help_btn_normal.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\help_btn_pressed.bmp
PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ico_browser_cr_default.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ico_browser_cr_disable.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ico_browser_ff_default.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ico_browser_ff_disable.bmp
PC bitmap, Windows 3.x format, 25 x 25 x 24, image size 1902, resolution 2834 x 2834 px/m, cbSize 1956, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ico_browser_ie_default.bmp
PC bitmap, Windows 3.x format, 26 x 25 x 24, image size 2002, resolution 2834 x 2834 px/m, cbSize 2056, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ico_browser_ie_disable.bmp
PC bitmap, Windows 3.x format, 26 x 25 x 24, image size 2002, resolution 2834 x 2834 px/m, cbSize 2056, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ico_shel_check.bmp
PC bitmap, Windows 3.x format, 16 x 16 x 24, image size 770, resolution 2834 x 2834 px/m, cbSize 824, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_firewall.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_log_viewer.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_message_complete.bmp
PC bitmap, Windows 3.x format, 36 x 41 x 24, image size 4430, resolution 2834 x 2834 px/m, cbSize 4484, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_message_error.bmp
PC bitmap, Windows 3.x format, 36 x 41 x 24, image size 4430, resolution 2834 x 2834 px/m, cbSize 4484, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_message_info.bmp
PC bitmap, Windows 3.x format, 36 x 41 x 24, image size 4430, resolution 2834 x 2834 px/m, cbSize 4484, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_message_warning.bmp
PC bitmap, Windows 3.x format, 36 x 41 x 24, image size 4430, resolution 2834 x 2834 px/m, cbSize 4484, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_on.bmp
PC bitmap, Windows 3.x format, 13 x 13 x 24, image size 522, resolution 2834 x 2834 px/m, cbSize 576, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_product_tray.bmp
PC bitmap, Windows 3.x format, 74 x 83 x 32, image size 24570, resolution 2834 x 2834 px/m, cbSize 24624, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_quarantine.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_scan.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_scan_complete.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_scan_detect.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_setting.bmp
PC bitmap, Windows 3.x format, 45 x 50 x 24, image size 6802, resolution 2834 x 2834 px/m, cbSize 6856, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_stx_info.bmp
PC bitmap, Windows 3.x format, 44 x 49 x 24, image size 6470, resolution 2834 x 2834 px/m, cbSize 6524, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_tray_alert.bmp
PC bitmap, Windows 3.x format, 25 x 27 x 24, image size 2054, resolution 2834 x 2834 px/m, cbSize 2108, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\icon_tray_complete.bmp
PC bitmap, Windows 3.x format, 25 x 27 x 32, image size 2702, resolution 2834 x 2834 px/m, cbSize 2756, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\img_listctrl_header.bmp
PC bitmap, Windows 3.x format, 1 x 12 x 24, image size 48, resolution 3780 x 3780 px/m, cbSize 102, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\img_popup_titlebar.bmp
PC bitmap, Windows 3.x format, 5 x 22 x 24, image size 354, resolution 2834 x 2834 px/m, cbSize 408, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ipcntry.db
SQLite 3.x database, last written using SQLite version 3014002, file counter 2, database pages 1127, cookie 0x1, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\klb64mkd.sig
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\klb64mkd.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\libacm.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\libcrypto-1_1-x64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\libnspr4.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\libplc4.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\libplds4.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\libssl-1_1-x64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
modified
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\license.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\mdp.scd
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\medcore.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\medcored.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\medext.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\medvpdrv.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\medvphkd.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\medvphku.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\medvphkuw6.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\mfc90u.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\mkd25.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\mkd2564.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\mkd25def.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\mkd25def64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\mkd25sdk.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\mkd25sdk64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\mkd3kfnt.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\msvcm90.dll
PE32+ executable (DLL) (GUI) x86-64 Mono/.Net assembly, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\msvcp90.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\msvcp90.dll.ahc
Microsoft Cabinet archive data, single, 150 bytes, 1 file, at 0x44 +AX "msvcp90.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\msvcr100.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\msvcr90.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\msvcr90.dll.ahc
Microsoft Cabinet archive data, single, 150 bytes, 1 file, at 0x44 +AX "msvcr90.dll.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\mupdate2.cfg
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\netizen_ply_default.ui
Microsoft Cabinet archive data, single, 7101 bytes, 1 file, at 0x44 +AX "netizen_ply_default.html.new", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\nss3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\nssckbi.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\nssdbm3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\nssutil3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\nzcmncfg.db
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\nzdefcfg.db
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ply_ver.ui
Microsoft Cabinet archive data, single, 137 bytes, 1 file, at 0x44 +AX "ply_ver.html.new", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\powapi.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\powapi32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\product.dat.ahc
Microsoft Cabinet archive data, single, 150 bytes, 1 file, at 0x44 +AX "product.dat.ahf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\scan_ico_safe.bmp
PC bitmap, Windows 3.x format, 24 x 24 x 24, image size 1730, resolution 2834 x 2834 px/m, cbSize 1784, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\scan_ico_warning.bmp
