<?xml version="1.0" encoding="utf-8"?>
<!--pestudio-pro 9.09 - Malware Initial Assessment - www.winitor.com-->
<image><overview name="e:\exe,a68243ced29d472dd28d455622b89c4d"><description>n/a</description><file-version>n/a</file-version><file-type>executable</file-type><cpu>32</cpu><size>33244</size><size-without-overlay>27136</size-without-overlay><subsystem>GUI</subsystem><signature>n/a</signature><entropy>5.277</entropy><compiler-stamp>Wed Feb 19 11:20:30 2014
</compiler-stamp><debugger-stamp>Wed Feb 19 11:20:30 2014
</debugger-stamp><resources-stamp>empty</resources-stamp><exports-stamp>n/a</exports-stamp><version-stamp>n/a</version-stamp><entry-point>55 89 E5 83 C4 B0 8B 34 24 83 C6 55 31 35 B5 50 40 00 8B 14 24 01 F2 8B 0C 24 13 0D 74 50 40 00 8B </entry-point><first-bytes-hex>4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 </first-bytes-hex><first-bytes-text>M Z .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. @ .. .. .. .. .. .. .. .. </first-bytes-text><md5>A68243CED29D472DD28D455622B89C4D</md5><md5-without-overlay>5984A1405A3D164E0D1AC88B75DF1147</md5-without-overlay><sha1>701F234A47F374079AA6B76EFC98B8A7E7F834C6</sha1><sha1-without-overlay>A3D214D45318699C773E2242555CA43A93B0A1AD</sha1-without-overlay><sha256>692C78D3FEC4F8FD455E97E7BAEAD3D6B174D3FE65491D954D608E74F7D37DEC</sha256><sha256-without-overlay>E521E62510AE4025E8C801C1B3E261D141F10E3FE88A1E1D14E05B6733770A96</sha256-without-overlay><imphash>222E7B320F36011FEB1642000D8FA826</imphash></overview><indicators hint="34"><indicator xml-id="1430" detail="count: 176" level="1">The file references string(s) tagged as blacklist</indicator><indicator xml-id="1525" detail="signature: unknown, location: overlay, offset: 0x000081DB, size: 6108" level="1">The file contains another file</indicator><indicator xml-id="1484" detail="The server name or address could not be resolved
" level="4">The file score is not available</indicator><indicator xml-id="1259" detail="text: !That program cannot be run in DOS mode." level="1">The dos-stub message is unusual</indicator><indicator xml-id="1019" detail="status: no" level="4">The file contains a rich-header</indicator><indicator xml-id="1050" detail="status: no" level="4">The file uses Control Flow Guard (CFG) as software security defense</indicator><indicator xml-id="1100" detail="status: no" level="4">The file opts for Data Execution Prevention (DEP) as software security defense</indicator><indicator xml-id="1102" detail="status: no" level="4">The file opts for Address Space Layout Randomization (ASLR) as software security defense</indicator><indicator xml-id="1043" detail="status: no" level="4">The file contains a Manifest</indicator><indicator xml-id="1152" detail="file: uiopferta.pdb" level="3">The file references debug symbols</indicator><indicator xml-id="1106" detail="status: no" level="4">The file opts for Stack Buffer Overrun Detection (GS) as software security defense</indicator><indicator xml-id="1040" detail="status: no" level="4">The file contains a digital Certificate</indicator><indicator xml-id="1269" detail="count: 2" level="1">The file references library(ies) tagged as blacklist</indicator><indicator xml-id="1261" detail="count: 9" level="3">The file imports deprecated function(s)</indicator><indicator xml-id="1266" detail="count: 17" level="1">The file imports symbol(s) tagged as blacklist</indicator><indicator xml-id="1124" detail="count: 4" level="2">The file references MITRE Technique(s)</indicator><indicator xml-id="1109" detail="status: no" level="4">The file opts for Code Integrity (CI) a software security defense</indicator><indicator xml-id="1036" detail="checksum: 0x00014BE4" level="3">The file checksum is invalid</indicator><indicator xml-id="1287" detail="type: GUI" level="4">The file subsystem has been found</indicator><indicator xml-id="1215" detail="ratio: 78.55%" level="4">The file-ratio of the section(s) has been determined</indicator><indicator xml-id="1634" detail="api: cryptography, count: 5" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: shell, count: 2" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: file, count: 7" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: memory, count: 5" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: execution, count: 8" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: data-exchange, count: 4" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: console, count: 2" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: synchronization, count: 2" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: dynamic-library, count: 3" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: storage, count: 1" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: diagnostic, count: 1" level="3">The file references a group of API</indicator><indicator xml-id="1634" detail="api: system-information, count: 2" level="3">The file references a group of API</indicator><indicator xml-id="1633" detail="hint: dos-message, count: 1" level="3">The file references a group of hint</indicator><indicator xml-id="1633" detail="hint: file, count: 156" level="3">The file references a group of hint</indicator></indicators><mitre hint="4"><mitre-tactic name="Execution"><mitre-technique ti="Execution through API"/></mitre-tactic><mitre-tactic name="Defense Evasion"><mitre-technique ti="Virtualization/Sandbox Evasion"/></mitre-tactic><mitre-tactic name="Defense Evasion"><mitre-technique ti="Process Injection"/></mitre-tactic><mitre-tactic name="Discovery"><mitre-technique ti="System Time Discovery"/></mitre-tactic></mitre><virustotal hint="offline"/><dos-header hint="64 bytes"><md5>2C06BE34F79BF075E3DF03631F2615AF</md5><sha1>63ECF7D70514CCF78D635C4C8DFA3EA14CBCD3D8</sha1><sha256>11EC86D452284B8C250C28F9ED2EBF93BD588499BDD4FE06B36AFC418333473D</sha256><e_magic>MZﾐ</e_magic><e_lfanew>0x00000080</e_lfanew><entropy>3.648</entropy><file-ratio>0.00%</file-ratio><size>64</size></dos-header><dos-stub hint="message"><md5>FD4115D4B2874457E0595AE99AAE3FE3</md5><sha1>B5AA1CE69972E3FD8858692D567E71BB62DE4BB3</sha1><sha256>60CE99F5E6D7721DBC1EC68EAD8AC53EA030B5FD7E4D78616F8291E47159F202</sha256><entropy>4.751</entropy><file-ratio>0.19%</file-ratio><message>!That program cannot be run in DOS mode.</message><size>64</size></dos-stub><rich-header>n/a</rich-header><file-header hint="Feb.2014
