General Info

File name

Anno 1800.exe

Full analysis
https://app.any.run/tasks/b3238b78-d84d-486c-9a73-d30b1b53e816
Verdict
Malicious activity
Analysis date
6/16/2019, 22:34:03
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

41bb95eb9ca47f71c495cf082b73dcf3

SHA1

cb5f18572b700edd03b8c0b4e6bf9b06ef0c53c4

SHA256

d93a7cc722a474c658da2109eee74ec787ddef6dead0e96ea9d609023f7e9256

SSDEEP

49152:jGfegs16OYyAdU+mscehwZyl+F8jQnAOobfaotN6CPgEqz3OWL+it:ONs16O77sceheyl+K0nAxfacIEqqWiG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • steamerrorreporter.exe (PID: 3252)
  • steamwebhelper.exe (PID: 2732)
  • steamwebhelper.exe (PID: 3292)
  • Steam.exe (PID: 3920)
  • steamwebhelper.exe (PID: 772)
  • steamwebhelper.exe (PID: 2968)
  • steamwebhelper.exe (PID: 3828)
  • steamwebhelper.exe (PID: 2464)
  • steamwebhelper.exe (PID: 4020)
  • Steam.exe (PID: 3056)
Application was dropped or rewritten from another process
  • SteamService.exe (PID: 304)
  • steamerrorreporter.exe (PID: 3252)
  • SteamService.exe (PID: 3100)
  • steamwebhelper.exe (PID: 772)
  • steamwebhelper.exe (PID: 2732)
  • steamwebhelper.exe (PID: 3292)
  • Steam.exe (PID: 3056)
  • Steam.exe (PID: 3920)
  • steamwebhelper.exe (PID: 3828)
  • steamwebhelper.exe (PID: 4020)
  • steamwebhelper.exe (PID: 2464)
  • steamwebhelper.exe (PID: 2968)
  • Steam.exe (PID: 1040)
Modifies the open verb of a shell class
  • SteamService.exe (PID: 304)
Executable content was dropped or overwritten
  • SteamService.exe (PID: 304)
  • Anno 1800.exe (PID: 3364)
  • Steam.exe (PID: 1040)
Uses TASKKILL.EXE to kill process
  • cmd.exe (PID: 3568)
  • cmd.exe (PID: 3444)
Uses REG.EXE to modify Windows registry
  • cmd.exe (PID: 3568)
  • cmd.exe (PID: 3444)
Application launched itself
  • steamwebhelper.exe (PID: 772)
  • steamwebhelper.exe (PID: 4020)
Starts CMD.EXE for commands execution
  • Anno 1800.exe (PID: 3364)
Manual execution by user
  • cmd.exe (PID: 3568)
Dropped object may contain Bitcoin addresses
  • Steam.exe (PID: 1040)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (52.9%)
.exe
|   Generic Win/DOS Executable (23.5%)
.exe
|   DOS Executable Generic (23.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:09:30 20:01:51+02:00
PEType:
PE32
LinkerVersion:
14
CodeSize:
144896
InitializedDataSize:
169472
UninitializedDataSize:
null
EntryPoint:
0x1234b
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
30-Sep-2018 18:01:51
Detected languages
Process Default Language
Debug artifacts
D:\Projects\WinRAR\sfx\build\sfxzip32\Release\sfxzip.pdb
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000118
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
6
Time date stamp:
30-Sep-2018 18:01:51
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00023453 0x00023600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.66306
.rdata 0x00025000 0x00009060 0x00009200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.10662
.data 0x0002F000 0x000319C0 0x00000C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.70928
.gfids 0x00061000 0x000000F4 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 2.1444
.rsrc 0x00062000 0x0001D000 0x0001D000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.03555
.reloc 0x0007F000 0x00002510 0x00002600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.68826
Resources
1

2

3

7

8

9

10

11

12

13

14

15

16

100

101

102

ASKNEXTVOL

GETPASSWORD1

LICENSEDLG

RENAMEDLG

REPLACEFILEDLG

STARTDLG

Imports
    KERNEL32.dll

    gdiplus.dll

    USER32.dll (delay-loaded)

Exports

    No exports.

Screenshots

Processes

Total processes
60
Monitored processes
20
Malicious processes
8
Suspicious processes
5

Behavior graph

+
start drop and start anno 1800.exe cmd.exe no specs taskkill.exe no specs reg.exe no specs steam.exe steam.exe steamwebhelper.exe steamwebhelper.exe no specs steamwebhelper.exe no specs steamwebhelper.exe cmd.exe no specs taskkill.exe no specs reg.exe no specs steam.exe steamwebhelper.exe steamwebhelper.exe no specs steamwebhelper.exe no specs steamservice.exe no specs steamservice.exe steamerrorreporter.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3364
CMD
"C:\Users\admin\AppData\Local\Temp\Anno 1800.exe"
Path
C:\Users\admin\AppData\Local\Temp\Anno 1800.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\anno 1800.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\riched20.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sfc.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll
c:\windows\system32\netutils.dll

PID
3444
CMD
cmd /c ""C:\Users\admin\AppData\Local\Temp\Denuvo\Steam.exe.bat" "
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
Anno 1800.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\denuvo\steam.exe

PID
2100
CMD
taskkill /im Steam.exe /f
Path
C:\Windows\system32\taskkill.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
2580
CMD
reg add HKEY_CURRENT_USER\Software\Valve\Steam /t reg_sz /v autologinuser /d doomednow /f
Path
C:\Windows\system32\reg.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Registry Console Tool
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1040
CMD
Steam.exe
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\Steam.exe
Indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
42
Version:
Company
Valve Corporation
Description
Steam Client Bootstrapper
Version
05.05.99.96
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\steam.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\psapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\apphelp.dll

PID
3056
CMD
C:\Users\admin\AppData\Local\Temp\Denuvo\Steam.exe
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\Steam.exe
Indicators
Parent process
Steam.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Valve Corporation
Description
Steam Client Bootstrapper
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\steam.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\psapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\wshtcpip.dll
c:\users\admin\appdata\local\temp\denuvo\crashhandler.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\temp\denuvo\steamui.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\denuvo\sdl2.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\users\admin\appdata\local\temp\denuvo\tier0_s.dll
c:\users\admin\appdata\local\temp\denuvo\v8.dll
c:\users\admin\appdata\local\temp\denuvo\icui18n.dll
c:\users\admin\appdata\local\temp\denuvo\icuuc.dll
c:\users\admin\appdata\local\temp\denuvo\video.dll
c:\users\admin\appdata\local\temp\denuvo\libavcodec-57.dll
c:\users\admin\appdata\local\temp\denuvo\libavutil-55.dll
c:\users\admin\appdata\local\temp\denuvo\libavformat-57.dll
c:\users\admin\appdata\local\temp\denuvo\libavresample-3.dll
c:\users\admin\appdata\local\temp\denuvo\libswscale-4.dll
c:\users\admin\appdata\local\temp\denuvo\vstdlib_s.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\hid.dll
c:\windows\system32\wintrust.dll
c:\users\admin\appdata\local\temp\denuvo\bin\xinput1_3.dll
c:\users\admin\appdata\local\temp\denuvo\bin\filesystem_stdio.dll
c:\users\admin\appdata\local\temp\denuvo\bin\vgui2_s.dll
c:\windows\system32\msimg32.dll
c:\users\admin\appdata\local\temp\denuvo\bin\chromehtml.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\steamwebhelper.exe
c:\windows\system32\dwrite.dll

PID
4020
CMD
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe "-lang=en_US" "-cachedir=C:\Users\admin\AppData\Local\Steam\htmlcache" "-steampid=3056" "-buildid=1560549607" "-steamid=0" "-steamuniverse=Dev" "-clientui=C:\Users\admin\AppData\Local\Temp\Denuvo\clientui" --disable-out-of-process-pac --enable-blink-features=ResizeObserver,Worklet,AudioWorklet --disable-features=TouchpadAndWheelScrollLatching,AsyncWheelEvents --enable-media-stream --enable-smooth-scrolling --num-raster-threads=4 --enable-direct-write --disablehighdpi --force-device-scale-factor=1 --device-scale-factor=1 "--log-file=C:\Users\admin\AppData\Local\Temp\Denuvo\logs\cef_log.txt"
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe
Indicators
Parent process
Steam.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Valve Corporation
Description
Steam Client WebHelper
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\steamwebhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\sdl2.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\version.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\libcef.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\chrome_elf.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\credui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\winspool.drv
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dhcpcsvc.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\winsta.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mscms.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wintrust.dll

PID
2968
CMD
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe --type=crashpad-handler /prefetch:7 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\Temp\Denuvo\dumps "--metrics-dir=C:\Users\admin\AppData\Local\CEF\User Data" --url=http://crash.steampowered.com/submit --annotation=platform=win32 --annotation=product=cefwebhelper --annotation=version=1560549607 --initial-client-data=0x154,0x158,0x15c,0x150,0x160,0x69828b40,0x69828b50,0x69828b5c
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe
Indicators
No indicators
Parent process
steamwebhelper.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Valve Corporation
Description
Steam Client WebHelper
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\steamwebhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\sdl2.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\libcef.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\chrome_elf.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\credui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\winspool.drv
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dhcpcsvc.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
3828
CMD
"C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe" --type=gpu-process --field-trial-handle=924,5013803375458585146,9145553075864151954,131072 --disable-features=AsyncWheelEvents,TouchpadAndWheelScrollLatching --log-file="C:\Users\admin\AppData\Local\Temp\Denuvo\logs\cef_log.txt" --product-version="Valve Steam Client" --lang=en-US --force-device-scale-factor=1 --disablehighdpi --buildid=1560549607 --steamid=0 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=17763836949860362137 --mojo-platform-channel-handle=996 --ignored=" --type=renderer " /prefetch:2
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe
Indicators
No indicators
Parent process
steamwebhelper.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Valve Corporation
Description
Steam Client WebHelper
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\steamwebhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\sdl2.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\libcef.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\chrome_elf.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\credui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\winspool.drv
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dhcpcsvc.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\swiftshader\libglesv2.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\swiftshader\libegl.dll

PID
2464
CMD
"C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe" --type=gpu-process --field-trial-handle=924,5013803375458585146,9145553075864151954,131072 --disable-features=AsyncWheelEvents,TouchpadAndWheelScrollLatching --disable-gpu-sandbox --use-gl=disabled --log-file="C:\Users\admin\AppData\Local\Temp\Denuvo\logs\cef_log.txt" --product-version="Valve Steam Client" --lang=en-US --force-device-scale-factor=1 --disablehighdpi --buildid=1560549607 --steamid=0 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=7777258933045713963 --mojo-platform-channel-handle=1424 /prefetch:2
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe
Indicators
Parent process
steamwebhelper.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Valve Corporation
Description
Steam Client WebHelper
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\steamwebhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\sdl2.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\libcef.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\chrome_elf.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\credui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\winspool.drv
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dhcpcsvc.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll

PID
3568
CMD
cmd /c ""C:\Users\admin\AppData\Local\Temp\Denuvo\Steam.exe.bat" "
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\denuvo\steam.exe

PID
3140
CMD
taskkill /im Steam.exe /f
Path
C:\Windows\system32\taskkill.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
1644
CMD
reg add HKEY_CURRENT_USER\Software\Valve\Steam /t reg_sz /v autologinuser /d doomednow /f
Path
C:\Windows\system32\reg.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Registry Console Tool
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3920
CMD
Steam.exe
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\Steam.exe
Indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Valve Corporation
Description
Steam Client Bootstrapper
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\steam.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\psapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\wshtcpip.dll
c:\users\admin\appdata\local\temp\denuvo\crashhandler.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\clbcatq.dll
c:\users\admin\appdata\local\temp\denuvo\steamui.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\denuvo\sdl2.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\users\admin\appdata\local\temp\denuvo\tier0_s.dll
c:\users\admin\appdata\local\temp\denuvo\v8.dll
c:\users\admin\appdata\local\temp\denuvo\icui18n.dll
c:\users\admin\appdata\local\temp\denuvo\icuuc.dll
c:\users\admin\appdata\local\temp\denuvo\video.dll
c:\users\admin\appdata\local\temp\denuvo\libavcodec-57.dll
c:\users\admin\appdata\local\temp\denuvo\libavutil-55.dll
c:\users\admin\appdata\local\temp\denuvo\libavformat-57.dll
c:\users\admin\appdata\local\temp\denuvo\libavresample-3.dll
c:\users\admin\appdata\local\temp\denuvo\libswscale-4.dll
c:\users\admin\appdata\local\temp\denuvo\vstdlib_s.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\hid.dll
c:\windows\system32\wintrust.dll
c:\users\admin\appdata\local\temp\denuvo\bin\xinput1_3.dll
c:\users\admin\appdata\local\temp\denuvo\bin\filesystem_stdio.dll
c:\users\admin\appdata\local\temp\denuvo\bin\vgui2_s.dll
c:\windows\system32\msimg32.dll
c:\users\admin\appdata\local\temp\denuvo\bin\chromehtml.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\steamwebhelper.exe
c:\windows\system32\dwrite.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\denuvo\bin\steamservice.exe
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\users\admin\appdata\local\temp\denuvo\steamerrorreporter.exe

PID
772
CMD
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe "-lang=en_US" "-cachedir=C:\Users\admin\AppData\Local\Steam\htmlcache" "-steampid=3920" "-buildid=1560549607" "-steamid=0" "-steamuniverse=Dev" "-clientui=C:\Users\admin\AppData\Local\Temp\Denuvo\clientui" --disable-out-of-process-pac --enable-blink-features=ResizeObserver,Worklet,AudioWorklet --disable-features=TouchpadAndWheelScrollLatching,AsyncWheelEvents --enable-media-stream --enable-smooth-scrolling --num-raster-threads=4 --enable-direct-write --disablehighdpi --force-device-scale-factor=1 --device-scale-factor=1 "--log-file=C:\Users\admin\AppData\Local\Temp\Denuvo\logs\cef_log.txt"
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe
Indicators
Parent process
Steam.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Valve Corporation
Description
Steam Client WebHelper
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\steamwebhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\sdl2.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\libcef.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\chrome_elf.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\credui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\winspool.drv
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dhcpcsvc.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\winsta.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mscms.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wintrust.dll

PID
3292
CMD
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe --type=crashpad-handler /prefetch:7 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\Temp\Denuvo\dumps "--metrics-dir=C:\Users\admin\AppData\Local\CEF\User Data" --url=http://crash.steampowered.com/submit --annotation=platform=win32 --annotation=product=cefwebhelper --annotation=version=1560549607 --initial-client-data=0x154,0x158,0x15c,0x150,0x160,0x6e868b40,0x6e868b50,0x6e868b5c
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe
Indicators
No indicators
Parent process
steamwebhelper.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Valve Corporation
Description
Steam Client WebHelper
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\steamwebhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\sdl2.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\libcef.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\chrome_elf.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\credui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\winspool.drv
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dhcpcsvc.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptbase.dll