PC bitmap, Windows 3.x format, 24 x 24 x 24, image size 1730, resolution 2834 x 2834 px/m, cbSize 1784, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\smime3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\softokn3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\sqlite3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\ssl3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\starter_ply.ui
Microsoft Cabinet archive data, single, 326717 bytes, 1 file, at 0x44 +AX "starter_ply.html.new", flags 0x4, number 1, extra bytes 20 in head, 10 datablocks, 0 compression
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_line.bmp
PC bitmap, Windows 3.x format, 10 x 28 x 24, image size 898, resolution 2834 x 2834 px/m, cbSize 952, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_normal_bg.bmp
PC bitmap, Windows 3.x format, 20 x 28 x 24, image size 1682, resolution 2834 x 2834 px/m, cbSize 1736, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_normal_line.bmp
PC bitmap, Windows 3.x format, 1 x 28 x 24, image size 114, resolution 2834 x 2834 px/m, cbSize 168, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_over_bg.bmp
PC bitmap, Windows 3.x format, 20 x 28 x 24, image size 1682, resolution 2834 x 2834 px/m, cbSize 1736, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_over_line.bmp
PC bitmap, Windows 3.x format, 1 x 28 x 24, image size 114, resolution 2834 x 2834 px/m, cbSize 168, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_sel_left.bmp
PC bitmap, Windows 3.x format, 20 x 28 x 24, image size 1682, resolution 2834 x 2834 px/m, cbSize 1736, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_sel_mid.bmp
PC bitmap, Windows 3.x format, 20 x 28 x 24, image size 1682, resolution 2834 x 2834 px/m, cbSize 1736, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_sel_right.bmp
PC bitmap, Windows 3.x format, 20 x 28 x 24, image size 1682, resolution 2834 x 2834 px/m, cbSize 1736, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_selected_left.bmp
PC bitmap, Windows 3.x format, 5 x 35 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_selected_right.bmp
PC bitmap, Windows 3.x format, 5 x 35 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_unselected_left.bmp
PC bitmap, Windows 3.x format, 5 x 35 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tab_unselected_right.bmp
PC bitmap, Windows 3.x format, 5 x 35 x 24, image size 562, resolution 2834 x 2834 px/m, cbSize 616, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\title_logo.bmp
PC bitmap, Windows 3.x format, 142 x 11 x 24, image size 4710, resolution 2834 x 2834 px/m, cbSize 4764, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\title_logo_about.bmp
PC bitmap, Windows 3.x format, 251 x 16 x 24, image size 12098, resolution 2834 x 2834 px/m, cbSize 12152, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tnnipprt.rul
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\trueeyesu.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\tsmime.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\uh.dat
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\warning_icon.bmp
PC bitmap, Windows 3.x format, 47 x 40 x 24, image size 5762, resolution 2834 x 2834 px/m, cbSize 5816, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\e\wlist.asd
data
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\ioSpecial.ini
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\modern-header.bmp
PC bitmap, Windows 3.x format, 175 x 59 x 24, image size 31154, resolution 3778 x 3778 px/m, cbSize 31208, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\modern-wizard.bmp
PC bitmap, Windows 3.x format, 179 x 312 x 24, image size 168482, resolution 3778 x 3778 px/m, cbSize 168536, bits offset 54
dropped
C:\Users\user\AppData\Local\Temp\nslB5A3.tmp\AhnIEx.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nslB5A3.tmp\NSIS.cat
data
dropped
C:\Users\user\AppData\Local\Temp\nslB5A3.tmp\System.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nslB5A3.tmp\nsExec.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\AhnInst.log
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\Windows\System32\drivers\AMonCDW7.sys
PE32+ executable (DLL) (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\AMonCDW8.sys
PE32+ executable (DLL) (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\AMonHKnt.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\AMonLWLH.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\AMonTDLH.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\AMonTDnt.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\AhnRghNt.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\Cdm2DrNt.sys
PE32+ executable (DLL) (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\HsbDrv64.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\Mkd2Nadr.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\Mkd2bthf.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\V3ElamDr.cat
data
dropped
C:\Windows\System32\drivers\V3ElamDr.inf
ASCII text, with CRLF line terminators
dropped
C:\Windows\System32\drivers\V3ElamDr.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\klb64mkd.sig
data
dropped
C:\Windows\System32\drivers\klb64mkd.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
C:\Windows\System32\drivers\mkd3kfnt.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
There are 704 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\astx_setup.exe
C:\Users\user\Desktop\astx_setup.exe
malicious
C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exe
"C:\Users\user\AppData\Local\Temp\asfB6FB.tmp\V3Medic.exe"
malicious
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /C "ECHO Y| cacls C:\Users\user\AppData\Local\Temp\asfB6FB.tmp /s:D:PAI(A;;FA;;;BA)"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /S /D /c" ECHO Y"
C:\Windows\SysWOW64\cacls.exe
cacls C:\Users\user\AppData\Local\Temp\asfB6FB.tmp /s:D:PAI(A;;FA;;;BA)
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\SysX64.exe
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\SysX64.exe
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\SysX64.exe
C:\Users\user\AppData\Local\Temp\nsdE18B.tmp\SysX64.exe
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://fedir.comsign.co.il/crl/ComSignSecuredCA.crl0
unknown
http://crl.chambersign.org/chambersroot.crl0
unknown
https://gactivation.ahnlab.com/api/auth/v1/activate/relay
unknown
http://www.certifikat.dk/repository0
unknown
http://www.chambersign.org1
unknown
http://www.compression.ru/ds/
unknown
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
http://www.diginotar.nl/cps/pkioverheid0
unknown
http://www.pkioverheid.nl/policies/root-policy0
unknown
http://repository.swisssign.com/0
unknown
http://www.info-zip.org/pub/infozip/license.html.
unknown
https://jp.ahnlab.com/site/support/qna/qnaAddForm2.do;
unknown
https://mgactivation.ahnlab.com/api/auth/v1/activate/client
unknown
http://www.phreedom.org/md5)MD5
unknown
http://www.trustcenter.de/crl/v2/tc_class_3_ca_II.crl
unknown
http://ca.disig.sk/ca/crl/ca_disig.crl0
unknown
http://sourceforge.net/p/infozip/patches/18/
unknown
http://yuilibrary.com/license/
unknown
http://www.certplus.com/CRL/class2.crl0
unknown
http://www.disig.sk/ca/crl/ca_disig.crl0
unknown
http://www.sk.ee/cps/0
unknown
http://sourceforge.jp/projects/lha/
unknown
http://json.org/).