"><file-offset>0x00000080</file-offset><file-header-offset>0x50450000</file-header-offset><pointer-symbol-table>0x00000000</pointer-symbol-table><relocation-stripped>true</relocation-stripped><executable>true</executable><large-address-aware>false</large-address-aware><processor-32bit>true</processor-32bit><uniprocessor>false</uniprocessor><system-image>false</system-image><dynamic-link-library>false</dynamic-link-library><debug-stripped>false</debug-stripped><media-run-from-swap>false</media-run-from-swap><network-run-from-swap>false</network-run-from-swap><machine>Intel</machine><compiler-stamp>Wed Feb 19 11:20:30 2014
</compiler-stamp><sections>4</sections><number-of-symbols>0</number-of-symbols><size-of-optional-header>224</size-of-optional-header></file-header><optional-header hint="GUI"><magic>0x010B</magic><linker-version>6.0</linker-version><size-of-code>8704</size-of-code><size-of-initialized-data>17408</size-of-initialized-data><size-of-uninitialized-data>0</size-of-uninitialized-data><entry-point>0x00001992</entry-point><base-of-code>0x00001000</base-of-code><base-of-data>0x00004000</base-of-data><image-base>0x00400000</image-base><section-alignment>0x00001000</section-alignment><file-alignment>0x00000200</file-alignment><os-version>4.0</os-version><image-version>0.0</image-version><subsystem-version>4.0</subsystem-version><Win32VersionValue>0x00000000</Win32VersionValue><size-of-image>36864</size-of-image><size-of-headers>1024</size-of-headers><file-checksum>0x00014BE4</file-checksum><subsystem>GUI</subsystem><address-space-layout-randomization>false</address-space-layout-randomization><code-integrity>false</code-integrity><data-execution-prevention>false</data-execution-prevention><image-isolation>true</image-isolation><structured-exception-handling>true</structured-exception-handling><image-bound>false</image-bound><windows-driver-model>false</windows-driver-model><terminal-server-aware>false</terminal-server-aware><size-of-stack-reserve>1048576</size-of-stack-reserve><size-of-stack-commit>4096</size-of-stack-commit><size-of-heap-reserve>1048576</size-of-heap-reserve><size-of-heap-commit>4096</size-of-heap-commit><LoaderFlags>0x00000000</LoaderFlags><directories-number>16</directories-number><control-flow-guard>false</control-flow-guard></optional-header><directories hint="4"><directory name="export-table" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/><directory name="import-name" address="0x41E4" size="120" section=".rdata" stamp="empty" missing="-" empty="-" invalid="-"/><directory name="resource" address="0x6000" size="11438" section=".rsrc" stamp="empty" missing="-" empty="-" invalid="-"/><directory name="exception" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/><directory name="security" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/><directory name="relocation" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/><directory name="debug" address="0x5D01" size="28" section=".data" stamp="Wed Feb 19 11:20:30 2014
" missing="-" empty="-" invalid="-"/><directory name="architecture" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/><directory name="global-pointer" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/><directory name="thread-storage" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/><directory name="load-configuration" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/><directory name="bound-import" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/><directory name="import-address" address="0x4100" size="484" section=".rdata" stamp="empty" missing="-" empty="-" invalid="-"/><directory name="delay-loaded" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/><directory name="com-runtime" address="0x0000" size="0" section="n/a" stamp="n/a" missing="-" empty="x" invalid="-"/></directories><sections hint="78.55%"><section name=".text" virtual-size="8458" raw-size="8704" raw-address="0x0400" virtual-address="0x401000" md5="FC391AC2428EA7A24E76DACE0B3CC772" entropy="6.977" file-ratio="n/a" file-cave="246" self-modifying="-" blacklisted="-" initialized-data="-" uninitialized-data="-" discardable="-" shareable="-" executable="x" readable="x" writable="-"/><section name=".rdata" virtual-size="1800" raw-size="2048" raw-address="0x2600" virtual-address="0x404000" md5="E2C015386D3ACDF3E3BE1CF07C78B6C9" entropy="4.108" file-ratio="n/a" file-cave="248" self-modifying="-" blacklisted="-" initialized-data="x" uninitialized-data="-" discardable="-" shareable="-" executable="-" readable="x" writable="-"/><section name=".data" virtual-size="3395" raw-size="3584" raw-address="0x2E00" virtual-address="0x405000" md5="445311E3D98DEF7677FED58BCFC67CED" entropy="5.175" file-ratio="n/a" file-cave="189" self-modifying="-" blacklisted="-" initialized-data="x" uninitialized-data="-" discardable="-" shareable="-" executable="-" readable="x" writable="x"/><section name=".rsrc" virtual-size="11438" raw-size="11776" raw-address="0x3C00" virtual-address="0x406000" md5="73AC533E806CEDA7018DAED83926D654" entropy="3.124" file-ratio="n/a" file-cave="338" self-modifying="-" blacklisted="-" initialized-data="x" uninitialized-data="-" discardable="-" shareable="-" executable="-" readable="x" writable="-"/></sections><libraries hint="4"><library blacklist="x" type="implicit" name="cryptdll.dll" imports="4" description="Cryptography