General Info Watch the FULL Interactive Analysis at ANY.RUN!

File name

oanda4setup.exe

Verdict
Malicious activity
Analysis date
2/11/2019, 05:05:53
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5

0db00a483673daa7e3355a9837db4090

SHA1

b205351045302f1a6608a0351330e78b3206dbe9

SHA256

7790740c1975a6903bda8cc5db687d6e4af7ce2aff46ea101074631efbe63f2f

SSDEEP

24576:Y+Gxs/2sDdVHpk4CtdjNz88X10h603HOTXapEijstHSmjd:zGxWDXHpk/jNzJl63sXapItH1R

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • terminal.exe (PID: 3220)
  • metaeditor.exe (PID: 1520)
  • metaeditor.exe (PID: 2316)
  • terminal.exe (PID: 3888)
  • metaeditor.exe (PID: 2528)
  • terminal.exe (PID: 2896)
Changes settings of System certificates
  • oanda4setup.exe (PID: 3628)
Executable content was dropped or overwritten
  • terminal.exe (PID: 2896)
  • oanda4setup.exe (PID: 3628)
Creates files in the user directory
  • metaeditor.exe (PID: 2316)
  • oanda4setup.exe (PID: 3000)
  • oanda4setup.exe (PID: 3628)
  • terminal.exe (PID: 2896)
Starts Internet Explorer
  • oanda4setup.exe (PID: 3628)
Low-level read access rights to disk partition
  • terminal.exe (PID: 3888)
  • oanda4setup.exe (PID: 3628)
Changes IE settings (feature browser emulation)
  • terminal.exe (PID: 3888)
Application launched itself
  • oanda4setup.exe (PID: 3000)
Creates a software uninstall entry
  • oanda4setup.exe (PID: 3628)
Reads internet explorer settings
  • oanda4setup.exe (PID: 3628)
Modifies the open verb of a shell class
  • terminal.exe (PID: 3888)
Adds / modifies Windows certificates
  • oanda4setup.exe (PID: 3628)
Creates files in the program directory
  • oanda4setup.exe (PID: 3628)
Reads internet explorer settings
  • iexplore.exe (PID: 684)
  • iexplore.exe (PID: 3800)
Changes internet zones settings
  • iexplore.exe (PID: 3108)
  • iexplore.exe (PID: 3816)
Application launched itself
  • iexplore.exe (PID: 3816)
Creates files in the user directory
  • iexplore.exe (PID: 3800)
Reads settings of System Certificates
  • oanda4setup.exe (PID: 3628)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (52.9%)
.exe
|   Generic Win/DOS Executable (23.5%)
.exe
|   DOS Executable Generic (23.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
1970:01:14 10:16:48+01:00
PEType:
PE32
LinkerVersion:
14.16
CodeSize:
999424
InitializedDataSize:
159744
UninitializedDataSize:
2224128
EntryPoint:
0x312d70
OSVersion:
6
ImageVersion:
null
SubsystemVersion:
6
Subsystem:
Windows GUI
FileVersionNumber:
5.0.0.1983
ProductVersionNumber:
5.0.0.1983
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Dynamic link library
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
https://www.metaquotes.net
CompanyName:
MetaQuotes Software Corp.
FileDescription:
Setup
FileVersion:
5.0.0.1983
InternalName:
Setup
LegalCopyright:
© 2000-2019, MetaQuotes Software Corp.
LegalTrademarks:
MetaTrader
OriginalFileName:
Setup
ProductName:
Setup
ProductVersion:
5.0.0.1983

Screenshots

Processes

Total processes
46
Monitored processes
14
Malicious processes
7
Suspicious processes
1

Behavior graph

+
start drop and start oanda4setup.exe no specs oanda4setup.exe terminal.exe no specs iexplore.exe iexplore.exe iexplore.exe iexplore.exe explorer.exe no specs explorer.exe no specs terminal.exe metaeditor.exe no specs terminal.exe no specs metaeditor.exe no specs metaeditor.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3000
CMD
"C:\Users\admin\AppData\Local\Temp\oanda4setup.exe"
Path
C:\Users\admin\AppData\Local\Temp\oanda4setup.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
MetaQuotes Software Corp.
Description
Setup
Version
5.0.0.1983
Modules
Image
c:\users\admin\appdata\local\temp\oanda4setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
3628
CMD
"C:\Users\admin\AppData\Local\Temp\oanda4setup.exe"
Path
C:\Users\admin\AppData\Local\Temp\oanda4setup.exe
Indicators
Parent process
oanda4setup.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
MetaQuotes Software Corp.
Description
Setup
Version
5.0.0.1983
Modules
Image
c:\users\admin\appdata\local\temp\oanda4setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\oanda - metatrader\terminal.exe
c:\program files\oanda - metatrader\metaeditor.exe
c:\program files\oanda - metatrader\uninstall.exe
c:\windows\system32\apphelp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\netutils.dll