PID
2732
CMD
"C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe" --type=gpu-process --field-trial-handle=908,17062790913235559792,12430669765592437393,131072 --disable-features=AsyncWheelEvents,TouchpadAndWheelScrollLatching --log-file="C:\Users\admin\AppData\Local\Temp\Denuvo\logs\cef_log.txt" --product-version="Valve Steam Client" --lang=en-US --force-device-scale-factor=1 --disablehighdpi --buildid=1560549607 --steamid=0 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=5981178630919527866 --mojo-platform-channel-handle=984 --ignored=" --type=renderer " /prefetch:2
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe
Indicators
No indicators
Parent process
steamwebhelper.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Valve Corporation
Description
Steam Client WebHelper
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\steamwebhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\sdl2.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\libcef.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\chrome_elf.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\credui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\winspool.drv
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dhcpcsvc.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\swiftshader\libglesv2.dll
c:\users\admin\appdata\local\temp\denuvo\bin\cef\cef.win7\swiftshader\libegl.dll

PID
3100
CMD
"C:\Users\admin\AppData\Local\Temp\Denuvo\bin\SteamService.exe" /install
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\SteamService.exe
Indicators
No indicators
Parent process
Steam.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Valve Corporation
Description
Steam Client Service
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\bin\steamservice.exe
c:\systemroot\system32\ntdll.dll

PID
304
CMD
"C:\Users\admin\AppData\Local\Temp\Denuvo\bin\SteamService.exe" /install
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\SteamService.exe
Indicators
Parent process
Steam.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Valve Corporation
Description
Steam Client Service
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\bin\steamservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\version.dll
c:\windows\system32\psapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\firewallapi.dll

PID
3252
CMD
C:\Users\admin\AppData\Local\Temp\Denuvo
Path
C:\Users\admin\AppData\Local\Temp\Denuvo\steamerrorreporter.exe
Indicators
Parent process
Steam.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Valve Corporation
Description
steamerrorreporter.exe
Version
05.17.04.05
Modules
Image
c:\users\admin\appdata\local\temp\denuvo\steamerrorreporter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\denuvo\tier0_s.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\psapi.dll
c:\users\admin\appdata\local\temp\denuvo\vstdlib_s.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\version.dll
c:\users\admin\appdata\local\temp\denuvo\steam.exe
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\users\admin\appdata\local\temp\denuvo\crashhandler.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\clbcatq.dll
c:\users\admin\appdata\local\temp\denuvo\steamui.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\denuvo\sdl2.dll
c:\users\admin\appdata\local\temp\denuvo\v8.dll
c:\users\admin\appdata\local\temp\denuvo\icui18n.dll
c:\users\admin\appdata\local\temp\denuvo\icuuc.dll
c:\users\admin\appdata\local\temp\denuvo\video.dll
c:\users\admin\appdata\local\temp\denuvo\libavcodec-57.dll
c:\users\admin\appdata\local\temp\denuvo\libavutil-55.dll
c:\users\admin\appdata\local\temp\denuvo\libavformat-57.dll
c:\users\admin\appdata\local\temp\denuvo\libavresample-3.dll
c:\users\admin\appdata\local\temp\denuvo\libswscale-4.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\hid.dll
c:\windows\system32\wintrust.dll
c:\users\admin\appdata\local\temp\denuvo\bin\xinput1_3.dll
c:\users\admin\appdata\local\temp\denuvo\bin\filesystem_stdio.dll
c:\users\admin\appdata\local\temp\denuvo\bin\vgui2_s.dll
c:\windows\system32\msimg32.dll
c:\users\admin\appdata\local\temp\denuvo\bin\chromehtml.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\mpr.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll

Registry activity

Total events
888
Read events
822
Write events
66
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASAPI32
EnableFileTracing
0
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASAPI32
EnableConsoleTracing
0
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASAPI32
FileTracingMask
4294901760
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASAPI32
ConsoleTracingMask
4294901760
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASAPI32
MaxFileSize
1048576
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASAPI32
FileDirectory
%windir%\tracing
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASMANCS
EnableFileTracing
0
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASMANCS
EnableConsoleTracing
0
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASMANCS
FileTracingMask
4294901760
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASMANCS
ConsoleTracingMask
4294901760
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASMANCS
MaxFileSize
1048576
3252
steamerrorreporter.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\steamerrorreporter_RASMANCS
FileDirectory
%windir%\tracing
3252
steamerrorreporter.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3252
steamerrorreporter.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000072000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2580
reg.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
autologinuser
doomednow
1040
Steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
SteamPID
1040
1040
Steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
TempAppCmdLine
1040
Steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
SteamPID
0
3056
Steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
SteamPID
3056
3056
Steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
TempAppCmdLine
3056
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam\ActiveProcess
pid
3056
3056
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam\ActiveProcess
SteamClientDll
C:\Users\admin\AppData\Local\Temp\Denuvo\steamclient.dll
3056
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam\ActiveProcess
SteamClientDll64
C:\Users\admin\AppData\Local\Temp\Denuvo\steamclient64.dll
3056
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
SteamExe
c:/users/admin/appdata/local/temp/denuvo/steam.exe
3056
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
SteamPath
c:/users/admin/appdata/local/temp/denuvo
3056
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
SuppressAutoRun
0
3056
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
Restart
0
3056
Steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
InstallPath
C:\Users\admin\AppData\Local\Temp\Denuvo
4020
steamwebhelper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
steamwebhelper.exe
2968
steamwebhelper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
steamwebhelper.exe
2464
steamwebhelper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
steamwebhelper.exe
3364
Anno 1800.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3364
Anno 1800.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1644
reg.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
autologinuser
doomednow
3920
Steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
SteamPID
3920
3920
Steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
TempAppCmdLine
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam\ActiveProcess
pid
3920
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam\ActiveProcess
SteamClientDll
C:\Users\admin\AppData\Local\Temp\Denuvo\steamclient.dll
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam\ActiveProcess
SteamClientDll64
C:\Users\admin\AppData\Local\Temp\Denuvo\steamclient64.dll
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
SteamExe
c:/users/admin/appdata/local/temp/denuvo/steam.exe
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
SteamPath
c:/users/admin/appdata/local/temp/denuvo
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
SuppressAutoRun
0
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
Restart
0
3920
Steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
InstallPath
C:\Users\admin\AppData\Local\Temp\Denuvo
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
AutoLoginUser_Unknown
3920
Steam.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
RememberPassword_Unknown
0
3920
Steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
SteamPID
0
772
steamwebhelper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
steamwebhelper.exe
3292
steamwebhelper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
steamwebhelper.exe
304
SteamService.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Steam Client Service
EventMessageFile
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\SteamService.exe
304
SteamService.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Steam Client Service
TypesSupported
7
304
SteamService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
InstallPath
C:\Users\admin\AppData\Local\Temp\Denuvo
304
SteamService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam
URL:steam protocol
304
SteamService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam
URL Protocol
304
SteamService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam\DefaultIcon
steam.exe
304
SteamService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam\Shell\Open\Command
"C:\Users\admin\AppData\Local\Temp\Denuvo\steam.exe" -- "%1"
304
SteamService.exe
write
HKEY_CLASSES_ROOT\steam
URL:steam protocol
304
SteamService.exe
write
HKEY_CLASSES_ROOT\steam
URL Protocol
304
SteamService.exe
write
HKEY_CLASSES_ROOT\steam\DefaultIcon
steam.exe
304
SteamService.exe
write
HKEY_CLASSES_ROOT\steam\Shell\Open\Command
"C:\Users\admin\AppData\Local\Temp\Denuvo\steam.exe" -- "%1"