unknown
http://policy.camerfirma.com0
unknown
https://mgactivation.ahnlab.com/api/auth/v1/activate/relay
unknown
http://ocsp.pki.gva.es0
unknown
http://www.phreedom.org/md5)
unknown
http://crl.oces.certifikat.dk/oces.crl0
unknown
https://github.com/necolas/normalize.css/
unknown
http://www.certicamara.com/dpc/0Z
unknown
http://crl.pki.wellsfargo.com/wsprca.crl0
unknown
https://mgactivation.ahnlab.com/api/auth/v1/activate/relayhttps://mgactivation.ahnlab.com/api/auth/v
unknown
http://javascript.nwbox.com/IEContentLoaded/)
unknown
http://www.aescrypt.com/
unknown
http://nsis.sf.net/NSIS_ErrorError
unknown
http://broofa.com/
unknown
http://www.symauth.com/cps0(
unknown
http://acedicom.edicomgroup.com/doc0
unknown
http://mathiasbynens.be/
unknown
http://www.rarlab.com/rar_add.htm
unknown
https://code.bandisoft.com/
unknown
https://gactivation.ahnlab.com/api/auth/v1/healthcheck
unknown
https://opensource.ahnlab.com
unknown
http://www.entrust.net/CRL/net1.crl0
unknown
http://site.icu-project.org/
unknown
https://www.catcert.net/verarrel
unknown
http://www.disig.sk/ca0f
unknown
http://www.e-szigno.hu/RootCA.crl
unknown
http://www.symauth.com/rpa00
unknown
http://www.sk.ee/juur/crl/0
unknown
http://crl.chambersign.org/chambersignroot.crl0
unknown
http://crl.xrampsecurity.com/XGCA.crl0
unknown
http://www.7-zip.org/sdk.html
unknown
http://www.info-zip.org/
unknown
http://www.quovadis.bm0
unknown
https://github.com/wycats/handlebars.js
unknown
http://www.trustdst.com/certificates/policy/ACES-index.html0
unknown
http://www.firmaprofesional.com0
unknown
http://www.openssl.org/)
unknown
http://www.pkioverheid.nl/policies/root-policy-G20
unknown
https://mgactivation.ahnlab.com/api/auth/v1/healthcheck
unknown
https://www.netlock.net/docs
unknown
http://www.phreedom.org/md5)0
unknown
http://www.trustcenter.de/crl/v2/tc_class_2_ca_II.crl
unknown
http://crl.entrust.net/2048ca.crl0
unknown
http://gladman.plushost.co.uk/oldsite/AES/index.php
unknown
http://%1/CertEnroll/%1_%3%4.crtfile://
unknown
http://www.aarongifford.com/
unknown
http://crl.netsolssl.com/NetworkSolutionsCertificateAuthority.crl0
unknown
http://fedir.comsign.co.il/crl/ComSignCA.crl0
unknown
http://ocsp.sectigo.com0
unknown
http://ocsp.entrust.net03
unknown
http://cps.chambersign.org/cps/chambersroot.html0
unknown
http://www.firmaprofesional.com/cps0
unknown
http://%1/CertEnroll/%3%8%9.crlfile://
unknown
http://wakaba.c3.cx/s/apps/unarchiver.html
unknown
http://crl.securetrust.com/SGCA.crl0
unknown
http://tss-geotrust-crl.thawte.com/ThawteTimestampingCA.crl0
unknown
https://code.bandisoft.com
unknown
http://crl.securetrust.com/STCA.crl0
unknown
http://mozilla.org/MPL/2.0/.
unknown
http://www.bzip.org/downloads.html
unknown
http://download.ahnlab.com/down/ahnreport/AhnRpt.exe
unknown
http://crl.thawte.com/ThawteTimestampingCA.crl0
unknown
http://www.e-szigno.hu/RootCA.crt0
unknown
http://www.quovadisglobal.com/cps0
unknown
http://ncompress.sourceforge.net/
unknown
http://www.wavpack.com/
unknown
https://seed.kisa.or.kr/iwt/ko/sup/EgovLeaInfo.do
unknown
http://www.valicert.com/1
unknown
https://gactivation.ahnlab.com/api/auth/v1/activate/client
unknown
http://www.e-szigno.hu/SZSZ/0
unknown
https://%1/CertEnroll/nsrev_%3.aspldap:///CN=%7%8
unknown
https://github.com/wycats/handlebars.js)
unknown
https://ocsp.quovadisoffshore.com0
unknown
http://ocsp.entrust.net0D
unknown
http://www.winace.com/
unknown
http://cps.chambersign.org/cps/chambersignroot.html0
unknown
http://mattmahoney.net/dc/zpaq.html
unknown
http://www.zlib.net/zlib_license.html
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
webclinic.ahnlab.com.cdngc.net
101.79.212.66
gms.wip.ahnlab.com
34.249.110.217
webclinic.ahnlab.com
unknown
gms.ahnlab.com
unknown

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mkd2Nadr
ImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\klb64mkd.sig
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\HsbDrv64.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\klb64mkd.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\Mkd2bthf.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\Mkd2Nadr.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\mkd3kfnt.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\AhnLab\Safe Transaction\SDK\AK\mkd25.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\AhnLab\Safe Transaction\MUpdate2\Microsoft.VC90.CRT.manifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\AhnLab\Safe Transaction\MUpdate2\msvcr90.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\AhnLab\Safe Transaction\MUpdate2\msvcp90.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\AhnLab\Safe Transaction\BldInfo.ini
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\V3ElamDr.cat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\V3ElamDr.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\V3ElamDr.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\AhnRghNt.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\AMonCDW7.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\AMonCDW8.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\AMonHKnt.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\AMonLWLH.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\AMonTDLH.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\AMonTDnt.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\drivers\Cdm2DrNt.sys
There are 13 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
768000
heap
page read and write
malicious
26B98279000
heap
page read and write
2ED0000
heap
page read and write
6AB1000
trusted library allocation
page read and write
5F00000
trusted library allocation
page read and write
3436000
heap
page read and write
2844668B000
heap
page read and write
3F42000
trusted library allocation
page read and write
6AB1000
trusted library allocation
page read and write
3A1D000
trusted library allocation
page read and write
39B0000
direct allocation
page read and write
B24EA7E000
stack
page read and write
3F47000
