General Info

File name

fj2nr789faz3.exe

Full analysis
https://app.any.run/tasks/6a1d4cad-3e23-47ea-9bc2-f56b5448c9ab
Verdict
Malicious activity
Analysis date
2/11/2019, 11:05:15
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

trojan

rat

revcode

backdoor

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5

2c1ed1aba10af7c676836cfd932fab90

SHA1

61515388b369fcbec12a6da44a2a89d4153431db

SHA256

774c0836fdc60849caca44150a7dbf769f0d8edd3a9b4b7bb6fe2349d32ac502

SSDEEP

24576:LxafzF+ZLuAgeCB+8uL63vlslrFuXRzBUtofLe:Lxacxp/6390rFWB6UK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads the Task Scheduler DLL interface
  • RogueKiller_portable32.exe (PID: 2116)
Writes to a start menu file
  • fj2nr789faz3.exe (PID: 3048)
Application was dropped or rewritten from another process
  • RogueKiller_portable32.exe (PID: 3004)
  • RogueKiller_portable32.exe (PID: 2116)
Loads the Task Scheduler COM API
  • RogueKiller_portable32.exe (PID: 2116)
REVCODE was detected
  • fj2nr789faz3.exe (PID: 316)
Changes the autorun value in the registry
  • fj2nr789faz3.exe (PID: 316)
Creates files in the driver directory
  • RogueKiller_portable32.exe (PID: 2116)
Executable content was dropped or overwritten
  • RogueKiller_portable32.exe (PID: 2116)
  • fj2nr789faz3.exe (PID: 3048)
  • chrome.exe (PID: 3116)
Removes files from Windows directory
  • RogueKiller_portable32.exe (PID: 2116)
Creates or modifies windows services
  • RogueKiller_portable32.exe (PID: 2116)
Creates files in the Windows directory
  • RogueKiller_portable32.exe (PID: 2116)
Low-level read access rights to disk partition
  • RogueKiller_portable32.exe (PID: 2116)
Reads the machine GUID from the registry
  • fj2nr789faz3.exe (PID: 316)
Creates files in the program directory
  • RogueKiller_portable32.exe (PID: 2116)
Application launched itself
  • fj2nr789faz3.exe (PID: 3048)
Starts Internet Explorer
  • RogueKiller_portable32.exe (PID: 2116)
Creates files in the user directory
  • fj2nr789faz3.exe (PID: 316)
  • fj2nr789faz3.exe (PID: 3048)
Application launched itself
  • iexplore.exe (PID: 3256)
  • chrome.exe (PID: 3116)
Reads settings of System Certificates
  • RogueKiller_portable32.exe (PID: 2116)
  • chrome.exe (PID: 3116)
Changes internet zones settings
  • iexplore.exe (PID: 3256)
Reads Internet Cache Settings
  • chrome.exe (PID: 3116)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   UPX compressed Win32 Executable (76%)
.exe
|   Win32 Executable (generic) (12.6%)
.exe
|   Generic Win/DOS Executable (5.6%)
.exe
|   DOS Executable Generic (5.6%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:02:08 17:34:36+01:00
PEType:
PE32
LinkerVersion:
14.15
CodeSize:
811008
InitializedDataSize:
118784
UninitializedDataSize:
405504
EntryPoint:
0x129d40
OSVersion:
6
ImageVersion:
null
SubsystemVersion:
6
Subsystem:
Windows GUI
FileVersionNumber:
0.8.2.0
ProductVersionNumber:
0.4.7.7
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
prize-taking
FileDescription:
adding
FileVersion:
0.8.2.0
InternalName:
untransported.exe
LegalCopyright:
Copyright (C) plenarty 2018
OriginalFileName:
tanistship.exe
ProductName:
interterminal
ProductVersion:
0.4.7.7
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
08-Feb-2019 16:34:36
Detected languages
English - United States
CompanyName:
prize-taking
FileDescription:
adding
FileVersion:
0.8.2.0
InternalName:
untransported.exe
LegalCopyright:
Copyright (C) plenarty 2018
OriginalFilename:
tanistship.exe
ProductName:
interterminal
ProductVersion:
0.4.7.7
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000118
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
3
Time date stamp:
08-Feb-2019 16:34:36
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
UPX0 0x00001000 0x00063000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
UPX1 0x00064000 0x000C6000 0x000C6000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 7.92768
.rsrc 0x0012A000 0x0001D000 0x0001D000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 5.60471
Resources
1

2

3

4

5

6

7

KZPTJRSIK

OYWSXBBXRPXFPJ

SRBTABHGDHUQ

VRQXN

XGJYZP

YESZBAEVL

ZGGFQLDO

ZOVE

Imports
    KERNEL32.DLL

Exports

    No exports.

Screenshots

Processes

Total processes
51
Monitored processes
16
Malicious processes
5
Suspicious processes
0

Behavior graph

+
drop and start start drop and start drop and start fj2nr789faz3.exe #REVCODE fj2nr789faz3.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs roguekiller_portable32.exe no specs roguekiller_portable32.exe iexplore.exe iexplore.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3048
CMD
"C:\Users\admin\Desktop\fj2nr789faz3.exe"
Path
C:\Users\admin\Desktop\fj2nr789faz3.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
prize-taking
Description
adding
Version
0.8.2.0
Modules
Image
c:\users\admin\desktop\fj2nr789faz3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll

PID
316
CMD
"C:\Users\admin\Desktop\fj2nr789faz3.exe"
Path
C:\Users\admin\Desktop\fj2nr789faz3.exe
Indicators
Parent process
fj2nr789faz3.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
prize-taking
Description
adding
Version
0.8.2.0
Modules
Image
c:\users\admin\desktop\fj2nr789faz3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\pdh.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\sspicli.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\avicap32.dll
c:\windows\system32\msvfw32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll

PID
3116
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe"
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221225547
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\credui.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\wpc.dll
c:\windows\system32\samlib.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\users\admin\downloads\roguekiller_portable32.exe
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
3884
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=68.0.3440.106 --initial-client-data=0x78,0x7c,0x80,0x74,0x84,0x6f5900b0,0x6f5900c0,0x6f5900cc
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
3192
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3112 --on-initialized-event-handle=304 --parent-handle=308 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_watcher.dll

PID
2396
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=956,13300915166592475419,930626275460223499,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAACAAwBAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=C1BB9A5EB2536F1F90D7B6B4D363D941 --mojo-platform-channel-handle=976 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\program files\google\chrome\application\68.0.3440.106\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\68.0.3440.106\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\68.0.3440.106\swiftshader\libegl.dll

