General Info

File name

mt4setup.exe

Full analysis
https://app.any.run/tasks/4c16f2c1-8fc3-4d09-beee-63da265faf98
Verdict
Malicious activity
Analysis date
3/14/2019, 10:15:57
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5

b259b841bd56337a550a978d4b8ad913

SHA1

1d5a9df6b336fb15db5bedf3653bea056e6dac23

SHA256

837aea40ab28617263378389f65cf3d80182f66e5e7630534ae945435399f24a

SSDEEP

24576:XIdzsDtRe+IjHIjPYOtAuGskOOxhbI9/nQnC+iLIIv7Lgu/gOrW8v:X2zwtk+gHI8OtPGskOSbI9/QnC+iLZvZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes settings of System certificates
  • mt4setup.exe (PID: 2220)
Reads the cookies of Mozilla Firefox
  • terminal.exe (PID: 3028)
Connects to unusual port
  • terminal.exe (PID: 3028)
Reads the cookies of Google Chrome
  • terminal.exe (PID: 3028)
Creates files in the user directory
  • terminal.exe (PID: 2184)
  • metaeditor.exe (PID: 864)
  • mt4setup.exe (PID: 3060)
  • mt4setup.exe (PID: 2220)
  • terminal.exe (PID: 3028)
Modifies the open verb of a shell class
  • terminal.exe (PID: 2184)
Creates a software uninstall entry
  • mt4setup.exe (PID: 2220)
Low-level read access rights to disk partition
  • terminal.exe (PID: 2184)
  • mt4setup.exe (PID: 2220)
Starts Internet Explorer
  • mt4setup.exe (PID: 2220)
Reads internet explorer settings
  • mt4setup.exe (PID: 2220)
Application launched itself
  • mt4setup.exe (PID: 3060)
Changes IE settings (feature browser emulation)
  • terminal.exe (PID: 2184)
Executable content was dropped or overwritten
  • mt4setup.exe (PID: 2220)
Adds / modifies Windows certificates
  • mt4setup.exe (PID: 2220)
Creates files in the program directory
  • mt4setup.exe (PID: 2220)
Reads settings of System Certificates
  • terminal.exe (PID: 3028)
  • mt4setup.exe (PID: 2220)
Application launched itself
  • iexplore.exe (PID: 3652)
Reads Internet Cache Settings
  • iexplore.exe (PID: 2768)
Changes internet zones settings
  • iexplore.exe (PID: 3652)
Dropped object may contain Bitcoin addresses
  • terminal.exe (PID: 3028)
Reads internet explorer settings
  • iexplore.exe (PID: 2768)
Creates files in the user directory
  • iexplore.exe (PID: 2768)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (52.9%)
.exe
|   Generic Win/DOS Executable (23.5%)
.exe
|   DOS Executable Generic (23.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
1970:01:14 10:16:48+01:00
PEType:
PE32
LinkerVersion:
14.16
CodeSize:
999424
InitializedDataSize:
159744
UninitializedDataSize:
2224128
EntryPoint:
0x312e10
OSVersion:
6
ImageVersion:
null
SubsystemVersion:
6
Subsystem:
Windows GUI
FileVersionNumber:
5.0.0.1985
ProductVersionNumber:
5.0.0.1985
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Dynamic link library
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
https://www.metaquotes.net
CompanyName:
MetaQuotes Software Corp.
FileDescription:
Setup
FileVersion:
5.0.0.1985
InternalName:
Setup
LegalCopyright:
© 2000-2019, MetaQuotes Software Corp.
LegalTrademarks:
MetaTrader
OriginalFileName:
Setup
ProductName:
Setup
ProductVersion:
5.0.0.1985

Screenshots

Processes

Total processes
45
Monitored processes
9
Malicious processes
6
Suspicious processes
0

Behavior graph

+
start mt4setup.exe no specs mt4setup.exe terminal.exe iexplore.exe iexplore.exe explorer.exe no specs explorer.exe no specs terminal.exe metaeditor.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3060
CMD
"C:\Users\admin\Desktop\mt4setup.exe"
Path
C:\Users\admin\Desktop\mt4setup.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
MetaQuotes Software Corp.
Description
Setup
Version
5.0.0.1985
Modules
Image
c:\users\admin\desktop\mt4setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
2220
CMD
"C:\Users\admin\Desktop\mt4setup.exe"
Path
C:\Users\admin\Desktop\mt4setup.exe
Indicators
Parent process
mt4setup.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
MetaQuotes Software Corp.
Description
Setup
Version
5.0.0.1985
Modules
Image
c:\users\admin\desktop\mt4setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\nsi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\credssp.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\metatrader\terminal.exe
c:\program files\metatrader\uninstall.exe
c:\windows\system32\apphelp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\netutils.dll

PID
2184
CMD
"C:\Program Files\MetaTrader\terminal.exe" /install
Path
C:\Program Files\MetaTrader\terminal.exe
Indicators
Parent process
mt4setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
MetaQuotes Software Corp.
Description
MetaTrader 5 Client Terminal
Version
5.0.0.2007
Modules
Image
c:\program files\metatrader\terminal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\version.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll

PID
3652
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
mt4setup.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\propsys.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll
c:\windows\system32\userenv.dll
c:\windows\system32\linkinfo.dll

PID
2768
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3652 CREDAT:79873
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\msimg32.dll

PID
3904
CMD
"C:\Windows\explorer.exe" "C:\Program Files\MetaTrader\terminal.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
mt4setup.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
3284
CMD
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\metatrader\terminal.exe
c:\windows\system32\mpr.dll

PID
3028
CMD
"C:\Program Files\MetaTrader\terminal.exe"
Path
C:\Program Files\MetaTrader\terminal.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
MetaQuotes Software Corp.
Description
MetaTrader 5 Client Terminal
Version
5.0.0.2007
Modules
Image
c:\program files\metatrader\terminal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\user32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\version.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\program files\metatrader\metaeditor.exe
c:\program files\metatrader\metatester.exe
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\imaadp32.acm
c:\windows\system32\msg711.acm
c:\windows\system32\msgsm32.acm
c:\windows\system32\msadp32.acm
c:\windows\system32\l3codeca.acm

PID
864
CMD
"C:\Program Files\MetaTrader\metaeditor.exe" /compile:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5" /time:0 /flg:0 /stop:se1724_1783890
Path
C:\Program Files\MetaTrader\metaeditor.exe
Indicators
No indicators
Parent process
terminal.exe
User
admin
Integrity Level
MEDIUM
Exit code
85
Version:
Company
MetaQuotes Software Corp.
Description
MetaEditor
Version
5.0.0.2007
Modules
Image
c:\program files\metatrader\metaeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wtsapi32.dll