PID
3888
CMD
"C:\Program Files\OANDA - MetaTrader\terminal.exe" /install
Path
C:\Program Files\OANDA - MetaTrader\terminal.exe
Indicators
No indicators
Parent process
oanda4setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
MetaQuotes Software Corp.
Description
MetaTrader
Version
4.0.0.1170
Modules
Image
c:\program files\oanda - metatrader\terminal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\version.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll

PID
3108
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
oanda4setup.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll
c:\windows\system32\userenv.dll
c:\windows\system32\linkinfo.dll

PID
3800
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3108 CREDAT:79873
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\sspicli.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll

PID
3816
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
oanda4setup.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll
c:\windows\system32\userenv.dll
c:\windows\system32\linkinfo.dll

PID
684
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3816 CREDAT:79873
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll

PID
3272
CMD
"C:\Windows\explorer.exe" "C:\Program Files\OANDA - MetaTrader\terminal.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
oanda4setup.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
3480
CMD
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\oanda - metatrader\terminal.exe
c:\windows\system32\mpr.dll

PID
2896
CMD
"C:\Program Files\OANDA - MetaTrader\terminal.exe"
Path
C:\Program Files\OANDA - MetaTrader\terminal.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
MetaQuotes Software Corp.
Description
MetaTrader
Version
4.0.0.1170
Modules
Image
c:\program files\oanda - metatrader\terminal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\version.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\program files\oanda - metatrader\metaeditor.exe
c:\windows\system32\apphelp.dll

PID
2316
CMD
"C:\Program Files\OANDA - MetaTrader\metaeditor.exe" /packed:2 /compile:"1728328_11576" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4" /flg:2
Path
C:\Program Files\OANDA - MetaTrader\metaeditor.exe
Indicators
No indicators
Parent process
terminal.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
MetaQuotes Software Corp.
Description
MetaEditor
Version
5.0.0.1966
Modules
Image
c:\program files\oanda - metatrader\metaeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\profapi.dll

PID
3220
CMD
"C:\Program Files\OANDA - MetaTrader\terminal.exe"
Path
C:\Program Files\OANDA - MetaTrader\terminal.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
MetaQuotes Software Corp.
Description
MetaTrader
Version
4.0.0.1170
Modules
Image
c:\program files\oanda - metatrader\terminal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\version.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptbase.dll

PID
2528
CMD
"C:\Program Files\OANDA - MetaTrader\metaeditor.exe" /packed:21 /compile:"1732093_22029" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4" /flg:2
Path
C:\Program Files\OANDA - MetaTrader\metaeditor.exe
Indicators
No indicators
Parent process
terminal.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
MetaQuotes Software Corp.
Description
MetaEditor
Version
5.0.0.1966
Modules
Image
c:\program files\oanda - metatrader\metaeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wtsapi32.dll

PID
1520
CMD
"C:\Program Files\OANDA - MetaTrader\metaeditor.exe"
Path
C:\Program Files\OANDA - MetaTrader\metaeditor.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
MetaQuotes Software Corp.
Description
MetaEditor
Version
5.0.0.1966
Modules
Image
c:\program files\oanda - metatrader\metaeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wtsapi32.dll