PID
3060
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,13300915166592475419,930626275460223499,131072 --enable-features=PasswordImport --service-pipe-token=1A51CFF9196A19F0F8CFA9EAFED174A9 --lang=en-US --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1A51CFF9196A19F0F8CFA9EAFED174A9 --renderer-client-id=5 --mojo-platform-channel-handle=1924 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3708
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,13300915166592475419,930626275460223499,131072 --enable-features=PasswordImport --service-pipe-token=DA735E2DB317991817EF4D9DBED52E18 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=DA735E2DB317991817EF4D9DBED52E18 --renderer-client-id=3 --mojo-platform-channel-handle=2052 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2588
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,13300915166592475419,930626275460223499,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=5539AFA79CEA4F7A0477662B19940208 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5539AFA79CEA4F7A0477662B19940208 --renderer-client-id=6 --mojo-platform-channel-handle=3520 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3828
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,13300915166592475419,930626275460223499,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=DEBFF18BBC79502DD58AA849A0AD573E --lang=en-US --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=DEBFF18BBC79502DD58AA849A0AD573E --renderer-client-id=7 --mojo-platform-channel-handle=3556 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
4000
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=956,13300915166592475419,930626275460223499,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=1C961F5021563D57D2CB13247A99BE84 --mojo-platform-channel-handle=3740 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3596
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,13300915166592475419,930626275460223499,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=55C88CD7738026434B422EE36168EDC2 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=55C88CD7738026434B422EE36168EDC2 --renderer-client-id=9 --mojo-platform-channel-handle=4372 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3004
CMD
"C:\Users\admin\Downloads\RogueKiller_portable32.exe"
Path
C:\Users\admin\Downloads\RogueKiller_portable32.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Description
Version
Modules
Image
c:\users\admin\downloads\roguekiller_portable32.exe
c:\systemroot\system32\ntdll.dll

PID
2116
CMD
"C:\Users\admin\Downloads\RogueKiller_portable32.exe"
Path
C:\Users\admin\Downloads\RogueKiller_portable32.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
Modules
Image
c:\users\admin\downloads\roguekiller_portable32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mstask.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\sspicli.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\apphelp.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\imageres.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\windanr.exe
c:\users\admin\desktop\fj2nr789faz3.exe
c:\windows\system32\ncrypt.dll
c:\windows\system32\gpapi.dll

PID
3256
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" "https://adlice.com/thanks-downloading-roguekiller/?utm_campaign=roguekiller&utm_source=soft&utm_medium=btn"
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
RogueKiller_portable32.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\linkinfo.dll

PID
2908
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3256 CREDAT:79873
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll

Registry activity

Total events
1150
Read events
846
Write events
300
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASAPI32
EnableFileTracing
0
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASAPI32
EnableConsoleTracing
0
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASAPI32
FileTracingMask
4294901760
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASAPI32
ConsoleTracingMask
4294901760
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASAPI32
MaxFileSize
1048576
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASAPI32
FileDirectory
%windir%\tracing
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASMANCS
EnableFileTracing
0
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASMANCS
EnableConsoleTracing
0
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASMANCS
FileTracingMask
4294901760
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASMANCS
ConsoleTracingMask
4294901760
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASMANCS
MaxFileSize
1048576
316
fj2nr789faz3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\fj2nr789faz3_RASMANCS
FileDirectory
%windir%\tracing
316
fj2nr789faz3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
316
fj2nr789faz3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
316
fj2nr789faz3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
316
fj2nr789faz3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
316
fj2nr789faz3.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
316
fj2nr789faz3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
RevCode-a319
C:\Users\admin\AppData\Roaming\RevCode-a319.exe
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
3116
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
3116
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
3116
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumAccounts
aggregate
sum()
3116
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumAccounts
S-1-5-21-1302019708-1500728564-335382590-1000
1
3116
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumSignedIn
aggregate
sum()
3116
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumSignedIn
S-1-5-21-1302019708-1500728564-335382590-1000
0
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13194353150504625
3116
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E307020001000B000A00050039005D0300000000
3116
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
1
3192
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
3116-13194353149301500
259
3192
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
3116-13194353149301500
0
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASAPI32
EnableFileTracing
0
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASAPI32
EnableConsoleTracing
0
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASAPI32
FileTracingMask
4294901760
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASAPI32
ConsoleTracingMask
4294901760
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASAPI32
MaxFileSize
1048576
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASAPI32
FileDirectory
%windir%\tracing
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASMANCS
EnableFileTracing
0
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASMANCS
EnableConsoleTracing
0
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASMANCS
FileTracingMask
4294901760
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASMANCS
ConsoleTracingMask
4294901760
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASMANCS
MaxFileSize
1048576
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RogueKiller_portable32_RASMANCS
FileDirectory
%windir%\tracing
2116
RogueKiller_portable32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2116
RogueKiller_portable32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006B000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\RogueKiller_portable32.exe
DumpFolder
C:\ProgramData\RogueKiller\Debug
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\RogueKiller_portable32.exe
DumpCount
10
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\RogueKiller_portable32.exe
DumpType
2
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\RogueKiller_portable32.exe
CustomDumpFlags
0
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight
Type
1
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight
ImagePath
\??\C:\Windows\System32\drivers\truesight.sys
2116
RogueKiller_portable32.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight
Start
3
2116
RogueKiller_portable32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2116
RogueKiller_portable32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\RogueKiller_portable32.exe
2116
RogueKiller_portable32.exe
delete key
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight\Enum
2116
RogueKiller_portable32.exe
delete key
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006C000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\AdminActive
{A3478379-2DE4-11E9-BAD8-5254004A04AF}
0
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
3
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307020001000B000A00060004005401
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
3
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307020001000B000A00060004005901
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3256
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
3
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307020001000B000A00060004004402
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
18
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
3
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307020001000B000A00060004008302
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
45
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
3
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307020001000B000A0006000400F002
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
29
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2908
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006D000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2908
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US

