| File name: | Netwrix_Account_Lockout_Examiner.exe |
| Full analysis: | https://app.any.run/tasks/b4b23653-fabf-4bde-bd4a-68ea15c6d523 |
| Verdict: | Malicious activity |
| Analysis date: | January 18, 2021, 15:14:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive |
| MD5: | 5BCC8A2D758DC02125E9F793B5F576F0 |
| SHA1: | B79ED07FA75631B3C843C974E482EF16E651EEFE |
| SHA256: | 9ABB15565DEDF349CF4CF0402A3A1A9302331B447FD481E83D86D0467E0E7AE9 |
| SSDEEP: | 196608:kD/hDv/ZBw6JCTHSh9z96Ml8h8BNhEn2M/IcT4Iji:kTVX3HCTMFlymNi26IcHi |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2011:03:02 08:40:24+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 72192 |
| InitializedDataSize: | 55296 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb4b5 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.2.213.0 |
| ProductVersionNumber: | 5.2.213.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileDescription: | Netwrix Account Lockout Examiner |
| InternalName: | Netwrix Account Lockout Examiner.exe |
| OriginalFileName: | Netwrix Account Lockout Examiner.exe |
| CompanyName: | Netwrix Corporation |
| LegalCopyright: | Copyright © 2020 Netwrix Corporation |
| ProductName: | Netwrix Account Lockout Examiner |
| FileVersion: | 5.2.213.0 |
| ProductVersion: | 5.2.213.0 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 02-Mar-2011 07:40:24 |
| Detected languages: |
|
| Debug artifacts: |
|
| FileDescription: | Netwrix Account Lockout Examiner |
| InternalName: | Netwrix Account Lockout Examiner.exe |
| OriginalFilename: | Netwrix Account Lockout Examiner.exe |
| CompanyName: | Netwrix Corporation |
| LegalCopyright: | Copyright © 2020 Netwrix Corporation |
| ProductName: | Netwrix Account Lockout Examiner |
| FileVersion: | 5.2.213.0 |
| ProductVersion: | 5.2.213.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 02-Mar-2011 07:40:24 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000118E0 | 0x00011A00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.5511 |
.rdata | 0x00013000 | 0x00001C15 | 0x00001E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.86525 |
.data | 0x00015000 | 0x0000FF2C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.51849 |
.CRT | 0x00025000 | 0x00000010 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.213101 |
.rsrc | 0x00026000 | 0x0000B434 | 0x0000B600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.09696 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.20816 | 1464 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 3.42481 | 9640 | Latin 1 / Western European | Process Default Language | RT_ICON |
3 | 3.29333 | 4264 | Latin 1 / Western European | Process Default Language | RT_ICON |
4 | 3.77216 | 2440 | Latin 1 / Western European | Process Default Language | RT_ICON |
7 | 3.24143 | 556 | Latin 1 / Western European | English - United States | RT_STRING |
8 | 3.26996 | 974 | Latin 1 / Western European | English - United States | RT_STRING |
9 | 3.04375 | 530 | Latin 1 / Western European | English - United States | RT_STRING |
10 | 3.16254 | 776 | Latin 1 / Western European | English - United States | RT_STRING |
11 | 3.06352 | 380 | Latin 1 / Western European | English - United States | RT_STRING |
100 | 2.71195 | 62 | Latin 1 / Western European | Process Default Language | RT_GROUP_ICON |
ADVAPI32.dll |
COMCTL32.dll |
COMDLG32.dll |
GDI32.dll |
KERNEL32.dll |
OLEAUT32.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2532 | "C:\ProgramData\Netwrix Account Lockout Examiner\Netwrix.ALE.Launcher.exe" | C:\ProgramData\Netwrix Account Lockout Examiner\Netwrix.ALE.Launcher.exe | — | Netwrix_Account_Lockout_Examiner.exe | |||||||||||
User: admin Company: Netwrix Corporation Integrity Level: MEDIUM Description: Netwrix Account Lockout Examiner Exit code: 3221226540 Version: 5.2.213.0 Modules
| |||||||||||||||
| 2736 | "C:\Users\admin\Downloads\Netwrix_Account_Lockout_Examiner.exe" | C:\Users\admin\Downloads\Netwrix_Account_Lockout_Examiner.exe | explorer.exe | ||||||||||||
User: admin Company: Netwrix Corporation Integrity Level: MEDIUM Description: Netwrix Account Lockout Examiner Exit code: 0 Version: 5.2.213.0 Modules
| |||||||||||||||
| 2776 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3032 CREDAT:275457 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3032 | "C:\Program Files\Internet Explorer\iexplore.exe" https://www.netwrix.com/go/ale_product | C:\Program Files\Internet Explorer\iexplore.exe | Netwrix.ALE.Launcher.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3676 | "C:\ProgramData\Netwrix Account Lockout Examiner\Netwrix.ALE.Launcher.exe" | C:\ProgramData\Netwrix Account Lockout Examiner\Netwrix.ALE.Launcher.exe | Netwrix_Account_Lockout_Examiner.exe | ||||||||||||