Registry activity

Total events
1272
Read events
1092
Write events
180
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3060
mt4setup.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software
ID
FE7D826E-42B2-T-190314
3060
mt4setup.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software
Install.Time
1552554979
3060
mt4setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3060
mt4setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2220
mt4setup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
0F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB090000000100000016000000301406082B0601050507030306082B06010505070308140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D80B000000010000001400000055005300450052005400720075007300740000001D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D4620000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
190000000100000010000000E843AC3B52EC8C297FA948C9B1FB2819030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D461D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF67080B00000001000000140000005500530045005200540072007500730074000000140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D8090000000100000016000000301406082B0601050507030306082B060105050703080F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB20000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
190000000100000010000000E843AC3B52EC8C297FA948C9B1FB2819090000000100000022000000302006082B0601050507030306082B06010505070308060A2B0601040182370A0304030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D461D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D80F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB0B00000001000000320000005500530045005200540072007500730074002000280043006F006400650020005300690067006E0069006E006700290000006200000001000000200000006FFF78E400A70C11011CD85977C459FB5AF96A3DF0540820D0F4B8607875E58F20000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B
Blob
0F00000001000000200000003560E45B41E46B8F36537025D1D5BC02D9652A10645B0EFF69E8B6A52191F335090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B000000010000005200000047006F00200044006100640064007900200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F00720069007400790020001320200047003200000053000000010000002500000030233021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C062000000010000002000000045140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA1400000001000000140000003A9A8507106728B6EFF6BD05416E20C194DA0FDE1D000000010000001000000070253FBCBDE32A014D38C1993098AD9903000000010000001400000047BEABC922EAE80E78783462A79F45C254FDE68B2000000001000000C9030000308203C5308202ADA003020102020100300D06092A864886F70D01010B0500308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D204732301E170D3039303930313030303030305A170D3337313233313233353935395A308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BF716208F1FA5934F71BC918A3F7804958E9228313A6C52043013B84F1E685499F27EAF6841B4EA0B4DB7098C73201B1053E074EEEF4FA4F2F593022E7AB19566BE28007FCF316758039517BE5F935B6744EA98D8213E4B63FA90383FAA2BE8A156A7FDE0BC3B6191405CAEAC3A804943B467C320DF3006622C88D696D368C1118B7D3B21C60B438FA028CCED3DD4607DE0A3EEB5D7CC87CFBB02B53A4926269512505611A44818C2CA9439623DFAC3A819A0E29C51CA9E95D1EB69E9E300A39CEF18880FB4B5DCC32EC85624325340256270191B43B702A3F6EB1E89C88017D9FD4F9DB536D609DBF2CE758ABB85F46FCCEC41B033C09EB49315C6946B3E0470203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604143A9A8507106728B6EFF6BD05416E20C194DA0FDE300D06092A864886F70D01010B0500038201010099DB5D79D5F99759670361F17E3B0631752DA1208E4F6587B4F7A69CBCD8E92FD0DB5AEECF748C73B43842DA057BF80275B8FDA5B1D7AEF6D7DE13CB53107E8A46D197FAB72E2B11AB90B02780F9E89F5AE9379FABE4DF6CB385179D3DD9244F799135D65F04EB8083AB9A022DB510F4D890C7047340ED7225A0A99FEC9EAB68129957C68F123A09A4BD44FD061537C19BE432A3ED38E8D864F32C7E14FC02EA9FCDFF076817DB2290382D7A8DD154F169E35F33CA7A3D7B0AE3CA7F5F39E5E275BAC5761833CE2CF02F4CADF7B1E7CE4FA8C49B4A5406C57F7DD5080FE21CFE7E17B8AC5EF6D416B243090C4DF6A76BB4998465CA7A88E2E244BE5CF7EA1CF5
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B
Blob
040000000100000010000000803ABC22C1E6FB8D9B3B274A321B9A0103000000010000001400000047BEABC922EAE80E78783462A79F45C254FDE68B1D000000010000001000000070253FBCBDE32A014D38C1993098AD991400000001000000140000003A9A8507106728B6EFF6BD05416E20C194DA0FDE62000000010000002000000045140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA53000000010000002500000030233021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C00B000000010000005200000047006F00200044006100640064007900200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F007200690074007900200013202000470032000000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070F00000001000000200000003560E45B41E46B8F36537025D1D5BC02D9652A10645B0EFF69E8B6A52191F3352000000001000000C9030000308203C5308202ADA003020102020100300D06092A864886F70D01010B0500308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D204732301E170D3039303930313030303030305A170D3337313233313233353935395A308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BF716208F1FA5934F71BC918A3F7804958E9228313A6C52043013B84F1E685499F27EAF6841B4EA0B4DB7098C73201B1053E074EEEF4FA4F2F593022E7AB19566BE28007FCF316758039517BE5F935B6744EA98D8213E4B63FA90383FAA2BE8A156A7FDE0BC3B6191405CAEAC3A804943B467C320DF3006622C88D696D368C1118B7D3B21C60B438FA028CCED3DD4607DE0A3EEB5D7CC87CFBB02B53A4926269512505611A44818C2CA9439623DFAC3A819A0E29C51CA9E95D1EB69E9E300A39CEF18880FB4B5DCC32EC85624325340256270191B43B702A3F6EB1E89C88017D9FD4F9DB536D609DBF2CE758ABB85F46FCCEC41B033C09EB49315C6946B3E0470203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604143A9A8507106728B6EFF6BD05416E20C194DA0FDE300D06092A864886F70D01010B0500038201010099DB5D79D5F99759670361F17E3B0631752DA1208E4F6587B4F7A69CBCD8E92FD0DB5AEECF748C73B43842DA057BF80275B8FDA5B1D7AEF6D7DE13CB53107E8A46D197FAB72E2B11AB90B02780F9E89F5AE9379FABE4DF6CB385179D3DD9244F799135D65F04EB8083AB9A022DB510F4D890C7047340ED7225A0A99FEC9EAB68129957C68F123A09A4BD44FD061537C19BE432A3ED38E8D864F32C7E14FC02EA9FCDFF076817DB2290382D7A8DD154F169E35F33CA7A3D7B0AE3CA7F5F39E5E275BAC5761833CE2CF02F4CADF7B1E7CE4FA8C49B4A5406C57F7DD5080FE21CFE7E17B8AC5EF6D416B243090C4DF6A76BB4998465CA7A88E2E244BE5CF7EA1CF5
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B
Blob