trusted library allocation
page read and write
6AB1000
trusted library allocation
page read and write
26B98313000
heap
page read and write
3F41000
trusted library allocation
page read and write
18DF2C02000
trusted library allocation
page read and write
26B98242000
heap
page read and write
28E3F119000
heap
page read and write
6AEE000
trusted library allocation
page read and write
28446530000
heap
page read and write
28446651000
heap
page read and write
62D000
heap
page read and write
28446642000
heap
page read and write
485000
unkown
page readonly
6021000
direct allocation
page read and write
28446691000
heap
page read and write
14C000
stack
page read and write
5D5000
heap
page read and write
2EE5000
heap
page read and write
22220D40000
trusted library allocation
page read and write
8E8A69B000
stack
page read and write
5F9000
heap
page read and write
62B000
heap
page read and write
5DD000
stack
page read and write
6AB1000
trusted library allocation
page read and write
22220B50000
heap
page read and write
629000
heap
page read and write
620000
heap
page read and write
62D000
heap
page read and write
23D56330000
heap
page read and write
7AD247B000
stack
page read and write
62B000
heap
page read and write
40A000
unkown
page write copy
8E8AAFB000
stack
page read and write
5EA3000
direct allocation
page read and write
148000
stack
page read and write
148000
stack
page read and write
222213D9000
heap
page read and write
389A000
trusted library allocation
page read and write
62D000
heap
page read and write
3530000
trusted library allocation
page read and write
23D56380000
heap
page read and write
387D000
trusted library allocation
page read and write
B24E87C000
stack
page read and write
5F1000
heap
page read and write
1FBF000
stack
page read and write
38A9000
trusted library allocation
page read and write
620000
heap
page read and write
61D000
heap
page read and write
5AE0000
direct allocation
page read and write
23D56400000
heap
page read and write
6AB1000
trusted library allocation
page read and write
629000
heap
page read and write
3A17000
trusted library allocation
page read and write
38CE000
trusted library allocation
page read and write
26B9825C000
heap
page read and write
5F9C000
direct allocation
page read and write
28446668000
heap
page read and write
2170000
heap
page read and write
222212E1000
heap
page read and write
35F0000
direct allocation
page read and write
1015C000
unkown
page readonly
28446662000
heap
page read and write
620000
heap
page read and write
1017D000
unkown
page readonly
2EE4000
heap
page read and write
426000
unkown
page read and write
2844663E000
heap
page read and write
3750000
direct allocation
page read and write
3186000
heap
page read and write
22220C3E000
heap
page read and write
3A1C000
trusted library allocation
page read and write
5DE6000
direct allocation
page read and write
18DF2513000
heap
page read and write
35F0000
trusted library allocation
page read and write
39B0000
direct allocation
page read and write
38BF000
trusted library allocation
page read and write
65F000
heap
page read and write
3F43000
trusted library allocation
page read and write
62B000
heap
page read and write
18DF2434000
heap
page read and write
38C8000
trusted library allocation
page read and write
6AB1000
trusted library allocation
page read and write
28446645000
heap
page read and write
2300000
heap
page read and write
3A27000
trusted library allocation
page read and write
2D40000
unkown
page readonly
343B000
heap
page read and write
620000
heap
page read and write
222212D1000
heap
page read and write
38CF000
trusted library allocation
page read and write
A9FBD4B000
stack
page read and write
277F000
stack
page read and write
3530000
trusted library allocation
page read and write
62C000
heap
page read and write
490000
heap
page read and write
B24E27B000
stack
page read and write
41045FA000
stack
page read and write
901EDFF000
stack
page read and write
38F0000
direct allocation
page read and write
71E000
stack
page read and write
8E8B07D000
stack
page read and write
5D37000
direct allocation
page read and write
28446654000
heap
page read and write
28446659000
heap
page read and write
35F0000
trusted library allocation
page read and write
3310000
direct allocation
page read and write
62C000
heap
page read and write
3530000
trusted library allocation
page read and write
18DF2402000
heap
page read and write
3750000
direct allocation
page read and write
901F0FE000
stack
page read and write
28446673000
heap
page read and write
62B000
heap
page read and write
625000
heap
page read and write
900000
direct allocation
page read and write
901F27E000
stack
page read and write
1E0000
trusted library allocation
page read and write
B24E47C000
stack
page read and write
6AB1000
trusted library allocation
page read and write
26B9822B000
heap
page read and write
7AD237E000
stack
page read and write
7AD1EFF000
stack
page read and write
35F0000
trusted library allocation
page read and write
1C0000
remote allocation
page read and write
7AD1DFD000
stack
page read and write
35F0000
trusted library allocation
page read and write
28446649000
heap
page read and write
6AEA000
trusted library allocation
page read and write
3856000
trusted library allocation
page read and write
628000
heap
page read and write
65F000
heap
page read and write
6278000
direct allocation
page read and write
3250000
direct allocation
page read and write
62A1000
direct allocation
page read and write
20000
trusted library allocation
page read and write
6AB1000
trusted library allocation
page read and write
614A000
direct allocation
page read and write
605000
heap
page read and write
28446687000
heap
page read and write
3F47000
trusted library allocation
page read and write
28446635000
heap
page read and write
3A43000
trusted library allocation
page read and write
2C3D000
stack
page read and write
3857000
trusted library allocation
page read and write
901F17E000
stack
page read and write
267E000
stack
page read and write