Files activity

Executable files
261
Suspicious files
56
Text files
5658
Unknown types
223

Dropped files

PID
Process
Filename
Type
3364
Anno 1800.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\Steam.exe
executable
MD5: e12a188ed555408016e6b6351b0af1bf
SHA256: 10851b314b44b89e59b331eac05d0cd57cc246d3ecb299c38c55d16341bb0669
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\vcruntime140.dll
executable
MD5: ccb7ea3aca7312594c1dcadba2d198cb
SHA256: 97d6e28651870f5f4a6b68958a6cec256bcdf734b1b44cc3f94cab8d916c2002
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\wow_helper.exe_
executable
MD5: 9f1ae66d7954fe2e0909a5ebc6b94798
SHA256: 1f9103af0bb28f1d15874877e4901602808719a416a5212f7f65666c4567b4d7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\vccorlib140.dll
executable
MD5: 4f34708d242cd76d235c3a80849fee57
SHA256: becfbead13fa8e6eceba379d9b99d33aa0df28f9e294eadd7b11b48b70d622ed
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\VkLayer_parameter_validation.dll_
executable
MD5: 43577f94d9effc5645bc06ce9ad1c678
SHA256: 62bddf7d7aaeb99c655c717531a74926601fad8e94d8aa2ac5ff52129ff48a1e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\ucrtbase.dll
executable
MD5: 35c9212e0df36da72dd23294829ef181
SHA256: 094a2aa96d47847c0d7866ab3c3b6d3dd096d4154c921686b856567e49adb3fd
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\libEGL.dll_
executable
MD5: 5412c7e8c101448d52ef50f5e084b3aa
SHA256: 4ca810e9756861c5729a0348a33c78bc6a19e5bb838c40158f669eaaa769f9ca
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\VkLayer_core_validation.dll
executable
MD5: 47369686f878dffa3763c3a5abb210e0
SHA256: 5d1685d0f971b99fc1d157748170f8130c3d03b5f958bddd70c197ec5d43ea20
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-stdio-l1-1-0.dll_
executable
MD5: cfa005c78e88508bb1738aea75bd5204
SHA256: 2ea8b2d79c57049802eb2d4fe0f4ec96c22fe5792ed73d00ed1c5b8a0cfccc0d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\VkLayer_object_tracker.dll
executable
MD5: bb41bb65e13454811ac649fb599cbcd8
SHA256: 722831d3aef97dd6b777dc7027b8a49dce596b20a441ab9a1338fdac8f78883e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\VkICD_mock_icd.dll
executable
MD5: c9bb63efd2eced6aa3f2918713beb334
SHA256: 013137624f527dd4b973643afdda52dd9afcd015ba20652d6cca4148272b5e9d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\VkLayer_object_tracker.dll_
executable
MD5: bb41bb65e13454811ac649fb599cbcd8
SHA256: 722831d3aef97dd6b777dc7027b8a49dce596b20a441ab9a1338fdac8f78883e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-debug-l1-1-0.dll_
executable
MD5: 47fa32b7cc0a473e5c0f8aac40882865
SHA256: aec95e6e2098a88c9f6db7d992a4d48b8333e30e8cd46c9548e1bed7497cb63f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\VkLayer_threading.dll
executable
MD5: 0f6a95f32dc5066736b771a35d22f079
SHA256: 177193161acdc1e8979101659972d0a6f8ba211b34d92c71551e6f890af4fd35
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\swiftshader\libGLESv2.dll
executable
MD5: 2a9e5b1c55137d3cd3203f4a604cad73
SHA256: 19e42c36d54367649a86162920c0a195475cf70ddac2991ed8d4e552d763993f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-console-l1-1-0.dll_
executable
MD5: f2a1ad0c28ac23a248db2e70f32c76ea
SHA256: d6ac3e9126466cb2dd5506311e487aae71f4298c3501efee9d95d1dd5a785249
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-environment-l1-1-0.dll_
executable
MD5: 5a332d36983655fa148a69d3867d0d3f
SHA256: 1a8b947c0b7fa85aa66f53628f98e10edd40d2d47fa69967674bde4acfe739fb
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\VkLayer_parameter_validation.dll
executable
MD5: 43577f94d9effc5645bc06ce9ad1c678
SHA256: 62bddf7d7aaeb99c655c717531a74926601fad8e94d8aa2ac5ff52129ff48a1e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\steamwebhelper.exe
executable
MD5: d50129c8d450c2e87121c41fd109a702
SHA256: cc4e434f524037c2224889c75b52b5df7c86ce7e8c9c1ec593fa47695d7e5e74
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-synch-l1-2-0.dll_
executable
MD5: f0dc3f311bb90d2b00ff0ee1b0de9b59
SHA256: f1a1eb948aad890f2b3bb76333b96f934a51a47b82b1d2e539653726d95b97e6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\VkICD_mock_icd.dll_
executable
MD5: c9bb63efd2eced6aa3f2918713beb334
SHA256: 013137624f527dd4b973643afdda52dd9afcd015ba20652d6cca4148272b5e9d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\wow_helper.exe
executable
MD5: 9f1ae66d7954fe2e0909a5ebc6b94798
SHA256: 1f9103af0bb28f1d15874877e4901602808719a416a5212f7f65666c4567b4d7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\swiftshader\libEGL.dll
executable
MD5: dad939b6f44b438bea43c6d5c12ae3f5
SHA256: bab1e547f9c2256e8da3c7bbb32befde390677f17885d757f54c10c7dcd16e08
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-process-l1-1-0.dll_
executable
MD5: 7229ab996f3d490869c18b1df2bfbb68
SHA256: 06a8121fff6526df342ba427dad96fbc9842a0eec3b9414ef271ea6ebaa6e21a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-utility-l1-1-0.dll_
executable
MD5: dbd0c74196f91ee95a678aa5ad8fd0d6
SHA256: fe50aa913964950961923b290a2833ea897e4926e5d81da8ad61572ef0be3794
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\winh264.dll
executable
MD5: 3f0ed7680f2bde7b91358127d06762a0
SHA256: e716b7f7b22e2e0a00f8aed5972d5d119151ab58c3c01eb56c846e2666fd99c8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\pgort140.dll
executable
MD5: 49f0142d284f904d25da9d8558ef03d4
SHA256: 2082eed8b00b9d1958ebe7749683c38d143252ee8ca5014b3fe019dbb756d819
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-string-l1-1-0.dll_
executable
MD5: c32f649afbaf9d2492c9931299b7c69e
SHA256: 858e15961d9112cc1e2d2cb8c6364494411e8b6f80a93158c77d597aafdb768f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\vcruntime140.dll_
executable
MD5: ccb7ea3aca7312594c1dcadba2d198cb
SHA256: 97d6e28651870f5f4a6b68958a6cec256bcdf734b1b44cc3f94cab8d916c2002
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\filesystem_stdio.dll
executable
MD5: 6667f60417636bb1b03416986b7bfc70
SHA256: 287fe1aabd3aa04c42c1b6fae463f318cfbabe068e2c916d8b6e3b76ebefd830
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\SDL2.dll
executable
MD5: 6c3cc33cec0b46db407f0d8d241386cc
SHA256: 9d85ffc484ae061ca242403a5b13b16e268623e19cb9e8b3f9fcd9337b861859
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-time-l1-1-0.dll_
executable
MD5: e634b078034bd51cd01fc7cd923bd2a0
SHA256: fa9f516902d141a4e652755f78071b8ea4b076843ca69e8a54169ae6c9983d91
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-math-l1-1-0.dll_
executable
MD5: b16fcfe796d5803816ac9c41d2cb0957
SHA256: d9c1aeac42c5c1fb3dfc1661dd6b4293aec80acff2916b3d5e1996949e33cf21
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\VkLayer_unique_objects.dll
executable
MD5: cc8c5318d7c73f4c349c6ea5e8e3ee11
SHA256: 55183a47cca3f86c48ca5c33800ece1670a83b7ab69d08465ec0eb24671e2312
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\msvcp140.dll
executable
MD5: 07c4a055456237176ed2de7991af36a6
SHA256: 981d5b2c2c6cbd5b24f15c16ab580ea11367cb80a8380ec8f4bad01f724975ce
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-timezone-l1-1-0.dll_
executable
MD5: 20ba3a0ab1336858bb1ed8d5f477ba3c
SHA256: e10c45c40b0318e381fddf408604603b788f67a83fbd90b1c8cbf0917e0496d2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-locale-l1-1-0.dll_
executable
MD5: dcf6d4868bcfe3894e261fd6977f0c4e
SHA256: 3b48e5d23ac943f648be5733584ff08f24f6af155669eb5bda8cffc1749ccf92
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\chromehtml.dll
executable
MD5: c5ef876077ddbcdef01711f208d8a5cf
SHA256: 2e794abff87fa22a050c59f2b1c12355b01aeec1c584c8bade849a557e660a16
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\libGLESv2.dll
executable
MD5: cf023557e40c1bcd8a1928b4d8a4a464
SHA256: 83e9b6d67e28211458b3e2c0471601866125c50d15cd7d0f9dfffd1d7e7fe0df
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-errorhandling-l1-1-0.dll_
executable
MD5: 6706bcbbc8b987a300b426cb74eea588
SHA256: 41e6ead13e861f749c3e087f2908800fe5b2a1415b87196c46affb60f023e1b4
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\msvcp140.dll_
executable
MD5: 07c4a055456237176ed2de7991af36a6
SHA256: 981d5b2c2c6cbd5b24f15c16ab580ea11367cb80a8380ec8f4bad01f724975ce
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\friendsui.dll
executable
MD5: 24590acd3eb0484b5e4facf6571e226a
SHA256: 174321f97d89c192e7c27de89f1f87aea725ade82cab17d09ba58b4a8468b418
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\libEGL.dll
executable
MD5: 5412c7e8c101448d52ef50f5e084b3aa
SHA256: 4ca810e9756861c5729a0348a33c78bc6a19e5bb838c40158f669eaaa769f9ca
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\pgort140.dll_
executable
MD5: 49f0142d284f904d25da9d8558ef03d4
SHA256: 2082eed8b00b9d1958ebe7749683c38d143252ee8ca5014b3fe019dbb756d819
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\API-MS-Win-core-xstate-l2-1-0.dll_
executable
MD5: b2b022dfb6e7d246ec978b2fe6cb3601
SHA256: e26a8da65199b12842ff5fedaa21e920c1dce72c857931d04a32301fef4a6fdc
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\mssmp3.asi
executable
MD5: d234e2c8ce00bb2c6183f2ebfe61aaab
SHA256: 27187de134e5ed1ab19a01e151e475a758560e10ec546acd7e389d2e89c5edc7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\html5app_steam.exe
executable
MD5: 9ab8a35d5214d921bbef8318fb7191c2
SHA256: 1db7c40bc589c42940859d8eb0c8e37cdb02a94f1421c6031c0123a8d68af245
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\libGLESv2.dll_
executable
MD5: cf023557e40c1bcd8a1928b4d8a4a464
SHA256: 83e9b6d67e28211458b3e2c0471601866125c50d15cd7d0f9dfffd1d7e7fe0df
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\VkLayer_core_validation.dll_
executable
MD5: 47369686f878dffa3763c3a5abb210e0
SHA256: 5d1685d0f971b99fc1d157748170f8130c3d03b5f958bddd70c197ec5d43ea20
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\gameoverlayui.dll
executable
MD5: a6605626fff9322a666290316f4de7f9
SHA256: 4bf5c945c1f69990d7dec526c45abbc959b8b161e40a437404f8e0a389c28900
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\dbgcore.dll
executable
MD5: 21c9fd6e4452f111a7a2645492f4f963
SHA256: 12c23cf76a975b21b0968b8d2d9587c4e54c39638e9c1f25cefd0a9e6c8083aa
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\SDL2.dll_
executable
MD5: 6c3cc33cec0b46db407f0d8d241386cc
SHA256: 9d85ffc484ae061ca242403a5b13b16e268623e19cb9e8b3f9fcd9337b861859
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-heap-l1-1-0.dll_
executable
MD5: 2d55cccf4abfe179ddd167d7b8fb2557
SHA256: 66db08092df6315f9463d8cc37404a765a29c6ed65ed575440a5f0e730e934a6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\mss32.dll
executable
MD5: d6d952c03fb8b6f9c63761213ec4d4af
SHA256: 9c832318a05290ebef3bd809cbbc7df70a08cbd86745899eaeb169d5a42bf99d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\d3dcompiler_47.dll
executable
MD5: d4e32ff16ddb113da729eab2aeb80ee9
SHA256: a0d95eaff1e957e73f1baa0e77bda0428812552ba33749337ded220d256df16a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-convert-l1-1-0.dll_
executable
MD5: 19f77d3d718610209cd90221c94ea315
SHA256: ce84b054a3b5e8f6b47ac39cc59c861be6d3ebeca9f4531722eefd4a997a6892
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-libraryloader-l1-1-0.dll_
executable
MD5: b843aac839da01690503507c8f729d86
SHA256: edc46533e53426558f69cfbd1a8e13fd226f0443671e998a5e6c0422007a4b55
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\gldriverquery64.exe
executable
MD5: 519ccd21fc4a0f26debd33320c50df57
SHA256: 23b4063251315814e188d64afe08ea49979f5fb2b74b86860e655a1a4d8fe4e3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\chrome_elf.dll
executable
MD5: f5146ab9ec6cbcad53f2dd9c261f5f69
SHA256: fde281b5e4949e23f635034659f560c7aacdf2da7cd5b54ebef4abf7b41966ff
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-memory-l1-1-0.dll_
executable
MD5: d6c520cd1c3a453a165064896491eca0
SHA256: 4a2d7b0a70ae8e950be5aff0197a46e1e312f3a1f98a2d0756ad71eb03786dc6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-rtlsupport-l1-1-0.dll_
executable
MD5: cf35cfe9c01b78f2343e1556dbf7dc09
SHA256: 98a7f04f2b5dfa9e79469f90dbfacb9546e51f0d07e63fb9c6a1f82ddae5fa1f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\gldriverquery.exe
executable
MD5: d6d6ddf71c2a46b4735c20ec16270ab6
SHA256: 0d422efdfa17dc6e1ebf0ed9e2902fd7c0eaa2f77b8a5a8f1df1478453a37ab8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-utility-l1-1-0.dll
executable
MD5: dbd0c74196f91ee95a678aa5ad8fd0d6
SHA256: fe50aa913964950961923b290a2833ea897e4926e5d81da8ad61572ef0be3794
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-processenvironment-l1-1-0.dll_
executable
MD5: 9093e38b20e875705fdfaf40b950e9ab
SHA256: f3360db96b70de1e8fb15fe8f0a8cb9d45e1a7976ea512e6587a30f3a402a8a3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-runtime-l1-1-0.dll_
executable
MD5: d19f6f7b8296c934051f5ad1b002dd5c
SHA256: 3642b2cc4f33dcab14796cdcec9d8c439c3d404574c0eb371b3bd7a715992da1
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\mssdsp.flt
executable
MD5: a41226ccdf8f4553960364e01d25e75b
SHA256: db4d5d314c245b664710d413d1499d6572de3330eb888cc5a693b65365d4ecd8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-time-l1-1-0.dll
executable
MD5: e634b078034bd51cd01fc7cd923bd2a0
SHA256: fa9f516902d141a4e652755f78071b8ea4b076843ca69e8a54169ae6c9983d91
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-processthreads-l1-1-1.dll_
executable
MD5: 1db1930194160446884d575a2163de64
SHA256: 9232be87e06971021f7d6da780980493eac6bb8fca6457585c7a35c88eb1937a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-multibyte-l1-1-0.dll_
executable
MD5: 039ad48f4b724bbbd839d0fa5d89f8ea
SHA256: 8d557c07fdf97374db3568bcc0b0b1e2e752e5ec05fb816cbe7b64b4c0287d52