19000000010000001000000021D008B47B7A2A81C8435903DED424C90F00000001000000200000003560E45B41E46B8F36537025D1D5BC02D9652A10645B0EFF69E8B6A52191F335090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B000000010000005200000047006F00200044006100640064007900200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F00720069007400790020001320200047003200000053000000010000002500000030233021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C062000000010000002000000045140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA1400000001000000140000003A9A8507106728B6EFF6BD05416E20C194DA0FDE1D000000010000001000000070253FBCBDE32A014D38C1993098AD9903000000010000001400000047BEABC922EAE80E78783462A79F45C254FDE68B040000000100000010000000803ABC22C1E6FB8D9B3B274A321B9A012000000001000000C9030000308203C5308202ADA003020102020100300D06092A864886F70D01010B0500308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D204732301E170D3039303930313030303030305A170D3337313233313233353935395A308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BF716208F1FA5934F71BC918A3F7804958E9228313A6C52043013B84F1E685499F27EAF6841B4EA0B4DB7098C73201B1053E074EEEF4FA4F2F593022E7AB19566BE28007FCF316758039517BE5F935B6744EA98D8213E4B63FA90383FAA2BE8A156A7FDE0BC3B6191405CAEAC3A804943B467C320DF3006622C88D696D368C1118B7D3B21C60B438FA028CCED3DD4607DE0A3EEB5D7CC87CFBB02B53A4926269512505611A44818C2CA9439623DFAC3A819A0E29C51CA9E95D1EB69E9E300A39CEF18880FB4B5DCC32EC85624325340256270191B43B702A3F6EB1E89C88017D9FD4F9DB536D609DBF2CE758ABB85F46FCCEC41B033C09EB49315C6946B3E0470203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604143A9A8507106728B6EFF6BD05416E20C194DA0FDE300D06092A864886F70D01010B0500038201010099DB5D79D5F99759670361F17E3B0631752DA1208E4F6587B4F7A69CBCD8E92FD0DB5AEECF748C73B43842DA057BF80275B8FDA5B1D7AEF6D7DE13CB53107E8A46D197FAB72E2B11AB90B02780F9E89F5AE9379FABE4DF6CB385179D3DD9244F799135D65F04EB8083AB9A022DB510F4D890C7047340ED7225A0A99FEC9EAB68129957C68F123A09A4BD44FD061537C19BE432A3ED38E8D864F32C7E14FC02EA9FCDFF076817DB2290382D7A8DD154F169E35F33CA7A3D7B0AE3CA7F5F39E5E275BAC5761833CE2CF02F4CADF7B1E7CE4FA8C49B4A5406C57F7DD5080FE21CFE7E17B8AC5EF6D416B243090C4DF6A76BB4998465CA7A88E2E244BE5CF7EA1CF5
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
190000000100000010000000E843AC3B52EC8C297FA948C9B1FB28196200000001000000200000006FFF78E400A70C11011CD85977C459FB5AF96A3DF0540820D0F4B8607875E58F0B00000001000000320000005500530045005200540072007500730074002000280043006F006400650020005300690067006E0069006E006700290000000F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D81D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46090000000100000022000000302006082B0601050507030306082B06010505070308060A2B0601040182370A030420000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B
Blob
19000000010000001000000021D008B47B7A2A81C8435903DED424C903000000010000001400000047BEABC922EAE80E78783462A79F45C254FDE68B1D000000010000001000000070253FBCBDE32A014D38C1993098AD991400000001000000140000003A9A8507106728B6EFF6BD05416E20C194DA0FDE62000000010000002000000045140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA53000000010000002500000030233021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C00B000000010000005200000047006F00200044006100640064007900200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F007200690074007900200013202000470032000000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070F00000001000000200000003560E45B41E46B8F36537025D1D5BC02D9652A10645B0EFF69E8B6A52191F3352000000001000000C9030000308203C5308202ADA003020102020100300D06092A864886F70D01010B0500308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D204732301E170D3039303930313030303030305A170D3337313233313233353935395A308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BF716208F1FA5934F71BC918A3F7804958E9228313A6C52043013B84F1E685499F27EAF6841B4EA0B4DB7098C73201B1053E074EEEF4FA4F2F593022E7AB19566BE28007FCF316758039517BE5F935B6744EA98D8213E4B63FA90383FAA2BE8A156A7FDE0BC3B6191405CAEAC3A804943B467C320DF3006622C88D696D368C1118B7D3B21C60B438FA028CCED3DD4607DE0A3EEB5D7CC87CFBB02B53A4926269512505611A44818C2CA9439623DFAC3A819A0E29C51CA9E95D1EB69E9E300A39CEF18880FB4B5DCC32EC85624325340256270191B43B702A3F6EB1E89C88017D9FD4F9DB536D609DBF2CE758ABB85F46FCCEC41B033C09EB49315C6946B3E0470203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604143A9A8507106728B6EFF6BD05416E20C194DA0FDE300D06092A864886F70D01010B0500038201010099DB5D79D5F99759670361F17E3B0631752DA1208E4F6587B4F7A69CBCD8E92FD0DB5AEECF748C73B43842DA057BF80275B8FDA5B1D7AEF6D7DE13CB53107E8A46D197FAB72E2B11AB90B02780F9E89F5AE9379FABE4DF6CB385179D3DD9244F799135D65F04EB8083AB9A022DB510F4D890C7047340ED7225A0A99FEC9EAB68129957C68F123A09A4BD44FD061537C19BE432A3ED38E8D864F32C7E14FC02EA9FCDFF076817DB2290382D7A8DD154F169E35F33CA7A3D7B0AE3CA7F5F39E5E275BAC5761833CE2CF02F4CADF7B1E7CE4FA8C49B4A5406C57F7DD5080FE21CFE7E17B8AC5EF6D416B243090C4DF6A76BB4998465CA7A88E2E244BE5CF7EA1CF5
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B
Blob
040000000100000010000000803ABC22C1E6FB8D9B3B274A321B9A010F00000001000000200000003560E45B41E46B8F36537025D1D5BC02D9652A10645B0EFF69E8B6A52191F335090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B000000010000005200000047006F00200044006100640064007900200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F00720069007400790020001320200047003200000053000000010000002500000030233021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C062000000010000002000000045140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA1400000001000000140000003A9A8507106728B6EFF6BD05416E20C194DA0FDE1D000000010000001000000070253FBCBDE32A014D38C1993098AD9903000000010000001400000047BEABC922EAE80E78783462A79F45C254FDE68B19000000010000001000000021D008B47B7A2A81C8435903DED424C92000000001000000C9030000308203C5308202ADA003020102020100300D06092A864886F70D01010B0500308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D204732301E170D3039303930313030303030305A170D3337313233313233353935395A308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BF716208F1FA5934F71BC918A3F7804958E9228313A6C52043013B84F1E685499F27EAF6841B4EA0B4DB7098C73201B1053E074EEEF4FA4F2F593022E7AB19566BE28007FCF316758039517BE5F935B6744EA98D8213E4B63FA90383FAA2BE8A156A7FDE0BC3B6191405CAEAC3A804943B467C320DF3006622C88D696D368C1118B7D3B21C60B438FA028CCED3DD4607DE0A3EEB5D7CC87CFBB02B53A4926269512505611A44818C2CA9439623DFAC3A819A0E29C51CA9E95D1EB69E9E300A39CEF18880FB4B5DCC32EC85624325340256270191B43B702A3F6EB1E89C88017D9FD4F9DB536D609DBF2CE758ABB85F46FCCEC41B033C09EB49315C6946B3E0470203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604143A9A8507106728B6EFF6BD05416E20C194DA0FDE300D06092A864886F70D01010B0500038201010099DB5D79D5F99759670361F17E3B0631752DA1208E4F6587B4F7A69CBCD8E92FD0DB5AEECF748C73B43842DA057BF80275B8FDA5B1D7AEF6D7DE13CB53107E8A46D197FAB72E2B11AB90B02780F9E89F5AE9379FABE4DF6CB385179D3DD9244F799135D65F04EB8083AB9A022DB510F4D890C7047340ED7225A0A99FEC9EAB68129957C68F123A09A4BD44FD061537C19BE432A3ED38E8D864F32C7E14FC02EA9FCDFF076817DB2290382D7A8DD154F169E35F33CA7A3D7B0AE3CA7F5F39E5E275BAC5761833CE2CF02F4CADF7B1E7CE4FA8C49B4A5406C57F7DD5080FE21CFE7E17B8AC5EF6D416B243090C4DF6A76BB4998465CA7A88E2E244BE5CF7EA1CF5
2220
mt4setup.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software
API.Time
1552555042
2220
mt4setup.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software
API
