Analysis
-
max time kernel
165s -
max time network
185s -
platform
windows7_x64 -
resource
win7-20240221-en -
resource tags
arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 17:59
Static task
static1
Behavioral task
behavioral1
Sample
filmora_setup_full1081.exe
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
filmora_setup_full1081.exe
Resource
win10v2004-20240611-en
General
-
Target
filmora_setup_full1081.exe
-
Size
2.0MB
-
MD5
2cebe47b7173d9c5347df5fefda7aa4d
-
SHA1
47fd78c898c19450e8b4392b2db648513b50a8aa
-
SHA256
c9965088b9c0333c1f95e4d0738cee30bce1297e6c51cdf9493ace105b95d098
-
SHA512
f069ea55e7db63c4b799a9a924ba20f7722cb01ad7b3f8d5f3e98368d2c8f784d088fcbd18929200b8188d1abdd3da89ffef98e2ac31c7240dd21fe50cecf62d
-
SSDEEP
49152:H05czfx+MZ5oqTGOFDyhFufVjypTQa9NSab8us1:HIczfX6mjFtfVm9NG
Malware Config
Signatures
-
Identifies VirtualBox via ACPI registry values (likely anti-VM) 2 TTPs 1 IoCs
Processes:
Wondershare Filmora.exedescription ioc process Key opened \REGISTRY\MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Wondershare Filmora.exe -
Checks BIOS information in registry 2 TTPs 2 IoCs
BIOS information is often read in order to detect sandboxing environments.
Processes:
Wondershare Filmora.exedescription ioc process Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion Wondershare Filmora.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion Wondershare Filmora.exe -
Adds Run key to start application 2 TTPs 1 IoCs
Processes:
Wondershare Helper Compact.tmpdescription ioc process Set value (str) \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Wondershare Helper Compact.exe = "C:\\Program Files (x86)\\Common Files\\Wondershare\\Wondershare Helper Compact\\WSHelper.exe" Wondershare Helper Compact.tmp -
Blocklisted process makes network request 1 IoCs
Processes:
msiexec.exeflow pid process 109 2864 msiexec.exe -
Boot or Logon Autostart Execution: Active Setup 2 TTPs 5 IoCs
Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine.
Processes:
ie4uinit.exedescription ioc process Key created \REGISTRY\MACHINE\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383} ie4uinit.exe Set value (int) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}\IsInstalled = "1" ie4uinit.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383} ie4uinit.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}\Locale = "*" ie4uinit.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}\Version = "11,0,9600,0" ie4uinit.exe -
Processes:
Wondershare Filmora.exedescription ioc process Key value queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA Wondershare Filmora.exe -
Downloads MZ/PE file
-
Enumerates connected drives 3 TTPs 24 IoCs
Attempts to read the root path of hard drives other than the default C: drive.
Processes:
msiexec.exedescription ioc process File opened (read-only) \??\H: msiexec.exe File opened (read-only) \??\U: msiexec.exe File opened (read-only) \??\V: msiexec.exe File opened (read-only) \??\Y: msiexec.exe File opened (read-only) \??\F: msiexec.exe File opened (read-only) \??\G: msiexec.exe File opened (read-only) \??\J: msiexec.exe File opened (read-only) \??\P: msiexec.exe File opened (read-only) \??\Z: msiexec.exe File opened (read-only) \??\O: msiexec.exe File opened (read-only) \??\E: msiexec.exe File opened (read-only) \??\I: msiexec.exe File opened (read-only) \??\L: msiexec.exe File opened (read-only) \??\M: msiexec.exe File opened (read-only) \??\N: msiexec.exe File opened (read-only) \??\S: msiexec.exe File opened (read-only) \??\T: msiexec.exe File opened (read-only) \??\W: msiexec.exe File opened (read-only) \??\A: msiexec.exe File opened (read-only) \??\B: msiexec.exe File opened (read-only) \??\K: msiexec.exe File opened (read-only) \??\Q: msiexec.exe File opened (read-only) \??\R: msiexec.exe File opened (read-only) \??\X: msiexec.exe -
Writes to the Master Boot Record (MBR) 1 TTPs 1 IoCs
Bootkits write to the MBR to gain persistence at a level below the operating system.
Processes:
Wondershare Filmora.exedescription ioc process File opened for modification \??\PhysicalDrive0 Wondershare Filmora.exe -
Event Triggered Execution: Component Object Model Hijacking 1 TTPs
Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.
-
Suspicious use of NtSetInformationThreadHideFromDebugger 3 IoCs
Processes:
Wondershare Filmora.exepid process 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe -
Checks installed software on the system 1 TTPs
Looks up Uninstall key entries in the registry to enumerate software on the system.
-
Drops file in Program Files directory 42 IoCs
Processes:
Wondershare Helper Compact.tmpdescription ioc process File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\style\is-LQ8LT.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\style\is-I681J.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\style\is-U7A0R.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\images\is-RSDGD.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Wondershare Helper Compact.exe Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\is-N33A8.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\is-8K6EV.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\is-RMFBA.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\is-4P836.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\images\is-GU3J0.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Skin\Default\is-D58QH.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\is-LAS13.tmp Wondershare Helper Compact.tmp File opened for modification C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\unins000.dat Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\is-PP5J8.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe_temp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\style\is-R6F21.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\style\is-M9FML.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\images\is-K5868.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Skin\Default\is-VK1H5.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\is-HLPE5.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\style\is-2OHRL.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Skin\Default\is-M36GL.tmp Wondershare Helper Compact.tmp File opened for modification C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Wondershare Helper Compact.exe Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\is-QCBI5.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\is-98HGF.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\is-F47TQ.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\is-O5RNG.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\style\is-GVKKJ.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Skin\Default\is-U16SF.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Skin\Default\is-8LQO8.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\unins000.dat Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\is-MV284.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\style\is-JR5PP.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\images\is-9I6GF.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\images\is-UGFQP.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Languages\is-5CD3B.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Skin\Default\is-FDBCB.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\is-NRGSP.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\style\is-LEJ14.tmp Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\images\is-AUTAT.tmp Wondershare Helper Compact.tmp File opened for modification C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.ini Wondershare Helper Compact.tmp File created C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\Pages\suit\style\is-4VOA2.tmp Wondershare Helper Compact.tmp -
Drops file in Windows directory 18 IoCs
Processes:
msiexec.exedescription ioc process File opened for modification C:\Windows\Installer\$PatchCache$\Managed\1007C6B46D7C017319E3B52CF3EC196E\9.0.30729\FL_msdia71_dll_2_60035_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8 msiexec.exe File created C:\Windows\Installer\f785b3f.msi msiexec.exe File opened for modification C:\Windows\WinSxS\InstallTemp\20240630180230248.0 msiexec.exe File created C:\Windows\Installer\f785b3a.msi msiexec.exe File opened for modification C:\Windows\Installer\$PatchCache$\Managed\1007C6B46D7C017319E3B52CF3EC196E\9.0.30729 msiexec.exe File opened for modification C:\Windows\WinSxS\InstallTemp\20240630180230295.0 msiexec.exe File opened for modification C:\Windows\Installer\f785b3d.ipi msiexec.exe File created C:\Windows\Installer\f785b3d.ipi msiexec.exe File created C:\Windows\WinSxS\InstallTemp\20240630180230248.0\amd64_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_22d6ba8a.manifest msiexec.exe File created C:\Windows\WinSxS\InstallTemp\20240630180230295.0\9.0.30729.4148.cat msiexec.exe File opened for modification C:\Windows\Installer\$PatchCache$\Managed\1007C6B46D7C017319E3B52CF3EC196E msiexec.exe File created C:\Windows\Installer\$PatchCache$\Managed\1007C6B46D7C017319E3B52CF3EC196E\9.0.30729\FL_msdia71_dll_2_60035_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8 msiexec.exe File opened for modification C:\Windows\Installer\MSI5F23.tmp msiexec.exe File created C:\Windows\WinSxS\InstallTemp\20240630180230248.0\amd64_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_22d6ba8a.cat msiexec.exe File created C:\Windows\WinSxS\InstallTemp\20240630180230295.0\9.0.30729.4148.policy msiexec.exe File created C:\Windows\WinSxS\InstallTemp\20240630180230248.0\vcomp90.dll msiexec.exe File opened for modification C:\Windows\Installer\f785b3a.msi msiexec.exe File opened for modification C:\Windows\Installer\ msiexec.exe -