Registry activity

Total events
1591
Read events
1411
Write events
180
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3000
oanda4setup.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software
ID
DD0FD7C5-735F-T-190211
3000
oanda4setup.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software
Install.Time
1549857981
3000
oanda4setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3000
oanda4setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3628
oanda4setup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
0F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB090000000100000016000000301406082B0601050507030306082B06010505070308140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D80B000000010000001400000055005300450052005400720075007300740000001D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D4620000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
190000000100000010000000E843AC3B52EC8C297FA948C9B1FB2819030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D461D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF67080B00000001000000140000005500530045005200540072007500730074000000140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D8090000000100000016000000301406082B0601050507030306082B060105050703080F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB20000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
190000000100000010000000E843AC3B52EC8C297FA948C9B1FB2819090000000100000022000000302006082B0601050507030306082B06010505070308060A2B0601040182370A0304030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D461D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D80F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB0B00000001000000320000005500530045005200540072007500730074002000280043006F006400650020005300690067006E0069006E006700290000006200000001000000200000006FFF78E400A70C11011CD85977C459FB5AF96A3DF0540820D0F4B8607875E58F20000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
190000000100000010000000E843AC3B52EC8C297FA948C9B1FB28196200000001000000200000006FFF78E400A70C11011CD85977C459FB5AF96A3DF0540820D0F4B8607875E58F0B00000001000000320000005500530045005200540072007500730074002000280043006F006400650020005300690067006E0069006E006700290000000F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D81D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46090000000100000022000000302006082B0601050507030306082B06010505070308060A2B0601040182370A030420000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B
Blob
040000000100000010000000803ABC22C1E6FB8D9B3B274A321B9A010F00000001000000200000003560E45B41E46B8F36537025D1D5BC02D9652A10645B0EFF69E8B6A52191F335090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B000000010000005200000047006F00200044006100640064007900200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F00720069007400790020001320200047003200000053000000010000002500000030233021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C062000000010000002000000045140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA1400000001000000140000003A9A8507106728B6EFF6BD05416E20C194DA0FDE1D000000010000001000000070253FBCBDE32A014D38C1993098AD9903000000010000001400000047BEABC922EAE80E78783462A79F45C254FDE68B19000000010000001000000021D008B47B7A2A81C8435903DED424C92000000001000000C9030000308203C5308202ADA003020102020100300D06092A864886F70D01010B0500308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D204732301E170D3039303930313030303030305A170D3337313233313233353935395A308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BF716208F1FA5934F71BC918A3F7804958E9228313A6C52043013B84F1E685499F27EAF6841B4EA0B4DB7098C73201B1053E074EEEF4FA4F2F593022E7AB19566BE28007FCF316758039517BE5F935B6744EA98D8213E4B63FA90383FAA2BE8A156A7FDE0BC3B6191405CAEAC3A804943B467C320DF3006622C88D696D368C1118B7D3B21C60B438FA028CCED3DD4607DE0A3EEB5D7CC87CFBB02B53A4926269512505611A44818C2CA9439623DFAC3A819A0E29C51CA9E95D1EB69E9E300A39CEF18880FB4B5DCC32EC85624325340256270191B43B702A3F6EB1E89C88017D9FD4F9DB536D609DBF2CE758ABB85F46FCCEC41B033C09EB49315C6946B3E0470203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604143A9A8507106728B6EFF6BD05416E20C194DA0FDE300D06092A864886F70D01010B0500038201010099DB5D79D5F99759670361F17E3B0631752DA1208E4F6587B4F7A69CBCD8E92FD0DB5AEECF748C73B43842DA057BF80275B8FDA5B1D7AEF6D7DE13CB53107E8A46D197FAB72E2B11AB90B02780F9E89F5AE9379FABE4DF6CB385179D3DD9244F799135D65F04EB8083AB9A022DB510F4D890C7047340ED7225A0A99FEC9EAB68129957C68F123A09A4BD44FD061537C19BE432A3ED38E8D864F32C7E14FC02EA9FCDFF076817DB2290382D7A8DD154F169E35F33CA7A3D7B0AE3CA7F5F39E5E275BAC5761833CE2CF02F4CADF7B1E7CE4FA8C49B4A5406C57F7DD5080FE21CFE7E17B8AC5EF6D416B243090C4DF6A76BB4998465CA7A88E2E244BE5CF7EA1CF5
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B
Blob
040000000100000010000000803ABC22C1E6FB8D9B3B274A321B9A0119000000010000001000000021D008B47B7A2A81C8435903DED424C903000000010000001400000047BEABC922EAE80E78783462A79F45C254FDE68B1D000000010000001000000070253FBCBDE32A014D38C1993098AD991400000001000000140000003A9A8507106728B6EFF6BD05416E20C194DA0FDE62000000010000002000000045140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA53000000010000002500000030233021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C00B000000010000005200000047006F00200044006100640064007900200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F007200690074007900200013202000470032000000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070F00000001000000200000003560E45B41E46B8F36537025D1D5BC02D9652A10645B0EFF69E8B6A52191F3352000000001000000C9030000308203C5308202ADA003020102020100300D06092A864886F70D01010B0500308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D204732301E170D3039303930313030303030305A170D3337313233313233353935395A308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BF716208F1FA5934F71BC918A3F7804958E9228313A6C52043013B84F1E685499F27EAF6841B4EA0B4DB7098C73201B1053E074EEEF4FA4F2F593022E7AB19566BE28007FCF316758039517BE5F935B6744EA98D8213E4B63FA90383FAA2BE8A156A7FDE0BC3B6191405CAEAC3A804943B467C320DF3006622C88D696D368C1118B7D3B21C60B438FA028CCED3DD4607DE0A3EEB5D7CC87CFBB02B53A4926269512505611A44818C2CA9439623DFAC3A819A0E29C51CA9E95D1EB69E9E300A39CEF18880FB4B5DCC32EC85624325340256270191B43B702A3F6EB1E89C88017D9FD4F9DB536D609DBF2CE758ABB85F46FCCEC41B033C09EB49315C6946B3E0470203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604143A9A8507106728B6EFF6BD05416E20C194DA0FDE300D06092A864886F70D01010B0500038201010099DB5D79D5F99759670361F17E3B0631752DA1208E4F6587B4F7A69CBCD8E92FD0DB5AEECF748C73B43842DA057BF80275B8FDA5B1D7AEF6D7DE13CB53107E8A46D197FAB72E2B11AB90B02780F9E89F5AE9379FABE4DF6CB385179D3DD9244F799135D65F04EB8083AB9A022DB510F4D890C7047340ED7225A0A99FEC9EAB68129957C68F123A09A4BD44FD061537C19BE432A3ED38E8D864F32C7E14FC02EA9FCDFF076817DB2290382D7A8DD154F169E35F33CA7A3D7B0AE3CA7F5F39E5E275BAC5761833CE2CF02F4CADF7B1E7CE4FA8C49B4A5406C57F7DD5080FE21CFE7E17B8AC5EF6D416B243090C4DF6A76BB4998465CA7A88E2E244BE5CF7EA1CF5