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\mssvoice.asi
executable
MD5: a8c356e91454c8a46862dfb338f965d8
SHA256: f2780549bc979b8874aa38ea7572f971091ab8a5902828d5d114c6f28e0385d7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-string-l1-1-0.dll
executable
MD5: c32f649afbaf9d2492c9931299b7c69e
SHA256: 858e15961d9112cc1e2d2cb8c6364494411e8b6f80a93158c77d597aafdb768f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\VkLayer_unique_objects.dll_
executable
MD5: cc8c5318d7c73f4c349c6ea5e8e3ee11
SHA256: 55183a47cca3f86c48ca5c33800ece1670a83b7ab69d08465ec0eb24671e2312
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-file-l1-2-0.dll_
executable
MD5: fc8a2f088cfa2ed2cc3fddf56eb088d8
SHA256: 7479f62d7c7f7e466b54898b41a22ef25ba325e39b92911db8cc0cdcc136b9ae
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\nattypeprobe.dll
executable
MD5: 9cc6f8899325ad229b5d05c339b89d4d
SHA256: 6856385a25e14ec77ac44902abf7cd79579cdc138f0b9c599fec0bf7ff637238
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-stdio-l1-1-0.dll
executable
MD5: cfa005c78e88508bb1738aea75bd5204
SHA256: 2ea8b2d79c57049802eb2d4fe0f4ec96c22fe5792ed73d00ed1c5b8a0cfccc0d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\swiftshader\libEGL.dll_
executable
MD5: dad939b6f44b438bea43c6d5c12ae3f5
SHA256: bab1e547f9c2256e8da3c7bbb32befde390677f17885d757f54c10c7dcd16e08
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-sysinfo-l1-1-0.dll_
executable
MD5: edd8ab5e7ffd7402898655207d6971b0
SHA256: 0881f642c71561be0752959d21c43816fd270573565ed8b3bc64cf00379bca74
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\serverbrowser.dll
executable
MD5: 474d4c73f1504f66f51c74cef567c17f
SHA256: 09e457768619ea497a67d7abe0340db73557ae9dc14f3e0f50179aa9ad9e9481
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-private-l1-1-0.dll
executable
MD5: 8124db6e9e80412fb5913f3617f298f7
SHA256: b59d9291ff93e934ac4ee2ff94c18dde19694705a5ff0aaef750acaf167e5e53
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-string-l1-1-0.dll_
executable
MD5: c74bbb5b0dbabb58eb3281cb3a9f05dc
SHA256: 8002742d77b6783910e9da4778ee6604e03ecec014eb3f782f32ba055c514d4d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-processthreads-l1-1-0.dll_
executable
MD5: 0cddbdea7239221725890300c2f61d89
SHA256: fbd8bd33a330298536e675dcaf5d3643c33f83ce44a82e41cf3e5f9956f08b34
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\secure_desktop_capture.exe
executable
MD5: 849925849adf20f2ac0eadca3bedc349
SHA256: 84f3484eca9b843cdff22143e3b02e085f3a6deeee84d93fb2c76ee891750bdd
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-process-l1-1-0.dll
executable
MD5: 7229ab996f3d490869c18b1df2bfbb68
SHA256: 06a8121fff6526df342ba427dad96fbc9842a0eec3b9414ef271ea6ebaa6e21a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-filesystem-l1-1-0.dll_
executable
MD5: 4501e02b2e453ef7a992c0ecf0bdf547
SHA256: 33f1178092a6c1ca6a363ec1d3ea30630a73fde1a61c0ace1aa8d073cb435808
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-namedpipe-l1-1-0.dll_
executable
MD5: 63c69aebf7910e6f445e1ba490385e56
SHA256: e3df87750709a3e89da8d096cb901e01c0754d8bfafc7774cf892cce0605ec71
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\panorama\panorama.dll
executable
MD5: 248bb70ca9cab1cd77490a661ead2eb0
SHA256: 2c8789a1d4407d9f0f9c43a2a43edab2a565eecc22e66f1f4a79ff401944ec13
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-multibyte-l1-1-0.dll
executable
MD5: 039ad48f4b724bbbd839d0fa5d89f8ea
SHA256: 8d557c07fdf97374db3568bcc0b0b1e2e752e5ec05fb816cbe7b64b4c0287d52
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-profile-l1-1-0.dll_
executable
MD5: cff4cb3983f01c4a8f02f7d7c5a492c8
SHA256: 256268f3311e954e6dff7be7a4eddcd0dbf7274cfa25e86b7b658e6c12a3072f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\chrome_elf.dll_
executable
MD5: f5146ab9ec6cbcad53f2dd9c261f5f69
SHA256: fde281b5e4949e23f635034659f560c7aacdf2da7cd5b54ebef4abf7b41966ff
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\steamservice.exe
executable
MD5: d03f04f97bd8f938e6dd741718f85a21
SHA256: 6985fddd016f26b7d990b298b2ff6b7ebb7ff4546bf9dc443a3ab7a8bf43d2b8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-runtime-l1-1-0.dll
executable
MD5: d19f6f7b8296c934051f5ad1b002dd5c
SHA256: 3642b2cc4f33dcab14796cdcec9d8c439c3d404574c0eb371b3bd7a715992da1
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows10\x64\SteamStreamingMicrophone.sys_
executable
MD5: 23f8a7c0d75aea4440db0a5f855db1a1
SHA256: 0ec2de32da3afbc63ea84e76d1f0322382c273b3162885c7254f3960802b3b5e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-private-l1-1-0.dll_
executable
MD5: 8124db6e9e80412fb5913f3617f298f7
SHA256: b59d9291ff93e934ac4ee2ff94c18dde19694705a5ff0aaef750acaf167e5e53
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\steamservice.dll
executable
MD5: c32531e708ed813b9499fb2a00e01e95
SHA256: 34999ff649da449d684f808bad381b56240fe285c94e4049820f90537f2ea700
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-math-l1-1-0.dll
executable
MD5: b16fcfe796d5803816ac9c41d2cb0957
SHA256: d9c1aeac42c5c1fb3dfc1661dd6b4293aec80acff2916b3d5e1996949e33cf21
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-util-l1-1-0.dll_
executable
MD5: c30ae2244c8b906264ff2d092e0318dd
SHA256: 75a47f17b407982f52b551008bade061003656d4efc4c152d93a3041026500d1
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\winh264.dll_
executable
MD5: 3f0ed7680f2bde7b91358127d06762a0
SHA256: e716b7f7b22e2e0a00f8aed5972d5d119151ab58c3c01eb56c846e2666fd99c8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\steam_monitor.exe
executable
MD5: be1bc16d6df2889eac1330cdf8b99f62
SHA256: 964be2c459399b9d8edaa1d01f747e6c7fe203c624befb6fbce3856d00ecaca2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-conio-l1-1-0.dll
executable
MD5: 8bb27434ba25841b238097b4811d91ce
SHA256: 0295ac86d4e9eef99fc330c867ff2851836fd5a4b3da6b5a53569e3d2e00f178
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-datetime-l1-1-0.dll_
executable
MD5: f3cc44bc5d4dbf5020b62699025406a6
SHA256: 1a3e77cd05fbbd8b8e801a232ffaca27bc73bb68a5b5e9ca560ed931a3e85dea
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\swiftshader\libGLESv2.dll_
executable
MD5: 2a9e5b1c55137d3cd3203f4a604cad73
SHA256: 19e42c36d54367649a86162920c0a195475cf70ddac2991ed8d4e552d763993f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\x86launcher.exe
executable
MD5: d5b1c4f1131b9e2f5cedc584cd940433
SHA256: b13bcfdf0ae2e75c6cb1313b4bcadd10004a1ed4f22cb4099f982662ca532b81
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-heap-l1-1-0.dll
executable
MD5: 2d55cccf4abfe179ddd167d7b8fb2557
SHA256: 66db08092df6315f9463d8cc37404a765a29c6ed65ed575440a5f0e730e934a6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\vccorlib140.dll_
executable
MD5: 4f34708d242cd76d235c3a80849fee57
SHA256: becfbead13fa8e6eceba379d9b99d33aa0df28f9e294eadd7b11b48b70d622ed
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\VkLayer_threading.dll_
executable
MD5: 0f6a95f32dc5066736b771a35d22f079
SHA256: 177193161acdc1e8979101659972d0a6f8ba211b34d92c71551e6f890af4fd35
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\vgui2_s.dll
executable
MD5: 420d82bc3e81246503858d271c072684
SHA256: 611c4e39f62ef5a38822e8fb8e154d2effadf894ab32d9f704787dc1fb66457e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-convert-l1-1-0.dll
executable
MD5: 19f77d3d718610209cd90221c94ea315
SHA256: ce84b054a3b5e8f6b47ac39cc59c861be6d3ebeca9f4531722eefd4a997a6892
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\icuuc.dll_
executable
MD5: 79c7511f2958974aa9ebea764b735e13
SHA256: 3bc5f41b88f04deb7865cee3a4fc10c4cd08da2e812a18cebf30ee4dc5316be6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\dbgcore.dll_
executable
MD5: 21c9fd6e4452f111a7a2645492f4f963
SHA256: 12c23cf76a975b21b0968b8d2d9587c4e54c39638e9c1f25cefd0a9e6c8083aa
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\xinput1_3.dll
executable
MD5: da9506e800e13da0abba32bb0c105382
SHA256: cc42da948da5be1186ed92265f2b5dd895795ac9ed264efe822b242946ad9f39
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-locale-l1-1-0.dll
executable
MD5: dcf6d4868bcfe3894e261fd6977f0c4e
SHA256: 3b48e5d23ac943f648be5733584ff08f24f6af155669eb5bda8cffc1749ccf92
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows8.1\x86\SteamStreamingMicrophone.sys_
executable
MD5: dd4d15317a0ff2cdc5128ad5e6fe4346
SHA256: 2ad756d8c70dc43d4f31b8ac49f61b09cfe650b31bada5cc1725ea8fc46339e7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-heap-l1-1-0.dll_
executable
MD5: 75b3a00f585d4c3abc57e24ba2bd3865
SHA256: 53643095fb7f33d19aa8efdb3bbfd8777c2780ec862d1b5a29a6a7774dab73c3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\xpad.dll
executable
MD5: da9506e800e13da0abba32bb0c105382
SHA256: cc42da948da5be1186ed92265f2b5dd895795ac9ed264efe822b242946ad9f39
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-filesystem-l1-1-0.dll
executable
MD5: 4501e02b2e453ef7a992c0ecf0bdf547
SHA256: 33f1178092a6c1ca6a363ec1d3ea30630a73fde1a61c0ace1aa8d073cb435808
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\mssdsp.flt_
executable
MD5: a41226ccdf8f4553960364e01d25e75b
SHA256: db4d5d314c245b664710d413d1499d6572de3330eb888cc5a693b65365d4ecd8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-localization-l1-2-0.dll_
executable
MD5: 1d5efb7c976b908ff80ba29e61eb0b9e
SHA256: 21b201eab225eaf0d2f72aba24342c6f9544ccafcf0da6e1d4fae208e10d2eb5
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\x64launcher.exe
executable
MD5: 9b75dc5a50eade900a213148949c2c51
SHA256: 971ee19a115bd0810610cdd00eefc76e668d44c04983bbd809e71405de54e57e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-crt-environment-l1-1-0.dll
executable
MD5: 5a332d36983655fa148a69d3867d0d3f
SHA256: 1a8b947c0b7fa85aa66f53628f98e10edd40d2d47fa69967674bde4acfe739fb
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\Steam2.dll_
executable
MD5: c6b57bc6559f86b3e34d8ab0fbb628d5
SHA256: 4d46e343e004c470efe28b81aa1e8f9f27b2c730790c7da3053ee0dc412c26ff
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-handle-l1-1-0.dll_
executable
MD5: ce1dbfcd375b973e83cb2f1dd1df64a2
SHA256: 7134104210d41b08f5d6bb0ea5016fcf24b86d2c6348300261f28165d4701124
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\crashhandler.dll
executable
MD5: ff799f5e2a3ca7b84e5262a31fa0654b
SHA256: ac4e41486b4c4980feaf2c1a3098c75de98b71522ffdd0323243a15c00374e12
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-string-l1-1-0.dll
executable
MD5: c74bbb5b0dbabb58eb3281cb3a9f05dc
SHA256: 8002742d77b6783910e9da4778ee6604e03ecec014eb3f782f32ba055c514d4d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows8.1\x64\WdfCoinstaller01009.dll_
executable
MD5: 4da5da193e0e4f86f6f8fd43ef25329a
SHA256: 18487b4ff94edccc98ed59d9fca662d4a1331c5f1e14df8db3093256dd9f1c3e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-interlocked-l1-1-0.dll_
executable
MD5: 7e2cc669ea68ad3c0863ca1730e73799
SHA256: 31cca4201b8f09968b0ea1745b4023fe34d25f3b689560ada55704a6b2336797
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\crashhandler64.dll
executable
MD5: ef6d824488a7441531b4bbf84fba2112
SHA256: 8bcf8f5851cba2d81758591e2f3adf549d6c0430a6a9ffd4214917ff3f5f9adf
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-timezone-l1-1-0.dll
executable
MD5: 20ba3a0ab1336858bb1ed8d5f477ba3c
SHA256: e10c45c40b0318e381fddf408604603b788f67a83fbd90b1c8cbf0917e0496d2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\nattypeprobe.dll_
executable
MD5: 9cc6f8899325ad229b5d05c339b89d4d
SHA256: 6856385a25e14ec77ac44902abf7cd79579cdc138f0b9c599fec0bf7ff637238
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\ucrtbase.dll_
executable
MD5: 35c9212e0df36da72dd23294829ef181
SHA256: 094a2aa96d47847c0d7866ab3c3b6d3dd096d4154c921686b856567e49adb3fd
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\d3dcompiler_46.dll
executable
MD5: c18caa9ba4f06a5d226a892df6dc1d72
SHA256: 996e5b57c06b5614ee7b26936b29bace62218fb3cad3a28dba9e72bcc66d2698
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-util-l1-1-0.dll
executable
MD5: c30ae2244c8b906264ff2d092e0318dd
SHA256: 75a47f17b407982f52b551008bade061003656d4efc4c152d93a3041026500d1
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\secure_desktop_capture.exe_
executable
MD5: 849925849adf20f2ac0eadca3bedc349
SHA256: 84f3484eca9b843cdff22143e3b02e085f3a6deeee84d93fb2c76ee891750bdd
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-file-l2-1-0.dll_
executable
MD5: ff5fce5f4d7037344594b3d1f704f757
SHA256: 421cfa9e9f38052a8a6da8f8504d0dbfe91932cac6eabf4aec7dd47799158b08
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\CSERHelper.dll
executable
MD5: 833d30fa5bd04e2011cb6b9d7081dded
SHA256: 09d4c2067217b1900d4d7a936969f809821649b10ed8afd0f49de2871f7a3784
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-synch-l1-1-0.dll
executable
MD5: b413f5f05115f7d59b99393611cc6689
SHA256: c613cca1e43f1e4e90815dd69d2798677ee34c6bb9b98f600f5dad0aa5d287e4
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\mssvoice.asi_
executable
MD5: a8c356e91454c8a46862dfb338f965d8
SHA256: f2780549bc979b8874aa38ea7572f971091ab8a5902828d5d114c6f28e0385d7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-crt-conio-l1-1-0.dll_
executable
MD5: 8bb27434ba25841b238097b4811d91ce
SHA256: 0295ac86d4e9eef99fc330c867ff2851836fd5a4b3da6b5a53569e3d2e00f178
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\d3dcompiler_46_64.dll
executable
MD5: 52a41f0e49b2208df75609699fc7254c
SHA256: 9614de7bac24091e2abaf70b3c852ddf9b92a48157c557c3c63d81d88d4d5ceb
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\API-MS-Win-core-xstate-l2-1-0.dll
executable
MD5: b2b022dfb6e7d246ec978b2fe6cb3601
SHA256: e26a8da65199b12842ff5fedaa21e920c1dce72c857931d04a32301fef4a6fdc