Executes dropped EXE 21 IoCs
Processes:
NFWCHK.exefilmora_64bit_full1081.exefilmora_64bit_full1081.tmp_setup64.tmpWondershare Filmora SubPack 1.exeWondershare Filmora SubPack 1.tmpWondershare Filmora SubPack 2.exeWondershare Filmora SubPack 2.tmpWondershare Filmora SubPack 3.exeWondershare Filmora SubPack 3.tmpWondershare NativePush.exeWondershare NativePush.tmpWondershare Helper Compact.exeWondershare Helper Compact.tmpWSHelper.exevcredist_x64.exeinstall.exe_setup64.tmp_setup64.tmpWondershare Filmora Launcher.exeWondershare Filmora.exepid process 912 NFWCHK.exe 1880 filmora_64bit_full1081.exe 1748 filmora_64bit_full1081.tmp 2376 _setup64.tmp 1152 Wondershare Filmora SubPack 1.exe 2748 Wondershare Filmora SubPack 1.tmp 2808 Wondershare Filmora SubPack 2.exe 2760 Wondershare Filmora SubPack 2.tmp 108 Wondershare Filmora SubPack 3.exe 2380 Wondershare Filmora SubPack 3.tmp 2056 Wondershare NativePush.exe 3040 Wondershare NativePush.tmp 2012 Wondershare Helper Compact.exe 1588 Wondershare Helper Compact.tmp 1000 WSHelper.exe 1680 vcredist_x64.exe 2932 install.exe 2280 _setup64.tmp 2516 _setup64.tmp 1628 Wondershare Filmora Launcher.exe 1728 Wondershare Filmora.exe -
Loads dropped DLL 64 IoCs
Processes:
filmora_setup_full1081.exefilmora_64bit_full1081.exefilmora_64bit_full1081.tmpWondershare Filmora SubPack 1.exeWondershare Filmora SubPack 2.exeWondershare Filmora SubPack 3.exeWondershare NativePush.exeWondershare Helper Compact.exeWondershare Helper Compact.tmpWSHelper.exeWondershare Filmora SubPack 2.tmpWondershare Filmora SubPack 1.tmpexplorer.exeWondershare Filmora.exepid process 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 1880 filmora_64bit_full1081.exe 1748 filmora_64bit_full1081.tmp 1748 filmora_64bit_full1081.tmp 1748 filmora_64bit_full1081.tmp 1748 filmora_64bit_full1081.tmp 1748 filmora_64bit_full1081.tmp 1748 filmora_64bit_full1081.tmp 1748 filmora_64bit_full1081.tmp 1152 Wondershare Filmora SubPack 1.exe 1748 filmora_64bit_full1081.tmp 2808 Wondershare Filmora SubPack 2.exe 1748 filmora_64bit_full1081.tmp 108 Wondershare Filmora SubPack 3.exe 1748 filmora_64bit_full1081.tmp 1748 filmora_64bit_full1081.tmp 1748 filmora_64bit_full1081.tmp 1156 1156 1156 1156 1748 filmora_64bit_full1081.tmp 2056 Wondershare NativePush.exe 1748 filmora_64bit_full1081.tmp 2012 Wondershare Helper Compact.exe 1588 Wondershare Helper Compact.tmp 1588 Wondershare Helper Compact.tmp 1588 Wondershare Helper Compact.tmp 1588 Wondershare Helper Compact.tmp 1588 Wondershare Helper Compact.tmp 1000 WSHelper.exe 1000 WSHelper.exe 1000 WSHelper.exe 1748 filmora_64bit_full1081.tmp 2760 Wondershare Filmora SubPack 2.tmp 2748 Wondershare Filmora SubPack 1.tmp 1748 filmora_64bit_full1081.tmp 1156 1156 2224 explorer.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe 1728 Wondershare Filmora.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Enumerates processes with tasklist 1 TTPs 1 IoCs
-
Enumerates system info in registry 2 TTPs 3 IoCs
Processes:
chrome.exedescription ioc process Key opened \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS chrome.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemProductName chrome.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemManufacturer chrome.exe -
Kills process with taskkill 46 IoCs
Processes:
TASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exepid process 1284 TASKKILL.exe 1012 TASKKILL.exe 1740 TASKKILL.exe 2292 TASKKILL.exe 2700 TASKKILL.exe 2692 TASKKILL.exe 2196 TASKKILL.exe 1360 TASKKILL.exe 2720 TASKKILL.exe 2736 TASKKILL.exe 324 TASKKILL.exe 3016 TASKKILL.exe 1420 TASKKILL.exe 624 TASKKILL.exe 992 TASKKILL.exe 1312 TASKKILL.exe 2380 TASKKILL.exe 2704 TASKKILL.exe 3020 TASKKILL.exe 2788 TASKKILL.exe 2564 TASKKILL.exe 876 TASKKILL.exe 668 TASKKILL.exe 2800 TASKKILL.exe 2692 TASKKILL.exe 940 TASKKILL.exe 3044 TASKKILL.exe 1920 TASKKILL.exe 1624 TASKKILL.exe 2068 TASKKILL.exe 2040 TASKKILL.exe 996 TASKKILL.exe 2648 TASKKILL.exe 2264 TASKKILL.exe 2148 TASKKILL.exe 3020 TASKKILL.exe 1888 TASKKILL.exe 2536 TASKKILL.exe 2088 TASKKILL.exe 2176 TASKKILL.exe 1600 TASKKILL.exe 1668 TASKKILL.exe 1904 TASKKILL.exe 2444 TASKKILL.exe 2776 TASKKILL.exe 2796 TASKKILL.exe -
Modifies Control Panel 1 IoCs
Processes:
filmora_setup_full1081.exedescription ioc process Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Control Panel\Desktop\MuiCached filmora_setup_full1081.exe -
Processes:
filmora_setup_full1081.exeie4uinit.exedescription ioc process Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch\Version = "WS not running" filmora_setup_full1081.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\BrowserEmulation ie4uinit.exe Set value (int) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\BrowserEmulation\CVListTTL = "0" ie4uinit.exe Set value (int) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main\OperationalData = "4" ie4uinit.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main filmora_setup_full1081.exe Key created \REGISTRY\MACHINE\Software\Microsoft\Internet Explorer\Capabilities ie4uinit.exe Set value (int) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Internet Explorer\Capabilities\Hidden = "0" ie4uinit.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main ie4uinit.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch filmora_setup_full1081.exe -
Modifies data under HKEY_USERS 3 IoCs
Processes:
msiexec.exedescription ioc process Key deleted \REGISTRY\USER\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E msiexec.exe Key deleted \REGISTRY\USER\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D msiexec.exe Key created \REGISTRY\USER\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2E msiexec.exe -
Modifies registry class 64 IoCs
Processes:
filmora_64bit_full1081.tmpWSHelper.exeie4uinit.exemsiexec.exedescription ioc process Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WFPSFile\ = "Wondershare Filmora 13 Project" filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E5E91D68-955D-4DE1-AB8E-89B26DF6A331}\ProxyStubClsid32\ = "{00020424-0000-0000-C000-000000000046}" WSHelper.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}\ = "CustomServicePlatform Object" WSHelper.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\http\DefaultIcon\ = "%SystemRoot%\\system32\\url.dll,0" ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\htmlfile\DefaultIcon ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\fmapplaunch\Shell\Open\Command filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\fmapplaunch\Shell\Open\Command\ = "\"C:\\Users\\Admin\\AppData\\Local\\Wondershare\\Wondershare Filmora\\Wondershare Filmora Launcher.exe\" \"%1\"" filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\.htm\ = "htmlfile" ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\xhtmlfile\shell\open ie4uinit.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WFPTSFile\DefaultIcon\ = "C:\\Users\\Admin\\AppData\\Local\\Wondershare\\Wondershare Filmora\\13.5.1.7566\\Wondershare Filmora.exe,3" filmora_64bit_full1081.tmp Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8E215B99-0763-42B4-9D47-AF5F8C26B49A}\Info filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{70AC1FC1-A22B-4327-9A54-754B9301A056}\TypeLib\Version = "1.1" WSHelper.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{F0ABE7E0-32E3-472E-924C-162B1996DC23} WSHelper.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\mhtmlfile\FriendlyTypeName = "@C:\\Windows\\system32\\ieframe.dll,-913" ie4uinit.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\https\shell\open\command\ = "\"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\" %1" ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{D85C6069-D628-4276-93C3-9A94E5338D8B}\1.1 WSHelper.exe Set value (int) \REGISTRY\MACHINE\SOFTWARE\Classes\Installer\Products\1007C6B46D7C017319E3B52CF3EC196E\AuthorizedLUAApp = "1" msiexec.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\InternetShortcut\ = "Internet Shortcut" ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\.website\OpenWithProgIds ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\.wfp filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WFPBundlexiisFile\Version = "13.5.1.7566" filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{E5E91D68-955D-4DE1-AB8E-89B26DF6A331}\ = "IUserExpData" WSHelper.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\.wfpxiis\ = "WFPXiisFile" filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{D85C6069-D628-4276-93C3-9A94E5338D8B}\1.1\0\win32\ = "C:\\Program Files (x86)\\Common Files\\Wondershare\\Wondershare Helper Compact\\WSHelper.exe" WSHelper.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{55DB3C89-37B9-41E8-87CC-7C578D2F5374}\ProxyStubClsid32 WSHelper.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{55DB3C89-37B9-41E8-87CC-7C578D2F5374}\TypeLib WSHelper.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{0FA988D3-BA51-48AD-A518-6462CD5FF547}\ProxyStubClsid32 WSHelper.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WFPFile\Shell filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\.wfpbundle\ = "WFPBundleFile" filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WFPTSFile\Shell\Open\ = "&Open" filmora_64bit_full1081.tmp Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WFPBundlexiisFile\Shell\Open filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{C5CAFA8E-F69D-4E6F-9BF3-1F4522AFD4BE}\TypeLib\Version = "1.1" WSHelper.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{0477E5C9-0877-499A-8A7C-154C777293DC}\ProxyStubClsid32 WSHelper.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{D85C6069-D628-4276-93C3-9A94E5338D8B}\1.1\HELPDIR\ = "C:\\Program Files (x86)\\Common Files\\Wondershare\\Wondershare Helper Compact\\" WSHelper.