api4.mql5.com=62;api1.mql5.com=63;api13.mql5.com=64;api3.mql5.com=147;api14.mql5.com=182;api11.mql5.com=184;api10.mql5.com=213;api2.mql5.com=221;api9.mql5.com=244;api8.mql5.com=252;api12.mql5.com=306;api15.mql5.com=318;api5.mql5.com=318;api6.mql5.com=340
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaTrader
DisplayName
MetaTrader
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaTrader
InstallLocation
C:\Program Files\MetaTrader
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaTrader
DisplayIcon
C:\Program Files\MetaTrader\terminal.ico
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaTrader
Publisher
MetaQuotes Software Corp.
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaTrader
HelpLink
https://www.metaquotes.net
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaTrader
UrlInfoAbout
https://www.metaquotes.net
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaTrader
UninstallString
C:\Program Files\MetaTrader\uninstall.exe
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaTrader
DisplayVersion
5.00
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaTrader
MajorVersion
5
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaTrader
MinorVersion
0
2220
mt4setup.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software\MetaTrader 5
PackagePath
C:\Users\admin\Desktop\mt4setup.exe
2220
mt4setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
57
2220
mt4setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2220
mt4setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MetaTrader 5 Export File
MetaTrader 5 Export
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MetaTrader 5 Export File\DefaultIcon
C:\Program Files\MetaTrader\terminal.exe,15
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MetaTrader 5 Export File\shell\open\command
C:\Program Files\MetaTrader\terminal.exe /import:"%1"
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mt5
MetaTrader 5 Export File
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
52
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EX5.File
MQL5 Program
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EX5.File\DefaultIcon
C:\Program Files\MetaTrader\terminal.exe,2
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EX5.File\shell\open\command
C:\Program Files\MetaTrader\terminal.exe /ex5:"%1"
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ex5
EX5.File
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
53
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mql5buy
URL:MQL5 Buy Protocol
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mql5buy\DefaultIcon
C:\Program Files\MetaTrader\terminal.exe,1
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mql5buy\shell\open\command
C:\Program Files\MetaTrader\terminal.exe "%1"
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
54
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mql5buy
URL Protocol
2184
terminal.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
terminal.exe
8000
2184
terminal.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software\Internet Explorer\Main
Disable Script Debugger
yes
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL5.File
MQL5 Source File
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL5.File\DefaultIcon
C:\Program Files\MetaTrader\metaeditor.exe,1
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL5.File\shell\open\command
C:\Program Files\MetaTrader\metaeditor.exe "%1"
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL5.File\ShellNew
NullFile
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mq5
MQL5.File
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mq5\ShellNew
NullFile
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
55
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL5.Header
MQL5 Header File
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL5.Header\DefaultIcon
C:\Program Files\MetaTrader\metaeditor.exe,2
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MQL5.Header\shell\open\command
C:\Program Files\MetaTrader\metaeditor.exe "%1"
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mqh
MQL5.Header
2184
terminal.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
56
2184
terminal.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\AdminActive
{138C69CF-463A-11E9-BAD8-5254004A04AF}
0
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
3
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307030004000E00090012000700F001
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
3
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307030004000E000900120007000002
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3652
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
3
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307030004000E000900120007001903
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
14
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
3
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307030004000E000900120007005703
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
44
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
3
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307030004000E00090012000700C503
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
46
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2768
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Internet Explorer\DOMStore
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CachePrefix
DOMStore
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CacheLimit
1000
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CacheOptions
8
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CacheRepair
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
27
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\mql5.com
27
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\mql5.com
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
26
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\mql5.com
26
3284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3028
terminal.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software\Settings
Time
1552555089
3028
terminal.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3028
terminal.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software\Internet Explorer\Main
Disable Script Debugger
yes
3028
terminal.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
terminal.exe
3028
terminal.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software\Settings
IP
85.206.166.82
3028
terminal.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software\Settings
Country
Lithuania
3028
terminal.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software
ChatAP
msg1.mql5.com=555;msg2.mql5.com=161;msg3.mql5.com=336
3028
terminal.exe
write
HKEY_CURRENT_USER\Software\MetaQuotes Software
ChatAP.Time
1552555171