Files activity

Executable files
5
Suspicious files
79
Text files
71
Unknown types
11

Dropped files

PID
Process
Filename
Type
3048
fj2nr789faz3.exe
C:\Users\admin\AppData\Roaming\windowsupdate\winupdate.exe
executable
MD5: 2c1ed1aba10af7c676836cfd932fab90
SHA256: 774c0836fdc60849caca44150a7dbf769f0d8edd3a9b4b7bb6fe2349d32ac502
3116
chrome.exe
C:\Users\admin\Downloads\RogueKiller_portable32.exe
executable
MD5: e6f8ceec9cf20655b20b7ea870563715
SHA256: 8a26f457270b2dcf690f4e55f8c9f803b47b6030a0d2ef9ace26f2c563ac6534
3116
chrome.exe
C:\Users\admin\Downloads\Unconfirmed 819309.crdownload
executable
MD5: e6f8ceec9cf20655b20b7ea870563715
SHA256: 8a26f457270b2dcf690f4e55f8c9f803b47b6030a0d2ef9ace26f2c563ac6534
3116
chrome.exe
C:\Users\admin\Downloads\Unconfirmed 819309.crdownload
executable
MD5: 7854e5912bcd98522f5f5783c923126e
SHA256: ddbe1a14be12634585cafb37765965e3e80f018ab624d7faacea383ab32b2671
2116
RogueKiller_portable32.exe
C:\Windows\system32\drivers\truesight.sys
executable
MD5: 0c997b061e3c66bd9e927c1288eb1cc7
SHA256: 3807e9a1bc159b9e8fc0c7caad10d7213ff8ed8ad1cea9ea552b093c81bf624b
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\logs\AdliceReport_SCN_02112019_100643.json
text
MD5: dd27af441715ec3c36516a8bc97b6cbe
SHA256: 4b1ccfdcadf84a8d97818ac45d6927265e5b86a0bca0c051b2b8607e0ba54146
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\vt.cache
text
MD5: c4301daaef1818eabfaee226ca517fd2
SHA256: 66c7313bd35335535591075366b61e23fceb9ab880674ef0e3c4637d898169de
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\version
text
MD5: 9710b0613d4b98482c777d321bf53bba
SHA256: 574243d57b48886280954fda8cec25fbfdc70e1058f55027e7488a7c3a6b945d
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\wmi
binary
MD5: a9e3823beb293cee5af33e37b6d51941
SHA256: 57101c3b6e819ecba9e364a935f5edb5d6754cf9b24c1496140f8145f9c5b012
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\tasks
binary
MD5: 19d26d4ca2a594f3f5f13118fd46dd2a
SHA256: b9e35c042aa80503bb309c8b1d7fa3f2bbfbf9bec3522c272bf791010d6e5482
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\webconfig
binary
MD5: 8c4f4455ee581811488202c2d38f1553
SHA256: d761d9f1e0c56a36b086799a83f1f7b1f6eaeaf1cce4861467a40abaf7ade902
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\windows
binary
MD5: 1deec0986ca2d19fd9e9e4d3421d572e
SHA256: 64bf7f6e161b41a58af910797151d1c35cdfc778a41793b2770a0b986cd8595a
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\services
binary
MD5: 3afe53c2b99bf7791a1aab0965695c23
SHA256: f140b08b93788d80e6729cfca1d17eb91fe9b4670ee3bc54161fae4c3f188fb6
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\signatures
binary
MD5: de8aaf293606f1376cbfdf56ecba7a14
SHA256: bd010a5fe4e28ff68ee1f70190b1264aeca40a7e2041401126b1b17bd603ae3f
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\regnames
––
MD5:  ––
SHA256:  ––
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\pdb
binary
MD5: db71ffb3e2cc6c227aa29257ff3814b7
SHA256: 54f56f13f4ccd64091b906bb5ca5ab96acfafc976aad146f659b5cb729cbf190
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\ips
binary
MD5: 5b9d7453cf7db331141098aafea44a0d
SHA256: 3162ed18ebd3bf13b59b8d28db2ea5783e4a9f21340da166b0481e74b5737408
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\mbr
binary
MD5: 7a11c1488ea96f09892fde6bef638dd4
SHA256: 8234a17d7734f0e80aa0fe8dacb840730a9f74ef977471a66e1c2f0f1ff88c21
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\hosts
binary
MD5: 7c0571805eefe7569a1d3cc4a9f9b3f1
SHA256: 3aeca634c258643a37409da3d30a25e3aecc085a5311bf43a8b6ee5617812409
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\guid
––
MD5:  ––
SHA256:  ––
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\filenames
––
MD5:  ––
SHA256:  ––
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\domains
binary
MD5: 8ebb18899c89205009c15c2e35c8424e
SHA256: 756ba23f9bd6b0da5264802f1f7957d18f0951109e3c38ad37b988d1d5833d46
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\digisig
binary
MD5: 905f3648f3285f79f2e59d7a056e2e33
SHA256: 94f4575d4f9b9a51a4e32f2ef285abccf6d54d367efcedfcf65c28c4c28bde27
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\signatures\addons
––
MD5:  ––
SHA256:  ––
2116
RogueKiller_portable32.exe
C:\Users\admin\AppData\Local\Temp\as_2F6F.tmp.zip
compressed
MD5: 3fa09b0284bddb167c094d7b13a7fb09
SHA256: 330c9a089014086d18d43387e7821ceaf1d6aeec7a49dca3354b9e23dbc36afc
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\config.ini
binary
MD5: 602bf5f9ae796a8600c8e62998c2a4e6
SHA256: 5c445c5c22b7d6644aa3a511446f9bc6ba918419770d3606401a5a45df690145
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\config.ini
binary
MD5: 446782ace714bf2abb89c097285eb9a2
SHA256: 451830486e702e4e403b6ad95d576ba60af045484a8441d45a33584c6de4cb1f
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\config.ini
binary
MD5: ea899580b5153fa446869db2fa518222
SHA256: 5a00268176dc54b1811f351b61cea1a0f4685903d2d27ced485146311f099f59
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\config.ini
binary
MD5: 25db0e035ee52f5f521c315ee8e5ad6a
SHA256: 88b4658546e96c09b7c3f246802990a7d73eac8370b2e7e2757039760d829620
3256
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{A3478379-2DE4-11E9-BAD8-5254004A04AF}.dat
––
MD5:  ––
SHA256:  ––
3256
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DFDF0481694F5FFE79.TMP
––
MD5:  ––
SHA256:  ––
2908
iexplore.exe
C:\Users\admin\AppData\Local\Temp\JavaDeployReg.log
text
MD5: e91497a726dc70445a80880a049bb4fb
SHA256: 553bdeeeae3357ce88128e8f930a564bc395bc5726bfc7b4c1cedb4b4db78663
3256
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DFDCCAA89E2C6477CA.TMP
––
MD5:  ––
SHA256:  ––
3256
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{A347837A-2DE4-11E9-BAD8-5254004A04AF}.dat
––
MD5:  ––
SHA256:  ––
3256
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\RecoveryStore.{A347837B-2DE4-11E9-BAD8-5254004A04AF}.dat
binary
MD5: cdc821b290865be1e04ea919ae28fd99
SHA256: 83baceb660e36b7608d9d6051597103552ca4bb79ce99d574bb022333b491c37
3256
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\{A347837C-2DE4-11E9-BAD8-5254004A04AF}.dat
binary
MD5: 83311659dd8d3ad9210d2520aea3af4c
SHA256: 495f7e017c95350e933998d0d2389e665efbfb84c6d17f81bae740ea76016bd9
3256
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DFCEE06EBE96B8204C.TMP
––
MD5:  ––
SHA256:  ––
3256
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DFE9B1C60AD4D91AA1.TMP
––
MD5:  ––
SHA256:  ––
3256
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[3].png
image
MD5: 9fb559a691078558e77d6848202f6541
SHA256: 6d8a01dc7647bc218d003b58fe04049e24a9359900b7e0cebae76edf85b8b914
3256
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
––
MD5:  ––
SHA256:  ––
3256
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000003.log
binary
MD5: b67900e52365a9358b9b345d3decf861
SHA256: 61968a829a71566ccc8174b61c2cef0cbd97f13794d07e85c7ca3708542e4474
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
text
MD5: df926954040274f3b4e455bdb16cc8b7
SHA256: 2354e3a986fc20577897063e69e1e8140b9e1b3a1d16a4ea95a6d87d3b5a8cda
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
text
MD5: 67ab2a870348fb7852b22bbe51e67d60
SHA256: fca3d47f84312bb79405d52d8b0b30e971d5a7cbf3f7a8dfbc55f0a014f8e044
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs
sqlite
MD5: 6dc149273999634db853c7d280035960
SHA256: 436a2a75a80008e98d55a42c9649e6a4aa3ee78028faa46786f42d4d65df9eaf
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cookies
sqlite
MD5: a7a21efdf2593098a399e55108bca957
SHA256: 75304559fb95efc9a38c06703e360daf905543555e8006643b339ec4bf8eadcf
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs-journal
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
binary
MD5: d932a31a0fb91833edb0325c6b434b34