61F000
heap
page read and write
901EEFB000
stack
page read and write
26B98202000
heap
page read and write
2320000
heap
page read and write
18DF242B000
heap
page read and write
624000
heap
page read and write
3437000
heap
page read and write
28E3E913000
heap
page read and write
22220AD0000
heap
page read and write
35F0000
trusted library allocation
page read and write
2307000
heap
page read and write
237FFED0000
heap
page read and write
62D000
heap
page read and write
901EE7F000
stack
page read and write
2844666B000
heap
page read and write
41046FF000
stack
page read and write
211E000
stack
page read and write
62D000
heap
page read and write
910000
direct allocation
page read and write
3885000
trusted library allocation
page read and write
901EF79000
stack
page read and write
6BB0000
direct allocation
page read and write
FCCCE7D000
stack
page read and write
62D000
heap
page read and write
22220BB1000
heap
page read and write
23800102000
heap
page read and write
4040000
direct allocation
page read and write
28E3E825000
heap
page read and write
62D000
heap
page read and write
6AC9000
trusted library allocation
page read and write
6AB1000
trusted library allocation
page read and write
1A0000
heap
page read and write
18DF2400000
heap
page read and write
5D9E000
direct allocation
page read and write
39B0000
direct allocation
page read and write
6ABD000
trusted library allocation
page read and write
910000
direct allocation
page read and write
3F4E000
trusted library allocation
page read and write
FCCCBFE000
stack
page read and write
6AEF000
trusted library allocation
page read and write
6605000
direct allocation
page read and write
3438000
heap
page read and write
5D0000
heap
page read and write
62D000
heap
page read and write
27D0000
heap
page read and write
620000
heap
page read and write
A9FC2FE000
stack
page read and write
3A24000
trusted library allocation
page read and write
3F41000
trusted library allocation
page read and write
408000
unkown
page readonly
3A14000
trusted library allocation
page read and write
5E3B000
direct allocation
page read and write
5AB1000
direct allocation
page read and write
28E3E8D9000
heap
page read and write
5FC7000
direct allocation
page read and write
222212F0000
heap
page read and write
3A9C000
trusted library allocation
page read and write
7A4000
heap
page read and write
35F0000
trusted library allocation
page read and write
400000
unkown
page readonly
28446620000
heap
page read and write
A9FC3FE000
stack
page read and write
3438000
heap
page read and write
4BB000
heap
page read and write
3A37000
trusted library allocation
page read and write
6AD4000
trusted library allocation
page read and write
3870000
direct allocation
page read and write
39B0000
direct allocation
page read and write
28E3E8F5000
heap
page read and write
28E3E867000
heap
page read and write
3F47000
trusted library allocation
page read and write
27E0000
heap
page read and write
608000
heap
page read and write
679F000
direct allocation
page read and write
627000
heap
page read and write
10000000
unkown
page readonly
28446669000
heap
page read and write
35F0000
direct allocation
page read and write
629000
heap
page read and write
14C000
stack
page read and write
35F0000
trusted library allocation
page read and write
222213D7000
heap
page read and write
414000
unkown
page read and write
2303000
heap
page read and write
23D56413000
heap
page read and write
5D2D000
direct allocation
page read and write
3290000
trusted library allocation
page read and write
414000
unkown
page read and write
620000
heap
page read and write
75E000
stack
page read and write
1A0000
heap
page read and write
146000
stack
page read and write
38D2000
trusted library allocation
page read and write
28446540000
heap
page read and write
28E3E902000
heap
page read and write
28E3F100000
heap
page read and write
620000
heap
page read and write
620000
heap
page read and write
28E3E8FB000
heap
page read and write
629000
heap
page read and write
5AB0000
direct allocation
page read and write
629000
heap
page read and write
901F079000
stack
page read and write
38D6000
direct allocation
page read and write
628000
heap
page read and write
28446671000
heap
page read and write
237FFE70000
heap
page read and write
222213F9000
heap
page read and write
28E3E730000
heap
page read and write
39A3000
trusted library allocation
page read and write
7AD2177000
stack
page read and write
28E3E887000
heap
page read and write
23D56455000
heap
page read and write
620000
heap
page read and write
627000
heap
page read and write
B24ECFF000
stack
page read and write
408000
unkown
page readonly
222213F9000
heap
page read and write
3DF0000
direct allocation
page read and write
29D0000
trusted library allocation
page read and write
FCCCFFE000
stack
page read and write
28E3F112000
heap
page read and write
65F000
heap
page read and write
5E6A000
direct allocation
page read and write
45D000
stack
page read and write
62D000
heap
page read and write
6AB1000
trusted library allocation
page read and write
62D000
heap
page read and write
62B000
heap
page read and write
343E000
heap
page read and write
35F0000
direct allocation
page read and write
22221290000
heap
page read and write
629000
heap
page read and write
910000
direct allocation
page read and write
23800002000
heap
page read and write
22220EF0000
heap
page read and write
3F47000
trusted library allocation
page read and write
26B98274000
heap
page read and write
620000
heap
page read and write
26B98010000
heap
page read and write
5DF000
heap
page read and write
38E1000
direct allocation
page read and write
629000
heap
page read and write
222213D9000
heap
page read and write
6EC55000
unkown
page readonly
6AD8000
trusted library allocation
page read and write
3A5C000
trusted library allocation
page read and write
28446693000
heap
page read and write
385D000
trusted library allocation
page read and write
28446613000
heap
page read and write
28446660000
heap
page read and write
2220000
heap