Files activity

Executable files
2
Suspicious files
171
Text files
801
Unknown types
29

Dropped files

PID
Process
Filename
Type
2220
mt4setup.exe
C:\Program Files\MetaTrader\uninstall.exe
executable
MD5: b259b841bd56337a550a978d4b8ad913
SHA256: 837aea40ab28617263378389f65cf3d80182f66e5e7630534ae945435399f24a
2220
mt4setup.exe
C:\Program Files\MetaTrader\metatester.exe
executable
MD5: dc1c453554d2993abd145a472795cc44
SHA256: 22c717d9a0d331822397b6a643814e41d2bd8dc9196245f1d5492544805293f0
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\Mail\6.virtualhosting.thai.welcome
html
MD5: 55c6202cd3d0adea6741b2ea489813a2
SHA256: 10ad9118d3d63dae3a844f3847ded6384c3bc5c7088e76521e8f34cba173cadc
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\PositionInfo\PositionInfoSample.ex5
binary
MD5: 2e78bcd34559fc58e7eed04db608b4ee
SHA256: add3dc548770f4437d055738bdecc15f7606e2c717e1136487167407264e4e72
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\OrderInfo\OrderInfoSample.ex5
binary
MD5: 9378f8bd1e5e5774dcb4c709a671e954
SHA256: 8dd4bbdcd18cdcec90e21ab251e01dd4f61b5b21f351f13b789ba6c1ca185566
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\OpenCL\Float\Wavelet.ex5
binary
MD5: 575515361fe2a787639dbabeac3c61d4
SHA256: 978e44dc831404d16115448938f914b95e74ebfc9d749dc74df9f0f0eb81fafd
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\OpenCL\Float\MatrixMult.ex5
binary
MD5: 2fa0385590cfeb1cbf3c38cd0c7305eb
SHA256: 6b73b3b601ec1d32585b02adc53473cef2995d33ca104b2007e28dc4fcb9dd57
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\OpenCL\Float\FFT.ex5
binary
MD5: c2c78f05973e5d182eabafeb643fada0
SHA256: 81aefd4fe51062a8a9f39f2c6e05a726c327eed02ab6f885a2a8ffd0ceb809c0
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\OpenCL\Float\BitonicSort.ex5
binary
MD5: 33e073b7df25d56f2b55aad4ce9194b1
SHA256: 3060816c296b2f14acaaba8b3e0192a784d7c58d9d22a73301b18397925f00b2
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\OpenCL\Double\Wavelet.ex5
binary
MD5: 87323547b41e1eb87ac18b91e9bddedf
SHA256: 33a3477d810cd7c5b285a96b59bcb05729037ea453726fbc99180be4d618829e
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\OpenCL\Double\MatrixMult.ex5
binary
MD5: f2d9b37dc3cfb7a0c6f0dabb25f29deb
SHA256: 9cb6ebfcd0058ac0201a8f15714c64a2ba23dd6548c45398f74d78c7b9355132
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\OpenCL\Double\FFT.ex5
binary
MD5: 8dfc647d84767b381da57889217930b4
SHA256: 1d21c7923557d51e1d770c9dfb53cf43e59acf7187e89f6e9e5f40ab8152dc32
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\OpenCL\Double\BitonicSort.ex5
binary
MD5: 15218f937bdbec6b22654b9109a5ade0
SHA256: f29807960725935659b025553e234df9598a411a0c0121f3ebe90d2f82f96092
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\ObjectSphere\SphereSample.ex5
binary
MD5: 00d424b2af9a2a6b3e9a8ff2740d97c3
SHA256: c0179e511daa3aed1f922a0d436c542c8cbdcf9f3c45d07984a8b0ab1a038aa4
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\ObjectChart\ObjChartSample.ex5
binary
MD5: 96314bd85f896136ba44200ab7804845
SHA256: 87630a804f2afa031bc1783a05f61c2b2c4a7da9c99cdacc3008a50d7e512ce1
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\Canvas\Charts\PieChartSample.ex5
binary
MD5: b63a0ed955ca9d4b3bb33f3c12e4a851
SHA256: ab426782c46236e2ae8bb43065350efb950860038c3ae49531f6b8912d050dc2
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\Canvas\Charts\LineChartSample.ex5
binary
MD5: a4e16c22788237a99602eef19c2c0696
SHA256: c331361ddb47e97b9361a3cc29b149f10cfc19fa235b7dde7b17801a85ea12ce
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\Canvas\Charts\HistogramChartSample.ex5
binary
MD5: 6b04c9b89d98e266e1a07964235a6cfd
SHA256: ca49d4d682bd110c8558b69e7a06eecbce8fc1607d835ac9b359ded60e42910c
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\Canvas\CanvasSample.ex5
binary
MD5: d50cc1c9838c23addfb5c0a29e3715e4
SHA256: 95ff16a6215fe580c745192667b5c1f420c7ecc3457186db56eb1324fa81d786
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\ArrayDouble\ArrayDoubleSample.ex5
binary
MD5: 0a97289cfc59f2fabac4463c62602844
SHA256: 776d081f63da5433fb5cde51ce86654f297ad6ab56ff9e316c40d717d1ec0f36
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Scripts\Examples\AccountInfo\AccountInfoSample.ex5
binary
MD5: bb4a3bbfee26f9e4d8cb85d6f5d5d99c
SHA256: f7db480c55b227c9abb9ab7868aa4d00e24c0d27d295d1b3597e7abac903a235
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ZigzagColor.ex5
binary
MD5: 44192356083d125d0eb14861d014d2e7
SHA256: 790ce1c8cc5b213eefea20a0fccdebf20598adbc00541113d59626e73090e6fe
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ZigZag.ex5
binary
MD5: 1c50e9c47d8a7b5e6e9018b623ad86e5
SHA256: f500d3259bd9333bd2c207b6ed2c5d388bb868c0a90d894201b59f57dd659bd7
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\W_AD.ex5
binary
MD5: 52e7de76d93160e0a3132de183078edc
SHA256: d5cd2ef3896fff0ba177201f61e80306fa73af56f59d90c7d5aa6f5d3dfb0927
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\WPR.ex5
binary
MD5: 887a5ebadbc02cb2c18ccb996cf27011
SHA256: 103fe76c3882e25e4a011ea3ca1c6206bb906335907fe615b556fdad5d55816e
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\VROC.ex5
binary
MD5: 3abfd14242f556f78378b6aba3f0437d
SHA256: a013a9982b66ccb6ca93039c2aba506c743de90387d53adc39c388d7be9268e7
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Volumes.ex5
binary
MD5: ea0dd8a22e7efe2ab6d6589cb7a715ec
SHA256: a05007cdda88773b3a5d6dc455b8b18240a5c4f6b4288c31f5312f7a4973c7ac
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\VIDYA.ex5
binary
MD5: 936962901838509bd9df4c59f8933485
SHA256: cb111e3e4a225079f8ebafe2e51639dde2bc6c331e12778696b819fca68e2117
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Ultimate_Oscillator.ex5
binary
MD5: a329ac786f37778b79965572f7e287f4
SHA256: b34571e2794d60a4b71e049eb4e2be0b82e2d220ec704c55f68d71f79cbcbd69
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\TRIX.ex5
binary
MD5: 4436e03fe8e3cb721e56b471c4da4afa
SHA256: a86c9e2693070da5c1893b7cffac0db6e9a5ec7b79dc48e25841eaa3ae0f17ce
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\TEMA.ex5
binary
MD5: 41e61431b0b08275c1d0c86705227245
SHA256: c9c58a7f91661ec4b9f50ab2903b768daa3def41a549b85eb4a2882b761c900d
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Stochastic.ex5
binary
MD5: 9f080e1352fd3b343412a7ef528957e2
SHA256: c58134d54b61c4a8a43b8b4d822e931daaa0b21ae50583dc898e0246c3920753
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\StdDev.ex5
binary
MD5: e26c71d1e4705e0b9e8b47570e7411d1