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{225BE4D8-64CA-49B1-9630-917F2D92F452}\ProxyStubClsid32 WSHelper.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\svgfile\shell\printto\command ie4uinit.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\svgfile\shell\opennew\ = "&Open" ie4uinit.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{55DB3C89-37B9-41E8-87CC-7C578D2F5374}\TypeLib\ = "{D85C6069-D628-4276-93C3-9A94E5338D8B}" WSHelper.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{70AC1FC1-A22B-4327-9A54-754B9301A056}\ = "IDataGather" WSHelper.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0FA988D3-BA51-48AD-A518-6462CD5FF547}\TypeLib\ = "{D85C6069-D628-4276-93C3-9A94E5338D8B}" WSHelper.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Installer\Features\1007C6B46D7C017319E3B52CF3EC196E\FT_VC_Redist_ATL_x64 = "VC_Redist_12222_amd64_enu" msiexec.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\xhtmlfile\shell\open\command\ = "\"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\" %1" ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WFPBundlesFile\DefaultIcon filmora_64bit_full1081.tmp Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WFPTSFile filmora_64bit_full1081.tmp Key deleted \REGISTRY\MACHINE\SOFTWARE\Classes\https\shell\open ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Microsoft.Website\Shell\open ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WFPBundlexiisFile filmora_64bit_full1081.tmp Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8E215B99-0763-42B4-9D47-AF5F8C26B49A} filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\mhtmlfile\shell\ = "opennew" ie4uinit.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\.website\OpenWithProgIds\Microsoft.Website ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WFPBundlexiisFile\DefaultIcon filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WFPBundlexiisFile\Shell\Open\ = "&Open" filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{E90BA470-0728-47E6-B2E7-0ED0C0CFEA8F}\ = "IContactCustomService" WSHelper.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0477E5C9-0877-499A-8A7C-154C777293DC}\TypeLib WSHelper.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\htmlfile ie4uinit.exe Key deleted \REGISTRY\MACHINE\SOFTWARE\Classes\htmlfile\shell\open\ddeexec\Application ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\svgfile\shell ie4uinit.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\xhtmlfile\shell\open\MUIVerb = "@C:\\Windows\\system32\\ieframe.dll,-5732" ie4uinit.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\.wfpbundle filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WFPTSFile\path = "C:\\Users\\Admin\\AppData\\Local\\Wondershare\\Wondershare Filmora" filmora_64bit_full1081.tmp Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{225BE4D8-64CA-49B1-9630-917F2D92F452}\ = "ISilentInstallProduct" WSHelper.exe Set value (data) \REGISTRY\MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global\Microsoft.VC90.ATL,version="9.0.30729.4148",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="amd64",type="win32" = 51005700510038004000640026004400640035006c0036005b004f0067005900790075002b007300460054005f00560043005f005200650064006900730074005f00410054004c005f007800360034003e0073006b0028004400540038006500400033003400490068006f006c00740067005d0065002400780000000000 msiexec.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Installer\Features\1007C6B46D7C017319E3B52CF3EC196E\Servicing_Key msiexec.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Installer\Features\1007C6B46D7C017319E3B52CF3EC196E\FT_VC_Redist_OpenMP_x64 = "VC_Redist_12222_amd64_enu" msiexec.exe -
Processes:
filmora_setup_full1081.exedescription ioc process Key created \REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436 filmora_setup_full1081.exe Set value (data) \REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob = 04000000010000001000000079e4a9840d7d3a96d7c04fe2434c892e0f0000000100000014000000b34ddd372ed92e8f2abfbb9e20a9d31f204f194b090000000100000034000000303206082b0601050507030106082b0601050507030206082b0601050507030406082b0601050507030306082b0601050507030814000000010000001400000003de503556d14cbb66f0a3e21b1bc397b23dd1550b00000001000000120000004400690067006900430065007200740000001d000000010000001000000059779e39e21a2e3dfced6857ed5c5fd9030000000100000014000000a8985d3a65e5e5c4b2d7d66d40c6dd2fb19c54361900000001000000100000000f3a0527d242de2dc98e5cfcb1e991ee2000000001000000b3030000308203af30820297a0030201020210083be056904246b1a1756ac95991c74a300d06092a864886f70d01010505003061310b300906035504061302555331153013060355040a130c446967694365727420496e6331193017060355040b13107777772e64696769636572742e636f6d3120301e06035504031317446967694365727420476c6f62616c20526f6f74204341301e170d3036313131303030303030305a170d3331313131303030303030305a3061310b300906035504061302555331153013060355040a130c446967694365727420496e6331193017060355040b13107777772e64696769636572742e636f6d3120301e06035504031317446967694365727420476c6f62616c20526f6f7420434130820122300d06092a864886f70d01010105000382010f003082010a0282010100e23be11172dea8a4d3a357aa50a28f0b7790c9a2a5ee12ce965b010920cc0193a74e30b753f743c46900579de28d22dd870640008109cece1b83bfdfcd3b7146e2d666c705b37627168f7b9e1e957deeb748a308dad6af7a0c3906657f4a5d1fbc17f8abbeee28d7747f7a78995985686e5c23324bbf4ec0e85a6de370bf7710bffc01f685d9a844105832a97518d5d1a2be47e2276af49a33f84908608bd45fb43a84bfa1aa4a4c7d3ecf4f5f6c765ea04b37919edc22e66dce141a8e6acbfecdb3146417c75b299e32bff2eefad30b42d4abb74132da0cd4eff881d5bb8d583fb51be84928a270da3104ddf7b216f24c0a4e07a8ed4a3d5eb57fa390c3af270203010001a3633061300e0603551d0f0101ff040403020186300f0603551d130101ff040530030101ff301d0603551d0e0416041403de503556d14cbb66f0a3e21b1bc397b23dd155301f0603551d2304183016801403de503556d14cbb66f0a3e21b1bc397b23dd155300d06092a864886f70d01010505000382010100cb9c37aa4813120afadd449c4f52b0f4dfae04f5797908a32418fc4b2b84c02db9d5c7fef4c11f58cbb86d9c7a74e79829ab11b5e370a0a1cd4c8899938c9170e2ab0f1cbe93a9ff63d5e40760d3a3bf9d5b09f1d58ee353f48e63fa3fa7dbb466df6266d6d16e418df22db5ea774a9f9d58e22b59c04023ed2d2882453e7954922698e08048a837eff0d6796016deace80ecd6eac4417382f49dae1453e2ab93653cf3a5006f72ee8c457496c612118d504ad783c2c3a806ba7ebaf1514e9d889c1b9386ce2916c8aff64b977255730c01b24a3e1dce9df477cb5b424080530ec2dbd0bbf45bf50b9a9f3eb980112adc888c698345f8d0a3cc6e9d595956dde filmora_setup_full1081.exe -
Suspicious behavior: EnumeratesProcesses 10 IoCs
Processes:
filmora_64bit_full1081.tmpWondershare Helper Compact.tmpmsiexec.exeWondershare Filmora Launcher.exechrome.exepid process 1748 filmora_64bit_full1081.tmp 1748 filmora_64bit_full1081.tmp 1588 Wondershare Helper Compact.tmp 1588 Wondershare Helper Compact.tmp 1588 Wondershare Helper Compact.tmp 2864 msiexec.exe 2864 msiexec.exe 1628 Wondershare Filmora Launcher.exe 1716 chrome.exe 1716 chrome.exe -
Suspicious use of AdjustPrivilegeToken 64 IoCs
Processes:
TASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeTASKKILL.exeinstall.exemsiexec.exedescription pid process Token: SeDebugPrivilege 2380 TASKKILL.exe Token: SeDebugPrivilege 2796 TASKKILL.exe Token: SeDebugPrivilege 2704 TASKKILL.exe Token: SeDebugPrivilege 2564 TASKKILL.exe Token: SeDebugPrivilege 3016 TASKKILL.exe Token: SeDebugPrivilege 2736 TASKKILL.exe Token: SeDebugPrivilege 3020 TASKKILL.exe Token: SeDebugPrivilege 1284 TASKKILL.exe Token: SeDebugPrivilege 1012 TASKKILL.exe Token: SeDebugPrivilege 624 TASKKILL.exe Token: SeDebugPrivilege 992 TASKKILL.exe Token: SeDebugPrivilege 1740 TASKKILL.exe Token: SeDebugPrivilege 1624 TASKKILL.exe Token: SeDebugPrivilege 996 TASKKILL.exe Token: SeDebugPrivilege 668 TASKKILL.exe Token: SeDebugPrivilege 2088 TASKKILL.exe Token: SeDebugPrivilege 324 TASKKILL.exe Token: SeDebugPrivilege 2176 TASKKILL.exe Token: SeDebugPrivilege 2196 TASKKILL.exe Token: SeDebugPrivilege 1360 TASKKILL.exe Token: SeDebugPrivilege 1888 TASKKILL.exe Token: SeDebugPrivilege 1600 TASKKILL.exe Token: SeDebugPrivilege 2292 TASKKILL.exe Token: SeDebugPrivilege 1668 TASKKILL.exe Token: SeDebugPrivilege 1904 TASKKILL.exe Token: SeDebugPrivilege 2800 TASKKILL.exe Token: SeDebugPrivilege 2788 TASKKILL.exe Token: SeDebugPrivilege 2692 TASKKILL.exe Token: SeDebugPrivilege 2444 TASKKILL.exe Token: SeDebugPrivilege 2720 TASKKILL.exe Token: SeDebugPrivilege 1312 TASKKILL.exe Token: SeDebugPrivilege 2536 TASKKILL.exe Token: SeDebugPrivilege 2648 TASKKILL.exe Token: SeDebugPrivilege 2264 TASKKILL.exe Token: SeDebugPrivilege 3044 TASKKILL.exe Token: SeDebugPrivilege 2148 TASKKILL.exe Token: SeDebugPrivilege 3020 TASKKILL.exe Token: SeShutdownPrivilege 2932 install.exe Token: SeIncreaseQuotaPrivilege 2932 install.exe Token: SeRestorePrivilege 2864 msiexec.exe Token: SeTakeOwnershipPrivilege 2864 msiexec.exe Token: SeSecurityPrivilege 2864 msiexec.exe Token: SeCreateTokenPrivilege 2932 install.exe Token: SeAssignPrimaryTokenPrivilege 2932 install.exe Token: SeLockMemoryPrivilege 2932 install.exe Token: SeIncreaseQuotaPrivilege 2932 install.exe Token: SeMachineAccountPrivilege 2932 install.exe Token: SeTcbPrivilege 2932 install.exe Token: SeSecurityPrivilege 2932 install.exe Token: SeTakeOwnershipPrivilege 2932 install.exe Token: SeLoadDriverPrivilege 2932 install.exe Token: SeSystemProfilePrivilege 2932 install.exe Token: SeSystemtimePrivilege 2932 install.exe Token: SeProfSingleProcessPrivilege 2932 install.exe Token: SeIncBasePriorityPrivilege 2932 install.exe Token: SeCreatePagefilePrivilege 2932 install.exe Token: SeCreatePermanentPrivilege 2932 install.exe Token: SeBackupPrivilege 2932 install.exe Token: SeRestorePrivilege 2932 install.exe Token: SeShutdownPrivilege 2932 install.exe Token: SeDebugPrivilege 2932 install.exe Token: SeAuditPrivilege 2932 install.exe Token: SeSystemEnvironmentPrivilege 2932 install.exe Token: SeChangeNotifyPrivilege 2932 install.exe -