Manager"/><library blacklist="-" type="implicit" name="shell32.dll" imports="16" description="Windows Shell Common Dll"/><library blacklist="x" type="implicit" name="dbnmpntw.dll" imports="3" description="Named Pipes Net DLL for SQL Clients"/><library blacklist="-" type="implicit" name="kernel32.dll" imports="30" description="Windows NT BASE API Client DLL"/></libraries><imports hint="53"><import name="CDBuildVect" library="cryptdll.dll" gp="cryptography" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="MD5Update" library="cryptdll.dll" gp="cryptography" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="CDLocateRng" library="cryptdll.dll" gp="cryptography" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="MD5Init" library="cryptdll.dll" gp="cryptography" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="DragAcceptFiles" library="shell32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="SHCreateShellItem" library="shell32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="ShellAboutA" library="shell32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="SHGetFileInfoA" library="shell32.dll" gp="file" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="x" mitre-technique="-" mitre-tactic="-"/><import name="StrChrA" library="shell32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="SHFileOperationA" library="shell32.dll" gp="file" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="DragQueryFileA" library="shell32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="FreeIconList" library="shell32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="SHGetDataFromIDListA" library="shell32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="SHGetDiskFreeSpaceA" library="shell32.dll" gp="shell" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="FindExecutableA" library="shell32.dll" gp="execution" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="SHGetDesktopFolder" library="shell32.dll" gp="shell" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="ShellMessageBoxW" library="shell32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="x" mitre-technique="-" mitre-tactic="-"/><import name="SHGetFolderPathA" library="shell32.dll" gp="file" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="x" mitre-technique="-" mitre-tactic="-"/><import name="SHGetMalloc" library="shell32.dll" gp="memory" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="x" mitre-technique="-" mitre-tactic="-"/><import name="DragFinish" library="shell32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="ConnectionClose" library="dbnmpntw.dll" gp="data-exchange" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="ConnectionWrite" library="dbnmpntw.dll" gp="data-exchange" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="ConnectionError" library="dbnmpntw.dll" gp="data-exchange" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="FileTimeToSystemTime" library="kernel32.dll" gp="file" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="SearchPathA" library="kernel32.dll" gp="storage" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="OpenMutexA" library="kernel32.dll" gp="synchronization" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="GetPrivateProfileIntW" library="kernel32.dll" gp="execution" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="x" mitre-technique="-" mitre-tactic="-"/><import name="GetModuleHandleW" library="kernel32.dll" gp="dynamic-library" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="GetLocalTime" library="kernel32.dll" gp="system-information" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="ReadConsoleW" library="kernel32.dll" gp="console" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="FindFirstFileA" library="kernel32.dll" gp="file" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="GetEnvironmentVariableA" library="kernel32.dll" gp="execution" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="DeviceIoControl" library="kernel32.dll" gp="-" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="SetEnvironmentVariableW" library="kernel32.dll" gp="execution" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="CompareStringW" library="kernel32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="GetStringTypeW" library="kernel32.dll" gp="memory" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="x" mitre-technique="-" mitre-tactic="-"/><import name="IsValidCodePage" library="kernel32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="lstrcmpiA" library="kernel32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="lstrcmpA" library="kernel32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="TlsGetValue" library="kernel32.dll" gp="execution" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="GetProcAddress" library="kernel32.dll" gp="dynamic-library" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="GetTickCount" library="kernel32.dll" gp="system-information" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="System Time Discovery" mitre-tactic="Discovery"/><import name="WriteConsoleA" library="kernel32.dll" gp="console" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="lstrcpynW" library="kernel32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="x" mitre-technique="-" mitre-tactic="-"/><import name="GetLastError" library="kernel32.dll" gp="diagnostic" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="CreateDirectoryA" library="kernel32.dll" gp="file" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="GetCurrentDirectoryW" library="kernel32.dll" gp="execution" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="SetErrorMode" library="kernel32.dll" gp="-" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="SleepEx" library="kernel32.dll" gp="execution" type="implicit" ordinal="-" blacklist="x" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="Virtualization/Sandbox