SHA256: 051ab962dd051847d6e3c9b993a589e40b75ddf38ace1a0d717a793d1a376e91
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\RVI.ex5
binary
MD5: 603575ab40b9b5e3baa4e3efdb5bde39
SHA256: 9034801fae43dd477a82abbf3916c834b6db6d521058999951837e7c45383d73
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\RSI.ex5
binary
MD5: 369c27108eb95c5d4b27be20bd01f00a
SHA256: 39f9f64b2f9dc8659f2b34633c7556122e9ae7af04602e6e9fb09a9d585fc7d1
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ROC.ex5
binary
MD5: 8c0f3560705c83fafa04a9e7a9105894
SHA256: 08850a17f8161c5292708c4752d3c4c847cbe5bc4c0e330695bd5f6a3381ba31
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\PVT.ex5
binary
MD5: 041d044b28edc2296db852ea32e12669
SHA256: d9b56f4d9c4610409617c99c23b252131879a2703c0fe2d8c19223e8b57aeb9a
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Price_Channel.ex5
binary
MD5: 83df829cea7c1593b40da7b1f3bb99aa
SHA256: 5c1367a5a44a0c8a5851673d086a01dc969706b833e55f9b8aab7db57721c572
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ParabolicSAR.ex5
binary
MD5: 8b620b900e6f64f8e580bbbc9387a47f
SHA256: cf5ce3522fbf07cc41f270eb202b7015a885e077bc0e8265f2767f49ab2baa89
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\symbols\selected-15882811.dat
binary
MD5: fd54cba020e89f8496765a5251d8a4fe
SHA256: 53014347f8dc0f29126ad5fa609c697fff1fdea0798f91572e5167826fc05cc8
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\accounts.dat
dbf
MD5: 78afeb0f666b31e07b477f049896b983
SHA256: b2ea4d125e8e5b549b9911fb37d447c69f5fb1bb5aebc3c102bcda7c24771365
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\servers.dat
binary
MD5: c2169190e48882bc465452addad21349
SHA256: 8ab719423598d780391548ff1e5cbc19954503b2732ba40a4aa0db9809d135ba
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Panels\SimplePanel\SimplePanel.ex5
binary
MD5: cc749b16e850a5e08a72e8f18b871574
SHA256: d61d34d0b169e5f3f95dffec3716c8912569fa71c6a6f02c883c84224fdfd215
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Panels\ChartPanel\ChartPanel.ex5
binary
MD5: f02a94fbaff7ea4a360adb7a781308d0
SHA256: 7f29a83f1ec7ab4be2d7b3c65a23016c123968cbb52a5db849c2b98ce737c8e8
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\OsMA.ex5
binary
MD5: a05e0754a7e78229ff845b048740c1f5
SHA256: 788facf4e610562ccaff79f323885f634e27692e697768e23b0e1dff461b88ff
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\OBV.ex5
binary
MD5: 142bc4fc0e42d1fd5160f98b2a101e07
SHA256: f0a9682c1f51c6161d8badbc74a76f9c701a2c675a81415958a646cff864d869
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Momentum.ex5
binary
MD5: bff912c2cd5ed749249dd7f9a68530fd
SHA256: b4e58ed7acd5a562b6c1a67233966f76d123bbd94582174a18c0b99a1a537cbe
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\MI.ex5
binary
MD5: 8d57deff5eedad1e9e013d99d7874bfd
SHA256: d80cc16b301a157f678b7f71ec48ec2bf95734aa338ebd75d2bec6bd337a0a2c
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\MFI.ex5
binary
MD5: f80221aae951f2fb6c6dbacb27ca3798
SHA256: fcbe464ecbb9366b79199b09d0acdab4e9f7f3dbd805d6e367dfeb076a29182e
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\MarketFacilitationIndex.ex5
binary
MD5: ea09da3bd60d407ed21a345095d1ebc3
SHA256: 8c3e90d0ab2ab49c409438f398f72cdc62cb090a227afc26a175d0711db205b9
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\MACD.ex5
binary
MD5: fd99640cc9670aaf546250000d5c3691
SHA256: fc95f8f2b08bce9b35c2ff060a5dc8094d6121002198824002d0f56ba7663b66
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Ichimoku.ex5
binary
MD5: 7b12126e4ebcd915c220923bf17a678f
SHA256: d24eb0935cc5c27defe13bec794301bdf4d5f00e92b00a4f3725b9902b4c1556
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Heiken_Ashi.ex5
binary
MD5: 423de65f47cc8a89ec0cda9161ab318f
SHA256: f151d14519dd7b8be64a7a0f427452b5817f3ae1f9471d30df569579bfdfff1d
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Gator_2.ex5
binary
MD5: ac0ac5094dbdebd1391a4ea2aac148b4
SHA256: 8760f080513c005c59bc0942defb2c7193fbec4ebb6101ea17199b3562a66747
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Gator.ex5
binary
MD5: a2439d96421b8227eb0727f223b3b209
SHA256: 71e1297b9e79306468f24d3a1dd85f4717e3aea87304061c23fc3a0f68481058
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\FrAMA.ex5
binary
MD5: 1451e38dd75b70eb33c7622c2fe364da
SHA256: f466ab9108f11b0e39f40f2374a408b9617eba9c3d6f73c3983f9b6e96d0b861
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Fractals.ex5
binary
MD5: 993882543599eb9cbbf17b09f16cecb8
SHA256: 677af009fa9ac3ff3fce8dee826a02686d266126f56cf411c9c58e180bd8ee03
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Force_Index.ex5
binary
MD5: 273f1c0d3e262a5fd9056f70a5e1e3db
SHA256: bd3cb4e18b3bb3207944718733e1ab20b7293fb77f455b28527412f3bfe016db
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Envelopes.ex5
binary
MD5: c7b7d8dc4c05ffac3f31276b41419448
SHA256: 7d9ae7bd0c1ca8b885843df0371e22c819f4efdde0182cdc33d0c770dda7d47c
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\DPO.ex5
binary
MD5: 5be30bf372418d88d1ba03f470a1a808
SHA256: e55e954152d681cbdca00b5b1c5d4e4efcd1ab265fa91257d100df8bac3a1f0c
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\DeMarker.ex5
binary
MD5: 80c5a27b6062378fb1af580caad6b2b4
SHA256: bcf4ea0e945c7d5d1a95c1d4653c3d60f017bf283bc1a252fbc03cda96061ed5
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\DEMA.ex5
binary
MD5: 994564bc1dfbf0515b009e017d34ed22
SHA256: f6f50c7b5aa183a477d6b42b77bbe8594a8db40cdb415add9d5422c3c32ca6f7
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Custom Moving Average.ex5
binary
MD5: b199be1a3fec7c4d501f6c7c935a5059
SHA256: d724e3980a408da8bca4ae33ade9d04c5d94d4b436e0ba50c7900ee981bd1100
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ColorLine.ex5
binary
MD5: 19315d7307217ea96bf766c4046606a3
SHA256: 568aa59e13fce2397997d9433ed09c039d9068ce33b88b07aa05e56a42134c7d
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ColorCandlesDaily.ex5
binary
MD5: c9ea5ede92360341dd3aab0c7222144c
SHA256: 9539704598248338dbb923a94d57097004b8bac854fc6c590e3557ea1553427b
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ColorBars.ex5
binary
MD5: c0157c8b04dfe6f914469b26b814b0dc
SHA256: c8a4408dae00668eff36126ca64caab096c2ee6ac1efaa0646e6d171badc26dc
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\CHV.ex5
binary
MD5: 45847ee5c4f3beba552172e016d30e92
SHA256: 5f9f8fe9cff6729530bdfc0b0c18d8ef764e6fb07694a467b723f48ee4fcda1c
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\CHO.ex5