Suspicious use of FindShellTrayWindow 64 IoCs
Processes:
filmora_setup_full1081.exepid process 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe -
Suspicious use of SendNotifyMessage 32 IoCs
Processes:
chrome.exepid process 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe 1716 chrome.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
filmora_setup_full1081.exeWSHelper.exepid process 2972 filmora_setup_full1081.exe 2972 filmora_setup_full1081.exe 1000 WSHelper.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
filmora_setup_full1081.exefilmora_64bit_full1081.exefilmora_64bit_full1081.tmpdescription pid process target process PID 2972 wrote to memory of 912 2972 filmora_setup_full1081.exe NFWCHK.exe PID 2972 wrote to memory of 912 2972 filmora_setup_full1081.exe NFWCHK.exe PID 2972 wrote to memory of 912 2972 filmora_setup_full1081.exe NFWCHK.exe PID 2972 wrote to memory of 912 2972 filmora_setup_full1081.exe NFWCHK.exe PID 2972 wrote to memory of 1880 2972 filmora_setup_full1081.exe filmora_64bit_full1081.exe PID 2972 wrote to memory of 1880 2972 filmora_setup_full1081.exe filmora_64bit_full1081.exe PID 2972 wrote to memory of 1880 2972 filmora_setup_full1081.exe filmora_64bit_full1081.exe PID 2972 wrote to memory of 1880 2972 filmora_setup_full1081.exe filmora_64bit_full1081.exe PID 2972 wrote to memory of 1880 2972 filmora_setup_full1081.exe filmora_64bit_full1081.exe PID 2972 wrote to memory of 1880 2972 filmora_setup_full1081.exe filmora_64bit_full1081.exe PID 2972 wrote to memory of 1880 2972 filmora_setup_full1081.exe filmora_64bit_full1081.exe PID 1880 wrote to memory of 1748 1880 filmora_64bit_full1081.exe filmora_64bit_full1081.tmp PID 1880 wrote to memory of 1748 1880 filmora_64bit_full1081.exe filmora_64bit_full1081.tmp PID 1880 wrote to memory of 1748 1880 filmora_64bit_full1081.exe filmora_64bit_full1081.tmp PID 1880 wrote to memory of 1748 1880 filmora_64bit_full1081.exe filmora_64bit_full1081.tmp PID 1880 wrote to memory of 1748 1880 filmora_64bit_full1081.exe filmora_64bit_full1081.tmp PID 1880 wrote to memory of 1748 1880 filmora_64bit_full1081.exe filmora_64bit_full1081.tmp PID 1880 wrote to memory of 1748 1880 filmora_64bit_full1081.exe filmora_64bit_full1081.tmp PID 1748 wrote to memory of 2776 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2776 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2776 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2776 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2700 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2700 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2700 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2700 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2692 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2692 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2692 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2692 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 1920 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 1920 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 1920 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 1920 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2380 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2380 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2380 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2380 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2796 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2796 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2796 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2796 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2704 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2704 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2704 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2704 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2564 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2564 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2564 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2564 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 3016 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 3016 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 3016 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 3016 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2736 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2736 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2736 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 2736 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 1420 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 1420 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 1420 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 1420 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 876 1748 filmora_64bit_full1081.tmp TASKKILL.exe PID 1748 wrote to memory of 876 1748 filmora_64bit_full1081.tmp TASKKILL.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\filmora_setup_full1081.exe"C:\Users\Admin\AppData\Local\Temp\filmora_setup_full1081.exe"1⤵
- Loads dropped DLL
- Modifies Control Panel
- Modifies Internet Explorer settings
- Modifies system certificate store
- Suspicious use of FindShellTrayWindow
- Suspicious use of SetWindowsHookEx
- Suspicious use of WriteProcessMemory
-
C:\Users\Public\Documents\Wondershare\NFWCHK.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exe2⤵
- Executes dropped EXE
-
C:\Users\Public\Documents\Wondershare\filmora_64bit_full1081.exe"C:\Users\Public\Documents\Wondershare\filmora_64bit_full1081.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\Admin\AppData\Local\Temp\WAE-Wondershare Filmora.log" /installpath: "C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\" /DIR="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\" /WAEWIN=70122 /PID=10812⤵
- Executes dropped EXE
- Loads dropped DLL
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\is-58URN.tmp\filmora_64bit_full1081.tmp"C:\Users\Admin\AppData\Local\Temp\is-58URN.tmp\filmora_64bit_full1081.tmp" /SL5="$201FA,686721434,401920,C:\Users\Public\Documents\Wondershare\filmora_64bit_full1081.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\Admin\AppData\Local\Temp\WAE-Wondershare Filmora.log" /installpath: "C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\" /DIR="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\" /WAEWIN=70122 /PID=10813⤵
- Executes dropped EXE
- Loads dropped DLL
- Modifies registry class
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Wondershare Filmora9.exe4⤵
- Kills process with taskkill
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Wondershare Filmora X.exe4⤵
- Kills process with taskkill
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Wondershare Filmora 11.exe4⤵
- Kills process with taskkill
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Wondershare Filmora.exe4⤵
- Kills process with taskkill
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM EffectsInstaller.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM FCreatorAcademy.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM CheckGraphicsType.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM FilmoraExportEngine.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM ImageHost.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM FRecorder.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Wondershare Screen Recorder.exe4⤵
- Kills process with taskkill
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Filmora Core UX Service.exe4⤵
- Kills process with taskkill
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Wondershare Filmora Update(x64).exe4⤵
- Kills process with taskkill
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM FilmStockService.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM CreatorAcademy.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM ScreenRecorder.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM AlgorithmRunTest.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM AudioPlayer.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM bspatch.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM CefViewWing.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM cmdCheckATI.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM cmdCheckHEVC.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM coremediaserver.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM CrashReporter.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM DataReporting.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM DownloadCenter.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Filmora.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM FilmoraNPS.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM FilmoraPlayer.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM gpu_check.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM magic_xe_supported_detect.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM MessageService.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM ocl_check.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM ofx_check.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM perf_check.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM RenewService.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM senseTimeGlDetect.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM SupportService.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM WebBrowser.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Performance.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Wondershare Helper Compact.exe4⤵