page read and write
22221391000
heap
page read and write
2ED4000
heap
page read and write
65F000
heap
page read and write
3876000
trusted library allocation
page read and write
632000
heap
page read and write
629000
heap
page read and write
620000
heap
page read and write
39B0000
direct allocation
page read and write
627000
heap
page read and write
3F44000
trusted library allocation
page read and write
28446644000
heap
page read and write
26B9828A000
heap
page read and write
63E000
heap
page read and write
901F37E000
stack
page read and write
5AB0000
direct allocation
page read and write
23D56320000
heap
page read and write
3CF0000
direct allocation
page read and write
2844666C000
heap
page read and write
180000
heap
page read and write
629000
heap
page read and write
620000
heap
page read and write
26FF000
stack
page read and write
6AB1000
trusted library allocation
page read and write
28E3E800000
heap
page read and write
414000
unkown
page write copy
628000
heap
page read and write
401000
unkown
page execute read
5EE000
heap
page read and write
3F48000
trusted library allocation
page read and write
62D000
heap
page read and write
18DF23A0000
heap
page read and write
141000
stack
page read and write
35F0000
trusted library allocation
page read and write
620000
heap
page read and write
39B0000
direct allocation
page read and write
28446625000
heap
page read and write
3A19000
trusted library allocation
page read and write
6332000
direct allocation
page read and write
6AB1000
trusted library allocation
page read and write
3870000
direct allocation
page read and write
22220B99000
heap
page read and write
3A6B000
trusted library allocation
page read and write
385F000
trusted library allocation
page read and write
451D000
direct allocation
page read and write
26B98213000
heap
page read and write
23D5644C000
heap
page read and write
43B000
unkown
page readonly
2844666F000
heap
page read and write
3DF0000
direct allocation
page read and write
3870000
direct allocation
page read and write
2844664B000
heap
page read and write
62D000
heap
page read and write
611000
heap
page read and write
628000
heap
page read and write
620000
heap
page read and write
2D50000
unkown
page readonly
28E3E82B000
heap
page read and write
23D56502000
heap
page read and write
A9FC4FF000
stack
page read and write
65F000
heap
page read and write
3A82000
trusted library allocation
page read and write
28E3E896000
heap
page read and write
28446600000
heap
page read and write
FCCCC7A000
stack
page read and write
18DF23E0000
trusted library allocation
page read and write
29B0000
heap
page read and write
3A18000
trusted library allocation
page read and write
22220EF5000
heap
page read and write
420000
heap
page read and write
401000
unkown
page execute read
629000
heap
page read and write
35F0000
trusted library allocation
page read and write
276F000
stack
page read and write
32A0000
direct allocation
page read and write
23D56431000
heap
page read and write
3947000
trusted library allocation
page read and write
23D56447000
heap
page read and write
3530000
trusted library allocation
page read and write
B24E67B000
stack
page read and write
3A5E000
trusted library allocation
page read and write
901F2F9000
stack
page read and write
3868000
trusted library allocation
page read and write
222213F9000
heap
page read and write
FCCC4FB000
stack
page read and write
62D000
heap
page read and write
440000
heap
page read and write
28E3E8C8000
heap
page read and write
2EA0000
heap
page read and write
FCCCB7F000
stack
page read and write
28E3E6C0000
heap
page read and write
620000
heap
page read and write
28E3E840000
heap
page read and write
28E3F002000
heap
page read and write
5E2A000
direct allocation
page read and write
28E3E760000
trusted library allocation
page read and write
62D000
heap
page read and write
18DF2413000
heap
page read and write
400000
unkown
page readonly
3892000
trusted library allocation
page read and write
400000
unkown
page readonly
628000
heap
page read and write
28E3F143000
heap
page read and write
900000
direct allocation
page read and write
620000
heap
page read and write
3A77000
trusted library allocation
page read and write
62D000
heap
page read and write
6AB1000
trusted library allocation
page read and write
3186000
heap
page read and write
3CF7000
trusted library allocation
page read and write
49C000
stack
page read and write
26B9826D000
heap
page read and write
6ADE000
trusted library allocation
page read and write
B24E97D000
stack
page read and write
27F3000
heap
page read and write
26B98200000
heap
page read and write
2844665F000
heap
page read and write
629000
heap
page read and write
10000
heap
page read and write
28E3E6D0000
heap
page read and write
638000
heap
page read and write
2844665A000
heap
page read and write
2380005C000
heap
page read and write
A30000
heap
page read and write
640F000
direct allocation
page read and write
3530000
trusted library allocation
page read and write
2844666D000
heap
page read and write
10000
heap
page read and write
2380002B000
heap
page read and write
3240000
direct allocation
page read and write
28446656000
heap
page read and write
2844665E000
heap
page read and write
26B97FB0000
heap
page read and write
28E3E8D3000
heap
page read and write
B24E5FE000
stack
page read and write
40A000
unkown
page read and write
638000
heap
page read and write
5AB0000
direct allocation
page read and write
2D60000
unkown
page read and write
5F2000
heap
page read and write
26B981E0000
trusted library allocation
page read and write
5AB0000
direct allocation
page read and write
8E8AD7C000
stack
page read and write
18DF2330000
heap
page read and write
4040000
direct allocation
page read and write
35F0000
trusted library allocation
page read and write
3A2D000
trusted library allocation
page read and write
385F000
trusted library allocation
page read and write
5AB0000
direct allocation
page read and write
28E3E813000
heap
page read and write
343E000
heap
page read and write
67B2000