binary
MD5: 1b228fb886bc408dd69a4912d5480493
SHA256: ff7b34bd423a5fbc13db8bc5eccbe7d0bb60502b23166ff626aa2f44b22d2320
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\CCI.ex5
binary
MD5: 82c31e9919dd1708dbc754b0744b6199
SHA256: 40f7533aa427eb913c084bdebb66089823843f78447dac8ab890070984521646
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Canvas\FlameChart.ex5
binary
MD5: 11812426b08e718fc9c27d947d42f58c
SHA256: d3ee5339393259bbed361ee65ee68cf4d9aa718e25d65d3634f4d2289bbb859d
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\BW-ZoneTrade.ex5
binary
MD5: a3b72413412a57846370841ffc9847a8
SHA256: a7863f4a479cff580f159d4d68610a2f792346a3e24630b11dbca8a6ce12b025
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Bulls.ex5
binary
MD5: 658c75716f62dc2cf1828cedc17cad64
SHA256: 94287f9d40463aa761038ea37457f87e469faf2d62385a613749ee8ca81144ba
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Bears.ex5
binary
MD5: a802a4c725c0e6d18e4e659748dac884
SHA256: 0dc70338c56afad9776917f65702328aaf83ebe19ffcc709b32c4097158124f1
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\BB.ex5
binary
MD5: d75b9cd4c93cd56943ee77c3d419ccd9
SHA256: 9437c39bf174e75a12aebeda42a3d7b5d2fe956573413e1e527e0e4c160abe18
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Awesome_Oscillator.ex5
binary
MD5: fd38f480538201b433fb6ac38d7708f0
SHA256: f314a484d049b33897e1f2893faa14cdbd22e5d1bebe7cb4c35681073096c1e1
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ATR.ex5
binary
MD5: f4ca925054e11f74c738c6cb86dc7d34
SHA256: dbc667242c97e38dda69c2aa48fa19e2831dff899a7db879f3297134940cca1b
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ASI.ex5
binary
MD5: 76cddcac2f19c602c650b845ff6c393c
SHA256: 8b56a5dbf8c244ffb78c0bc7c3bc2e48d1225a6e9daf87bfca9a273e7c0ff146
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\AMA.ex5
binary
MD5: a32f053d30031140fcd5e892ccca5e03
SHA256: 8d83dc9e36b09d61bfbf20c7add466a4f51d583b3a3670df4e5217627817e07f
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Alligator.ex5
binary
MD5: 40299b042ac086c34523e514887e545a
SHA256: aa860dbe566b69decf8106c5324a298d6f6ef3e48a0726bf2b1ebbc1bfd1c5bf
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ADXW.ex5
binary
MD5: ead5faf1cddb6f960abfbdecb9654e94
SHA256: 2fc903552ca66d90da4847ce6020e742c26e06fceed2063e6da8f456caa6c8d5
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\ADX.ex5
binary
MD5: e8adf9f8b43c6338be15d9e79f58ec25
SHA256: 2d7f99795cda5768494862a318aae4208b59d83881b82dd334b755f431a959bb
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\AD.ex5
binary
MD5: b5ca7607ed61fd3e13febb4b4ffcf912
SHA256: b2fa96c2d9136590885799f14479853534fb85b1b3b69e5b8c95871f2e49ec4a
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Indicators\Examples\Accelerator.ex5
binary
MD5: 8f40016e1fb67ccb4a0313579acbc574
SHA256: 69738d4c826b20a8a3e0c069bb905d48daaf9b133f4fa9a9cc10defc21a517e3
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Experts\Examples\Moving Average\Moving Average.ex5
binary
MD5: a8a0a66a8c38ba9eb9dd9ea4b880f921
SHA256: bc3fed7f6ce2c5cc5531ee4177d96f75f72edf079088336c30dc8deb1afd84a1
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Experts\Examples\MACD\MACD Sample.ex5
binary
MD5: d298ade034cc6a9f205af7fa8986f99f
SHA256: d3a85f3ce0921e406a2dcb23f408b98a44268e4a3c87f9056eec52600a1ebfdb
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Experts\Examples\Controls\Controls.ex5
binary
MD5: 32b37cd51a80e981eaf6d67ae9b4c824
SHA256: b1f1046cd089623ddd8aa5a48f01e14b73d5ed66ce2a1b98b9dcf645c3cf1343
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\terminal.ini
text
MD5: 8c5f8ecb701214a3b527b29413e2f131
SHA256: fe39d1d3ad773b74994afc0e7304fef4c8be14be557746e49f63544c36afc0ca
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\terminal.ini
text
MD5: 702578b40e483065054d32a503ef2e4f
SHA256: aa0500f3aff5c597173a95b183f00fb34012be9b834d7f9fd85b8f305fd8eb75
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Experts\Examples\ChartInChart\ChartInChart.ex5
binary
MD5: bb5477fd052ed77a0f8b9af1f7cbf8f7
SHA256: c2226011ee433ca2317354ce52fc1b3096ef6886a1d443d18ddef3edeb42db4d
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Experts\Advisors\ExpertMAPSARSizeOptimized.ex5
binary
MD5: dea3976b732b04b57554ff09a6b6dead
SHA256: 050b27eb176f4843d9753de5ae2f66cc5a6b1867705a029dd3f4d8f4dfc35d33
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Experts\Advisors\ExpertMAPSAR.ex5
binary
MD5: bd821a5a3a9daa44f193bb21d5c6af4a
SHA256: 5752db1dc6ef5d5e0dd59173ea003dc20aa6c2d288291156d08b52e6d0ca3514
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Experts\Advisors\ExpertMAMA.ex5
binary
MD5: d8b7a9de107c48f66e9ee2cf4491cd98
SHA256: 263d82921055d6a71e59efc3c01cdaeeb3fb898efac5cfef88898a7729b2ec99
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\terminal.ini
text
MD5: 9f632081573704fbe57c84dc89f4bfcd
SHA256: 6a311c266699f48b7d87a03b49c8954e0610386f25f6a2d46dad1d1a4704ccce
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\symbols\selected-15882811.dat
binary
MD5: f724131d3901d39370cbda0c6d80c885
SHA256: 4091cb081399c9fd5f5898599d3ae851c887f6b78403621e550120f9a97e78ac
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\servers.dat
binary
MD5: 51e9fb66ecbf89a94f544690549caed6
SHA256: 3a79894618fb60a9a9858664db5756933d309502ef8a241c3d1e8d475427930e
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\accounts.dat
dbf
MD5: f1431940b78640acb26cfa553ae55bd0
SHA256: a68a3f885d9be445906a3f34e2b3ba7b8658fea2bbd9d9d5353b6f1dd9da5b98
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\accounts.dat
dbf
MD5: 8143b4eddd54b333c4a4e4447e59ba98
SHA256: f568cea5cb2a3a1000ed82f0354e96eeee774d5eb35cef4bafad7d17ce8e2017
864
metaeditor.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5\Experts\Advisors\ExpertMACD.ex5
binary
MD5: 469b4c04780701902fb46f385b06eecf
SHA256: 89ed19545db25f99fe37839298784f692ffc9905ae5df2cc6094ee8f981888a1
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\GBPUSD\2019.hcc
––
MD5:  ––
SHA256:  ––
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\GBPUSD\2018.hcc
––
MD5:  ––
SHA256:  ––
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\USDCHF\2019.hcc
––
MD5:  ––
SHA256:  ––
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\USDCHF\2018.hcc
––
MD5:  ––
SHA256:  ––
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\USDJPY\2019.hcc
––
MD5:  ––
SHA256:  ––
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\USDJPY\2018.hcc
––
MD5:  ––
SHA256:  ––