Evasion" mitre-tactic="Defense Evasion"/><import name="InterlockedDecrement" library="kernel32.dll" gp="synchronization" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="GetFullPathNameW" library="kernel32.dll" gp="file" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="-" mitre-technique="-" mitre-tactic="-"/><import name="GetPrivateProfileIntW" library="kernel32.dll" gp="execution" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="x" mitre-technique="-" mitre-tactic="-"/><import name="IsBadStringPtrA" library="kernel32.dll" gp="memory" type="implicit" ordinal="-" blacklist="-" anti-debug="-" undocumented="-" deprecated="x" mitre-technique="-" mitre-tactic="-"/></imports><exports>n/a</exports><relocations>n/a</relocations><exceptions>n/a</exceptions><resources hint="3"><instance file-offset="0x00004306" type="icon" name="1" size="9640" language="neutral" md5="CA3A14F12F15230A08465A820956352D" entropy="3.199" file-ratio="3.20%" first-bytes-hex="20 00 00 00 00 00 80 25 00 00 00 00 00 00 00 00 " first-bytes-text="  .. .. .. .. .. .. % .. .. .. .. .. .. .. .. "/><instance file-offset="0x00003CF0" type="menu" name="512" size="1536" language="English-United States" md5="53E979547D8C2EA86560AC45DE08AE25" entropy="0.000" file-ratio="0.00%" first-bytes-hex="00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 " first-bytes-text=".. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. "/><instance file-offset="0x000042F0" type="icon-group" name="512" size="22" language="neutral" md5="F3D227DFC801CAF28EE829998441DB48" entropy="1.818" file-ratio="1.82%" first-bytes-hex="A8 25 00 00 01 00 00 00 28 00 00 00 30 00 00 00 " first-bytes-text=".. % .. .. .. .. .. .. ( .. .. .. 0 .. .. .. "/></resources><manifest>n/a</manifest><debug hint="path"><md5>ECCACCCB04D4C6C40A66CEEA7B622DB3</md5><sha1>46B94A1F6539E93A8327654E13A684EC05C8A2CF</sha1><sha256>91865CBE99065BD1387AC72BF42EF993DD6C3D5BAB3163E7FB9A38F77511D1C6</sha256><format>RSDS</format><path>uiopferta.pdb</path><guid>79B52-71D6- 5-55F2-20ACED50</guid><age>1</age><size>38</size><debugger-stamp>Wed Feb 19 11:20:30 2014
</debugger-stamp></debug><version hint="n/a"><md5>n/a</md5><sha1>n/a</sha1><sha256>n/a</sha256><description>n/a</description><version>n/a</version><file-type>n/a</file-type><file-subtype>n/a</file-subtype></version><strings hint="400"><ascii count="241"><string bl="x" size="40" hint="dos-message" gp="-" mitre-technique="-" mitre-tactic="-">.That.program.cannot.be.run.in.DOS.mode.</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.text</string><string bl="-" size="7" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">`.rdata</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">@.data</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.rsrc</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">h=\@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">h2\@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.WQ@</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">g.=4P@</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">^.5@Q@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.&gt;P@</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.=.P@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.aQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">h=\@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">h2\@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5.P@</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.=.P@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">=;P@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">55P@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.6P@</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">t;8{1</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.5oQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.QP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">=8U@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5tP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.jQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5OQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5.Q@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5.P@</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.5.Q@</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">..XQ@</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">3.5RQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">..P@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">=bP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">..P@</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.=BP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5=Q@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5^P@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.GP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5&lt;P@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">..Q@</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.5`Q@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5.P@</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">1=sP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.hQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.VP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">h=\@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">h2\@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">=KQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.VP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5{P@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.AP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5nQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5CQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5bQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">h.U@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.PQ@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">=vQ@</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">H.