User: admin Company: Netwrix Corporation Integrity Level: HIGH Description: Netwrix Account Lockout Examiner Exit code: 0 Version: 5.2.213.0 Modules
| |||||||||||||||
| (PID) Process: | (2736) Netwrix_Account_Lockout_Examiner.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2736) Netwrix_Account_Lockout_Examiner.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3676) Netwrix.ALE.Launcher.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3676) Netwrix.ALE.Launcher.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3676) Netwrix.ALE.Launcher.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3676) Netwrix.ALE.Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 |
| Operation: | write | Name: | Blob |
Value: 040000000100000010000000CB17E431673EE209FE455793F30AFA1C0F0000000100000014000000E91E1E972B8F467AB4E0598FA92285387DEE94C90300000001000000140000004EB6D578499B1CCF5F581EAD56BE3D9B6744A5E57E00000001000000080000000040D0D1B0FFD4017F000000010000000C000000300A06082B060105050703011D0000000100000010000000C6CBCAFA17955C4CFD41ECA0C654C3610B000000010000001200000056006500720069005300690067006E0000001400000001000000140000007FD365A7C2DDECBBF03009F34339FA02AF3331336200000001000000200000009ACFAB7E43C8D880D06B262A94DEEEE4B4659989C3D0CAF19BAF6405E41AB7DF09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000004600000030443021060B6086480186F8450107170630123010060A2B0601040182373C0101030200C0301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0190000000100000010000000D8B5FB368468620275D142FFD2AADE372000000001000000D7040000308204D3308203BBA003020102021018DAD19E267DE8BB4A2158CDCC6B3B4A300D06092A864886F70D01010505003081CA310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303620566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79314530430603550403133C566572695369676E20436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479202D204735301E170D3036313130383030303030305A170D3336303731363233353935395A3081CA310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303620566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79314530430603550403133C566572695369676E20436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479202D20473530820122300D06092A864886F70D01010105000382010F003082010A0282010100AF240808297A359E600CAAE74B3B4EDC7CBC3C451CBB2BE0FE2902F95708A364851527F5F1ADC831895D22E82AAAA642B38FF8B955B7B1B74BB3FE8F7E0757ECEF43DB66621561CF600DA4D8DEF8E0C362083D5413EB49CA59548526E52B8F1B9FEBF5A191C23349D843636A524BD28FE870514DD189697BC770F6B3DC1274DB7B5D4B56D396BF1577A1B0F4A225F2AF1C926718E5F40604EF90B9E400E4DD3AB519FF02BAF43CEEE08BEB378BECF4D7ACF2F6F03DAFDD759133191D1C40CB7424192193D914FEAC2A52C78FD50449E48D6347883C6983CBFE47BD2B7E4FC595AE0E9DD4D143C06773E314087EE53F9F73B8330ACF5D3F3487968AEE53E825150203010001A381B23081AF300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106306D06082B0601050507010C0461305FA15DA05B3059305730551609696D6167652F6769663021301F300706052B0E03021A04148FE5D31A86AC8D8E6BC3CF806AD448182C7B192E30251623687474703A2F2F6C6F676F2E766572697369676E2E636F6D2F76736C6F676F2E676966301D0603551D0E041604147FD365A7C2DDECBBF03009F34339FA02AF333133300D06092A864886F70D0101050500038201010093244A305F62CFD81A982F3DEADC992DBD77F6A5792238ECC4A7A07812AD620E457064C5E797662D98097E5FAFD6CC2865F201AA081A47DEF9F97C925A0869200DD93E6D6E3C0D6ED8E606914018B9F8C1EDDFDB41AAE09620C9CD64153881C994EEA284290B136F8EDB0CDD2502DBA48B1944D2417A05694A584F60CA7E826A0B02AA251739B5DB7FE784652A958ABD86DE5E8116832D10CCDEFDA8822A6D281F0D0BC4E5E71A2619E1F4116F10B595FCE7420532DBCE9D515E28B69E85D35BEFA57D4540728EB70E6B0E06FB33354871B89D278BC4655F0D86769C447AF6955CF65D320833A454B6183F685CF2424A853854835FD1E82CF2AC11D6A8ED636A | |||
| (PID) Process: | (3676) Netwrix.ALE.Launcher.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: Netwrix.ALE.Launcher.exe | |||
| (PID) Process: | (3676) Netwrix.ALE.Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Netwrix_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3676) Netwrix.ALE.Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Netwrix_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3676) Netwrix.ALE.Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Netwrix_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2736 | Netwrix_Account_Lockout_Examiner.exe | C:\ProgramData\Netwrix Account Lockout Examiner\Common\Netwrix.ALE.UsageStatistics.dll | executable | |
MD5:— | SHA256:— | |||