SHA256: 8049465356163740d6e4c0bb56b9dcaa90149631646fa6bb56d01de223bd1f8e
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF19dcaa.TMP
text
MD5: 41e2c26463ba0c255095aa8cef719c4b
SHA256: 014864a2bb39588f78a4364f689af140419611ec2cee51b8db1f87871c3fae09
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State
text
MD5: 41e2c26463ba0c255095aa8cef719c4b
SHA256: 014864a2bb39588f78a4364f689af140419611ec2cee51b8db1f87871c3fae09
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 32f16b5edd24c84208b7b0daa5016e0d
SHA256: 32e50addc07a93c2464881eb4ad7cad371bd0ad410a4756a29046df72e168f2a
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF19dcaa.TMP
text
MD5: 32f16b5edd24c84208b7b0daa5016e0d
SHA256: 32e50addc07a93c2464881eb4ad7cad371bd0ad410a4756a29046df72e168f2a
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\18505384-8ce2-4c36-83a5-248611c0887f.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
binary
MD5: ed3d1c71e33729de7febf8fe5e6ec916
SHA256: 69c86a85adc870f4b414d529894f622580db21bbefb5e2c4da4ba14141c7b1fc
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index-dir\the-real-index
binary
MD5: 583bcf96f6f6b406dd1bd159640d136b
SHA256: 35ad7f7d2f43f74e16272ff7ab34c67f51684245d72eb54a0484750a5985a17d
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\bd05e174-dcdd-478b-bd69-0974dbcabdda\index-dir\the-real-index
binary
MD5: 09afead8c21a12a5073c513ad922ed75
SHA256: c0112b29842f0702c4470a2321a50ef9545b72d1c51da5127a3c3b45f37e9c4f
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\bd05e174-dcdd-478b-bd69-0974dbcabdda\index-dir\the-real-index~RF19dc8b.TMP
binary
MD5: 09afead8c21a12a5073c513ad922ed75
SHA256: c0112b29842f0702c4470a2321a50ef9545b72d1c51da5127a3c3b45f37e9c4f
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index-dir\the-real-index~RF19dc8b.TMP
binary
MD5: 583bcf96f6f6b406dd1bd159640d136b
SHA256: 35ad7f7d2f43f74e16272ff7ab34c67f51684245d72eb54a0484750a5985a17d
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\9d414097-51e7-4874-9e62-467cbfae87bc.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\QuotaManager
sqlite
MD5: 978142eb76517dd59489020b4d17bfb8
SHA256: b0bc1d4267514be3ce7f86e730601b1f4ba594a4260b72703c1e6f4669618595
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
binary
MD5: 319488873828e4763957a19397bbf972
SHA256: 5ab0c2580c2699cbff0149c1480f34065c96b3cfdd0f47914d0b008c6005a186
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies
sqlite
MD5: f3bc8f6d7f5865207e8d48df35396b7f
SHA256: f9ab75acf12ef2ea363e8ecc2cc8d09c726decf6d65707680af646e63ba7fdaf
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
binary
MD5: dad7a721a3b8785c9acb43e27178d033
SHA256: 28615ee5ad0953d5f79f3c1223fe34136db573ff66801854d5e46fc148e4b754
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
binary
MD5: a8dfa50097679dd4e9839443e0400766
SHA256: 6f4ba9c9a198d1a5edefef57c79a70718e3d065593b0d27c376ace520a0d67ac
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG
text
MD5: 7ee1b83e8f3457fb10930c641fb2f60f
SHA256: 1f07f2b700776da79b3ee9ff27263c60ad2555bec98de859d8bb0bcb0a1652df
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF19dc6c.TMP
text
MD5: e0c898872e5231b4a0b809add31f0c8d
SHA256: 76dc9252258940bdb95e2aa6d534a7f8a63da31e7a5f083b19815b1fee240cf2
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: e0c898872e5231b4a0b809add31f0c8d
SHA256: 76dc9252258940bdb95e2aa6d534a7f8a63da31e7a5f083b19815b1fee240cf2
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\QuotaManager-journal
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies-journal
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index-dir\temp-index
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\bd05e174-dcdd-478b-bd69-0974dbcabdda\index-dir\temp-index
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\000003.log
binary
MD5: cf60531216d084f188e6998d949bc29b
SHA256: 4c1e03d80238c0216f5610f9e4ebc93d3d8c32015c43213b4eec7dc3b7043acc
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF19dc5c.TMP
text
MD5: 32f16b5edd24c84208b7b0daa5016e0d
SHA256: 32e50addc07a93c2464881eb4ad7cad371bd0ad410a4756a29046df72e168f2a
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
text
MD5: ee87b251e7e16622f2149eccfe9acd7b
SHA256: 0020ed5bfb4ec3b8dd8fb828fefec8a0a8e7ac6dd09d2c348cbf200d7632c49a
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
binary
MD5: 7abf84a9c8fd089138e77bf577944b20
SHA256: 677c5c208563f0ba771857b51ba8311dadd25bcb625890f01f6e41675370d6f2
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\be55145e-69cc-46a7-bff8-f1ad8c5f7155.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\2ee09898-3f13-4c94-a9ec-811d35c41eb5.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Tabs
binary
MD5: 9409bab446b7204c6235dfddd6066e89
SHA256: 68c1cb50ec24ac5a1dbdc7d9c845e94a1e9d60f312cf92a694f0791cd7ea105e
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
text
MD5: a055871a927e644465178ceb370618c9
SHA256: ba06e3f863ae9b51d24bba8b2b1d2347ca3dfbfbf2250168efe5d379111732b9
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
text
MD5: de428b8ce67493771ab9474a93683ab0
SHA256: 0fc16fedc58fc38fdf89f8d00e13262ce650f80e4aee94ef64bd29d0fd966ba9
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000016
binary
MD5: cf286cb4fd0f3dcc234806e1b865987b
SHA256: 21dc23520bba7268b53957a39981c9a85d3658edc4f5455e98cac3378a440d76
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG
text
MD5: f12466e3c3090634cba8b8b5b9c9104a
SHA256: c8ae2798e59c2bf399fbab299aadd0cab3cec87e3821c20f5485d60975f88e05
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG
text
MD5: 4d9ac062c6aad87aa4c8035f6fa95361
SHA256: 555fe6303978536fc4c9b4650c243690b94b7fff757f0fb0f3e635904f40417c
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
text
MD5: d593db331c05d4c577e98c40fa83205a
SHA256: 452dc1c93c9bcac95c9c821629960461d7e4000803c9b357b8aea306a45f5efe
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
text
MD5: 8058b30be0e632287a1351afdcfa2aba
SHA256: d82794e9be37e90b1a76f0181c5f69bc7918eeb1ce9c74ef028ea1a5004c06f7
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\MANIFEST-000016
binary
MD5: cf286cb4fd0f3dcc234806e1b865987b
SHA256: 21dc23520bba7268b53957a39981c9a85d3658edc4f5455e98cac3378a440d76
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data
sqlite
MD5: 294ffa3fef32aa3699cd23414f8ce53e
SHA256: fffc895d544a0049b09d122bd872d0691ff16c277e0dd74f4efb418835879e43
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Shortcuts
sqlite
MD5: bf35a15d48cfe473e61311794b68100b
SHA256: 52a0949799eb18af4bb56834973b511acab3619727143a8be5290ce4b2428a34
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Shortcuts-journal
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: 189e400507a7c9c0d0831276555cd7b3
SHA256: 70fd3eaa66b80bb4b8950bb6d83bb5bdf1a4b11594a4b6ae113705f62c13583b
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Favicons
sqlite
MD5: dddf8f440dd82b7e7faa496729902502
SHA256: 15768c984800f33601b18d63e11bc6969f7a310085113bf4eb4b2d132a452dd7
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
binary
MD5: a9851aa4c3c8af2d1bd8834201b2ba51
SHA256: e708be5e34097c8b4b6ecb50ead7705843d0dc4b0779b95ef57073d80f36c191
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History
sqlite
MD5: f04f1621fe826cc541caf584c3a7b8b3
SHA256: 345c668e635f6c15b5ab9dd4b4637a3fe343873ab76e2209e64703e65b6f797f
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Login Data
sqlite
MD5: 54ad1e10b6b57bc9b9eed994e581dd5f
SHA256: 24d2a7516de320c3e91b1513cad94ce5ce2b964bbb8a3d1f66e8083b3205b19c
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF19dbc0.TMP
text
MD5: 189e400507a7c9c0d0831276555cd7b3
SHA256: 70fd3eaa66b80bb4b8950bb6d83bb5bdf1a4b11594a4b6ae113705f62c13583b
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History-journal
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Current Session