=}Q@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">5aP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.kP@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">hT\@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">hH\@</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">Y1=9Q@</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">W..|Q@</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">a99a</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">a==aG</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">CllC</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">B..B</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">B..B</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">KW31</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">Sa88a</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">iT?&gt;h</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">\D~M</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">SDdP</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">K.KL</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">s.x7</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.}}.</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">cjuCC</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">EQ0T</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">..G@</string><string bl="-" size="7" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">PXOrrOX</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">F??F</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">c.\.</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">eQQe</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">3Y0.n</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">rTW0\</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">7.Xy</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">~.FJ</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">0j3G</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">jIiE</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">^XO8</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">K66K</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">f[=f</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">[DWR</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">_[KPk</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">ePKKPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">wPEEPw</string><string bl="x" size="7" hint="-" gp="cryptography" mitre-technique="-" mitre-tactic="-">MD5Init</string><string bl="x" size="9" hint="-" gp="cryptography" mitre-technique="-" mitre-tactic="-">MD5Update</string><string bl="-" size="11" hint="-" gp="cryptography" mitre-technique="-" mitre-tactic="-">CDLocateRng</string><string bl="-" size="11" hint="-" gp="cryptography" mitre-technique="-" mitre-tactic="-">CDBuildVect</string><string bl="-" size="12" hint="" gp="cryptography" mitre-technique="-" mitre-tactic="-">cryptdll.dll</string><string bl="-" size="17" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">SHCreateShellItem</string><string bl="-" size="10" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">ShellAbout</string><string bl="-" size="18" hint="-" gp="shell" mitre-technique="-" mitre-tactic="-">SHGetDiskFreeSpace</string><string bl="-" size="13" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">DragQueryFile</string><string bl="-" size="15" hint="-" gp="file" mitre-technique="-" mitre-tactic="-">SHGetFolderPath</string><string bl="x" size="13" hint="-" gp="file" mitre-technique="-" mitre-tactic="-">SHGetFileInfo</string><string bl="-" size="12" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">FreeIconList</string><string bl="-" size="11" hint="-" gp="memory" mitre-technique="-" mitre-tactic="-">SHGetMalloc</string><string bl="-" size="10" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">DragFinish</string><string bl="-" size="15" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">ShellMessageBox</string><string bl="-" size="18" hint="-" gp="shell" mitre-technique="-" mitre-tactic="-">SHGetDesktopFolder</string><string bl="-" size="6" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">StrChr</string><string bl="x" size="14" hint="-" gp="execution" mitre-technique="-" mitre-tactic="-">FindExecutable</string><string bl="x" size="15" hint="-" gp="file" mitre-technique="-" mitre-tactic="-">SHFileOperation</string><string bl="-" size="15" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">DragAcceptFiles</string><string bl="-" size="19" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">SHGetDataFromIDList</string><string bl="-" size="11" hint="" gp="-" mitre-technique="-" mitre-tactic="-">shell32.dll</string><string bl="x" size="15" hint="-" gp="data-exchange" mitre-technique="-" mitre-tactic="-">ConnectionError</string><string bl="x" size="15" hint="-" gp="data-exchange" mitre-technique="-" mitre-tactic="-">ConnectionClose</string><string bl="x" size="15" hint="-" gp="data-exchange" mitre-technique="-" mitre-tactic="-">ConnectionWrite</string><string bl="-" size="12" hint="" gp="data-exchange" mitre-technique="-" mitre-tactic="-">dbnmpntw.dll</string><string bl="-" size="12" hint="-" gp="console" mitre-technique="-" mitre-tactic="-">WriteConsole</string><string bl="-" size="15" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">IsValidCodePage</string><string bl="-" size="14" hint="-" gp="memory" mitre-technique="-" mitre-tactic="-">IsBadStringPtr</string><string bl="-" size="15" hint="-" gp="file" mitre-technique="-" mitre-tactic="-">CreateDirectory</string><string bl="-" size="9" hint="-" gp="synchronization" mitre-technique="-" mitre-tactic="-">OpenMutex</string><string