File name:

MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIP

Full analysis: https://app.any.run/tasks/6a032be7-2f54-4465-9f80-8ebded1f1fcd
Verdict: Malicious activity
Analysis date: December 15, 2024, 13:17:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

888815068CDBF9753AF0DB573984A733

SHA1:

58FCEEBAA508410DC2A17A7EB9EE4B985B370734

SHA256:

4A494A848B646F43368A85414AEAF59E330C7C93D1EC8ECE559371229D784AE9

SSDEEP:

98304:Kq5lmAS1FjgExgDH4P43aIVh+kcQA++qIVzTiQMm4qUtu3jzl3FNdku8tPaq03Nq:6mWViQg27v03HTc2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6696)
      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6692)
    • Application launched itself

      • WinRAR.exe (PID: 6696)
    • Executable content was dropped or overwritten

      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6452)
      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 3060)
    • Reads the date of Windows installation

      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6692)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6696)
      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6692)
      • WinRAR.exe (PID: 7008)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7008)
    • Checks supported languages

      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 3060)
      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6692)
      • xmplayer.exe (PID: 3544)
      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6452)
    • Create files in a temporary directory

      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 3060)
      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6452)
    • Reads the computer name

      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6692)
      • xmplayer.exe (PID: 3544)
      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6452)
    • The sample compiled with english language support

      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 3060)
    • Sends debugging messages

      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6692)
    • Process checks computer location settings

      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6692)
    • Manual execution by a user

      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 6452)
      • Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE (PID: 2940)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: 0x0800
ZipCompression: None
ZipModifyDate: 2024:12:15 05:16:54
ZipCRC: 0x1532d15f
ZipCompressedSize: 8
ZipUncompressedSize: 8
ZipFileName: MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIP.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
7
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe trainer+16 middle-earth shadow of mordor ver 1.0.1951.27 (update 8)by{maxtre}.exe no specs trainer+16 middle-earth shadow of mordor ver 1.0.1951.27 (update 8)by{maxtre}.exe trainer+16 middle-earth shadow of mordor ver 1.0.1951.27 (update 8)by{maxtre}.exe trainer+16 middle-earth shadow of mordor ver 1.0.1951.27 (update 8)by{maxtre}.exe xmplayer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2940"C:\Users\admin\Desktop\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE" C:\Users\admin\Desktop\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\trainer+16 middle-earth shadow of mordor ver 1.0.1951.27 (update 8)by{maxtre}.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3060"C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE" -ORIGIN:"C:\Users\admin\Desktop\"C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\cetrainers\cet8ddc.tmp\trainer+16 middle-earth shadow of mordor ver 1.0.1951.27 (update 8)by{maxtre}.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
3544"C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\xmplayer.exe" CEAE187DD8F_A893_4DF3_96AD9706BF341093C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\xmplayer.exeTrainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\cetrainers\cet8ddc.tmp\extracted\xmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
6452"C:\Users\admin\Desktop\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE" C:\Users\admin\Desktop\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\trainer+16 middle-earth shadow of mordor ver 1.0.1951.27 (update 8)by{maxtre}.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6692"C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE" "C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\CET_TRAINER.CETRAINER" "-ORIGIN:C:\Users\admin\Desktop\"C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
User:
admin
Company:
Cheat Engine
Integrity Level:
HIGH
Description:
Cheat Engine
Version:
6.4.0.4107
Modules
Images
c:\users\admin\appdata\local\temp\cetrainers\cet8ddc.tmp\extracted\trainer+16 middle-earth shadow of mordor ver 1.0.1951.27 (update 8)by{maxtre}.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6696"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIP.zipC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7008"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa6696.47360\MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIPC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
4 230
Read events
4 212
Write events
18
Delete events
0

Modification events

(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIP.zip
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7008) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7008) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
Executable files
6
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6452Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEC:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\CET_Archive.dat
MD5:
SHA256:
3060Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEC:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\CET_TRAINER.CETRAINER
MD5:
SHA256:
7008WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7008.47858\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEexecutable
MD5:8144BD0598A3F245B6FE09C9969C8250
SHA256:F8710ADD7F4A4B06995678E7D2A2670BAB124CEB600A9D3101108DF9E3C6D239
6696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa6696.47360\MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIPcompressed
MD5:B85793D25FF9EDF781C01350B1ED9381
SHA256:7A68AEBD4FACF23BD00754630028700909583BB330F8391C9D67A5499F916DD9
3060Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEC:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEexecutable
MD5:1748F63933E6202E82691341CAFB986B
SHA256:65730EDAB718F812ECC9C0EC41032DFFC961A163BF9CE0BA6CA61E99DA83C31D
3060Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEC:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\speedhack-x86_64.dllexecutable
MD5:0BAD639F7549E3AEC3C7043BA10037A4
SHA256:5EC85A0F12E4AE2A7007BA5252F743C5476B6BA0C5A0870484E6C8407F428E04
3060Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEC:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\xmplayer.exeexecutable
MD5:B1761FCB265515ADB02D3675C6E0D135
SHA256:D66240856AD4A49CDCBAD9DCDD03422E46F269F245B5A74CB750875535A6DC5A
6452Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEC:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEexecutable
MD5:808DE473370EF6B5D98AB752F245A3CA
SHA256:65CBED2E8DB313B8966638E40EB27F94156C294EB060B28A02C130D146518C39
3060Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEC:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\lua5.1-64.dllexecutable
MD5:32718A4EC812B81FD70D4246A94C8731
SHA256:1CB952CA2BCD5646164AE0D1415DE6B6BD1841DE4609481716FCC67BBB6D872E
3060Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXEC:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\defines.luatext
MD5:D8F9B4A10A48EBD8936255F6215C8A43
SHA256:D4347332B232622283E7DD3781F64966BD1097D06CCA7052B467CF99E62898F2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
31
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6164
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6576
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6164
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.16.110.123:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
www.bing.com
  • 2.16.110.123
  • 2.16.110.195
  • 2.16.110.193
  • 2.16.110.170
whitelisted
google.com
  • 142.250.185.238
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.67
  • 20.190.159.68
  • 20.190.159.73
  • 40.126.31.73
  • 40.126.31.71
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
Process
Message
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
sizeof fxstate = 512
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
Offset of LBR_Count=760
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
Symbolhandler: sync: Calling finishedloadingsymbols
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
symbolloader thread finished
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
after finishedloadingsymbols
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
exit finishedLoadingSymbols()
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
Symbol loader thread has finished without errors
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE
finishedLoadingSymbols called