binary
MD5: df9509c5ea8c1816276f8da202224378
SHA256: b84241813d941164d960b7504331fd19ffeb7abd604582378f2d1328e0e20687
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\53f48cb2-dedc-4dc6-9576-346ce6321377.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF19dae5.TMP
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\43390687-0d88-4e99-9401-33ada3adf274.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF19da68.TMP
text
MD5: df64e47a3ab23717818a2d48902f24ea
SHA256: 7d8b5e5e489781ad8cbb1d32183bc6e1ed89f7957f0f7db4df99be6996f4e05f
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: df64e47a3ab23717818a2d48902f24ea
SHA256: 7d8b5e5e489781ad8cbb1d32183bc6e1ed89f7957f0f7db4df99be6996f4e05f
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\5297e76d-9021-41f6-b1b4-deba1df07d5c.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\DownloadMetadata
binary
MD5: 61216fc0173b46ec44616474b9d9bf9b
SHA256: c7c3f440202a62806a439efe952d4ec1828ed1a0a4beb7a5692199c1d5abc761
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\DownloadMetadata~RF19d5e4.TMP
binary
MD5: 61216fc0173b46ec44616474b9d9bf9b
SHA256: c7c3f440202a62806a439efe952d4ec1828ed1a0a4beb7a5692199c1d5abc761
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\3a0d754a-6f2d-4301-9e9a-5a76fb0139b1.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\caecb3bd-7969-4305-84d6-3a376453ec73\index-dir\the-real-index
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\caecb3bd-7969-4305-84d6-3a376453ec73\index-dir\the-real-index~RF19d519.TMP
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\caecb3bd-7969-4305-84d6-3a376453ec73\index-dir\temp-index
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\index.txt
binary
MD5: 8971a4e3307dc2b3e39a77c81b54d5a5
SHA256: 6d3d940a736a79f7787d6f7f22685d110698c8f1eec72494bb56261dc6072303
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\index.txt~RF19d4f9.TMP
binary
MD5: 8971a4e3307dc2b3e39a77c81b54d5a5
SHA256: 6d3d940a736a79f7787d6f7f22685d110698c8f1eec72494bb56261dc6072303
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\caecb3bd-7969-4305-84d6-3a376453ec73\index-dir\the-real-index~RF19d4ea.TMP
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\index.txt.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\bd05e174-dcdd-478b-bd69-0974dbcabdda\e64f4a26267430e4_1
binary
MD5: 9ee335d4c3be0dc5c9793072bc26c8ba
SHA256: 8291d1a48c29f8a3ff053d70e52ae23622f66db134c40c57e4bc329cd3a18f41
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\bd05e174-dcdd-478b-bd69-0974dbcabdda\e64f4a26267430e4_0
binary
MD5: 5f80521a60dc16b47da1542f5bfcbb54
SHA256: 6f645d53a522b05f4efb276d410519328c63d05cb6edd71fc1842cd99f32364b
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\bd05e174-dcdd-478b-bd69-0974dbcabdda\4db55b0a5eaa7ca5_0
binary
MD5: 8fd53cbfbad522c7edfc2bc88eeba41f
SHA256: 1ed61841f2605a07038cc0e40f057b3ef7a78bd672e9686bc085c2ca252d393c
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000013
flc
MD5: 6fc386b3403bd022fcb73a30a5045c9d
SHA256: 4e30e892faee5cd30cd67c4fc26ac8c7e397dc70c1d58a37a9e77e993504b476
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\index.txt
binary
MD5: 80dc508395af9dc60a34acab64fb6972
SHA256: 276a058cb98b7a008c8903a2ed087a75a1c4552babdd1d4caf5f42778a4baf51
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\index.txt~RF19d382.TMP
binary
MD5: 80dc508395af9dc60a34acab64fb6972
SHA256: 276a058cb98b7a008c8903a2ed087a75a1c4552babdd1d4caf5f42778a4baf51
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\bd05e174-dcdd-478b-bd69-0974dbcabdda\index
text
MD5: 4f67aba5cb5b04976834ad6da18d2017
SHA256: 4476d281b3d119577eb8f19fd90e042e5a456cba30d0bb16d05654acc91aec5b
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\ba23d8ecda68de77_1
binary
MD5: 4d040256e35f2728b0bad5741f385657
SHA256: e0f22fffe17afce44a253dbebf0354f48911b4c8fe75a5a791bab15f8181452d
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\ba23d8ecda68de77_0
binary
MD5: 7abdbe2b02ace1890ef7c7f7c3648883
SHA256: 584df34178dcaf0f153b0a58e6f2921caf2903f52e404dcd486d29df9925e981
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\DownloadMetadata
binary
MD5: d8d79912bb957b8497a9c6bd1c7458bd
SHA256: 2f7d01beecc1a89d0577b051f46dca16bcbf2609980a838ca66a92288ead4dec
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\in_progress_download_metadata_store
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\in_progress_download_metadata_store~RF19d18e.TMP
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\43831b37-c976-4517-b736-fb11fc5c5813.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ab77e94b-5a5c-404d-a215-94e97164d2e6.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.de_0.indexeddb.leveldb\000003.log
binary
MD5: 991641dbcc63a7eacba784846f16492f
SHA256: d402a1e89776f26565012ebd063638b57e09e58efc77105415906eebafc0fdd0
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.de_0.indexeddb.leveldb\LOG
text
MD5: 83c2b2c96a8858282bc6831ca0cc9732
SHA256: 09f2d11dd18ea0bbd9aaf7a6dcb3c2525f335603ebef8ee5b528d69a8c3baae0
3116
chrome.exe
C:\Users\admin\Downloads\RogueKiller_portable32.exe:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\logs\AdliceReport_SCN_02112019_100643.json
text
MD5: 0e2ecc970cb279c64a488c77b107c102
SHA256: abb0ca82b5212486e0977742134a531a6da78dab8817d6d2ccaf51ae51e50704
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000012
compressed
MD5: 7a3cb9df72697034f7a9b99af59983b6
SHA256: 61770cbac81339f8cd850a20321bfc4320d03b29711b8991d47f6b34a6528b08
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\index.txt
binary
MD5: 118d8ceef066c724713401939b326e91
SHA256: fa94bc9fd4bf3df0b3456472bae7acf3517ea387a207225e29f4dec62831a4cd
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\index.txt~RF19ce43.TMP
binary
MD5: 118d8ceef066c724713401939b326e91
SHA256: fa94bc9fd4bf3df0b3456472bae7acf3517ea387a207225e29f4dec62831a4cd
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000011
binary
MD5: 128c2b622d1e6b7418c99a1637fb9a31
SHA256: afb47645b91d976f95d132320ddf96c3a6e2b3bd0116d90588243d6c52f7842f
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\logs\AdliceReport_DEL_02112019_100654.json
text
MD5: d6441c55f3becbec1e85f8392709523b
SHA256: 41db018105c2544a201834e8f6a2fe6db752e8c61a332cd6f20d638255bf74bb
2116
RogueKiller_portable32.exe
C:\ProgramData\RogueKiller\config.ini
binary
MD5: 49ecdac6bf1511f2da5ba1870d6ffa83
SHA256: 7c1596735901889351a6cdd79b99dde72ec73c777899fd12752c85223f4164eb
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\in_progress_download_metadata_store
binary
MD5: b99f2a98ef6ca183d02bd35b1b22c93e
SHA256: 79a554c5cf0996d5448f076a9631947eb3acadeaeac86b582408c6c3a9a8c3ed
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\in_progress_download_metadata_store~RF19c402.TMP
binary
MD5: b99f2a98ef6ca183d02bd35b1b22c93e
SHA256: 79a554c5cf0996d5448f076a9631947eb3acadeaeac86b582408c6c3a9a8c3ed
3116
chrome.exe
C:\Users\admin\Downloads\3eada729-7bdf-47ac-af23-3be896f5e8cb.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\d0a1addb-dc10-4e3f-a54f-468bdb6c624f.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000010
compressed
MD5: 1b7227da00e4bd9da370113d89ca7f40
SHA256: 45e11133387ab0fefe4705aa0a641ac39723412b504a03192ac825487d95aa96
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Session
binary
MD5: 02536c23edc1e418a6fea313d20b2a39
SHA256: 8e8de8689482b477d0beebe0a4ac24b9cabcbfa84848f66b4c0f55cd96dc0fe9
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old
text
MD5: 80b8c44b60f8bd20d1cf8277ec794bb1
SHA256: 6371157cf7270dd227625ddf799da6c38c60b3e2110fe540b8bc9df48aef09a6
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old~RF19bd7a.TMP
text
MD5: 80b8c44b60f8bd20d1cf8277ec794bb1
SHA256: 6371157cf7270dd227625ddf799da6c38c60b3e2110fe540b8bc9df48aef09a6