direct allocation
page read and write
39B0000
direct allocation
page read and write
3A3A000
trusted library allocation
page read and write
3F47000
trusted library allocation
page read and write
5AB0000
direct allocation
page read and write
23800043000
heap
page read and write
B24EBFB000
stack
page read and write
284465A0000
heap
page read and write
6AB1000
trusted library allocation
page read and write
62B000
heap
page read and write
284465D0000
trusted library allocation
page read and write
35F0000
direct allocation
page read and write
22220B30000
heap
page read and write
2380006D000
heap
page read and write
602000
heap
page read and write
23800039000
heap
page read and write
6AF0000
trusted library allocation
page read and write
7AD1FF8000
stack
page read and write
3F47000
trusted library allocation
page read and write
FCCC87E000
stack
page read and write
6ADF000
trusted library allocation
page read and write
28446697000
heap
page read and write
222212DF000
heap
page read and write
222213B5000
heap
page read and write
3A80000
trusted library allocation
page read and write
14A000
stack
page read and write
23D563B0000
trusted library allocation
page read and write
170000
remote allocation
page read and write
38B1000
trusted library allocation
page read and write
180000
heap
page read and write
901EFFE000
stack
page read and write
3310000
direct allocation
page read and write
385B000
trusted library allocation
page read and write
28446647000
heap
page read and write
309F000
unkown
page read and write
620000
heap
page read and write
2D3C000
stack
page read and write
627000
heap
page read and write
5DEC000
direct allocation
page read and write
2EAA000
heap
page read and write
3A7E000
trusted library allocation
page read and write
62C000
heap
page read and write
3530000
trusted library allocation
page read and write
343A000
heap
page read and write
42A000
unkown
page read and write
901F1FD000
stack
page read and write
620000
heap
page read and write
35F0000
direct allocation
page read and write
28446663000
heap
page read and write
2844668D000
heap
page read and write
28446641000
heap
page read and write
3855000
trusted library allocation
page read and write
1E4000
heap
page read and write
52C000
heap
page read and write
385D000
trusted library allocation
page read and write
30DE000
stack
page read and write
620000
heap
page read and write
19A000
stack
page read and write
23D56402000
heap
page read and write
3310000
direct allocation
page read and write
32A0000
direct allocation
page read and write
603000
heap
page read and write
35F0000
direct allocation
page read and write
6AB1000
trusted library allocation
page read and write
FCCCEFE000
stack
page read and write
B24EAFC000
stack
page read and write
3872000
trusted library allocation
page read and write
7AD207F000
stack
page read and write
4B0000
heap
page read and write
900000
direct allocation
page read and write
5BB0000
direct allocation
page read and write
71F000
stack
page read and write
3530000
trusted library allocation
page read and write
1D0000
heap
page read and write
608F000
direct allocation
page read and write
3180000
heap
page read and write
222213CC000
heap
page read and write
18DF2445000
heap
page read and write
28446664000
heap
page read and write
7AD19BC000
stack
page read and write
28446685000
heap
page read and write
10000
heap
page read and write
5E41000
direct allocation
page read and write
6EC50000
unkown
page readonly
629000
heap
page read and write
8E8B17F000
stack
page read and write
328F000
stack
page read and write
3840000
direct allocation
page read and write
3F46000
trusted library allocation
page read and write
3436000
heap
page read and write
26B98300000
heap
page read and write
910000
direct allocation
page read and write
1E0000
heap
page read and write
23D56439000
heap
page read and write
10001000
unkown
page execute read
638000
heap
page read and write
65F000
heap
page read and write
3CF0000
direct allocation
page read and write
28446646000
heap
page read and write
2844666A000
heap
page read and write
62D000
heap
page read and write
35F0000
trusted library allocation
page read and write
32A1000
trusted library allocation
page read and write
620000
heap
page read and write
23D56C02000
trusted library allocation
page read and write
760000
heap
page read and write
3330000
trusted library allocation
page read and write
3855000
trusted library allocation
page read and write
22220B78000
heap
page read and write
8E8AC7F000
stack
page read and write
5AB0000
direct allocation
page read and write
22220C04000
heap
page read and write
5F2E000
trusted library allocation
page read and write
3868000
trusted library allocation
page read and write
28446676000
heap
page read and write
629000
heap
page read and write
A9FC1FE000
stack
page read and write
647000
heap
page read and write
286F000
stack
page read and write
23800013000
heap
page read and write
65F000
heap
page read and write
28446677000
heap
page read and write
3436000
heap
page read and write
3310000
direct allocation
page read and write
230C000
heap
page read and write
520000
heap
page read and write
10170000
unkown
page read and write
28446658000
heap
page read and write
29C0000
trusted library allocation
page read and write
3A52000
trusted library allocation
page read and write
35F0000
trusted library allocation
page read and write
6AB1000
trusted library allocation
page read and write
629000
heap
page read and write
3F41000
trusted library allocation
page read and write
8E8AE7C000
stack
page read and write
5B0000
heap
page read and write
6EC51000
unkown
page execute read
6597000
direct allocation
page read and write
22220B70000
heap
page read and write
3436000
heap
page read and write
7AD20FD000
stack
page read and write
6AE2000
trusted library allocation
page read and write
3610000
direct allocation
page read and write
237FFFD0000
trusted library allocation
page read and write
67A9000
direct allocation
page read and write
35F0000
direct allocation