- Kills process with taskkill
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM Wondershare NativePush.exe4⤵
- Kills process with taskkill
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM BsSndRpt64.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM BugSplatHD64.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM CaptureGameWin.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\SysWOW64\TASKKILL.exe"C:\Windows\system32\TASKKILL.exe" /F /IM CaptureGameWin_64.exe4⤵
- Kills process with taskkill
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\_isetup\_setup64.tmphelper 105 0x2984⤵
- Executes dropped EXE
-
C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Filmora SubPack 1.exe"C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Filmora SubPack 1.exe" /VERYSILENT /SUPPRESSMSGBOXES /DIR="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566" /LOG="C:\Users\Admin\AppData\Local\Temp\WAE-1081.SubPack1.log" /UPGRADE_HWND=5246364⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Users\Admin\AppData\Local\Temp\is-STF8B.tmp\Wondershare Filmora SubPack 1.tmp"C:\Users\Admin\AppData\Local\Temp\is-STF8B.tmp\Wondershare Filmora SubPack 1.tmp" /SL5="$20194,164038312,401920,C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Filmora SubPack 1.exe" /VERYSILENT /SUPPRESSMSGBOXES /DIR="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566" /LOG="C:\Users\Admin\AppData\Local\Temp\WAE-1081.SubPack1.log" /UPGRADE_HWND=5246365⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Users\Admin\AppData\Local\Temp\is-5NK29.tmp\_isetup\_setup64.tmphelper 105 0x1B46⤵
- Executes dropped EXE
-
C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Filmora SubPack 2.exe"C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Filmora SubPack 2.exe" /VERYSILENT /SUPPRESSMSGBOXES /DIR="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566" /LOG="C:\Users\Admin\AppData\Local\Temp\WAE-1081.SubPack2.log" /UPGRADE_HWND=1314904⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Users\Admin\AppData\Local\Temp\is-HGJBV.tmp\Wondershare Filmora SubPack 2.tmp"C:\Users\Admin\AppData\Local\Temp\is-HGJBV.tmp\Wondershare Filmora SubPack 2.tmp" /SL5="$2019C,160048916,401920,C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Filmora SubPack 2.exe" /VERYSILENT /SUPPRESSMSGBOXES /DIR="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566" /LOG="C:\Users\Admin\AppData\Local\Temp\WAE-1081.SubPack2.log" /UPGRADE_HWND=1314905⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Users\Admin\AppData\Local\Temp\is-7V549.tmp\_isetup\_setup64.tmphelper 105 0x1B46⤵
- Executes dropped EXE
-
C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Filmora SubPack 3.exe"C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Filmora SubPack 3.exe" /VERYSILENT /SUPPRESSMSGBOXES /DIR="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566" /LOG="C:\Users\Admin\AppData\Local\Temp\WAE-1081.SubPack3.log" /UPGRADE_HWND=661004⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Users\Admin\AppData\Local\Temp\is-8N61B.tmp\Wondershare Filmora SubPack 3.tmp"C:\Users\Admin\AppData\Local\Temp\is-8N61B.tmp\Wondershare Filmora SubPack 3.tmp" /SL5="$10238,144948898,401920,C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Filmora SubPack 3.exe" /VERYSILENT /SUPPRESSMSGBOXES /DIR="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566" /LOG="C:\Users\Admin\AppData\Local\Temp\WAE-1081.SubPack3.log" /UPGRADE_HWND=661005⤵
- Executes dropped EXE
-
C:\Windows\system32\regsvr32.exe"C:\Windows\system32\regsvr32.exe" /s atimpenc.dll4⤵
-
C:\Windows\system32\regsvr32.exe"C:\Windows\system32\regsvr32.exe" /s atixcode.dll4⤵
-
C:\Windows\system32\regsvr32.exe"C:\Windows\system32\regsvr32.exe" /s CFDecode64.ax4⤵
-
C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare NativePush.exe"C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare NativePush.exe" /VERYSILENT /BINDINSTALL4⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Users\Admin\AppData\Local\Temp\is-UU6J9.tmp\Wondershare NativePush.tmp"C:\Users\Admin\AppData\Local\Temp\is-UU6J9.tmp\Wondershare NativePush.tmp" /SL5="$1027A,2822387,938496,C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare NativePush.exe" /VERYSILENT /BINDINSTALL5⤵
- Executes dropped EXE
-
C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Helper Compact.exe"C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Helper Compact.exe" /VERYSILENT /SP-4⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Users\Admin\AppData\Local\Temp\is-UV2EC.tmp\Wondershare Helper Compact.tmp"C:\Users\Admin\AppData\Local\Temp\is-UV2EC.tmp\Wondershare Helper Compact.tmp" /SL5="$2027A,2101212,54272,C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Wondershare Helper Compact.exe" /VERYSILENT /SP-5⤵
- Adds Run key to start application
- Drops file in Program Files directory
- Executes dropped EXE
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
-
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" /regserver6⤵
- Executes dropped EXE
- Loads dropped DLL
- Modifies registry class
- Suspicious use of SetWindowsHookEx
-
C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\vcredist_x64.exe"C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\vcredist_x64.exe" /q4⤵
- Executes dropped EXE
-
\??\f:\d5baf80d5e13b572f81ef8644500\install.exef:\d5baf80d5e13b572f81ef8644500\.\install.exe /q5⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\system32\ie4uinit.exe"C:\Windows\system32\ie4uinit.exe" "-show"4⤵
- Boot or Logon Autostart Execution: Active Setup
- Modifies Internet Explorer settings
- Modifies registry class
-
C:\Windows\SysWOW64\explorer.exe"C:\Windows\System32\explorer.exe" C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\Wondershare Filmora Launcher.exe2⤵
-
C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe" http://cbs.wondershare.com/go.php?m=ic&back_url=https%3A%2F%2Ffilmora.wondershare.es%2Fthankyou%2Finstall-filmora-video-editor.html&client_sign={00129376-36de-4eb0-96a0-02eb3fd40594G}&m_nProductID=1081&installtime=1719770560&product_version=13.5.1.75662⤵
- Enumerates system info in registry
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of SendNotifyMessage
-
C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=106.0.5249.119 --initial-client-data=0xc0,0xc4,0xc8,0x94,0xcc,0x7fef5939758,0x7fef5939768,0x7fef59397783⤵
-
C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1192 --field-trial-handle=1248,i,14464124641947686979,4265936871532298093,131072 /prefetch:23⤵
-
C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1524 --field-trial-handle=1248,i,14464124641947686979,4265936871532298093,131072 /prefetch:83⤵
-
C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1624 --field-trial-handle=1248,i,14464124641947686979,4265936871532298093,131072 /prefetch:83⤵
-
C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --display-capture-permissions-policy-allowed --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2132 --field-trial-handle=1248,i,14464124641947686979,4265936871532298093,131072 /prefetch:13⤵
-
C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --display-capture-permissions-policy-allowed --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2140 --field-trial-handle=1248,i,14464124641947686979,4265936871532298093,131072 /prefetch:13⤵
-
C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --display-capture-permissions-policy-allowed --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=3200 --field-trial-handle=1248,i,14464124641947686979,4265936871532298093,131072 /prefetch:13⤵
-
C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1420 --field-trial-handle=1248,i,14464124641947686979,4265936871532298093,131072 /prefetch:23⤵
-
C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1296 --field-trial-handle=1248,i,14464124641947686979,4265936871532298093,131072 /prefetch:23⤵
-
C:\Windows\system32\msiexec.exeC:\Windows\system32\msiexec.exe /V1⤵
- Blocklisted process makes network request
- Enumerates connected drives
- Drops file in Windows directory
- Modifies data under HKEY_USERS
- Modifies registry class
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1694856404159141690373565679-2008135883-17631944282131155415152503716-550074840"1⤵
-
C:\Windows\explorer.exeC:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding1⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\Wondershare Filmora Launcher.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\Wondershare Filmora Launcher.exe"2⤵
- Executes dropped EXE
- Suspicious behavior: EnumeratesProcesses
-
C:\Windows\explorer.exe"C:\Windows\explorer.exe" C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\Wondershare Filmora.exe3⤵
-
C:\Windows\explorer.exeC:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding1⤵
- Loads dropped DLL
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\Wondershare Filmora.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\Wondershare Filmora.exe"2⤵
- Identifies VirtualBox via ACPI registry values (likely anti-VM)
- Checks BIOS information in registry
- Checks whether UAC is enabled
- Writes to the Master Boot Record (MBR)
- Suspicious use of NtSetInformationThreadHideFromDebugger
- Executes dropped EXE
- Loads dropped DLL
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\DataReporting.exeDataReporting.exe {\"process_guid\":\"a5c2bff0-4c65-4351-a2de-b760e2041ad9\",\"process_name\":\"DataReporting\",\"process_type\":3,\"server_guid\":\"fc03843e-f07d-4faa-9f8d-97b46565dd4f\",\"server_name\":\"WS_Filmora\",\"server_process_id\":1728,\"server_process_start_time\":1719770564970}3⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\Performance.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\Performance.exe"3⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\FilmoraPlayer.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\FilmoraPlayer.exe" check3⤵