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000f
compressed
MD5: 52084fa108193d5b2c71a12c410b5652
SHA256: ad2853845c2e83d33e4618d72f881f5fbdcd3a2dc605d3e217ebb0552624410d
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000e
image
MD5: 0515236318ac3251ff39eb8372a0c129
SHA256: 228cb9c602929e1a2fb17408fe812af3599ab9f734d0b7c499ab79e15c5b8dd4
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000d
binary
MD5: c70c8577dc61519a4ed87836240e5d3c
SHA256: 6ae71e28683a3d227c4adbe7d325f6016e99f774ac1b2658e4535f8de7b8f623
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\caecb3bd-7969-4305-84d6-3a376453ec73\40bba07c05914591_0
binary
MD5: af359b85819003ae2a8e4444637b38b1
SHA256: 238303c5422f4231922369c4a8614b0bcb222ec341b045a3e48a053f01e0d066
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.de_0.indexeddb.leveldb\LOG.old
text
MD5: 65e3a899ee20811d157b572ffa34a607
SHA256: fdbc070214092df54b10dc06b2a40f0cc30ad00d410ba67de9f98a3d53f08a75
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF19ba7c.TMP
text
MD5: 7282c871a31b4aae7e61cdbb39a13331
SHA256: af615c556e2a22e87135a967c01e869216f65268a88bd218fd6ab70467bdf733
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old
text
MD5: 7282c871a31b4aae7e61cdbb39a13331
SHA256: af615c556e2a22e87135a967c01e869216f65268a88bd218fd6ab70467bdf733
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\caecb3bd-7969-4305-84d6-3a376453ec73\e64f4a26267430e4_0
binary
MD5: 9791b74a1616035a490a766eaaf50b38
SHA256: 0fec8ac52148063347f274f38f752b005bd90095d06130ab244c058d44bf5969
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000c
compressed
MD5: 1a2e809ef04228cd18e3e2158c073614
SHA256: 1dc3f335d9bbc0fbea412449a63d1b96e4e610468b61f04249c9193e1ab46d48
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old
text
MD5: ea6d75c35eb812fdc5762d84963de026
SHA256: a4e911f2978a45872ede6742468623884a33bca6e015dfb35dd4d55034d9ab74
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old~RF19b9d0.TMP
text
MD5: ea6d75c35eb812fdc5762d84963de026
SHA256: a4e911f2978a45872ede6742468623884a33bca6e015dfb35dd4d55034d9ab74
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\caecb3bd-7969-4305-84d6-3a376453ec73\50da1ec5d44a313d_0
binary
MD5: dd646fd3d7c2e1f9c4606ed3280d4578
SHA256: 398e3db22f172ab26ee6817b2166779375d424ec53466a7532d33f40d09e5125
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\caecb3bd-7969-4305-84d6-3a376453ec73\3a41e250d088c297_0
binary
MD5: af54f970c7dc1161db86ab9dddff21ba
SHA256: e5b3fe37b68c05dc76ecce9abb76f853627c772ccf7c9653889e12f1c476e3c1
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old
text
MD5: 84042895723ac99f9599edfc7500051c
SHA256: ac49bbf4b490c77bddf11de45ef4965c72b16b00cb2519fdb627363f760c6219
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF19b963.TMP
text
MD5: 84042895723ac99f9599edfc7500051c
SHA256: ac49bbf4b490c77bddf11de45ef4965c72b16b00cb2519fdb627363f760c6219
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\caecb3bd-7969-4305-84d6-3a376453ec73\index-dir\the-real-index~RF19b934.TMP
binary
MD5: 7310bf883e828ae9b8e6bd793d45e139
SHA256: 6a17c6592725f64037ee1e3ce5a71ebc0535c92c7ca7ecdca4f055dee0ca6fac
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\e6622492fa163609ddd4212f54512baa07929ed3\caecb3bd-7969-4305-84d6-3a376453ec73\index-dir\the-real-index
binary
MD5: 7310bf883e828ae9b8e6bd793d45e139
SHA256: 6a17c6592725f64037ee1e3ce5a71ebc0535c92c7ca7ecdca4f055dee0ca6fac
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\4cb013792b196a35_1
binary
MD5: 6823f182de81f18e2bc7a083c5bd2c83
SHA256: 89d6c9b76440cae4b38175812f2da9b966f04ceb30becf9727b9c0572e4dc98a
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Translate Ranker Model~RF19b83a.TMP
binary
MD5: 8a086e8c57f61e02e888acc7d7813313
SHA256: 0be93d7aff82bedf45fd9c3cd81964836b3be8cec84a218d5e4a5f1b65ac6579
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Translate Ranker Model
binary
MD5: 8a086e8c57f61e02e888acc7d7813313
SHA256: 0be93d7aff82bedf45fd9c3cd81964836b3be8cec84a218d5e4a5f1b65ac6579
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\5e97de50-47cb-4014-908e-d2e8b5ddb4e3.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old
text
MD5: f727dd25cda7b2cc574098cee1f5764a
SHA256: 5f7bd6926940e400ee7faa6d620192ca299f7b5aaa92d672f8173a767b3fbbff
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old~RF19b53c.TMP
text
MD5: f727dd25cda7b2cc574098cee1f5764a
SHA256: 5f7bd6926940e400ee7faa6d620192ca299f7b5aaa92d672f8173a767b3fbbff
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT
text
MD5: edd71dd3bade6cd69ff623e1ccf7012d
SHA256: befea596b4676ccf7cc37ea8048044bfa0556c8931d76fdeeb693d20264e50d6
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT~RF19b4bf.TMP
text
MD5: edd71dd3bade6cd69ff623e1ccf7012d
SHA256: befea596b4676ccf7cc37ea8048044bfa0556c8931d76fdeeb693d20264e50d6
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\CURRENT
text
MD5: edd71dd3bade6cd69ff623e1ccf7012d
SHA256: befea596b4676ccf7cc37ea8048044bfa0556c8931d76fdeeb693d20264e50d6
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\CURRENT~RF19b4bf.TMP
text
MD5: edd71dd3bade6cd69ff623e1ccf7012d
SHA256: befea596b4676ccf7cc37ea8048044bfa0556c8931d76fdeeb693d20264e50d6
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000016.dbtmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\000016.dbtmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old~RF19b452.TMP
text
MD5: 1aa66efdb743fb0a8dcc1cd79b0b6542
SHA256: 28d56532cced7375a2a1c7731e57c1a1c2ec1ac9827f3e5beee7f8069a5f87dd
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old
text
MD5: 1aa66efdb743fb0a8dcc1cd79b0b6542
SHA256: 28d56532cced7375a2a1c7731e57c1a1c2ec1ac9827f3e5beee7f8069a5f87dd
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\c748aabe-f7b3-49cd-acaf-4bff11d56782.tmp
––
MD5:  ––
SHA256:  ––
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF19b452.TMP
text
MD5: 197882774a7ecec9046bc48f63189b66
SHA256: 27377b0d5f989997c2c3f74acf163eed44b60631ddaa768f6655d7be555742b2
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old
text
MD5: 92be6b127e72365885ad4c3fb6534ee2
SHA256: 54302a2573acc775720e7db0ad85873276713302b4f72596a8dcc44b01c70e51
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF19b452.TMP
text
MD5: 92be6b127e72365885ad4c3fb6534ee2
SHA256: 54302a2573acc775720e7db0ad85873276713302b4f72596a8dcc44b01c70e51
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old
text
MD5: 197882774a7ecec9046bc48f63189b66
SHA256: 27377b0d5f989997c2c3f74acf163eed44b60631ddaa768f6655d7be555742b2
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old
text
MD5: 8ca4ba2b95d7089861a48ed69fde6561
SHA256: aa64c14d0c68b62bbab62a6d6fa4662ff89e1fbc7b337c926ac213c191d6406c
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old~RF19b423.TMP
text
MD5: 8ca4ba2b95d7089861a48ed69fde6561
SHA256: aa64c14d0c68b62bbab62a6d6fa4662ff89e1fbc7b337c926ac213c191d6406c
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version
text
MD5: c10ebd4db49249efc8d112b2920d5f73
SHA256: 90a1b994cafe902f22a88a22c0b6cc9cb5b974bf20f8964406dd7d6c9b8867d1
3884
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
binary
MD5: b59113c2dcd2d346f31a64f231162ada
SHA256: 1d97c69aea85d3b06787458ea47576b192ce5c5db9940e5eaa514ff977ce2dc2
3116
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
binary
MD5: 9c016064a1f864c8140915d77cf3389a
SHA256: 0e7265d4a8c16223538edd8cd620b8820611c74538e420a88e333be7f62ac787
3048
fj2nr789faz3.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winupdate.eu.url
ini
MD5: 28044b6d322b876f138b248bbecbbc07
SHA256: 85cc4eb5883ac26902562da0a5f2ea7e04647d9184f7748bc6f922fa27f43f89
316
fj2nr789faz3.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
dat
MD5: d7a950fefd60dbaa01df2d85fefb3862
SHA256: 75d0b1743f61b76a35b1fedd32378837805de58d79fa950cb6e8164bfa72073a