bl="-" size="14" hint="-" gp="dynamic-library" mitre-technique="-" mitre-tactic="-">GetProcAddress</string><string bl="-" size="20" hint="-" gp="synchronization" mitre-technique="-" mitre-tactic="-">InterlockedDecrement</string><string bl="-" size="13" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">CompareString</string><string bl="x" size="7" hint="-" gp="execution" mitre-technique="Virtualization/Sandbox Evasion" mitre-tactic="Defense Evasion">SleepEx</string><string bl="x" size="11" hint="-" gp="console" mitre-technique="-" mitre-tactic="-">ReadConsole</string><string bl="-" size="15" hint="-" gp="dynamic-library" mitre-technique="-" mitre-tactic="-">GetModuleHandle</string><string bl="-" size="15" hint="-" gp="file" mitre-technique="-" mitre-tactic="-">GetFullPathName</string><string bl="x" size="10" hint="-" gp="storage" mitre-technique="-" mitre-tactic="-">SearchPath</string><string bl="-" size="12" hint="-" gp="diagnostic" mitre-technique="-" mitre-tactic="-">GetLastError</string><string bl="-" size="8" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">lstrcpyn</string><string bl="x" size="13" hint="-" gp="file" mitre-technique="-" mitre-tactic="-">FindFirstFile</string><string bl="-" size="12" hint="-" gp="system-information" mitre-technique="-" mitre-tactic="-">GetLocalTime</string><string bl="x" size="15" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">DeviceIoControl</string><string bl="-" size="13" hint="-" gp="memory" mitre-technique="-" mitre-tactic="-">GetStringType</string><string bl="-" size="12" hint="-" gp="system-information" mitre-technique="System Time Discovery" mitre-tactic="Discovery">GetTickCount</string><string bl="-" size="19" hint="-" gp="execution" mitre-technique="-" mitre-tactic="-">GetCurrentDirectory</string><string bl="-" size="7" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">lstrcmp</string><string bl="x" size="22" hint="-" gp="execution" mitre-technique="-" mitre-tactic="-">GetEnvironmentVariable</string><string bl="-" size="20" hint="-" gp="execution" mitre-technique="-" mitre-tactic="-">GetPrivateProfileInt</string><string bl="-" size="20" hint="-" gp="file" mitre-technique="-" mitre-tactic="-">FileTimeToSystemTime</string><string bl="-" size="20" hint="-" gp="execution" mitre-technique="-" mitre-tactic="-">GetPrivateProfileInt</string><string bl="-" size="8" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">lstrcmpi</string><string bl="-" size="11" hint="-" gp="execution" mitre-technique="-" mitre-tactic="-">TlsGetValue</string><string bl="x" size="22" hint="-" gp="execution" mitre-technique="-" mitre-tactic="-">SetEnvironmentVariable</string><string bl="-" size="12" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">SetErrorMode</string><string bl="-" size="12" hint="" gp="-" mitre-technique="-" mitre-tactic="-">kernel32.dll</string><string bl="-" size="11" hint="" gp="-" mitre-technique="-" mitre-tactic="-">jscript.DLL</string><string bl="-" size="11" hint="-" gp="dynamic-library" mitre-technique="Execution through API" mitre-tactic="Execution">LoadLibrary</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">..}m</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">Y.2.</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">PpcY</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">_[.M</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">sy3S</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">t&gt;Eb</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">[_&gt;3</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.lll</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">{:e1v</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">&gt;Gw|</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">.6^o</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">VCdf</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">|b1q</string><string bl="-" size="4" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">8~=m</string><string bl="-" size="10" hint="-" gp="memory" mitre-technique="-" mitre-tactic="-">HeapCreate</string><string bl="x" size="18" hint="-" gp="memory" mitre-technique="Process Injection" mitre-tactic="Defense Evasion">WriteProcessMemory</string><string bl="-" size="10" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">fmtmtzlnik</string><string bl="-" size="10" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">fmtmtzlnik</string><string bl="-" size="11" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">ldlaivqxuju</string><string bl="-" size="8" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">vonrjrzk</string><string bl="-" size="11" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">nbarkmefzda</string><string bl="-" size="13" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">vjiyymiqvgoxh</string><string bl="-" size="17" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">hwiwjgtqkyrjleqld</string><string bl="-" size="8" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">kltjziry</string><string bl="-" size="16" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">ishueinxvfhblayn</string><string bl="-" size="16" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">ulbitvgjhqsnlryi</string><string bl="-" size="9" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">iymyivqsw</string><string bl="-" size="9" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">iymyivqsw</string><string bl="-" size="11" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">hqedcpekvgn</string><string bl="-" size="12" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">mvmpnewbmhkc</string><string bl="-" size="5" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">RSDSR</string><string bl="-" size="13" hint="" gp="-" mitre-technique="-" mitre-tactic="-">uiopferta.pdb</string></ascii><unicode count="159"><string bl="x" size="57" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Documents.and.Settings\test\Desktop\M\Ref_11082014.scr</string><string bl="x" size="67" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">C:\a06be67d585e68cc273f590e2f2ddeda71a2315eecd34e6309c6cbcbdb1700be</string><string bl="x" size="67" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">C:\5836bb806de14caadf8f612013c3e15d4376b87c3808b64c26569b546ef13372</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\WJGEcsHZ.exe</string><string bl="x" size="67" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">C:\27602e960f45f3b8dfb2655ad63932c61d4f85bd375b623caad64cdfce421bf5</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\HN7LfbAL.