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\resource\sourceinit.dat_
executable
MD5: be4af164563b8af31da75b368704df63
SHA256: 7b717fea39ce416bdb5e30e6de01053f6ea10912dd6df3884838082711ccba8a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-file-l1-1-0.dll_
executable
MD5: 24a8f9f30ebc97fecfac2125892e8f2d
SHA256: 0863bf3c809a1cf78696aa35502fa56105d303e03f0c521df55e538a31e2f034
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows10\x64\SteamStreamingMicrophone.sys
executable
MD5: 23f8a7c0d75aea4440db0a5f855db1a1
SHA256: 0ec2de32da3afbc63ea84e76d1f0322382c273b3162885c7254f3960802b3b5e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-rtlsupport-l1-1-0.dll
executable
MD5: cf35cfe9c01b78f2343e1556dbf7dc09
SHA256: 98a7f04f2b5dfa9e79469f90dbfacb9546e51f0d07e63fb9c6a1f82ddae5fa1f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows10\x86\SteamStreamingMicrophone.sys_
executable
MD5: 9f3779836f80a52f2f0ae866f18bf118
SHA256: 135cc5ac87ad971e8069068f2e971dfe170962eea7b446d24796fb01004eccc9
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\d3dcompiler_47.dll_
executable
MD5: d4e32ff16ddb113da729eab2aeb80ee9
SHA256: a0d95eaff1e957e73f1baa0e77bda0428812552ba33749337ded220d256df16a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows10\x64\SteamStreamingSpeakers.sys
executable
MD5: f23381e193dbc8d47b4c113dd57360cc
SHA256: ee1ee0d1346328da18d70988f01bd961437e95be5ab82059a28cbcc7d4b23239
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-sysinfo-l1-1-0.dll
executable
MD5: edd8ab5e7ffd7402898655207d6971b0
SHA256: 0881f642c71561be0752959d21c43816fd270573565ed8b3bc64cf00379bca74
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows10\x64\WdfCoinstaller01009.dll_
executable
MD5: 5f73260107664b4854404bfa5b0b16aa
SHA256: 6805b55d87a8cfd77b43a2fc5a311be6d4c4209b08ecbe294c0e6b1a2488ad9b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\html5app_steam.exe_
executable
MD5: 9ab8a35d5214d921bbef8318fb7191c2
SHA256: 1db7c40bc589c42940859d8eb0c8e37cdb02a94f1421c6031c0123a8d68af245
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows10\x86\SteamStreamingMicrophone.sys
executable
MD5: 9f3779836f80a52f2f0ae866f18bf118
SHA256: 135cc5ac87ad971e8069068f2e971dfe170962eea7b446d24796fb01004eccc9
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-synch-l1-2-0.dll
executable
MD5: f0dc3f311bb90d2b00ff0ee1b0de9b59
SHA256: f1a1eb948aad890f2b3bb76333b96f934a51a47b82b1d2e539653726d95b97e6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\icui18n.dll_
executable
MD5: ab189439d2c625793b4ab4eb15641687
SHA256: 3334b44ea1eb888dbc240c80c78e0f78040ff1f6d458ca69357bc22db776b1f5
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\steamwebhelper.exe_
executable
MD5: d50129c8d450c2e87121c41fd109a702
SHA256: cc4e434f524037c2224889c75b52b5df7c86ce7e8c9c1ec593fa47695d7e5e74
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows10\x64\WdfCoinstaller01009.dll
executable
MD5: 5f73260107664b4854404bfa5b0b16aa
SHA256: 6805b55d87a8cfd77b43a2fc5a311be6d4c4209b08ecbe294c0e6b1a2488ad9b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-processthreads-l1-1-0.dll
executable
MD5: 0cddbdea7239221725890300c2f61d89
SHA256: fbd8bd33a330298536e675dcaf5d3643c33f83ce44a82e41cf3e5f9956f08b34
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows8.1\x64\SteamStreamingMicrophone.sys_
executable
MD5: 716c6517f638b0f58cdb5fdf3d2f1530
SHA256: f4d850e6a1adc763f1f2765589872a90b1fe581714c8f26f7f998ddfb48c49fe
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\GameOverlayRenderer64.dll_
executable
MD5: a7279697d614f216ba6c64f4644bd09c
SHA256: 2ee5a77220e7f2b566a6715d356b2767b45c97f2c9b0b370a5506aac6184c149
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows10\x86\SteamStreamingSpeakers.sys
executable
MD5: 4edf6900980aef983ff3c5b5df2df925
SHA256: 6fad221c4a723d0be0932be819591bd40bd9d9bf73f4dda25e0ed56aa0c675b0
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-memory-l1-1-0.dll
executable
MD5: d6c520cd1c3a453a165064896491eca0
SHA256: 4a2d7b0a70ae8e950be5aff0197a46e1e312f3a1f98a2d0756ad71eb03786dc6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\d3dcompiler_46.dll_
executable
MD5: c18caa9ba4f06a5d226a892df6dc1d72
SHA256: 996e5b57c06b5614ee7b26936b29bace62218fb3cad3a28dba9e72bcc66d2698
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\tier0_s.dll_
executable
MD5: 257453fc07a2c4469bd0b455bca03c23
SHA256: 50e9ae770437106a4e0437fcd4216d26dc27b78be4ff7b54454f3bcf7275cca3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows10\x86\WdfCoinstaller01009.dll
executable
MD5: 59b55989ab09508e2fd9ad5fda5a8081
SHA256: 252a24c95f143649a7898e940fe4bb6a8271047d4d872681489602106ef1b7a7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-processthreads-l1-1-1.dll
executable
MD5: 1db1930194160446884d575a2163de64
SHA256: 9232be87e06971021f7d6da780980493eac6bb8fca6457585c7a35c88eb1937a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows8.1\x64\SteamStreamingSpeakers.sys_
executable
MD5: 76df9dbaf8a6ae554ee1dd1f2c283398
SHA256: cd4d520811dd6b64cdcb18d78e6fd07600092c72eab5295fea18c34b82f6f2f1
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\filesystem_stdio.dll_
executable
MD5: 6667f60417636bb1b03416986b7bfc70
SHA256: 287fe1aabd3aa04c42c1b6fae463f318cfbabe068e2c916d8b6e3b76ebefd830
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows8.1\x64\SteamStreamingMicrophone.sys
executable
MD5: 716c6517f638b0f58cdb5fdf3d2f1530
SHA256: f4d850e6a1adc763f1f2765589872a90b1fe581714c8f26f7f998ddfb48c49fe
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-profile-l1-1-0.dll
executable
MD5: cff4cb3983f01c4a8f02f7d7c5a492c8
SHA256: 256268f3311e954e6dff7be7a4eddcd0dbf7274cfa25e86b7b658e6c12a3072f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows8.1\x86\SteamStreamingSpeakers.sys_
executable
MD5: 203d1fb625ccf2fc9cac73ff5adff7d0
SHA256: d6c027e4b90164c09f973416580be69831e76590be861dba5ce05372fb3390a8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\vstdlib_s.dll_
executable
MD5: 1e0d44f06eaf52b95019ea76ad04d285
SHA256: e866433bd9c5d37dc48c3d5553a8d38791415568a3750132eb27ad5d1b37524b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows8.1\x64\SteamStreamingSpeakers.sys
executable
MD5: 76df9dbaf8a6ae554ee1dd1f2c283398
SHA256: cd4d520811dd6b64cdcb18d78e6fd07600092c72eab5295fea18c34b82f6f2f1
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-namedpipe-l1-1-0.dll
executable
MD5: 63c69aebf7910e6f445e1ba490385e56
SHA256: e3df87750709a3e89da8d096cb901e01c0754d8bfafc7774cf892cce0605ec71
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows10\x64\SteamStreamingSpeakers.sys_
executable
MD5: f23381e193dbc8d47b4c113dd57360cc
SHA256: ee1ee0d1346328da18d70988f01bd961437e95be5ab82059a28cbcc7d4b23239
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\steamclient.dll_
executable
MD5: 6e3feb1271a6dd337896d37ab8cc9b98
SHA256: f741f45471d4eb14c6dfd3b87a6c7316c79f5dd46e8192427d0df90c68a5163c
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows8.1\x64\WdfCoinstaller01009.dll
executable
MD5: 4da5da193e0e4f86f6f8fd43ef25329a
SHA256: 18487b4ff94edccc98ed59d9fca662d4a1331c5f1e14df8db3093256dd9f1c3e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-processenvironment-l1-1-0.dll
executable
MD5: 9093e38b20e875705fdfaf40b950e9ab
SHA256: f3360db96b70de1e8fb15fe8f0a8cb9d45e1a7976ea512e6587a30f3a402a8a3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\WriteMiniDump.exe_
executable
MD5: ee57dfa8cde83118e8745be09d5e8259
SHA256: f29c7a4a0d45c020a0cb93db1147cb81e913ef83b4e840cbba7c87b2da3a363b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\steam_monitor.exe_
executable
MD5: be1bc16d6df2889eac1330cdf8b99f62
SHA256: 964be2c459399b9d8edaa1d01f747e6c7fe203c624befb6fbce3856d00ecaca2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows8.1\x86\WdfCoinstaller01009.dll
executable
MD5: a9970042be512c7981b36e689c5f3f9f
SHA256: 7a6bf1f950684381205c717a51af2d9c81b203cb1f3db0006a4602e2df675c77
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-libraryloader-l1-1-0.dll
executable
MD5: b843aac839da01690503507c8f729d86
SHA256: edc46533e53426558f69cfbd1a8e13fd226f0443671e998a5e6c0422007a4b55
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\v8.dll_
executable
MD5: 7b4acbf9ee05b7f6c8626b76bac4b7ee
SHA256: da42f5ac7490ca17306596619b1b92c314bc8101e4ac8fc3c3cf81f529ffdfaa
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\VkLayer_steam_fossilize.dll_
executable
MD5: 57d30020a71522cd47b3424bd09d5afa
SHA256: 0e9f162aeeaf5a21935fe6bc1b3344fa4263d5c7fddde5b47922ee171798fef0
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows8.1\x86\SteamStreamingSpeakers.sys
executable
MD5: 203d1fb625ccf2fc9cac73ff5adff7d0
SHA256: d6c027e4b90164c09f973416580be69831e76590be861dba5ce05372fb3390a8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-localization-l1-2-0.dll
executable
MD5: 1d5efb7c976b908ff80ba29e61eb0b9e
SHA256: 21b201eab225eaf0d2f72aba24342c6f9544ccafcf0da6e1d4fae208e10d2eb5
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\xinput1_3.dll_
executable
MD5: da9506e800e13da0abba32bb0c105382
SHA256: cc42da948da5be1186ed92265f2b5dd895795ac9ed264efe822b242946ad9f39
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\SteamOverlayVulkanLayer.dll_
executable
MD5: ad329751f7bfa32d4fb2a40a91641bde
SHA256: 970a1f1bc507b7b20cbfafb0e0fe15b8f8ccf82a0040ea3f182c3b828647c73d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\drivers\Windows8.1\x86\SteamStreamingMicrophone.sys
executable
MD5: dd4d15317a0ff2cdc5128ad5e6fe4346
SHA256: 2ad756d8c70dc43d4f31b8ac49f61b09cfe650b31bada5cc1725ea8fc46339e7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-handle-l1-1-0.dll
executable
MD5: ce1dbfcd375b973e83cb2f1dd1df64a2
SHA256: 7134104210d41b08f5d6bb0ea5016fcf24b86d2c6348300261f28165d4701124
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\steamwebrtc.dll_
executable
MD5: f1afbe5d1fcf1cf5b9d902480efd2e4f
SHA256: 61a3d2fa5de611547bf38b2278ccaff6470b0ad3fe580df46a090030c0d113fe
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\audio.dll_
executable
MD5: 17305e37a9350e730bb7c6a60084ae8b
SHA256: 66f821d72b9881040c2b140ef2a2d5fce81a2c464547b67f41b9eba82d668ede
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\GameOverlayRenderer.dll
executable
MD5: 85e442269457a559f8ce5660c83f7733
SHA256: f02418fc7c072855c67056152842e58ffef13776b30fa8c81868397ef697d081
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-file-l1-2-0.dll
executable
MD5: fc8a2f088cfa2ed2cc3fddf56eb088d8
SHA256: 7479f62d7c7f7e466b54898b41a22ef25ba325e39b92911db8cc0cdcc136b9ae
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\xpad.dll_
executable
MD5: da9506e800e13da0abba32bb0c105382
SHA256: cc42da948da5be1186ed92265f2b5dd895795ac9ed264efe822b242946ad9f39
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\panorama\panorama.dll_
executable
MD5: 248bb70ca9cab1cd77490a661ead2eb0
SHA256: 2c8789a1d4407d9f0f9c43a2a43edab2a565eecc22e66f1f4a79ff401944ec13
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\GameOverlayRenderer64.dll
executable
MD5: a7279697d614f216ba6c64f4644bd09c
SHA256: 2ee5a77220e7f2b566a6715d356b2767b45c97f2c9b0b370a5506aac6184c149
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-heap-l1-1-0.dll
executable
MD5: 75b3a00f585d4c3abc57e24ba2bd3865
SHA256: 53643095fb7f33d19aa8efdb3bbfd8777c2780ec862d1b5a29a6a7774dab73c3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\mssmp3.asi_
executable
MD5: d234e2c8ce00bb2c6183f2ebfe61aaab
SHA256: 27187de134e5ed1ab19a01e151e475a758560e10ec546acd7e389d2e89c5edc7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\friendsui.dll_
executable
MD5: 24590acd3eb0484b5e4facf6571e226a
SHA256: 174321f97d89c192e7c27de89f1f87aea725ade82cab17d09ba58b4a8468b418
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\GameOverlayUI.exe
executable
MD5: 4138965c041f1631547fb66042900e90
SHA256: 1adc829dd2a6789c4f7a798ee29cce42ef0990987023b4fcd2c6fb423df5d2c1
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-file-l2-1-0.dll
executable
MD5: ff5fce5f4d7037344594b3d1f704f757
SHA256: 421cfa9e9f38052a8a6da8f8504d0dbfe91932cac6eabf4aec7dd47799158b08
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\mss32.dll_
executable
MD5: d6d952c03fb8b6f9c63761213ec4d4af
SHA256: 9c832318a05290ebef3bd809cbbc7df70a08cbd86745899eaeb169d5a42bf99d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\x64launcher.exe_
executable
MD5: 9b75dc5a50eade900a213148949c2c51
SHA256: 971ee19a115bd0810610cdd00eefc76e668d44c04983bbd809e71405de54e57e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\icui18n.dll
executable
MD5: ab189439d2c625793b4ab4eb15641687
SHA256: 3334b44ea1eb888dbc240c80c78e0f78040ff1f6d458ca69357bc22db776b1f5
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-interlocked-l1-1-0.dll
executable
MD5: 7e2cc669ea68ad3c0863ca1730e73799
SHA256: 31cca4201b8f09968b0ea1745b4023fe34d25f3b689560ada55704a6b2336797
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\CSERHelper.dll_
executable
MD5: 833d30fa5bd04e2011cb6b9d7081dded
SHA256: 09d4c2067217b1900d4d7a936969f809821649b10ed8afd0f49de2871f7a3784
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\GameOverlayUI.exe_
executable
MD5: 4138965c041f1631547fb66042900e90
SHA256: 1adc829dd2a6789c4f7a798ee29cce42ef0990987023b4fcd2c6fb423df5d2c1
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\icuuc.dll
executable
MD5: 79c7511f2958974aa9ebea764b735e13
SHA256: 3bc5f41b88f04deb7865cee3a4fc10c4cd08da2e812a18cebf30ee4dc5316be6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-datetime-l1-1-0.dll
executable
MD5: f3cc44bc5d4dbf5020b62699025406a6
SHA256: 1a3e77cd05fbbd8b8e801a232ffaca27bc73bb68a5b5e9ca560ed931a3e85dea