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
1
TCP/UDP connections
56
DNS requests
21
Threats
50

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3256 iexplore.exe GET 200 204.79.197.200:80 http://www.bing.com/favicon.ico US
image
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
316 fj2nr789faz3.exe 37.59.134.55:443 OVH SAS FR malicious
3116 chrome.exe 172.217.23.131:443 Google Inc. US whitelisted
3116 chrome.exe 216.58.205.227:443 Google Inc. US whitelisted
3116 chrome.exe 172.217.18.99:443 Google Inc. US whitelisted
3116 chrome.exe 216.58.206.10:443 Google Inc. US whitelisted
3116 chrome.exe 172.217.22.13:443 Google Inc. US whitelisted
3116 chrome.exe 172.217.22.46:443 Google Inc. US whitelisted
3116 chrome.exe 178.33.106.117:443 OVH SAS FR suspicious
3116 chrome.exe 172.217.18.100:443 Google Inc. US whitelisted
3116 chrome.exe 172.217.16.195:443 Google Inc. US whitelisted
3116 chrome.exe 216.58.208.46:443 Google Inc. US whitelisted
3116 chrome.exe 172.217.21.202:443 Google Inc. US whitelisted
3116 chrome.exe 172.217.22.3:443 Google Inc. US whitelisted
2116 RogueKiller_portable32.exe 178.33.106.117:443 OVH SAS FR suspicious
2908 iexplore.exe 104.27.164.26:443 Cloudflare Inc US shared
3256 iexplore.exe 204.79.197.200:80 Microsoft Corporation US whitelisted
2116 RogueKiller_portable32.exe 74.125.34.46:443 Google Inc. US whitelisted