3628
oanda4setup.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software
API.Time
1549857994
3628
oanda4setup.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software
API
api1.mql5.com=35;api13.mql5.com=37;api4.mql5.com=62;api3.mql5.com=121;api11.mql5.com=151;api14.mql5.com=182;api2.mql5.com=247;api8.mql5.com=252;api6.mql5.com=280;api12.mql5.com=315;api5.mql5.com=334;api10.mql5.com=341;api9.mql5.com=1026
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OANDA - MetaTrader
DisplayName
OANDA - MetaTrader
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OANDA - MetaTrader
InstallLocation
C:\Program Files\OANDA - MetaTrader
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OANDA - MetaTrader
DisplayIcon
C:\Program Files\OANDA - MetaTrader\terminal.ico
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OANDA - MetaTrader
Publisher
MetaQuotes Software Corp.
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OANDA - MetaTrader
HelpLink
https://www.metaquotes.net
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OANDA - MetaTrader
UrlInfoAbout
https://www.metaquotes.net
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OANDA - MetaTrader
UninstallString
C:\Program Files\OANDA - MetaTrader\uninstall.exe
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OANDA - MetaTrader
DisplayVersion
4.00
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OANDA - MetaTrader
MajorVersion
4
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OANDA - MetaTrader
MinorVersion
0
3628
oanda4setup.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software\MetaTrader 4
PackagePath
C:\Users\admin\AppData\Local\Temp\oanda4setup.exe
3628
oanda4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
54
3628
oanda4setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3628
oanda4setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mql4buy
URL:MQL4 Buy Protocol
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mql4buy\DefaultIcon
C:\Program Files\OANDA - MetaTrader\terminal.exe,1
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mql4buy\shell\open\command
C:\Program Files\OANDA - MetaTrader\terminal.exe "%1"
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
52
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mql4buy
URL Protocol
3888
terminal.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
terminal.exe
8000
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL4.File
MQL4 Source File
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL4.File\DefaultIcon
C:\Program Files\OANDA - MetaTrader\MetaEditor.exe,3
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL4.File\shell\open\command
C:\Program Files\OANDA - MetaTrader\MetaEditor.exe "%1"
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL4.File\ShellNew
NullFile
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mq4
MQL4.File
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mq4\ShellNew
NullFile
3888
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
53
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\AdminActive
{73CC75E1-2DB2-11E9-BAD8-5254004A04AF}
0
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
3
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307020001000B000400060031006102
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
3
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307020001000B000400060031006102
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Path
C:\Users\admin\Favorites\Links\Suggested Sites.url
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
FeedUrl
https://ieonline.microsoft.com/#ieslice
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayName
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
ErrorState
0
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayMask
0
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Path
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
FeedUrl
http://go.microsoft.com/fwlink/?LinkId=121315
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayName
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
ErrorState
0
3108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayMask
0
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
3
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307020001000B000400060031006B03
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
15
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
3
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307020001000B000400060031009903
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
46
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
3
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307020001000B000400060032002E00
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
33
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3800
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3800
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006B000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\AdminActive
{7BC2F077-2DB2-11E9-BAD8-5254004A04AF}
0
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
4
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307020001000B000400070002006B03
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
4
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307020001000B000400070002006B03
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3816
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
4
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307020001000B000400070003001F00
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
20
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
4
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307020001000B000400070003005D00
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
49
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
4
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307020001000B000400070003007D00
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
27
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
684
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006C000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
684
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3480
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3480
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1