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\d3dcompiler_46_64.dll_
executable
MD5: 52a41f0e49b2208df75609699fc7254c
SHA256: 9614de7bac24091e2abaf70b3c852ddf9b92a48157c557c3c63d81d88d4d5ceb
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\steamservice.exe_
executable
MD5: d03f04f97bd8f938e6dd741718f85a21
SHA256: 6985fddd016f26b7d990b298b2ff6b7ebb7ff4546bf9dc443a3ab7a8bf43d2b8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\libavcodec-57.dll
executable
MD5: fcd302af48f9066397a028c5af68b638
SHA256: 3ad814784d7e1abbe9a481b22aee51d2ecbe5a76fcc8e13c67210fa76f7d892c
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-console-l1-1-0.dll
executable
MD5: f2a1ad0c28ac23a248db2e70f32c76ea
SHA256: d6ac3e9126466cb2dd5506311e487aae71f4298c3501efee9d95d1dd5a785249
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\gldriverquery64.exe_
executable
MD5: 519ccd21fc4a0f26debd33320c50df57
SHA256: 23b4063251315814e188d64afe08ea49979f5fb2b74b86860e655a1a4d8fe4e3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\video.dll_
executable
MD5: a8c9789c9cd7cc1e6a86a50384d9b56d
SHA256: 7e0ab3944a1a5ac1c864ad3a0f06b942aaf17407fabfc6a6abf4bfb0250732b4
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\libavformat-57.dll
executable
MD5: 74d73a48008270ab7ac96d81d0deb04a
SHA256: 2725df2a97c2dc2d29f22460d6bd34ad4e8d40c31899092a5db37bf3eef12b24
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-errorhandling-l1-1-0.dll
executable
MD5: 6706bcbbc8b987a300b426cb74eea588
SHA256: 41e6ead13e861f749c3e087f2908800fe5b2a1415b87196c46affb60f023e1b4
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows10\x86\WdfCoinstaller01009.dll_
executable
MD5: 59b55989ab09508e2fd9ad5fda5a8081
SHA256: 252a24c95f143649a7898e940fe4bb6a8271047d4d872681489602106ef1b7a7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\crashhandler.dll_
executable
MD5: ff799f5e2a3ca7b84e5262a31fa0654b
SHA256: ac4e41486b4c4980feaf2c1a3098c75de98b71522ffdd0323243a15c00374e12
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\libavresample-3.dll
executable
MD5: be7e7dedaa3d706a96c1dafa703ec5d3
SHA256: 32ec6aa768a2e28812b1775c47bf059980260676fa865e1bec9de1ab44889fe2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-file-l1-1-0.dll
executable
MD5: 24a8f9f30ebc97fecfac2125892e8f2d
SHA256: 0863bf3c809a1cf78696aa35502fa56105d303e03f0c521df55e538a31e2f034
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\gldriverquery.exe_
executable
MD5: d6d6ddf71c2a46b4735c20ec16270ab6
SHA256: 0d422efdfa17dc6e1ebf0ed9e2902fd7c0eaa2f77b8a5a8f1df1478453a37ab8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\crashhandler64.dll_
executable
MD5: ef6d824488a7441531b4bbf84fba2112
SHA256: 8bcf8f5851cba2d81758591e2f3adf549d6c0430a6a9ffd4214917ff3f5f9adf
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\libswscale-4.dll
executable
MD5: b30d1f0a213a2738d5060b1a874486c0
SHA256: e9465b6d5dee3be55bcfb4681c1ada11b2f48c7d0ec93ea53a3ac777c3d68261
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\api-ms-win-core-debug-l1-1-0.dll
executable
MD5: 47fa32b7cc0a473e5c0f8aac40882865
SHA256: aec95e6e2098a88c9f6db7d992a4d48b8333e30e8cd46c9548e1bed7497cb63f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows10\x86\SteamStreamingSpeakers.sys_
executable
MD5: 4edf6900980aef983ff3c5b5df2df925
SHA256: 6fad221c4a723d0be0932be819591bd40bd9d9bf73f4dda25e0ed56aa0c675b0
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\steamservice.dll_
executable
MD5: c32531e708ed813b9499fb2a00e01e95
SHA256: 34999ff649da449d684f808bad381b56240fe285c94e4049820f90537f2ea700
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\libavutil-55.dll
executable
MD5: 8c1cecf547bf6e454094d5b7201da0cc
SHA256: 46ca3eb09dc47e39dc5b211cca8fa08557e719ecc927c3703ecdb2a02d9ec8ce
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\audio.dll
executable
MD5: 17305e37a9350e730bb7c6a60084ae8b
SHA256: 66f821d72b9881040c2b140ef2a2d5fce81a2c464547b67f41b9eba82d668ede
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\openvr_api.dll_
executable
MD5: 2fdfa82223228c1e9430d0bad68a8328
SHA256: 7b83ed968423ed724a8668c4126d81faf099a5fb5e457f806b3256b1caf9b596
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\SteamUI.dll_
executable
MD5: 69a52b1954b9a0fee041748b0e0bfde9
SHA256: 9110d7bc171d20afc5926b33ea3fb5f47de94d6efb1650e5b07ce7b16657a865
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\openvr_api.dll
executable
MD5: 2fdfa82223228c1e9430d0bad68a8328
SHA256: 7b83ed968423ed724a8668c4126d81faf099a5fb5e457f806b3256b1caf9b596
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\Steam.exe_
executable
MD5: 7c4209a6671f5da429db3f32eb093237
SHA256: d5346fbacb5db4a279f2748f890943cb4157d90516bb4db0feb5a20c43645dac
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\drivers\Windows8.1\x86\WdfCoinstaller01009.dll_
executable
MD5: a9970042be512c7981b36e689c5f3f9f
SHA256: 7a6bf1f950684381205c717a51af2d9c81b203cb1f3db0006a4602e2df675c77
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\steamerrorreporter.exe_
executable
MD5: dec413c38d0106b6740e806036e9f10c
SHA256: 0e29bbfd6d3f5b1d73263521bab2e03b5b5054aa5aea12c48752116d4607af18
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\SteamOverlayVulkanLayer.dll
executable
MD5: ad329751f7bfa32d4fb2a40a91641bde
SHA256: 970a1f1bc507b7b20cbfafb0e0fe15b8f8ccf82a0040ea3f182c3b828647c73d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\x86launcher.exe_
executable
MD5: d5b1c4f1131b9e2f5cedc584cd940433
SHA256: b13bcfdf0ae2e75c6cb1313b4bcadd10004a1ed4f22cb4099f982662ca532b81
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\libavutil-55.dll_
executable
MD5: 8c1cecf547bf6e454094d5b7201da0cc
SHA256: 46ca3eb09dc47e39dc5b211cca8fa08557e719ecc927c3703ecdb2a02d9ec8ce
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\tier0_s64.dll_
executable
MD5: ad185b3a0367b81a0a75c1cf056cd754
SHA256: 9aeb1522ad82bc964f9217a301abe42fe1a9c76527481efefde62723dc6aa6da
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\SteamOverlayVulkanLayer64.dll
executable
MD5: a34a8649331deda568ac67f1274ccb43
SHA256: 626bc062eddc939a835f4697c3a69ba93836f7cd5fb438bb7d93523164349a77
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\vgui2_s.dll_
executable
MD5: 420d82bc3e81246503858d271c072684
SHA256: 611c4e39f62ef5a38822e8fb8e154d2effadf894ab32d9f704787dc1fb66457e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\libavformat-57.dll_
executable
MD5: 74d73a48008270ab7ac96d81d0deb04a
SHA256: 2725df2a97c2dc2d29f22460d6bd34ad4e8d40c31899092a5db37bf3eef12b24
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\steamerrorreporter64.exe_
executable
MD5: 2a7b6e75e695a0baaed58669c8a52352
SHA256: bf511d568f323443a58b07cc3031670e01c054122d34817b2e01c7c688594117
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\steamwebrtc.dll
executable
MD5: f1afbe5d1fcf1cf5b9d902480efd2e4f
SHA256: 61a3d2fa5de611547bf38b2278ccaff6470b0ad3fe580df46a090030c0d113fe
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\VkLayer_steam_fossilize64.dll_
executable
MD5: afb2b0eec5d25d362853c9776f0b6bca
SHA256: f2aac60328fb0dc69ac537f645e2250985c6878ec3e66ef96515d23130da20c1
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\libswscale-4.dll_
executable
MD5: b30d1f0a213a2738d5060b1a874486c0
SHA256: e9465b6d5dee3be55bcfb4681c1ada11b2f48c7d0ec93ea53a3ac777c3d68261
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\steamclient64.dll_
executable
MD5: 5d86fb56ef881b11300159250b4ad2fd
SHA256: 0e36e9458f671450654ff2983718285cab94631154ca8af4c36296540a4c24f2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\SteamUI.dll
executable
MD5: 69a52b1954b9a0fee041748b0e0bfde9
SHA256: 9110d7bc171d20afc5926b33ea3fb5f47de94d6efb1650e5b07ce7b16657a865
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\serverbrowser.dll_
executable
MD5: 474d4c73f1504f66f51c74cef567c17f
SHA256: 09e457768619ea497a67d7abe0340db73557ae9dc14f3e0f50179aa9ad9e9481
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\libavcodec-57.dll_
executable
MD5: fcd302af48f9066397a028c5af68b638
SHA256: 3ad814784d7e1abbe9a481b22aee51d2ecbe5a76fcc8e13c67210fa76f7d892c
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\vstdlib_s64.dll_
executable
MD5: ccfb09b9b9078dd755b47b9c792f13ec
SHA256: 717d365947d94dff335b757b00cea5eaeb4a1d649ed2c2901567e760522ab638
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\streaming_client.exe
executable
MD5: 4465d588e3829a69e9a8d51bffee9e79
SHA256: 6be592bc61934616364255e7c70a19e049c14348474ea18fcf384c653d80844b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\streaming_client.exe_
executable
MD5: 4465d588e3829a69e9a8d51bffee9e79
SHA256: 6be592bc61934616364255e7c70a19e049c14348474ea18fcf384c653d80844b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\libavresample-3.dll_
executable
MD5: be7e7dedaa3d706a96c1dafa703ec5d3
SHA256: 32ec6aa768a2e28812b1775c47bf059980260676fa865e1bec9de1ab44889fe2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\Steam.dll_
executable
MD5: c70f1e54597bd4f53ee96fa4a78bc1ce
SHA256: ea34814805805ca20fdf5e90f090f7b9bcee3eb3871951fd919daab5b7bf7626
304
SteamService.exe
C:\Program Files\Common Files\Steam\SteamService.exe
executable
MD5: d03f04f97bd8f938e6dd741718f85a21
SHA256: 6985fddd016f26b7d990b298b2ff6b7ebb7ff4546bf9dc443a3ab7a8bf43d2b8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\chromehtml.dll_
executable
MD5: c5ef876077ddbcdef01711f208d8a5cf
SHA256: 2e794abff87fa22a050c59f2b1c12355b01aeec1c584c8bade849a557e660a16
3364
Anno 1800.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\Wub.exe
executable
MD5: e2a9b4527cbb6755a23b9988b58f0f9c
SHA256: 9834978cf80815691e698ce6e7fb6c9bf6f74dca2a0a10f41dcbdb1776cbee68
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\GameOverlayRenderer.dll_
executable
MD5: 85e442269457a559f8ce5660c83f7733
SHA256: f02418fc7c072855c67056152842e58ffef13776b30fa8c81868397ef697d081
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\SteamOverlayVulkanLayer64.dll_
executable
MD5: a34a8649331deda568ac67f1274ccb43
SHA256: 626bc062eddc939a835f4697c3a69ba93836f7cd5fb438bb7d93523164349a77
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\gameoverlayui.dll_
executable
MD5: a6605626fff9322a666290316f4de7f9
SHA256: 4bf5c945c1f69990d7dec526c45abbc959b8b161e40a437404f8e0a389c28900
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\SDL2.dll_
executable
MD5: 6c3cc33cec0b46db407f0d8d241386cc
SHA256: 9d85ffc484ae061ca242403a5b13b16e268623e19cb9e8b3f9fcd9337b861859
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\package\tmp\bin\cef\cef.win7\api-ms-win-core-synch-l1-1-0.dll_
executable
MD5: b413f5f05115f7d59b99393611cc6689
SHA256: c613cca1e43f1e4e90815dd69d2798677ee34c6bb9b98f600f5dad0aa5d287e4
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamui_french.txt
text
MD5: f15dcae10ee2b0b703e113c875cd7067
SHA256: 9181ed47638c856ff97b5fd5a99d9c0251bc346d8d7c04355af494f0890d0cd2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamui_finnish.txt
text
MD5: e25cd4851d3588cdb1394d6d1ed1b67e
SHA256: 562ce6a50ebbc36864fb1b074641af100cb890856af90b206941eb2b29448b44
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamui_dutch.txt
text
MD5: 3e8dfa47f880731cbfa4e227b5938c50
SHA256: 45d03cd4cb938a304004c3a9a7a30c8665c3a5f225b6da00b2d3da8463b61163
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamui_bulgarian.txt
txt
MD5: ac5c2959de7a7e412eecae4736f20cc8
SHA256: cf04d1e4d884b6e4210b3deb1e13f89e5ace0bd00c2cd9ec8f203fe910699bac
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\SteamLoginDialog.res
text
MD5: d4131cf6a6ba63554c0b2707197c559a
SHA256: e68be75649ff2dfc0ac62baba9dec11463379f973c605f52d35975867f484b59
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamui_czech.txt
text
MD5: 168af5c26d29c20347b90931033c18ff
SHA256: 07154953a2a4002d636bf567a484ddb4148ea47f92910b183412680f7676b497
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamui_brazilian.txt
text
MD5: 20bba9b03a4f6bfcfcccb85968f8ff2d
SHA256: 75770684c27c387075574a0e0c842e9ef3e6ab8c4943b0273c963d7bba9f31be
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamui_danish.txt
text
MD5: 2e62c85e9563de7e3189e1bc8a7b01a6
SHA256: 02f8e14a5f7885a68c874567f78bf508e180c7d45cf175d0dc6ca85dcbb64057
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamhtml_english.txt
text
MD5: 957b105ba38c16726b0e533f9f3e50ae
SHA256: 7af82ba79e073b2cd8834ca29c2593fc4bca101b868160d3eeed31519a968b1a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\SteamInputControllerConnectedNotification.res
text
MD5: ea3fa7f4214b386ebaf88f7ae236d94e
SHA256: d06560d9680b8a0e5ecd0f6a22111e2191b8b121652a6a8cde18483a23d9e075
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\SteamInputControllerConfigNotification.res
text
MD5: 0ae495304b9405a55ff9fe1a1dd1d535
SHA256: 8df698c27aa52096ae3e310d8f4e1ae16f76baa92e693cac0f730417195a194b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_ukrainian.txt
text
MD5: d4d37aa16b1681fd94cee1aa262929ec
SHA256: 2076afca2c62ca79d05bd8f8bb197f8473a0e4d7ea9ddafb6d33b7a972576faf
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_turkish.txt
text
MD5: f515fc0f23f2dc28b574cfbfe19fd151
SHA256: be1358beb09a2871977504bc19f3c43ea30c9a2ab0c8f392bb0707d98f26cd80
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_tchinese.txt
text
MD5: 3844157927ab9a7564c5098ff7418d02
SHA256: 517d4c41a3b5fdbfe422678cfa1642ca12b4ed2dd7e5ff1f13cf48ddc6be1ab6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_thai.txt
text
MD5: 230ae95c89fa19b6f1f1726a64e69f25
SHA256: a63afbb922fc8efebe79df45ccf36326a7e585c8d232fc7a3fa9455732347018
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_swedish.txt
text
MD5: 4eed2df7a65222316321c290d89ef5ea
SHA256: cb873aa46a0f6dad0ae2f819262000686b0b24d2a7ec4536732476280c749567