page read and write
27E8000
heap
page read and write
61F000
heap
page read and write
3740000
direct allocation
page read and write
6AE9000
trusted library allocation
page read and write
611000
heap
page read and write
10117000
unkown
page readonly
2844665C000
heap
page read and write
3530000
trusted library allocation
page read and write
900000
direct allocation
page read and write
5F6000
heap
page read and write
22221391000
heap
page read and write
910000
direct allocation
page read and write
3882000
trusted library allocation
page read and write
2380004F000
heap
page read and write
389E000
trusted library allocation
page read and write
3F42000
trusted library allocation
page read and write
62B000
heap
page read and write
627000
heap
page read and write
26B98802000
trusted library allocation
page read and write
476A000
direct allocation
page read and write
38A6000
trusted library allocation
page read and write
627000
heap
page read and write
B24E77F000
stack
page read and write
3F4C000
trusted library allocation
page read and write
18DF2459000
heap
page read and write
A9FC07E000
stack
page read and write
FCCCD7F000
stack
page read and write
6EC53000
unkown
page readonly
901E9FC000
stack
page read and write
62D000
heap
page read and write
35F0000
trusted library allocation
page read and write
18DF2340000
heap
page read and write
628000
heap
page read and write
23D5642B000
heap
page read and write
22221392000
heap
page read and write
2844668E000
heap
page read and write
6AB1000
trusted library allocation
page read and write
610000
heap
page read and write
6D22000
direct allocation
page read and write
2844669E000
heap
page read and write
22220BBC000
heap
page read and write
273E000
stack
page read and write
2D80000
heap
page read and write
40F000
unkown
page readonly
620000
heap
page read and write
62E000
heap
page read and write
1F0000
trusted library allocation
page read and write
6088000
direct allocation
page read and write
170000
remote allocation
page read and write
201D000
stack
page read and write
6AEE000
trusted library allocation
page read and write
28446656000
heap
page read and write
65F000
heap
page read and write
389C000
trusted library allocation
page read and write
FCCD0FD000
stack
page read and write
39F0000
direct allocation
page read and write
26B98271000
heap
page read and write
23D56440000
heap
page read and write
41044FF000
stack
page read and write
62B000
heap
page read and write
5AB0000
direct allocation
page read and write
65F000
heap
page read and write
3DF0000
direct allocation
page read and write
77E000
stack
page read and write
18DF23D0000
trusted library allocation
page read and write
3609000
direct allocation
page read and write
7A0000
heap
page read and write
6AC0000
trusted library allocation
page read and write
FCCCA7D000
stack
page read and write
627000
heap
page read and write
5DC2000
direct allocation
page read and write
26B97FC0000
heap
page read and write
18DF2444000
heap
page read and write
629000
heap
page read and write
23800000000
heap
page read and write
20C4000
heap
page read and write
900000
direct allocation
page read and write
35F0000
direct allocation
page read and write
3A7E000
trusted library allocation
page read and write
222213BC000
heap
page read and write
222213DC000
heap
page read and write
6AB1000
trusted library allocation
page read and write
2380007E000
heap
page read and write
18DF2502000
heap
page read and write
629000
heap
page read and write
3CF0000
direct allocation
page read and write
620000
heap
page read and write
40F000
unkown
page readonly
435000
unkown
page read and write
3870000
direct allocation
page read and write
FCCD17E000
stack
page read and write
62B000
heap
page read and write
22221358000
heap
page read and write
2E9E000
unkown
page read and write
397A000
trusted library allocation
page read and write
35F0000
direct allocation
page read and write
3A1D000
trusted library allocation
page read and write
2844667D000
heap
page read and write
5EBB000
trusted library allocation
page read and write
3DF0000
direct allocation
page read and write
2870000
trusted library allocation
page read and write
237FFE80000
heap
page read and write
6012000
direct allocation
page read and write
6A9B000
direct allocation
page read and write
8E8AF7E000
stack
page read and write
388A000
trusted library allocation
page read and write
62C000
heap
page read and write
28E3F141000
heap
page read and write
3A58000
trusted library allocation
page read and write
27D6000
heap
page read and write
62C000
heap
page read and write
31B0000
heap
page read and write
20C0000
heap
page read and write
65F000
heap
page read and write
3F47000
trusted library allocation
page read and write
1017A000
unkown
page read and write
3F47000
trusted library allocation
page read and write
7AD227C000
stack
page read and write
418000
unkown
page readonly
620000
heap
page read and write
222213F9000
heap
page read and write
3F45000
trusted library allocation
page read and write
4546000
direct allocation
page read and write
601E000
direct allocation
page read and write
4103FEB000
stack
page read and write
5D70000
direct allocation
page read and write
3640000
direct allocation
page read and write
26B98302000
heap
page read and write
28446E02000
trusted library allocation
page read and write
23800802000
trusted library allocation
page read and write
26BE000
stack
page read and write
2240000
heap
page read and write
3A1E000
trusted library allocation
page read and write
28446702000
heap
page read and write
22221390000
heap
page read and write
61F000
heap
page read and write
620000
heap
page read and write
6408000
direct allocation
page read and write
222212D8000
heap
page read and write
3530000
trusted library allocation
page read and write
A9FBDCE000
stack
page read and write
38AA000
trusted library allocation
page read and write
9C000
stack
page read and write
6AB1000
trusted library allocation
page read and write
There are 740 hidden memdumps, click here to show them.