-
C:\Windows\System32\Wbem\wmic.exewmic diskdrive where index=1 get serialnumber3⤵
-
C:\Windows\System32\Wbem\wmic.exewmic diskdrive where index=1 get serialnumber3⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\WebBrowser.exeWebBrowser.exe {\"prload_url_list\":[\"https://accounts.wondershare.cn/web/login_cn?default_login=1&hide_sns=2&login_mode=2&mode=2&oauth=1&product_id=13770\",\"https://miao.wondershare.cn/mobile-service-popup.html\",\"https://wae.wondershare.cc/nps2/?embed=desktop&preload=yes\",\"https://app.filmora.io/#/ai/copilot?embed=client\"],\"process_guid\":\"e1591f6c-8464-4275-b8de-acee1d807d7c\",\"process_name\":\"WebBrowser\",\"process_type\":1,\"proxy_info_mode\":0,\"proxy_info_password\":\"\",\"proxy_info_port\":0,\"proxy_info_server\":\"\",\"proxy_info_type\":2,\"proxy_info_user\":\"\",\"server_guid\":\"fc03843e-f07d-4faa-9f8d-97b46565dd4f\",\"server_name\":\"WS_Filmora\"}3⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\CefViewWing.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\CefViewWing" --type=gpu-process --field-trial-handle=1512,6969562107558421394,15770905318139502074,131072 --enable-features=CastMediaRouteProvider --disable-features=CalculateNativeWinOcclusion --no-sandbox --locales-dir-path="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cefresources\locales" --log-file="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\debug.log" --resources-dir-path="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cefresources" --user-agent="CEF89.0.0.win64/QCefView 1.0 (Windows; en-us) wondershare_filmora_win" --lang=en-US --use-mock-keychain --renderer-process-limit=1 --disable-gpu --bridge-obj-name=filmora --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --use-gl=swiftshader-webgl --log-file="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\debug.log" --mojo-platform-channel-handle=1544 /prefetch:24⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\CefViewWing.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\CefViewWing" --type=utility --utility-sub-type=storage.mojom.StorageService --field-trial-handle=1512,6969562107558421394,15770905318139502074,131072 --enable-features=CastMediaRouteProvider --disable-features=CalculateNativeWinOcclusion --lang=en-US --service-sandbox-type=utility --no-sandbox --locales-dir-path="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cefresources\locales" --log-file="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\debug.log" --resources-dir-path="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cefresources" --user-agent="CEF89.0.0.win64/QCefView 1.0 (Windows; en-us) wondershare_filmora_win" --lang=en-US --use-mock-keychain --renderer-process-limit=1 --disable-gpu --bridge-obj-name=filmora --log-file="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\debug.log" --mojo-platform-channel-handle=1688 /prefetch:84⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\CefViewWing.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\CefViewWing" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1512,6969562107558421394,15770905318139502074,131072 --enable-features=CastMediaRouteProvider --disable-features=CalculateNativeWinOcclusion --lang=en-US --service-sandbox-type=network --no-sandbox --locales-dir-path="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cefresources\locales" --log-file="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\debug.log" --resources-dir-path="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cefresources" --user-agent="CEF89.0.0.win64/QCefView 1.0 (Windows; en-us) wondershare_filmora_win" --lang=en-US --use-mock-keychain --renderer-process-limit=1 --disable-gpu --bridge-obj-name=filmora --log-file="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\debug.log" --mojo-platform-channel-handle=1704 /prefetch:84⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\CefViewWing.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\CefViewWing" --type=renderer --no-sandbox --log-file="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\debug.log" --field-trial-handle=1512,6969562107558421394,15770905318139502074,131072 --enable-features=CastMediaRouteProvider --disable-features=CalculateNativeWinOcclusion --disable-gpu-compositing --lang=en-US --locales-dir-path="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cefresources\locales" --log-file="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\debug.log" --resources-dir-path="C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cefresources" --user-agent="CEF89.0.0.win64/QCefView 1.0 (Windows; en-us) wondershare_filmora_win" --use-mock-keychain --renderer-process-limit=1 --disable-gpu --bridge-obj-name=filmora --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1864 /prefetch:14⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\PlayServer.exePlayServer.exe {\"process_guid\":\"2dd5685e-0b69-446a-856f-c4229b79a3bf\",\"process_name\":\"PlayServer\",\"process_type\":11,\"server_guid\":\"fc03843e-f07d-4faa-9f8d-97b46565dd4f\",\"server_name\":\"WS_Filmora\"}3⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\Wondershare Filmora Update(x64).exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\\Wondershare Filmora Update(x64).exe" /VERYSILENT /SP- "/DIR=C:/Users/Admin/AppData/Local/Wondershare/Wondershare Filmora Update/"3⤵
-
C:\Users\Admin\AppData\Local\Temp\is-LAJLP.tmp\Wondershare Filmora Update(x64).tmp"C:\Users\Admin\AppData\Local\Temp\is-LAJLP.tmp\Wondershare Filmora Update(x64).tmp" /SL5="$90170,8272281,163840,C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\Wondershare Filmora Update(x64).exe" /VERYSILENT /SP- "/DIR=C:/Users/Admin/AppData/Local/Wondershare/Wondershare Filmora Update/"4⤵
-
C:\Users\Admin\AppData\Local\Temp\is-71EP8.tmp\_isetup\_setup64.tmphelper 105 0x1E05⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cmdCheckATI.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cmdCheckATI.exe"3⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cmdCheckHEVC.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\cmdCheckHEVC.exe" 875967049 320 240 1000 30003⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\coremediaserver.exe"C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\coremediaserver.exe" 6071f564648041d4-bd8da1e38af9b8f3 16854 1728 "C:\Users\Admin\AppData\Local\Temp\Wondershare Filmora\MediaInfo\Wondershare Filmora.exe.sqldb" "C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\proxypath" "C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\" "C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\" "C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\Log"3⤵
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\magic_xe_supported_detect.exemagic_xe_supported_detect.exe single audio_separation_lite "C:\ProgramData\Wondershare Filmora\VblProductData/VblExtension/Models/" ./resources/wfx_effect/material/models/model_data.json ./resources/wfx_effect/material/models/magic_xe.lic ./log3⤵
-
C:\Windows\system32\tasklist.exetasklist /FI "\"PID EQ 1728 \""3⤵
- Enumerates processes with tasklist
-
C:\Program Files\Google\Chrome\Application\106.0.5249.119\elevation_service.exe"C:\Program Files\Google\Chrome\Application\106.0.5249.119\elevation_service.exe"1⤵
-
C:\Windows\system32\AUDIODG.EXEC:\Windows\system32\AUDIODG.EXE 0x4e81⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Persistence
Boot or Logon Autostart Execution
2Registry Run Keys / Startup Folder
1Active Setup
1Pre-OS Boot
1Bootkit
1Event Triggered Execution
1Component Object Model Hijacking
1Privilege Escalation
Boot or Logon Autostart Execution
2Registry Run Keys / Startup Folder
1Active Setup
1Event Triggered Execution
1Component Object Model Hijacking
1Defense Evasion
Virtualization/Sandbox Evasion
1Modify Registry
4Pre-OS Boot
1Bootkit
1Subvert Trust Controls
1Install Root Certificate
1Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\KPByName.dllFilesize
35KB
MD54ef13e267ebbf804dd4157b447aa7059
SHA1b9507c5b02bbae456ae5de7132ebafd27206b944
SHA2562476d897a6d20653578fcb98737c85ccd96a42e57f67843ffbc431c0d05909a7
SHA51281df3f309b6a734fae2e824a4535d9a7251d94885593c7c37ee70853f7c721062023d0d22ba1c92845c6fd14356048478b83c132aa9cec9360690a65b74bf360
-
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.iniFilesize
4KB
MD528be6905c609aba1f7390d4e0f64ce55
SHA1ef637f64ce69228001714da7b056738d54baccc4
SHA256dc75d50b43f4d95bd916bf49101e2f8cf4e0f0a89f69530a86579e4086020a73
SHA512cc39bad3da354e23705f5c4adedc86f4eb3bd4539e106325d34918a06d0948bb13ec0ea72bc7d98cde6aa6504a4a958b5d47d34852cdb4f007e2924cf9121534
-
C:\ProgramData\Wondershare Filmora\AnimationThumbnail\Motion\is-9QDU3.tmpFilesize
14KB
MD5a815bbbf3454db9d628ac8938635dea8
SHA1608f00187f0f032ec26afaf050a6ee29f36e8526
SHA256080cf38a264bd06666e8e7750f29942a026e959fd89fc59873794ddcaa1f0680
SHA5124e8b386dc36618232e42bfaa49618e6e25dfec20c5ba04f2c49ab6f4a2a668d17d38b058c76cc1842633d8f6a8854fd1e202468f3281590254cebc1bf8365f98
-
C:\ProgramData\Wondershare Filmora\AnimationThumbnail\Motion\is-M61A9.tmpFilesize
4KB
MD5e89361ff315588513bd3daebb894ee22
SHA1a96d62b3be56835eba78eb22868ba0b093407d53
SHA256c9e19bc5ca79ddd3eef37e443eacc8161acd92c312afccd4be6294a72618b8c7
SHA512764e9898abd754cd92bb880bd8731e2730a1092dc23304e37ba29fffcf963fd7a7f00f32f089dcb562cc51e3a397e0763892317c6c1a460783510c3ed3e61576
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-0BLFQ.tmpFilesize
869B
MD5bf02d0a20b3df0a78b134aff36c9598d
SHA1e85d3be7431e94cc2d5fe6c07650079b2f141058
SHA2561d73d0a001daa01387c3259f7a7a49e2be82e79a500f102a6594bc72dd72e0ef