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_spanish.txt
text
MD5: 97bdae804d2e526530fd08647231cc79
SHA256: f7c9b696b4e1c14b3668aa9d15921ed7050fd61986bbc8f5c26d222495c085c3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_schinese.txt
text
MD5: d8def0aa0d6e5f0225cd4d144636eea1
SHA256: e79ebb1f146cf87dfd65b0c6d9aaca98149ac49cd936b08c94926fe5062f3aac
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_russian.txt
text
MD5: ad43fb2d72ba54070c51856ef2ba389e
SHA256: 8dd1b9800b8478ee8392eada5a64736c196d2249698ebb2015cd3bf8bccbab5d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_korean.txt
text
MD5: 7b20fb796a87580d28e25c364eb91d51
SHA256: 818455b2357c191b051ed1d4e2851736575881ec07e95df13558165e7c121af7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_japanese.txt
text
MD5: 5955e8072cb35339a3d7bf217d7ba98a
SHA256: ea65685ff33503fef3024b5dbaf2ff9d9f17de098b0136982ee367d0d9a41268
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_norwegian.txt
text
MD5: f03a0a7d77be4c9a71d78054866fafc5
SHA256: 8a60e16e5e435288605def999eb5a5d0122b975d14829819c427574e211ff33d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_romanian.txt
text
MD5: e5186273c7b2481c2de8db86ac1736fe
SHA256: bc76911223e0a1c5a4d9dd82bd269d6081c9a78d9af548ab482d1ae3612ffb2e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_polish.txt
text
MD5: d5055a7dc9786c8d988ee7fe6a76e8c0
SHA256: 24b30e47f486e4dfdf62c0f90662561b86b4077c1804df039eeff08f6547f6e0
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_portuguese.txt
text
MD5: 80d022889d9b3959ab0ac4866add654c
SHA256: 4df8de211fd290ffeb8d46223f93aa8fa835f438004125ff4708ca12d9534ec2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_greek.txt
text
MD5: 00a605d30cef3624e1e5891af74ab0c0
SHA256: 49119cab5c57ada3c840193d9ab7c1869e4274616944a8f2963f32123e56d3a6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_hungarian.txt
text
MD5: d8e74680619268e572a014d7b4b2a614
SHA256: ca9991a261ec2a29f2ee9c14464cef6b147128806f145e29dd5be39d3d8642a0
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_german.txt
text
MD5: bdf1cc38a0f8f1299a4c553af65f4a1d
SHA256: 06d568bb98cf8e44757522eb5f277c4c0eee4f6929baa394841f3dc3d5f6f612
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_italian.txt
text
MD5: a9a8e24a40fe7878a2e120d9c34ab800
SHA256: 4edc7708b92ec2a6146d2692ad8f958e538edddfa2e4fe0305b143c1858a8b52
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_finnish.txt
text
MD5: 551b3b25d45fbf43690da016403ae2d2
SHA256: 3c9a7b57976ef7c767bba5d09f45dfeabccdc492f1553ac314b1d19ee31db8ab
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_english.txt
text
MD5: ce510d345906a7b2f0839e1556d8b98e
SHA256: bf2b01814e672ec5c6b11d269d244e72a62053d1b39f8c28c46f60612811894a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_french.txt
text
MD5: 07b39bcdeca6f2bb09202db02bdaa431
SHA256: cb7e88c03b376cae6a1413404cd2e83a08cf0192829e1bfb87f1854907582581
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_ukrainian.txt
text
MD5: 546e0ba3e1279b714bd2e508be0664cb
SHA256: 604385e011215b6c6ad754157d706b9dbd9ce44391ab6eec1f0ac6264895772a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_danish.txt
text
MD5: 03e1f77981fbef68c6edb8f8c480728d
SHA256: cbb5246b738211bb9bd0ca116fbad7a07692bc26ff57d1ccb986de79eea6536b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_brazilian.txt
text
MD5: 4f83ab085f1682d88ea17570526b5734
SHA256: a80f823f325aa8ca6e6c508630937c0789f6a3d57a5f9764e7e39d635b827fe9
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_turkish.txt
text
MD5: 35d2f04cd42e1213c00da6e344020222
SHA256: 8d3295845f73a85c2d3e24d753507b92c8b67f07793b4c96b8c5a8e99a3feb6d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_dutch.txt
text
MD5: 3519cb01b781533df08439a8a04a3daa
SHA256: 8a0b9504aa90e53cf277a7ae7cb5c3fef84476f4268059a2cb5d45cd3813349c
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_vietnamese.txt
text
MD5: 896dc9c06bc1e7b35d69bd7b4495599f
SHA256: 28985a2a69479d6e702f31e6bbc005f059ca9859b095d8cb5a6af012a0b2bcd3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steamclean_czech.txt
text
MD5: 090d5372293f336cdb4c49c2bb48df24
SHA256: b9c0cf2b8a3c1d80dbddb9e2e09c10c5f55c8fc307780b3d85d60ddce1e090dc
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_spanish.txt
text
MD5: 8618368c5d5f10d0fa5a3f9c01302ffe
SHA256: 477bb04067079e0b03fb249a76fcb3b275777ed8f9f098fa4ce88713f9fb939d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_romanian.txt
text
MD5: b746fe313a80272eba7a2eeb1cbe6246
SHA256: 20b1de05c6bab2351f9e9ea7642c9f725bab2c4f07638ed418798c84608877e4
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_swedish.txt
text
MD5: ab80618e3eea20d2f24439f22a486a5b
SHA256: 4d422050aacf0c845784cfa7a9b17145f2228e6be79e5988b525c742f2e477d2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_russian.txt
text
MD5: 4eb6333821e9e2700dbcd7107ee0d642
SHA256: 134a91351f473a1cf89f19e405d32fb2f1df255c07b16dd9198712f1559e3fde
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_tchinese.txt
text
MD5: 23be397fbe0c187c1fd9606b84483e7e
SHA256: 5b316da156bf9c29baa3fae2ac2a82559b714c0c50908ac40b0fa025094fd2a8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_schinese.txt
text
MD5: 8e2a054ae22bc62d295ff878c9c22061
SHA256: 555b576c60c75dfa58581b27a3bd1ca820263aeabd7316c54b0728ffdb0f731f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_thai.txt
text
MD5: a54a2d0b4efe03484b9577b466488476
SHA256: 0ed570073c3a2791a0e5c30af4dd9b4e37314cb5d80e8c51caa78580850ae894
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_italian.txt
text
MD5: ac046af83d38c38c2c42ec77c0133cb7
SHA256: c07fd2f1c2d876aa5f6de9d02eeb56f71ea4d2dd58542bae940bcb05e49404d7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_korean.txt
text
MD5: 3b9f2c42b09c74fc432b375866909bbd
SHA256: 2f1afb94057d26ecbd09264e96a34902b6cc9dcbec061fc257e4e20183f7b7f3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_japanese.txt
text
MD5: 84a1604ec804c4dab4089812fe25ef0a
SHA256: 6e52387d76c4c316534f959dcb2ff065c1f649dca6cc9387d6a0ea1c9d0314a7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_norwegian.txt
text
MD5: b437aea95828924c6869a0e586561291
SHA256: aeac85d6c88c92411f4e675a5e27a8bf4b54e976bac7b0857b47a4a50017330c
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_hungarian.txt
text
MD5: 356d8c45ce522859406f5177b8db5f69
SHA256: 99aeadaf0e8d421e40aebeb1e02373d72d3a6cdec744d2c163ae9c784498ef6a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_portuguese.txt
text
MD5: 0b9526283c361b434249ebd68ef36065
SHA256: 49c0f57782c5653b20ce6cfa9d824bd3f97354733bc02096eead99b58e250a38
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_koreana.txt
text
MD5: 3b9f2c42b09c74fc432b375866909bbd
SHA256: 2f1afb94057d26ecbd09264e96a34902b6cc9dcbec061fc257e4e20183f7b7f3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_polish.txt
text
MD5: 6060fc3d85a793e90162ef8c1be0b788
SHA256: 517ead6c95e0229401a1e048ab93f0b5b1f295cb3e2d81705a172664c59c3ee7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_latam.txt
text
MD5: 0d97eea3e752e370ea490bad41714f06
SHA256: bbcd939f73b8ae218e3ab154c7f69265347803210350708301a35e63b869684a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_czech.txt
text
MD5: e87997905583a63234e5766afa4b7e9a
SHA256: 96455c6d2a34a212c202da24cced90cc2ac2a87b41fbc144c3273eb2eb347c39
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_french.txt
text
MD5: fd6b93932de0cbeab258a187177f5d59
SHA256: 0b90fc09d99e9665d48fac01b991f3b13fc4a88036abcbd9c3891e3a0d24f984
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_german.txt
text
MD5: a72b39bfc41de802605335284ebd1608
SHA256: a3ae891fe9488893369543fef99202c05516b7541687c2d50d0bcbdb4318e00e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_english.txt
text
MD5: 60c539a8c041ad788dcbed6cce76703b
SHA256: 9a04ac006428e6c3e814117c39952c7f9628a273054ed1e82e1ea27be0e2bf55
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_greek.txt
text
MD5: bd7b312f35fe7e6760a76d27fcdfd888
SHA256: 6d8c5a72ba17d61d0ed60f89c68b31411dd6d8c9facdac51c2c94132f2652736
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_danish.txt
text
MD5: ca923b1d33e419ee1ed9bb2df4058e5f
SHA256: 37a931fdb3dc2575814f4c4415682c219cadaa44bc6591258c40095a46bc20b8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_dutch.txt
text
MD5: 869d65e466846fa2b597345a170ecba6
SHA256: e0c9cddd2a99d2dba25e2592b30228bb0c981d819895b5d800c99e00923a2014
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_finnish.txt
text
MD5: 234ab4d250bb8a57250d60f4b75bba02
SHA256: 1e4544b1e17bc05f2ec5384bc3f25c5ef95478a326aab9ce62a9df973a10af3d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa_portuguese.htm
html
MD5: 746fa6ae4c77122abe0d67b250215387
SHA256: ed726c5c38e8c170d4ed1cce11c545b43e46a0389f02dd9e57ef779d43fa1c67
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa_spanish.htm
html
MD5: 9882b09feebfb2f02899c65029a88f62
SHA256: a525bfac0d949e5cfd47f5c1fc4f243ae471449a2b19d8bc9f89dba08dcb48de
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa_russian.htm
html
MD5: 5a3eee83adc0e013dd360020089f5ec4
SHA256: 6dd60439c8951753b04015878f6acbfa72ee1c162738243d83d343f354004e83
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_bulgarian.txt
text
MD5: a1c59fc6390b58487e2a6eff23b73b89
SHA256: 335da7b3bc2b4041965af47cb7a3d25c10f2ad91a2853aa4c4dca6a812c3a84f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\steambootstrapper_brazilian.txt
text
MD5: 20daa23678600f3a4f9ef5a449308e05
SHA256: 08db87bdd367298649963a08cc37a0aeb92e5bb7f6945dbf43ec07503b0788b7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa_japanese.htm
html
MD5: 3d6a230c4a31b4d163c43de237bd068c
SHA256: 128fe0033c7429635d57bf7d17d44754ee856b0b030465e64fa87f52dba4801a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa_german.htm
html
MD5: b398adbc8c3e816ac79d4c25eddba055
SHA256: 5b0938c11f2ec8dfd0683a6eeaff285a530e51191199bea48cc55490d9bcd637
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa_english.htm
html
MD5: d805e86d27a7c864d6cbfcaacb8bfbfe
SHA256: 0187ae85b2a51875b23df78ae98d1858cfcca57458f127b4eba120cb1c69cdee
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa_brazilian.htm
html
MD5: 14c891d53b77d7d5a8e8c8cc0ba63c7b
SHA256: 65efb1c1e62330561b43909a0534976d4e11ae33bb41829472a012a45b91b497
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa_italian.htm
html
MD5: 840542fb722bf8c4960738b1c8cc8a20
SHA256: 42e224878281b47abf9372e7374261aa7c96de304ae2133fedbf01dd1249a64b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa_french.htm
html
MD5: 94d1a1db413066f01793d4f941adb8ef
SHA256: dfa1f959bb8ad6f4e75d5f3deae6d7de4fc912ba320f57461a0a29956f2720ba
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ssa_japanese_bigpicture.html
html
MD5: f0ba37cc0befc424186105f9ce832f39
SHA256: 69e0fea90dce7c3ef73096063c4daa0b4550c7d9b3c8700a5f0c8c8332ad3edf
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ssa_russian_bigpicture.html
html
MD5: 76a0ce2ea70b9a1400a4c9946a1fc590
SHA256: a56346e5f42317e82a55224d8c5a02edd55093f4a7f358614547f76ee2654659
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ssa_italian_bigpicture.html
html
MD5: 3d587f5b26ae6d2692cf5ac483aed077
SHA256: 81f52ed2c15bf760f8ef14b08efc8ce9203dccf342a21664e36b74d416b68953
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ssa_portuguese_bigpicture.html
html
MD5: 07c2a88e6c7292ac98b34a0a392f9045
SHA256: ea03b1d53f5acf4014ace46c893bc3d7b9478a09308cb3fdc96ea9c643416bbd
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssasubpanel.res
text
MD5: 0d55c4503e75ef542aa896b1b5ac2fa2
SHA256: 160cb47a97e22df97460895d412912874e6809b45aa9e94ba435d1b23e9361eb
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssadialog.res
text
MD5: 208314fd3e75901783909ce9b0d37fb1
SHA256: 64dbe835906c649cab72ce657b09fb654d45c38d3eb39ab5f7ab5e9ba9817801
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ssa_spanish_bigpicture.html
html
MD5: ef9d0d931745b3ca01aff285349e510d
SHA256: 8640554798c7105ad7f75b2ecfa10a24547dba324f90d98e55573b32e7e0e760
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ssa_french_bigpicture.html
html
MD5: 54d843c8f84a69a1363e667f6f153589
SHA256: 923d962ca0e409c6a15978e70bf6926d8170c1ebebde287ea5b01e4c1ee4ac8b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ppa_spanish_bigpicture.html
html
MD5: 4bd6f62a806a219595ef6d08c82d2c6d
SHA256: 89fabe865acce029328dc30a00a8ee8d8261f56d88926f8c211b8c6fbbc25c81
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ssa_english_bigpicture.html
html
MD5: 2358ae73df2e6c57088276a6d78ec40e
SHA256: fc81382f46e05a81bd555f03ee7d0d785faa0f72a44bad72b6143211ef0b730f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ssa_bigpicture.css
text
MD5: a52fd75524d494899a6ce88bf4c943ba
SHA256: 2bf7794b5c0b6e658100b42ccac9d2bde81052938a7449794cd1135b0dafd31a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ppa_russian_bigpicture.html
html
MD5: 0f8ec8ff324ec651ccfa37e514a88eed
SHA256: 2e032b3f9ab1c200494034d78896831fdd905aff78f117fd440df849187eb7d8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ssa_brazilian_bigpicture.html
html
MD5: 7f3728739444a44019168601e5a718e7
SHA256: 747e6efdb97671ee2bfbd9671e399773d20cc20fde9dde82d45a1614ec24618a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ssa_german_bigpicture.html
html
MD5: f0eabb064152ea5acbb3848f6c57699e
SHA256: b77b8cbc828e54f8b70b4f4082084c60987bf04fd70bd0d0fe252f78d0fba38d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ppa_brazilian_bigpicture.html
html
MD5: 6146328aa3a4b79f8500bf28f0efa671
SHA256: c93253f455e79bb53ff47aa1bca008ce4502213342b8b56efa032b40e6e579d8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ppa_english_bigpicture.html
html