| 2736 | Netwrix_Account_Lockout_Examiner.exe | C:\ProgramData\Netwrix Account Lockout Examiner\Common\Netwrix.AuditCore.Common.dll | executable | |
MD5:— | SHA256:— | |||
| 2736 | Netwrix_Account_Lockout_Examiner.exe | C:\ProgramData\Netwrix Account Lockout Examiner\Common\Netwrix.AuditCore.Node.dll | executable | |
MD5:— | SHA256:— | |||
| 2736 | Netwrix_Account_Lockout_Examiner.exe | C:\ProgramData\Netwrix Account Lockout Examiner\Common\Netwrix.AuditCore.ComponentsLib.dll | executable | |
MD5:— | SHA256:— | |||
| 2736 | Netwrix_Account_Lockout_Examiner.exe | C:\ProgramData\Netwrix Account Lockout Examiner\Common\System.Data.SQLite.dll | executable | |
MD5:17BB52713D75F8B334A311BD27CF5F23 | SHA256:6C156F7CF30A6C1E2538E8EE8744F641A9270E9B3A1D5B13C8486EA8B8CD5B03 | |||
| 2736 | Netwrix_Account_Lockout_Examiner.exe | C:\ProgramData\Netwrix Account Lockout Examiner\Common\Netwrix.AuditCore.UsageStatisticsSender.dll | executable | |
MD5:— | SHA256:— | |||
| 2736 | Netwrix_Account_Lockout_Examiner.exe | C:\ProgramData\Netwrix Account Lockout Examiner\Common\x64\ComponentsLib.dll | executable | |
MD5:— | SHA256:— | |||
| 2736 | Netwrix_Account_Lockout_Examiner.exe | C:\ProgramData\Netwrix Account Lockout Examiner\Common\EntityFramework.dll | executable | |
MD5:FFDCF232D0BB2FFF78721FB347641A76 | SHA256:FF42BCA704605E187ABB45523868B15128D6AF1C28AD40A4579D507D34A953B2 | |||
| 2736 | Netwrix_Account_Lockout_Examiner.exe | C:\ProgramData\Netwrix Account Lockout Examiner\Common\x86\DataLayer.dll | executable | |
MD5:— | SHA256:— | |||
| 2736 | Netwrix_Account_Lockout_Examiner.exe | C:\ProgramData\Netwrix Account Lockout Examiner\Common\x86\ComponentsLib.dll | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2776 | iexplore.exe | GET | 301 | 52.71.115.183:80 | http://www.netwrix.com/resources/shorturl/?keyword=ale_product | US | — | — | suspicious |
3676 | Netwrix.ALE.Launcher.exe | GET | 404 | 35.168.64.89:80 | http://updates.netwrix.com/aleVersion.xml | US | html | 212 b | unknown |
3676 | Netwrix.ALE.Launcher.exe | GET | 404 | 35.168.64.89:80 | http://updates.netwrix.com/aleVersion.xml | US | html | 212 b | unknown |
2776 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR0tOcjGcdlkhVARHvHzj6Qwhh26wQUpI3lvnx55HAjbS4pNK0jWNz1MX8CEAkYsqaUcPEyeOWdfHN6MNI%3D | US | der | 471 b | whitelisted |
3676 | Netwrix.ALE.Launcher.exe | GET | 404 | 35.168.64.89:80 | http://updates.netwrix.com/aleVersion.xml | US | html | 212 b | unknown |
2776 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAeYNgOt45kIIZygDCe8imw%3D | US | der | 471 b | whitelisted |
2776 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | US | der | 471 b | whitelisted |
2776 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D | US | der | 1.47 Kb | whitelisted |
2776 | iexplore.exe | GET | 200 | 216.58.212.131:80 | http://ocsp.pki.goog/gts1o1core/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQD9enfDLjOiuAUAAAAAgwva | US | der | 472 b | whitelisted |
2776 | iexplore.exe | GET | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/rootr1/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDkbwjNvPLFRm7zMB3V80 | US | der | 1.49 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2776 | iexplore.exe | 108.161.188.153:443 | img.netwrix.com | netDNA | US | unknown |
3032 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2776 | iexplore.exe | 151.101.2.109:443 | cdn.jsdelivr.net | Fastly | US | suspicious |
2776 | iexplore.exe | 151.139.128.14:80 | ocsp.comodoca.com | Highwinds Network Group, Inc. | US | suspicious |
2776 | iexplore.exe | 172.217.22.104:443 | www.googletagmanager.com | Google Inc. | US | whitelisted |
2776 | iexplore.exe | 104.18.21.226:80 | ocsp.globalsign.com | Cloudflare Inc | US | shared |
2776 | iexplore.exe | 216.58.212.131:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
2776 | iexplore.exe | 104.111.236.192:443 | munchkin.marketo.net | Akamai International B.V. | NL | unknown |
2776 | iexplore.exe | 216.58.205.238:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
2776 | iexplore.exe | 151.101.0.143:443 | s.swiftypecdn.com | Fastly | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
updates.netwrix.com |
| unknown |
www.netwrix.com |
| suspicious |
ocsp.digicert.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
cdnjs.cloudflare.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
code.jquery.com |
| whitelisted |
img.netwrix.com |
| suspicious |
cdn.jsdelivr.net |
| whitelisted |
Process | Message |
|---|---|
Netwrix.ALE.Launcher.exe | Native library pre-loader is trying to load native SQLite library "C:\ProgramData\Netwrix Account Lockout Examiner\Common\x86\SQLite.Interop.dll"...
|