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\EURUSD\2019.hcc
––
MD5:  ––
SHA256:  ––
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\EURUSD\2018.hcc
––
MD5:  ––
SHA256:  ––
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\accounts.dat
dbf
MD5: e4c64c041337ab3e6398e51bcba1c3bd
SHA256: 9b13e19995e1d82234f9ddf9cf615bfe31aa386ef67c400792fb5e3ccad95f21
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\trades\15882811\deals_2019.03.dat
binary
MD5: 4dc4f53037908d02c418dd98ce70e542
SHA256: 9af9b05fedc3000cfac264a2c1f4d1ef76065ec5b43d105c343763664a709cf6
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\mail\mail-15882811.dat
binary
MD5: cbd135bee719a1a1164f08536be1ef8a
SHA256: a255a299c25795a36e1dc957ed3cce54c4d21aa1ed8106c20a223867711dd5b7
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\common.ini
text
MD5: e82fc50764d7ecdd76ba7c38c0252a83
SHA256: 9cd729c664df04885c481f418888e6d6eb1cb052577d871477e807e8a49edf83
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\terminal.ini
text
MD5: e0c9a57ef1e3a90147aad588833a80db
SHA256: 8a0d1cccee978553c7418a08987f8b8565545a273f4b076391cd095723cc1cfb
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\accounts.dat
dbf
MD5: 668c62470a97383c0f0e711f991b04e8
SHA256: 307c7976301038e030155913d29e2be290adeb146f8118882974361b366e0b5c
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\symbols\symbols-15882811.dat
dbf
MD5: 30973810d6c5ccbb1e97bcde0657d371
SHA256: fdc28253ecb79ae45c0148308d0c25b7fe60f28c194f21e07a0a776751b9f5ec
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\symbols\selected-15882811.dat
binary
MD5: 1e190f9aa1c7ee30d9803391e666ef4e
SHA256: 40d90c80b76e228c1d1f8f23d0ccfd83565a31a0e4a7e2fe04ffb342909f77dd
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\config\servers.dat
binary
MD5: d4ffaa309fb023631a89e2faf6a6a229
SHA256: fa3c1844fef5d2e254ffb30665df1d477793fad8334ecb75fa83bf678540e804
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\history\GBPUSD\2019.hcc
binary
MD5: 587c9689084128660e87991d18f28ec7
SHA256: c4d2d6ae3aa0e2e797cce3c26697a34d10ecc45b9179e5ec25837ba6950d1974
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\history\USDJPY\2019.hcc
binary
MD5: e3f9f0853f0a46839294a431bf3283a8
SHA256: 04b2200e0e82322e3e5cdf38b81c0cb4992f385f0030778bd42e8c75d3d8fe3a
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\history\USDCHF\2019.hcc
binary
MD5: f7a7d75843b0056b6d8ae8bbafb5f476
SHA256: 298334fffbb125e6894274fa4ef7e2f923289d24373f73502877dbf0ee0bd516
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\history\EURUSD\2019.hcc
binary
MD5: 06421defa370b665e519af363d49edd5
SHA256: 76c9b90db44d9ae98246bb301bfe54fc4be3253944b7869f5a032c297a04a1b3
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\history\USDCHF\cache\H1.hc
binary
MD5: 8b864dc043ad0cadd6fad27bab9bbcaf
SHA256: 0c77394eda58b528312d255a0fbb2c5a8aa9b11c8e49e32a4713350da79e4d1e
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\history\USDJPY\cache\H1.hc
binary
MD5: e71644037a73af950432453cb1e264c6
SHA256: 87603f9d040133d890284cde3d83adb2d3388daa0bc997fd28d671ec8d40cf3c
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\history\GBPUSD\cache\H1.hc
binary
MD5: 3771040314dfaec5c192c6038864d702
SHA256: 8f0edc97bfe78a436500d4752a06311e021e69e2e374421dad6522f64ea68faf
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\history\EURUSD\cache\H1.hc
binary
MD5: ffc01ffc025becf71c2d0009ae73774b
SHA256: 1a8d61330f634673d6a84129e98f92fa2efda6fbd0bcd13c2d103084f6eeae35
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\news\news.dat
binary
MD5: d71d39fdb885cefcc88142cd9adbc28e
SHA256: cb275f7357def8518cd25c7a0f90ca914509adc955e566360d8ba5bb5fad8d96
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\symbols\spreads-15882811.dat
binary
MD5: dbd8ce264d058f5e87bd0960d5c2ed92
SHA256: c053dee60d325aa4c10a7f2831d26c1575bf9e94ce8d7cd36cf80734c25c5748
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\symbols\symbols-15882811.dat
dbf
MD5: 5627235521e883b899c82622b149b062
SHA256: 0ff201c1fea2826e41cf08de94a0b15aea3321206f3bedb1b35ec6ffddd570da
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\symbols\selected-15882811.dat
binary
MD5: ffc9a90db1142476eb01e3507cda0202
SHA256: b8fbd6a5ccf52377f9f24836ce3079f804a9b7a72167491b78c1295aafe60304
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\mail\mail-15882811.dat
binary
MD5: ab39a74aa42b8b0445d25890160ce86b
SHA256: 50b2b978b7eb534871739c6b8164ee0c473d8297e72806b9ed0cb8b5ec67745d
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\USDCHF\2019.hcc
binary
MD5: 2e0f94c56a615a92fdd160b48f019d98
SHA256: 6c0696d1150b6adc064ae10727e80ec386f8ecfb230498ce467116f64f643350
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\USDJPY\2019.hcc
binary
MD5: c1f29aa694f2cd9db25869d412126ecf
SHA256: ae0260fd874622c3a31e868780cc89f364a90ffdbe841f05724b0301938e4333
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\GBPUSD\2019.hcc
binary
MD5: d000acf0b68ebd4f5a276121ec68a617
SHA256: 9c82ad982e319e67d9ebaeb215234deb361bbab5d1265de7f52520dcd85e5497
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\MetaQuotes-Demo\history\EURUSD\2019.hcc
binary
MD5: 4ec5fdefa4d449480e70625e40b19f3c
SHA256: 63bfed8d9eaee1cf34d2345d48e36aa2bcc2b90233c54f8548dce69a7291832c
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\symbols\selected-0.dat
binary
MD5: ffc9a90db1142476eb01e3507cda0202
SHA256: b8fbd6a5ccf52377f9f24836ce3079f804a9b7a72167491b78c1295aafe60304
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\symbols\spreads-15882811.dat
binary
MD5: dbd8ce264d058f5e87bd0960d5c2ed92
SHA256: c053dee60d325aa4c10a7f2831d26c1575bf9e94ce8d7cd36cf80734c25c5748
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\mail\mail-15882811.dat
binary
MD5: ab39a74aa42b8b0445d25890160ce86b
SHA256: 50b2b978b7eb534871739c6b8164ee0c473d8297e72806b9ed0cb8b5ec67745d
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\symbols\symbols-0.dat
dbf
MD5: 4592f4ee0b81340a679f71badd3fabc7
SHA256: 5d6dace96dfc65f010d817f831e8ffdfa2a290db4867ebec15fd5b2ae58cf7e3
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\symbols\selected-15882811.dat
binary
MD5: 5c6cc9d2a1707999896706e1a57c4ad8
SHA256: 1732fa83145a82e52fac6ea0e17e62f4a1d6bd14264dade79189f165b3dc1825
3028
terminal.exe
C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\bases\Default\symbols\symbols-15882811.dat
binary
MD5: 20bdd9adaabd13fe854e521f25f4ccb9
SHA256: d066b42e9b0906a377cda67901bb084e38730e02b84edab8af32919b234f55b7