MD5: 58d19a10d26c9cbdbb20175574306a5a
SHA256: 0ff22cba543c11926b905d3fef13acac6df386013216004f599d04c63abba653
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ppa_japanese_bigpicture.html
html
MD5: 24968f55ed1ca5badd6a140f6ef4498f
SHA256: 87ad4ed564e55e372bf8916809e23afdc73c5061c7b7aeb80b1a59e03b4fe59c
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_spanish_bigpicture.html
html
MD5: a6cd27ef2c8c8a7271b6d65044eba9f2
SHA256: c6549520e7d6ff9fa02565f03db44eb863fc2fede2b092375983d9ddddaee0c7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_schinese_bigpicture.html
html
MD5: cfd0c57136a588411b5eb9f996a6408c
SHA256: f3b49a7931768fd4c0a90cc0905637cc580b9e3863477f3e5815000327439979
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ppa_french_bigpicture.html
html
MD5: b34bca3df307ce12400ab91f17441008
SHA256: 615cb60896ffdd4ef772ad0f61d877712602de157bb62155feb78cacb159a272
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ppa_portuguese_bigpicture.html
html
MD5: 2d0b3b96ac524ac89bdf06487ae1b9d0
SHA256: 2cc726af417b1dba648ae3a007359d68550ae28ef68a780050a95cd679ea6ff1
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ppa_italian_bigpicture.html
html
MD5: d406d2cf8ed80b91f3b3d5914aecba68
SHA256: aa4ab90b61f2703bcebcf9aa2fc9caa8e3203be40d3bbd1490dae1e81ce3e186
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\ppa_german_bigpicture.html
html
MD5: 3a7df2535805cc5e0aba736de3516af1
SHA256: fed8b1f0a2adbe66e808d7563321fc441a04c7be2881db825ee14f8a2adbbb4e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_french_bigpicture.html
html
MD5: c8de2ec67d387682815b0fc3d8a15ca4
SHA256: 616150f4aed8a39f818fe3bb19e76fb75af85f3bb304e2cc4a0a15c779795d2c
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_japanese_bigpicture.html
html
MD5: fb4b4c06f154775487eea3537ce1d7a1
SHA256: 51468fdd1e8b8b8b6eb20ca355cb2e18bc9f0e17b4aa5be4ceb29b98acf151e8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_korean_bigpicture.html
html
MD5: 2d88ba7823a5fbda197cfb069ddafa30
SHA256: 524e20ce6498ff22225fca221657ca7486c4af00dab5cef8e9314fc4bb4681e8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_german_bigpicture.html
html
MD5: e615fadfe5bf700f0fd61c41e031f854
SHA256: b02153b9ab70e96654bad47ad1b35886604ea6f79a3f08dec9734047b46011fa
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_portuguese_bigpicture.html
html
MD5: 5d7d55798ee36e6799f497862877e1b0
SHA256: c26cd1408a660bd630596be4bf2b3a565ee0f0a12d693c9f0c0fbce172024705
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_koreana_bigpicture.html
html
MD5: 2d88ba7823a5fbda197cfb069ddafa30
SHA256: 524e20ce6498ff22225fca221657ca7486c4af00dab5cef8e9314fc4bb4681e8
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_italian_bigpicture.html
html
MD5: cb43022a155c93af86987988e77aac06
SHA256: 44b566adc314506f7a81cdd3165dda66fad9a6d42325bd10c243f57cc5a56e9d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_russian_bigpicture.html
html
MD5: 7e8fa1f7b22605b1d211d123f0ef3305
SHA256: 860c23b4e700e0a7612c9b44bc7ee162597357ed561eec9d2e9254886cc6e916
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\RefreshLoginDialog.res
text
MD5: e2856691247fe5e252cc39bc2b6e5c0d
SHA256: 39ff4f5e6036da927b71ae443d7197b54a9f70e3ec32f58de6a649edec3441a5
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ScreenshotErrorNotification.res
text
MD5: d286823013448527635c648f41a7baad
SHA256: c776cf627e851652add8f8d7921a19adf1feb69ed10022936c5e123cfaaa7932
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_english_bigpicture.html
html
MD5: 7618eb5a42ca17d073d28e3c1d12db23
SHA256: 09fc4714cf4eab72db39fb2fa0954457ef6590dcb3d22027875a78194793015d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ssa\eula_brazilian_bigpicture.html
html
MD5: b4389e51e3189c2843b145ddc1a8b238
SHA256: ff3eebe409ef4e77efac158de6656a5fff87e05eaee0caadfce4a3228a37219a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\psnaccountsetupdialog.res
text
MD5: 587ca6357b79e364f98293e3f4ed8c31
SHA256: cc2273edffd6b6d72813d612d46b627493a7ba8609bdb23cbd015069e4bdc263
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ScreenshotNotification.res
text
MD5: 37f25419846757ad25254424eb0abe3d
SHA256: 1330d2e9d3509c7a82455a82a3184739ae4dd09687fc08e638e717331d7f3cf2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ppa_russian.htm
html
MD5: 01c05c97b58ab17de9fe744723ca20ea
SHA256: 24ccf3e7901847355d68a474391f0fb51ae58d7f2136333b3e60766fae627c04
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ppa_portuguese.htm
html
MD5: 881fa6327e9409d1a01e209056b95589
SHA256: b2d2c5f6fc4574017170cee281e2f4a7bb9dd4fa37aa967d554aa1ea55a70e95
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ppa_german.htm
html
MD5: 0c7d56ba38ad44dfb9a797cd3c04e344
SHA256: 1f6c7b5a79ecb535299398fbaa7f05f206981721f0f2cdd1bfc6312da4128d77
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ppa_italian.htm
html
MD5: dea9e53b282400842bba64141e41befc
SHA256: 15dcac838fd28a7286af14ae331db30497ec917934cab49909bec8958c80b593
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ppa_french.htm
html
MD5: 7e99d098a89205ec8185f6775bd12895
SHA256: 6e5df2c0601bececf7db910846c2ffcaa8f29f34a04435a11d542d87c1b950da
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ppa_japanese.htm
html
MD5: 5b909666838296f2ca979c573f62a48b
SHA256: ed0d49071336bae09ebb5b3bc355a442651407723899a4597689bd687c580636
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ppa_spanish.htm
html
MD5: e11086d277c8853ef89167fea9d8ea99
SHA256: 3e9ce564724108a356aff71b740da38ce694c426d950406b670cdfe1c75c527c
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ppasubpanel.res
text
MD5: 196de3ab0a992cfd5ebe9f220cbd7154
SHA256: adfbe7255529ef832d1f8dc49dc11d608e269bbfa631a9d15b9443ebcfaf7de2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\LimitedUserDialog.res
text
MD5: 531f727bc183fa5977f5903a68392751
SHA256: 9f7f77af525cdfcb5603e4d89ae5c0adf722ffba35aaddfb7f9a9a5c3f792626
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ErrorSteamAlreadyRunningDialog.res
text
MD5: 5173756c6a6eaf97020a3b4760844647
SHA256: dbb4e5da098cb3f0a4c4228de2050e808a6c014c74199618351971f40852c9d5
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ppa_brazilian.htm
html
MD5: 7f40b00ce82598003673156c3bf98735
SHA256: ed9114579e998aa0bff0a7422d74d4a9e09e2fd3822ea24e0259da125e79ff74
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ConnectionIssuesDialog.res
text
MD5: f393a033a156ec0a0b8431f618bb3688
SHA256: 4b55c9bed068515cc0e81a23f37f69134d239e22e65806f5595fcc2b7fbc21b6
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\ppa_english.htm
html
MD5: e4225e8b1b1e8ce583a2dcd6245b1093
SHA256: ff37b27ed0bdb5db84487814dc2a3518bad0e588bde0ca93ac75806aa4a78218
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c6.tga
image
MD5: 0dcd650bae5004af00496a707d26ad4c
SHA256: d85324c4a0f3ea57a87caabe8449f1b1df9277faee63d1214dc77590e23a9eee
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c8.tga
image
MD5: f5e36d56244eaab5f0894ad0be115900
SHA256: a62bde20c4bdc296adf3023db9082c4259e109317e18878c5c314c55d23b0307
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\check.ico
image
MD5: 56e7baee0b04673bf9bcd6248018f7e2
SHA256: 21c70c22b6a8f25421cda4d1a67b1dad912ac33dfaedd35c29554dbca5edbd77
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c9.tga
image
MD5: 2051d212a518705b92c73b985dcd4ac8
SHA256: a163ef9d7aa88c4543dadbfdb43590ef070161d490022e027d18d9866638141d
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c7.tga
image
MD5: d18ed079bd6b5231e13499b6b7f98ff3
SHA256: f24f73f54d871d9465c57082d7143e0df37f4d2160d81f588c4c5cb4daa2e15c
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c4.tga
image
MD5: 9d8faea3c4c5b1aa87c84be651ca0469
SHA256: 5104d92ef04ec0e5fdce962fb7d123636213245c1dd9a13e6cc4496706e24e30
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c3.tga
image
MD5: 16d9588d7b18974bad421fda95863ac7
SHA256: 6daf34715ad1a65505a222bb1259c83b43679050173329d69e812b91488c53fa
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c5.tga
image
MD5: 76603ea72cb51485013b4baf05e91bcf
SHA256: 3006020c81b9e90aad960a477502797b4836a6c00eacf3b6cc220d0d43a05614
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c16.tga
image
MD5: a774a18b04e8e987870314f850d9062b
SHA256: ebd86594f017820c1c8381cb5662a36b7701b296e1e428aae52ed8d17fb65b76
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c18.tga
image
MD5: 4d5a6ec35f3ac922a21c375ce9806e08
SHA256: 7db8dfdb96d91976a24bc0696af66b114aa8abef0f902f2cbefa39f3f5853d2b
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c15.tga
image
MD5: b807ddf9663223591683126e0f0af117
SHA256: bb856a575026988e0b526b12697d5b4ac1b0a794a46ab51905d3072f737c50b2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c20.tga
image
MD5: 35c4faf980b38a170cb183fb6312e375
SHA256: db648a2711deb1e80c610c9eab0a70728e694effdf266436e473327f9e84bb68
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c14.tga
image
MD5: a29de19e61e8a90e37f0547ef644df6a
SHA256: 174c387ca8ec7717f7dcd10cc8d928931d1e4bae5396b056404a7203f630e694
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c19.tga
image
MD5: 270903a102ff0faa648052b223bdf3fc
SHA256: a5de1ae906861b1a8ce834d8ff5ba38c9be5508be765ca838096076161a4ac7c
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c2.tga
image
MD5: 1a76a0badb99dde11270249ecd566565
SHA256: 9fc65d78eb3db4d4982d0a29635d0358de95de0d28583437a01e406576716420
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c17.tga
image
MD5: 746a6642f7833987d3826a1b38ebb47d
SHA256: 267d920f05609db2602ad76da4d34b12950ee77b4b9f98c7fa3734574503d18f
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\AppDownloadNotification.res
text
MD5: 20686019bf3c94b956f16bb249a087fd
SHA256: bd6a3b96f19bbcb203ce0908cb65ff9ddae74153c7f3aac42f96a07f33386d79
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c11.tga
image
MD5: b53310e401751d7f536f6a8f40c6c2ad
SHA256: 3c33d085aa6d66875f959f06b8a5f380d5b079abd29b9714bb06c8e5e633f780
772
steamwebhelper.exe
C:\Users\admin\AppData\Local\Steam\htmlcache\UserPrefs.json
text
MD5: 6d0fd8d39effe979f590400daaa1a095
SHA256: 7cb454b29dda25c13ca2acfb5e4070237c5d6863c66a85bd96693abee1d741f2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c13.tga
image
MD5: 295cb70060bd0e04a5e1cb258ee06377
SHA256: 212c4f4840d2e83e48522bb3479428a0d4d9b00be866233d6c7ec8179ebe9f44
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c10.tga
image
MD5: 036b932d6ad2403f9497278199de8dfc
SHA256: aad663ca877c747043da5cc6bcdebebb5353c4fdfe88dbf02e1bf12b1ca6b9c7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c1.tga
image
MD5: bfd4e2dff0a3cfd52a8ed1ee31749937
SHA256: 3e4fa68c9c39edbddfabb2b673c5cf9bd49b7bcf3c9d554fbbe51c5fe1c1cbcb
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\libx264-142.dll.md5
text
MD5: 6d9a5841cabb958eee31095ffe1856ef
SHA256: b54b38e0ea043c9ffaa98389521e419aa1475654af50956c44a0d864c28e7940
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\c12.tga
image
MD5: 0e9a4581c29066a287a2636ad18907a5
SHA256: 1c1933bbd2e9cb93ef05a32fc7c03006d53cb80109b5bb19315a66ae270c273a
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\public\Account.html
html
MD5: 6d4289098ce57f0c61a32727c240161c
SHA256: f5e39e4b29376b13672afa4cd717a9bc01405170c3f994298d87163e8b4f1adc
772
steamwebhelper.exe
C:\Users\admin\AppData\Local\Steam\htmlcache\UserPrefs.json~RF17954a.TMP
text
MD5: 6d0fd8d39effe979f590400daaa1a095
SHA256: 7cb454b29dda25c13ca2acfb5e4070237c5d6863c66a85bd96693abee1d741f2
772
steamwebhelper.exe
C:\Users\admin\AppData\Local\Steam\htmlcache\4fcc4a3a-f748-4bfc-b186-907823a49c81.tmp
––
MD5:  ––
SHA256:  ––
3292
steamwebhelper.exe
C:\Users\admin\AppData\Local\CEF\User Data\CrashpadMetrics.pma~RF176dfc.TMP
binary
MD5: b59113c2dcd2d346f31a64f231162ada
SHA256: 1d97c69aea85d3b06787458ea47576b192ce5c5db9940e5eaa514ff977ce2dc2
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\libx264-142.dll.crypt
binary
MD5: 281313e11b57635ec9b2156d7a461e2a
SHA256: cdfe8afddf70b21986cacbe2064c4e711efdb8980cd56f55522ce53b840944ad
772
steamwebhelper.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\dumps\settings.dat
dbf
MD5: 311e486b27fb473e0477e33622dd7b34
SHA256: c70040aeabad47e287bd4c358f5e90237a84d31767b8caa833367284cf13c083
3292
steamwebhelper.exe
C:\Users\admin\AppData\Local\CEF\User Data\CrashpadMetrics.pma
binary
MD5: b59113c2dcd2d346f31a64f231162ada
SHA256: 1d97c69aea85d3b06787458ea47576b192ce5c5db9940e5eaa514ff977ce2dc2
3920
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\crash_reporter.cfg
text
MD5: f462c17f20f5b83bb5d2424713022ef0
SHA256: 3b7c907772437d885adea21531579ed0e442bd1c2aba0493cb6caeb1a857002e
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\html5app\package.json
text
MD5: 6d735575fc891f2d8128dde607f186ea
SHA256: ebaf331712a008710872e39e3d93700465eb4175d73d5e244432a4b51995b3eb
2968
steamwebhelper.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\bin\cef\cef.win7\debug.log
text
MD5: e90d86baff0b626a2d496892b0bf0991
SHA256: daf056312282717ebbea93d6ae01aa333e8180d26f59e1d7909aa3a231adcad5
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\html5app\keybinds.cfg
text
MD5: ce8cdf470198eb7c3c581216e0f77263
SHA256: dcf62c9e719442d37b8b91968407538226d0a8e3f5e53a1a39590d530196eaf3
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\graphics\win32_win_restore_hover.tga
image
MD5: 57cf45cf8714025b18ece7559ca8f77d
SHA256: 6ca719f54f72c37228de8aa363a724c1234ad0a3a5a110187a25cbaf79dd5dd7
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\html5app\html5app_steam_video.bmp
image
MD5: 5a0359105ea7f04c73056ac8f015e576
SHA256: 93e17f5ff42926aa03f9a145d5c9aac6ed0c359e0b9cb7cea82edfbd24fe4472
1040
Steam.exe
C:\Users\admin\AppData\Local\Temp\Denuvo\graphics\[email pr