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\6Q6YjpZb.exe</string><string bl="x" size="67" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">C:\ec7e9a0002524e329da53523db52a0d703fa6f049db8f3147ab739559f332fe1</string><string bl="x" size="67" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">C:\86fef6cdf1c49ec45dc06cfb878d6103424ddebc1c0f0808e27758d73f152d3e</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\LWiZYhT1.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\R4vhmmig.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\d3wOpEIX.exe</string><string bl="x" size="67" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">C:\9c1e699f978d138fd0361b5b400fdeca020d2d7f46f394fd1fd9eddcd74d972c</string><string bl="x" size="67" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">C:\0c9523b00d8aef996656b84c5477b00800a6588b850b65968dcf4ef925ffe00f</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Q4mOtJeJ.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\X1bNTGGY.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\F7XC0J6J.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\MdrncZ7n.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Qbqup827.exe</string><string bl="x" size="67" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">C:\258c20b64192af91c4795887fbc226c5f01896ba33f7f4325818cff0a018a482</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\UuAlrQyJ.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\cIsfDfv2.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\PZRtjA7u.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\4dUDBxOv.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\0d1MUdnf.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\MzIPRbL7.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\7ylcKjW2.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\ZYYWCDEj.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\4lNpgTDT.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\zNLCGezj.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\MILToRXz.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\rU9sl2ap.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\t1kCmhdn.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Df9e6DBJ.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\6b6oDGSW.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\0PyQqcTB.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\gYCdSQpv.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\YVliXPxX.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\pQnw9MWl.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\WkHOuaLm.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\XwgTcNIi.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\dnRrWzR5.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\8WQgIEUb.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\jZ6SN4va.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\HpO5J4VZ.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\PitgTUlE.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\uufprShy.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\JVK7pwQw.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\MX9K4XWd.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\daK1osVI.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\lVF2gifd.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\K1GNI8Sc.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\GNV28G41.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\7Pu6zNbL.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\BdPDobZ3.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\W2crSXDj.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\JnnrR_2T.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\vXcij8XI.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\rpjCUCsc.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\2QRxp1OZ.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\OL8aNkSZ.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\YMZcUBB5.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\btOOidbU.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\qNChA1D1.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\6my45o6F.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\bl59yBSU.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\gFxxVZa2.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\bDwzC1E0.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\XQ5vzPy0.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\MTWjLnde.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\WW4zJBoq.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\6YMHlkEd.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\uhYOqAj3.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\OvMEvpAE.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\hdNKx8_b.exe</string><string bl="x" size="67" hint="-" gp="-" mitre-technique="-" mitre-tactic="-">C:\b3e2dc7b07217a23866e693153b4fb94536a5ad353759bdba8fa73afa32ea318</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\gq_gwbia.