SHA512475e2db4300f232f4d8230725e1eb01b7572dbc50357b7a0165ae17614fbaba27197570fb03247476da50d1013e3fe4bb5209f19a374e1235e6c556ea211fcdc
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-1D6EF.tmpFilesize
869B
MD557d9b035cbb64b851b2624f0b35ecf2d
SHA1773589a552d10019473d8cd9ba740a4d70f4fd59
SHA256ec3d238d912ea9f0bfe781ad764945ae5343244d047743e02635f52804210188
SHA5124ba57cd9e1519ca771788c483760951ce7b77ecfc76e09d36d2f3f94a97c19f738c00de902899cc7950c76a69f085a46896587ecacc4cbbb0efd36e05c35dab5
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-3GFJ6.tmpFilesize
872B
MD533811422691e188e560d96c65f773d28
SHA11f23bbbaff87beca0136d08719675c8c6f3bc1ae
SHA256356716bd0b47c47bfab1ce62808ecba98c6cf1bf97108862bc6fe75a253c3dae
SHA512a8b81401d9d408ff267404202bb80f288c66d830cdb4f16b6a1f1a800cbfdbb4db167fa86bffbd21bf6f76bebbab985842641dcb62d9169a362ea20d367ab087
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-5LUSC.tmpFilesize
869B
MD568033d74680bdfd660babe965a772668
SHA17a73d110f66eb23b38d93a05cb1296c1e3d8dbaf
SHA256a7d4902a50086b407f62b20f38c08990dbdfd655517c9f14fb15f47705bd4eda
SHA5125b49321cb89bea819391020054b9e08e4ea20ff3de9c2b3eed1c2af92b0fa5ca323ad8d9ff2572d372993e2a0b0343142ce5b14a94603f223db72d87262a60e6
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-7QBS7.tmpFilesize
871B
MD5c5638d0205bf788dc58701a7b0feb153
SHA19aeddef17674b8f245ad5ab23c1544d33eddbd2d
SHA256a724d74a8a8397b9ad9c5d897fbd2ef0a7b8c1c611489a6b499e3b672a3e6730
SHA5126bbacfaae590501af2d02ef559ecc804c24a2680ad1dd7b5515c77cf84d2e3bc16a342a1633d030c3536c4eee8221e092bcfcffdd23f8fd578b4af4e41e09ea1
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-83VM0.tmpFilesize
872B
MD51b4664140efbc00bf0ecca03168cc216
SHA194bcfe2b1501cd82e23ae394be2cec424ad7f440
SHA25639be632613d649c385088a0b2e385b2551413754b3f2bf397e08dbba75748ae6
SHA51287bc52279c94aeb5ec5b5274f4faf28fa9d9b7e9006245cb996b07d20079b516cf2383feaefbeda49d65b69fc26b6ba345e764beb2073e66438527c0905c8ec1
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-CHREL.tmpFilesize
868B
MD50baea59db5f6ff0bc006a7ed149964ab
SHA14ee06ffef82bd0ab4ac8d90be32365c5eb000db1
SHA256e1ece607477c51659ee152f802a37da359c517157c179295d2aafd11f0666f89
SHA512bdb41232079c0f754eade6bca97cefd5a6eb77a638cbbea43bf505751387adc25ef8388a39c76ae1c4ac082b0604317096fdbd3cbdc077464c3079f3f2c54744
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-DCPHL.tmpFilesize
868B
MD5377462625a39bdd6586d3bae3a6ead9e
SHA1b5b50de5b08c16d1493c92957eb420511761c8bf
SHA25622a07da2b217afb478993f21af2c909d92289ac0eb899290b290b5b00ee0292b
SHA512154b000048a406f972fe4148e2ac2484a41f25d1bcb5c042ab4c7f07ca9b558d1e3d8772929035d7311c1cbe3f2599a31611e254a5e1202de7c379722a574da5
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-HQNK9.tmpFilesize
869B
MD5b2556f286a74dfc32ded889b9011c0b4
SHA12f280da4bcb362f5ae04886540e126cedc900435
SHA2560b2d213c0d143e8fb53400458ce7b1f05797fffb9264237e27af9f60b6219de5
SHA5129bfd838697c4e89c0d6592d872c1f6edf3c28c8d0cdbf3488be01c8a78b8f0306046e4aa2f84e1197a8174e657c768376920c4f6aec8dc2087ede45ecec471a7
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-IFJFM.tmpFilesize
870B
MD5da228583d181522a3be34db2f3270a5d
SHA19c9a8c24c2854e5b7d62a461f1a37191cefd8d41
SHA2566aacec619d4c3c77baef7a86e65b018ae88b6ff244b2ce64bd54f4bd6d31a52e
SHA5126b7f519956d47ae9c2df8ea31993a6ae3aa5a04d53f3a64724662b9b6820f06f46a2573c85ef0354e62bf68e2b8d52d408e729fc96a5d191e25b12c23e62a4fe
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-QCLBF.tmpFilesize
869B
MD53071beec50236845dddf6a65b42a80fa
SHA1aeb76d7a7dc2d86dcb74aad19499bbfcd64cb696
SHA2567f42e4e411cf791fe847db4d272381fc2d194c78ce70e35dc8877b35250f1d0b
SHA51227ecf6efa01689b458e0351ae12be8e1c48ff318dffcf59059ff081cc569c53793e307ed6c4cba09d0f44dc3b50e8aa652ea5930d42ae8482a6b23b2de67d93b
-
C:\ProgramData\Wondershare Filmora\Default Effects\ActionCam\CameraSettingFiles\is-SRAFR.tmpFilesize
872B
MD50607b8b310933b5dd9a25430e7233367
SHA1ee7c02dad447cce41edc172303baea1170b845cb
SHA2561fc78174d305af5c6aeb39a2bfdfa1a27759f108d02a3b1977a715e111c88530
SHA512855e937509bb2680839c6f67407f32eb3c36a2a77ec2ee78a624a588be610fc724e6ff55bfc74706f6a76bb63f600d37a18ca7cac35c432def02b6fd91e574a3
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-3TIR6.tmpFilesize
896KB
MD56c813fb92c7c1db27105ef5324c88d04
SHA1c6e0d68abd352983c8337d3d2dfa90acf68895b0
SHA25673374a19daa1603b8cde5ae2dd130542b18f0b2e36f5dc658b416c9bff0a4f49
SHA512999d54ddc2b927b3507522641242bee06b6fbeb101261616289f20dc401750be1579bef98983b932051cfbb186358be9f6e064e10200ca8c8a2dfcbc2b52aa14
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-66FSA.tmpFilesize
896KB
MD567e4e2eacea9a625138cd46b6e592585
SHA174622516cc90316d82dc1faf32c3bcd3843c7911
SHA2568a0ddca0a4f2900564b81ebf5300adb74674dc2a098d090c0103ac1894995cf3
SHA5124f20eb8d1ba8378a97ea9c1f4a2bfc80ff6da6890ca530d7f5ae832a57a303dc78970fd485c5c95e2ddb981cbd267f67b4b04352f1f9cdf23aec89d5bc45d3c4
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-9RL19.tmpFilesize
896KB
MD5faf8badb5f8cef512c1f968abc45f6cc
SHA160dfa1ca68ec8748eefc522937f4a4c7dfce31e6
SHA256d0038fa1cce4122ad373cb621126a1c752734d4ee1bdbad67d74f4af557a94c9
SHA512f0d6a89495f2ba0e8d005e605316b40c10c5e469abb8d9f2a13a1d582c9382c57a37c69187616df24e3ea73418328cbc800d8100d64c9ff3073e4a67227b45a5
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-AG2GP.tmpFilesize
896KB
MD5640e0bbd516ded306c147296fd3661bf
SHA13145222c1958529c7596294a45173ab7d20912a1
SHA256c6be9d6e7391f2527fdbe49947fb2e0029866921ed33e1f2e4f364085f7ac951
SHA512cda1a43bc9b57750b3a9ca39a91576ec7e4eabc7f21c973ac33fcdef3266112c4781e25cb671236b992b65a52c28d907f50c95c4c439df5619a51188dc30cd27
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-AMSE7.tmpFilesize
896KB
MD5647a89cb616007af51fb8a1b382d0044
SHA1aa58ad4681864d9dc6fec6c8f08f358849941102
SHA2567af6f666cc4087326fc05f282c5a894b5aa3c89cbf4e0665e0cf3dc8bc061005
SHA5120700b5f74b26fe043cbd15a79bc233d1efc23493c44458393d0691c353c5fe9e3e797dd628e1a55de778831b7588a7130c53bc9ae060f59d56bc625dc461cefe
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-B1RS9.tmpFilesize
896KB
MD556ec752dc2056c0cc9cf9b0cd9f4302f
SHA1fce881cd92352bb893c64c5a3d79fc976c46609e
SHA25621aeabf1641980e77388abe5a2c9553176d7ee873e13cfcecc9f1eaa3616525b
SHA51257d8eef11dc536c3be9e30e2a252292510f3cc3e8d3a8fc3cffa2adc4b460b794c7fb47aac240358ffd0b4f4417e1ee3f98b6967c5455f7ede854fb812465ccb
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-EB6UV.tmpFilesize
896KB
MD53de1634dac404ef92542c5aa9b162722
SHA18772646211e4c9447902434f7c26ddce2be2c571
SHA256803264c78fb91b15f438ad6b8dc05eeed8b38978afd12752bd0d25986b905ad0
SHA512c5909b6d5e0c0b9c9226648c3f19cb2f831541ae831b704b3987a56cd0b53383f053cd6bb91a1f07cad29242ff4fef9cf2d317c8ddc73b6969955a6810b5d7a1
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-GUFTR.tmpFilesize
896KB
MD54b116ee72a283bd845c67d843495e31b
SHA1dbe8a61a688d8f3f627370c3ea85262aae7b8924
SHA25657a86dc3f7af3d6c125de2787f2f277c58433b1ac1800ced18213f5f15de6413
SHA51293464e303fbae51be8801f5f6c6f23cf599937c6fd4f023ff50cb799465ef983d42e210531027c3039c53621e85be57fe864c2ea8b490d41b5cf9e400cbb200c
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-LVGCS.tmpFilesize
896KB
MD57121670fdba91f2718ad8cb21d3bfecc
SHA14853169eda231e0693830dbfdad6fadb824e8732
SHA256da87241148b9244c0e45a875ffa365994cd5003034bf497d3e0f8450175528c9
SHA5125839b3bd0678b794bd6cc9c066756b5738d087052144c6f2580f2d3a19f55aa4867aa3177c2077d7cd7cd176a33d2584857735068527c3432d99d7359902cee6
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-O6ECS.tmpFilesize
896KB
MD570ca4889d8b79de3cef0a84000938dab
SHA127ec1437f2fab4678734697454a6a6d3cb6936ae
SHA2561be3d7bf5df34657ecd4375d74600efea703f8d3bbead26bb239d6733044560b
SHA512bbb084c7918b4b2280f31239f0399a6ee06937543ee87dcc0cbde4bc729a1e061fd004658262bf0fcc667e9586e47959603a89a7fbbc269a2a5d10676b702b7b
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-OAI24.tmpFilesize
896KB
MD57697bbea57fb711bf232b09adacb5b7a
SHA1b50c35285c0118053dce70a7085651bbe314ae6a
SHA256fa6c9586d9a301a12240da7af73598906768f1a585175c8fcea99c5de2732a90
SHA5127293fe2bdec6ac96be90cb2772b84a52a11b68d3ede29db116ae3a9c5f8011884a0058c7ddfa28b25299a02aa983e2857d088bf16e667d16dc70303489ed313a
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-RN5VB.tmpFilesize
896KB
MD58dbcded5d9476cd5cd32d9ec7195cbf5
SHA19ec1f2311c5180779096802e87f854d0bdf5b8be
SHA25678d54e5f7a5d16c0379155294de80b079d7f204813d120fdd0a11b810c7c67e0
SHA512c06a128e8edf35291ea3ad6a30913e324caafec75c358a6d9efac0b26f6de3ff1f7b0f94bef374ecf29d7d14dbd9821d9419d5aae70b9b3e2b7b87c8676f69be
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-SLF2D.tmpFilesize
896KB
MD5f49444ff5a0e6d62e63df65344ada2de
SHA11522f234cf317200dc7444a411a25c52c61cd7fd
SHA2564efcf045f97bfc3452dbc90a1c12076c49851e4f8e65418ea1f80fa8f54d248b
SHA5123b80ec48a39fccd19c60f583d270bfa56101ee2f2cc09c71c95c56b83d22ada41373ac5e2c1dc2de69695d8eb0d855ed8d8248e154b466fc31563be8044633e2
-
C:\ProgramData\Wondershare Filmora\Default Effects\LightRoom\CubeLUTFiles\is-UG5E9.tmpFilesize
896KB
MD5190f7f94884a6015757c69a0c9b705f9
SHA19ea8b29ec51323f4869800ce8118900a45a3b3a9
SHA256a434f4028d113176cc96bfe2a35c6abd4fd099ec62da7cd9a3887ad8dfefb97e
SHA512a93e508b06c40dd751237d83f7c95bac0ab0a5da87890493806ed302a3009bdfeaaa7eae6470d737f21c292d2a98a4e33f4648c06e468dad9a821ae9632a545f
-
C:\ProgramData\Wondershare Filmora\FConfig.iniFilesize
5KB
MD5d525b740ee355d659221dbc2ce76a51d
SHA14a1c70528610601d8ea12b7afb63cf8fbabfd0d4
SHA25679c22f291f2cf71eb4bce6268c827d8d36ab0fbe076a3d2945d22f62e815371c
SHA512db34ee1106a9ae2df8a7d00a0b7864a0c8bc34407560621634d4e4ac7b9b059c83a4136796b1a4ce2d1250ed3b12c7d01c278ff09508d3414c5a046a289518da
-
C:\ProgramData\Wondershare Filmora\FConfig.iniFilesize
5KB
MD561b566199b7efe25d52d4afe59abd56f
SHA1ce2c8853e21d434fa66fbbeba09b5cc487456a2a