Files activity

Executable files
4
Suspicious files
391
Text files
234
Unknown types
33

Dropped files

PID Process Filename Type
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Scripts\Examples\DLL\Libraries\DLLSample.dll executable
3628 oanda4setup.exe C:\Program Files\OANDA - MetaTrader\terminal.exe executable
3628 oanda4setup.exe C:\Program Files\OANDA - MetaTrader\metaeditor.exe executable
3628 oanda4setup.exe C:\Program Files\OANDA - MetaTrader\uninstall.exe executable
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998427.chinese (simplified) binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\Community\mql4.community.dat binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1549858037.English binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1549858036.English binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1549858035.English binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1549858034.English binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1549858033.English binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1549858032.English binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\config\community.ini binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\config\terminal.ini text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\origin.txt text
3220 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\lastprofile.ini text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Scripts\Examples\DLL\DLLSample.def text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\RSI.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\ZigZag.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Libraries\stdlib.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Scripts\Examples\DLL\DLLSampleTester.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Scripts\Examples\DLL\DLLSample.vcxproj xml
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Scripts\Examples\DLL\DLLSample.cpp text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Stochastic.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Scripts\PeriodConverter.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Scripts\Examples\Pipes\PipeClient.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Scripts\Examples\Pipes\PipeClientPure.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Parabolic.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Bears.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Heiken Ashi.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Awesome.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\CCI.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Bulls.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Examples\SimplePanel\SimplePanel.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Momentum.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Alligator.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Ichimoku.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\MACD.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\ATR.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Custom Moving Averages.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Accelerator.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Bands.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Accumulation.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\OsMA.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\iExposure.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Indicators\Examples\SimplePanel\PanelDialog.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\stdlib.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Indicators\Indicators.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Strings\String.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Files\FileTxt.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Object.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\StdLibErr.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Indicators\Oscilators.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Indicators\Volumes.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Indicators\Series.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\WinUser32.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Indicators\TimeSeries.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Indicators\BillWilliams.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Tools\DateTime.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Indicators\Custom.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\stderror.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Indicators\Indicator.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\MovingAverages.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Indicators\Trend.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\Turn.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\up_smoll.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\Up.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\WndClient.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\TimePicker.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\TurnOff.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\WndContainer.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\TurnOn.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Files\FileBin.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\Scrolls.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\WndObj.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\UpDisable.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\UpSmall.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\SpinEdit.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\ThumbVertDisable.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Files\FilePipe.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\Wnd.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\UpTransp.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Files\File.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\SpinInc.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\HelpOff.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\HelpOn.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\ThumbVert.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\RightDisable.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\RadioButtonOff.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\RestoreDisable.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\SpinDec.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\Left.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\Restore.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\RightTransp.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\RestoreOn.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\RadioButtonOn.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\ThumbHor.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\LeftDisable.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\RestoreOff.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\Right.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\ThumbHorDisable.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\LeftTransp.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\CheckBoxOn.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\CloseOff.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\DownSmall.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\DownTransp.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\RadioButton.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\ExpandDisable.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\DownDisable.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\ExpandOff.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\Close.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\Down.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\down_smoll.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\HelpDisable.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\CheckBoxOff.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\DropOn.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\DateDropOn.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\RadioGroup.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\CloseDisable.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\ExpandOn.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\DateDropOff.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\Rect.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\DropOff.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\res\CloseOn.bmp image
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\Button.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\Panel.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\ListView.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\CheckGroup.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\Edit.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\Picture.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\ComboBox.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\Label.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\BmpButton.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\DateDropList.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\DatePicker.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\Defines.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\Dialog.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Controls\CheckBox.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\ChartObjects\ChartObjectsShapes.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\ChartObjects\ChartObject.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Charts\Chart.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\ChartObjects\ChartObjectsLines.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\ChartObjects\ChartObjectsBmpControls.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\ChartObjects\ChartObjectsChannels.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\ChartObjects\ChartObjectsGann.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\ChartObjects\ChartObjectsArrows.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\List.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\Tree.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\ChartObjects\ChartObjectsTxtControls.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\ArrayString.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Canvas\Canvas.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\TreeNode.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\ChartObjects\ChartObjectPanel.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\ChartObjects\ChartObjectsFibo.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\ArrayDouble.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\Array.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\ArrayLong.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Experts\Moving Average.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\ArrayObj.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\ArrayChar.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\ArrayShort.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\ArrayFloat.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Include\Arrays\ArrayInt.mqh text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\MQL4\Experts\MACD Sample.mq4 text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\mql4.zip ––
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\OptimizationReport.htm html