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\n3gs5BJL.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\QbDLYSG6.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\IP3ZhN6K.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\eR4FiQa2.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\N4qPLTRR.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\SwHP9bDu.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\K5z2DpJk.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\gJkNQpUl.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\w_eWSLsV.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\XBmYQlbl.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\C7F0FBjY.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\s2PQ7NxK.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\M3a79Raj.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\U1CuFLC3.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\zN4w3vkb.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\NamB1m7i.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\szJvE2_l.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\LnvObCrm.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\XcfEbQKG.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\h47VUr7m.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\63F2K7aJ.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Vlld7dvC.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Cch1Lm06.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\0bNYfPrM.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\24U_1YKc.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\JFkPIqhB.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\RB64Vt9f.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\CBeXD79L.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\GmrlwL7s.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\RKoW039D.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\OxZXm6Pp.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Rt9V9P13.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\YHRK4o7m.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\DZxBEty7.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\BsObZrrC.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\MU90uqil.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\5sTb8PW8.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\2Llr31MJ.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\X9QQh8DH.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Cv3YQE4s.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\2Rfu61ug.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\tL2TUK0C.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\04YLF5TB.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\kgitHyKo.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\1WkNf7Uk.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\92xu0Bc9.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Vngtkqqm.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\XkcnT7xM.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\a6u2Qzo0.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\w3pNN5io.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\LZjN87gp.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\WsL7D_os.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\boULQbVE.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\O9bQcFtu.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\2mvke9xf.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\0SFR1WkP.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\2tTik6Bo.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\03Zgkz2p.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\CfXqxZ05.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\u0vRSIqz.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\LvBs5OL2.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\7iSphVGk.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\M2UFEDAP.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\R3cTAuLo.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\r4IWBskg.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\ddbJBT6Y.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\gia5x9Sq.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Qo3Jbpfq.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\r3I_67vJ.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\5TOTFqU8.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\nfwsYsPo.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\dMwPk3ve.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\08Zm8VWn.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\Ig1MeK0U.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\MPJ_lhxE.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\ZSyDvT1G.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\yw8drLYF.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\oT8JIN9U.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\nVNA8YNi.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\p4A_fuC0.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\n5R00RWt.exe</string><string bl="x" size="15" hint="" gp="-" mitre-technique="-" mitre-tactic="-">C:\i77pcbaM.exe</string></unicode></strings><tls-callbacks>n/a</tls-callbacks><certificate>n/a</certificate><overlay hint="unknown"><file-offset>0x00006A00</file-offset><size>6108</size><signature>unknown</signature><md5>35742737CC51972023D6E9F4198ADB6D</md5><sha1>2628A869FB3E3D39A3F231F5AE6CDE3F8AF46DBB</sha1><sha256>F5D0731A83C762F05DE2405FDBA889B50BE7E2BE6334CF981722EB9EC48BD8C6</sha256><entropy>3.546</entropy><first-bytes-hex>43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 </first-bytes-hex><first-bytes-text>C .. : .. \ .. D .. o .. c .. u .. m .. e .. n .. t .. s ..   .. a .. n .. d .. </first-bytes-text><file-ratio>18.37%</file-ratio></overlay></image>