DNS requests

Domain IP Reputation
slicid.wm01.to 37.59.134.55
malicious
www.google.de 216.58.205.227
whitelisted
www.gstatic.com 172.217.18.99
whitelisted
clientservices.googleapis.com 172.217.23.131
whitelisted
safebrowsing.googleapis.com 216.58.206.10
whitelisted
accounts.google.com 172.217.22.13
shared
ssl.gstatic.com 172.217.23.131
whitelisted
apis.google.com 172.217.22.46
whitelisted
download.adlice.com 178.33.106.117
whitelisted
www.google.com 172.217.18.100
whitelisted
www.google.no 172.217.16.195
whitelisted
sb-ssl.google.com 216.58.208.46
whitelisted
fonts.googleapis.com 172.217.21.202
whitelisted
fonts.gstatic.com 172.217.22.3
whitelisted
adlice.com 104.27.164.26
104.27.165.26
suspicious
www.bing.com 204.79.197.200
13.107.21.200
whitelisted
sigs.adlice.com 178.33.106.117
malicious
adflux.adlice.com 178.33.106.117
malicious
www.virustotal.com 74.125.34.46
whitelisted
stats.adlice.com 178.33.106.117
whitelisted

Threats

PID Process Class Message
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert
316 fj2nr789faz3.exe A Network Trojan was detected MALWARE [PTsecurity] RevCode RAT Cert

25 ETPRO signatures available at the full report

Debug output strings

Process Message
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_portable32.exe libpng warning: iCCP: known incorrect sRGB profile
RogueKiller_po