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\Williams.tpl text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\Popular.tpl text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\StatementDetailed.htm html
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\Volume.tpl text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\ADX.tpl text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\Layers.tpl text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\statement.htm html
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\Momentum.tpl text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\BollingerBands.tpl text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\templates\strategytester.htm html
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Swiss Franc\chart03.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Swiss Franc\chart01.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\lastprofile.ini text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Market Overview\chart03.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Market Overview\order.wnd text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Market Overview\chart01.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Swiss Franc\chart02.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Market Overview\chart02.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Market Overview\chart04.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Euro\order.wnd text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Swiss Franc\order.wnd text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Euro\chart02.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\default\chart02.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\British Pound\order.wnd text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\default\chart01.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\British Pound\chart03.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Euro\chart03.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\default\chart03.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\Euro\chart01.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\default\order.wnd text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\default\chart04.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998548.uzbek binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998549.vietnamese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\British Pound\chart01.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\profiles\British Pound\chart02.CHR text
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998547.vietnamese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998545.turkish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998541.slovenian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998543.slovenian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998546.thai binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998542.spanish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998542.russian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998545.tajik binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998547.turkish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998543.tajik binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998544.thai binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998546.uzbek binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998544.spanish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998539.portuguese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998536.japanese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998537.italian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998540.russian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998541.portuguese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998538.japanese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998539.malay binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998538.polish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998540.polish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998537.malay binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998534.hungarian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998536.indonesian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998535.italian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998535.hungarian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998528.chinese (traditional) binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998534.hebrew binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998532.german binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998525.arabic binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998526.bulgarian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998531.french binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998524.vietnamese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998523.uzbek binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998522.turkish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998530.english binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998529.czech binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998527.chinese (simplified) binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998533.greek binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998519.spanish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998520.tajik binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998518.slovenian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998516.portuguese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998514.malay binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998513.japanese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998517.russian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998521.thai binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998515.polish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998511.indonesian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998512.italian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998510.hungarian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998503.chinese (traditional) binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998505.english binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998508.greek binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998506.french binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998504.czech binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998507.german binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998509.hebrew binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998494.spanish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998493.slovenian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998501.bulgarian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998499.vietnamese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998496.thai binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998495.tajik binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998498.uzbek binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998500.arabic binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998497.turkish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998502.chinese (simplified) binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998492.russian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998491.portuguese ini
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998488.japanese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998480.english binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998483.greek binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998484.hebrew binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998486.indonesian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998489.malay binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998482.german binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998485.hungarian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998490.polish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998479.czech binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998487.italian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998481.french binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998473.uzbek binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998468.slovenian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998470.tajik binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998467.russian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998471.thai bs
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998477.chinese (simplified) binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998476.bulgarian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998474.vietnamese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998472.turkish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998475.arabic binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998478.chinese (traditional) binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998469.spanish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998460.hungarian html
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998457.german binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998456.french binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998461.indonesian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998462.italian vc
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998459.hebrew binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998455.english binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998463.japanese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998458.greek binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998464.malay binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998466.portuguese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998465.polish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998452.chinese (simplified) binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998451.bulgarian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998447.turkish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998443.slovenian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998454.czech binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998445.tajik binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998449.vietnamese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998450.arabic binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998444.spanish binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998448.uzbek binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998453.chinese (traditional) binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998446.thai binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998439.malay binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998436.indonesian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998437.italian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998434.hebrew binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998435.hungarian binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998438.japanese binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998430.english binary
2896 terminal.exe C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\71808ACDDF4589A555C107AF1E5AEBA0\history\mailbox\1356998431.french binary