SHA25611e8c4a54ae7067204588cb8558f18d1e60c4b297b42d2d19bf99932b70d0a47
SHA5128a3a7c34ec1e55031c355cdbb17d8f84bfa0018522310558db0d11fc0794c185dbd449823fe8c7d0c8b3b34d33cc73e636c7fc03ef07b0bbdee761a4cec0228e
-
C:\ProgramData\Wondershare Filmora\Filmora.iniFilesize
671B
MD5025dd56b4f76bef6a9226d7343ba608c
SHA123b0326fb99a439fa87c2091a279cb6b79830bc0
SHA256464db6752747fc64d2e9518c838add2520c039b6b065a25a966aa8cba1b1bcc1
SHA512090e8522d583f5d1b746152fc2848c064d73eb4c0ba451fce3af762b7525e7020064cbb147417acdc4204a6a594667281e6304f32e0f0c5d9af9d0c3514fb874
-
C:\ProgramData\Wondershare Filmora\Filmora.ini.GRoNBYFilesize
681B
MD5cd41340ce2caeac6f089d655795f4ad0
SHA1ff8b74882584d7612c72d74c3b595b4192d18179
SHA256cb13669fbbb60130f8612fbcff464dbdcd07d047a58e099992dddfbf956342d2
SHA512ceca43c7269693825655f25ab97a92a8cde814da15f8a194528cf31d4ba6fe3d22d6881a0a20e2253560c72627882a1f0796ca4d2a886f5ea4654723997c05ca
-
C:\ProgramData\Wondershare Filmora\Skin\Dark\Stand\Dark.qssFilesize
620KB
MD50c118cf43e84dae42a08f4c18d62fbd4
SHA1a111b769d0ce200f4849c5191a022ac60da189a3
SHA256b93b85be77c408282c3e6fb72e196a2d4eb0b310dc26c30c9c4f169066828f92
SHA512ee9c944f35fc012745215c36fcce924aa41072026b4826ee1c4157b0dadd399e931c02f84ac206a3c4a763ba64517e39423104c9c946e5b392d761526d59b39e
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\audio_separation_lite\WM_AudioSeparationLite_CPU_OpenVino_online_FP32_v1.0.0.modelFilesize
28.3MB
MD5050e5223113b98019e28cd2044a6bc5f
SHA10dd18ac9f87735d2bd2e79fd39cc3d39645334e5
SHA25662e56234dd900b380a651939e19b63ceb0d739ba1f51d1bfec3cbc3bf9a3b7f1
SHA512ba11bbb9bbe283bd9cabf3bec3f7d3604aa47635aeb1b5f39c8ca8bf919204a94094e7cbab5b773a7a25388a96ff68927609eab66473976b7c6ff90f524506a2
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\audio_separation_lite\versionFilesize
5B
MD547cd76e43f74bbc2e1baaf194d07e1fa
SHA191e95be6b6634e3c21072dfcd661146728694326
SHA25692521fc3cbd964bdc9f584a991b89fddaa5754ed1cc96d6d42445338669c1305
SHA51210910aab7de5e168e04fa5d8df2ecc66e4aab45e676bc4ac6f222787cd461cfa6efbe9fe81769747c1993c76c3e744600134778dd83df837cafa1e6689372f40
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\autoreframe\WM_AutoReframe_X86_Openvino_Fp16.modelFilesize
3.5MB
MD544ca21267dd650664c956fc30d48f842
SHA17b77e9f40dae5472b943115e2a0e151e20e524ac
SHA2560c3082d072db970ce7f0058d4b4463b62334ed456b5ff1521eccde273f84be6f
SHA512b8294eb1544b951b6c62fe5474ec4f01176f9299acdb7047f51d5859a511dd1f311a93f8298ec8e0f82a408e87feaeb4c9b6fe850ee04978c33053d302677f13
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\autoreframe\versionFilesize
5B
MD53accddf64b1dd03abeb9b0b3e5a7ba44
SHA1d1b76f3800b4ffa88b1062b60da950bacf4f54b0
SHA256d51e6ec94058554a84558a5b402ee6ef5fdf5455e35c902feda61cda8752943a
SHA5124106f83d3c1665aea668cb0e8473e2dddc6b3597eeff59bbc266fcfdb8ba9ee1146ec3a0c2788071f5ef53bec776a5984847705ebed757d240d9ec26a69ca5c4
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\depth_estimate\WM_DepthEstimate_CPU_Openvino_Fp16_1.0.0.modelFilesize
31.9MB
MD5c1b3b06f0b249cf4f29f4a32674c6bdc
SHA13c44c62d29780210d833b15bf3a6e8923fdfd1fd
SHA256fcdabc1358d97e17b4755b3859b669703820a5a36754ff9f77e26bd42e78ddee
SHA51256e4d2b9dbfa407d8f8b14d15908f790693da677f78dd7afcf20ab5aae68a905043951906fcb7381caf22a334fc14b8652d39d4fafb5c9dceba31be125d54bac
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\eye_landmarks\WM_EyeLandmarks_CPU_Online_Openvino_FP32_3.0.0.0.modelFilesize
408KB
MD5dc97d444329f11d12481f6b3ccbf866f
SHA1c6ccf0ba8f20edd6c8d784d55bd349c98ad8972e
SHA256268272c47132d073483f855794f92b9b5f7c599694adf99302a8d09a151785e9
SHA512c09fb2cd799a087ebf1eb7645f9a0d111ab57a3f471b0c3963206d86d8d1f703f4fad65e7839928951866078931ba8fc6c4c68e3ef7bd900ff012e5e533c0a04
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\eye_landmarks\versionFilesize
5B
MD5272f0a04b740763e0a29316bc4af89a4
SHA15515ad546a48c1ee47dda370ad728977e1e31518
SHA256c9163ff21f1f2b0390dc48bdda47179718f772f507a7cebceca59ce1a7129029
SHA512ee8adfaffb1d7bedd6e962476f76fe1aa2bc6bb9bc7c5a7cc81d4322543fd9ebd77bf0c2b5600749fb30e80a52a27e59a681d543d70487862b89f49e4d1cc25c
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\face_cluster\WM_FaceCluster_Openvino_v2.0.0.modelFilesize
3.8MB
MD55ede3150a2f7488195940b3c7dbabf6e
SHA1f8fd43a88063a42e58e543f9b56207ada3d1aada
SHA2566d4c5c44dc588a021deba8c991c90d697d05cdc3f9864e8f5242266123214801
SHA51244ddfdbbed10d6d35aa0dc8e244fc57e3f058dda2f802252eaab075ce316e72941fd335e4359acf5ba227a17ecd6a34131cc31804327da99848d3dabcd377643
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\face_cluster\versionFilesize
5B
MD5d233662f9c26d1a06118c93ef2fd1de9
SHA1f7ca6a21d278eb5ce64611aadbdb77ef1511d3dd
SHA256f22abd6773ab232869321ad4b1e47ac0c908febf4f3a2bd10c8066140f741261
SHA51271b5a4ccb7dee75dc5df15cce8a3aa7f242da2b3b1b0137bc9e1d861971edf84b89757ed811a541e278a0ab11aa26a33958da2104d17b9aa83323a03fc58f439
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\face_landmarks\WM_FaceLandmarks_CPU_Openvino_FP32_3.0.0.0.modelFilesize
1.8MB
MD5d75b20a18e14153b8cab5be628eb7a6e
SHA1e12e677480c846832c7665b5b913f4b45c28f2af
SHA256409e98e49c0a278b393b612cb4338b2d30439579c779dbee6db95110c20fed11
SHA512b284649d8d8845410eca03697e7b0580b64c97a3b554e24d8cd42deb9e58f595c8bddfd4cab33880f33c15b088a64a4ef34cba57b3ff6494b5d5400365fa4318
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\face_landmarks\versionFilesize
5B
MD53d4b11f6ee2a89fd5ace87c910cee04b
SHA16dd1f25f2a4f5c9c73793bed06929318969169c0
SHA256892bef45a1a5205bfddb7849303ee13093d77185b84931419c334a38bc035672
SHA5122a10e0dc8a8968d148cef7fbbe3bf8ca5a924dd2eecf25c69a08b866149dfb904f8bd3da680bbbeeff5c4c301247159d53b5971d1b1c6ba759c08ff914913882
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\face_pose_estimator\WM_FacePoseEstimator_Net_Binary_1.0.0.0.modelFilesize
120KB
MD5fed2917b75a219141c6026ca7da30349
SHA1f852b15a07c779c5e7da7dbe41c9bfe6241a8426
SHA2565e6d82e60dbe66ba34b44a5157f83172a115b3ff99f75187ae08c13c8a5b8e98
SHA51264053e513268c4877dede19d7d107bf86dcfce70241e7696114161db11bdbac17afb83fa7984438cdba73a8116689d2cbe21cd3bd8fd38b69d451041fc526cb3
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\face_visibility\WM_FaceVisibility_Online_Openvino_CPU_FP32_1.0.0.0.modelFilesize
1.8MB
MD55d2b07fb41ca89e4afde7dbd19ff40d8
SHA1ab8c63b2340c66731ed51b6a62f27c843a644dd0
SHA2564ec62fa883e00a3afa5335594c398ce7ef1e7ff08768ca2da0b2d4d894c35a09
SHA512fdedd255b9fc7f92915c71ae582511e3d97d8c4059bd402bf91ce2f76b40ee4d499b0eb30cc58b48fa3f1c1a3178788048b632864381bbf0e38be8cea2dfb575
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\facedetector\WM_FaceDetector_x86_Openvino_v1.0.0.0.modelFilesize
1.2MB
MD5ccfe0c0c80ed13eeac47413595881137
SHA119a0fc2cb4e01ef6d5a3ddc45255d47f1a1a5c36
SHA25659346887750aa3e16fdb79c702b0f185bc8216142cf5bc004256c39098e9c73c
SHA51290999dfd13f4a6efa70f003e0a41c4e705ee5457418887e6c38dd6e5766a359b5643996f661f1310be5e82c1a95e8cf7d3b412a261e8460dbdb2d74f2b0fce95
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\facedetector\versionFilesize
5B
MD55d36c29483386600ea4bf8921a417a46
SHA1d77590d37919716846277a4d8ee2e51fef66a9ef
SHA256ce0a2005da2b159fde33efc005d063470ccc2ccc54ffb702dfafb2c330285040
SHA5126a6dbd4fea68e24263233eb27a472d7aa6f8c531fefa50f06654980c94705b017cb6a657712b5d87c8499f5dc5d669329de2737ce6d22df3b96eaa495e0870f5
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\humansegmentation_effect\WM_EffectHumanSegment_X86_CPU_Openvino_Fp16_2.4.1.1.modelFilesize
1.7MB
MD51272392ee2a98086ff6c3981c0b99cf3
SHA1c6f3eabd02e161a31ddb7f544e7fe1f090101862
SHA25657507175c2286d674a1d06fcc4fa61e030b852023953960f073835dcea4e5901
SHA51288aeb9f54e9ac4fc84e5c99b919bbbcee41d8fb6ea4bbef516ccd2f0e034a1874296dab610fbfc0df262f7892455ee2b2fcb3947722464e5019e4892636f3710
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\humansegmentation_effect\versionFilesize
5B
MD506950f48c38665016e5def7ecd7b0045
SHA1cc005cc7de6351bdaa671675148c076564275a57
SHA256b3d093ffde5f9d8d1530cd57966760ffd2730bf73aa90d592d13a88663984dc4
SHA512f86d7f8bf1430ac1a7a9bdcea58e680c41c2f921221c995cec90c70dcf8040f77ef9c204f1bec41b4e65ba806632f5dc7769a241e2a97f274e34fe5919d2d650
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\humansegmentation_hair\WM_HumanSegmentHair_CPU_Openvino_Fp16_V4.0.8.modelFilesize
17.4MB
MD5cf9556a050d6318f74815bb9473a6d0c
SHA138e1f7a9bd0b78c4a34a2c66b81d7133494ecb38
SHA2569e121eac4448a4f0f5a3623a3b86871648c4bfbc328a67d3c4aa9b6548501c4c
SHA512ad997273d40c98cfc5fcda5f14b1f8afed6b04b46279826f167b014b9dee8afcdf576fceec58f08416e8df93a04aaced73866da91725351ff5db5894d2aa2094
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\humansegmentation_hair\versionFilesize
5B
MD56a1b4107815badbaae88384a7a2fb60b
SHA1516757a8fe4b8f49177c908105cac2b4f3f3615d
SHA2563aaed613a228f7a7b5413e91e1dc2aa307f0b1aba8eaba4f6033c2aa9b8c7eb4
SHA512bd6715398047d3f8f78a21bb2b1cd0e158ac6d7c48250fe36a18a0273a0c2745e174252cf976507de9934be373a0a2cdca667078e1f788e09793d29171e8833c
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\humansegmentation_highacc\WM_HumanSegmentHighAcc_CPU_Openvino_FP16_3.1.0.4.modelFilesize
6.9MB
MD58e381cd04e34b034cca47827e8c9f0d4
SHA16869f25b4678be51b490100f71ea2cc1bd867f32
SHA256aa6997c58298c62871dc3b646b8d6fc2feb6d0fd9cdd86b84165fabedbe0f791
SHA512cb7b937ac695791c6da0536fca8d24e5b49edc096615b0c5a815f52177512ca7558b06d1882ad15f261ff30064cc275bcfd86d42219db0e287d617a9c99ae9e0
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\humansegmentation_highacc\WM_HumanSegmentHighAcc_CPU_Openvino_INT8_3.1.0.5.modelFilesize
3.9MB
MD5ee154fe731e9fb303953b8bcbcd0c144
SHA1241eadd89461216a4a9971c1781f892b73847d2c
SHA256b919c3f1d4aeceb5eb5ca37723940a28b9596a800285ef5e6dde8615cfb7e29e
SHA5127f718d9c6dddcf67eb89d9d2e9eb99bf5ef38dc4fe5c96877efaba5432a2fcf8b7b67406126b95c5bdab3791d268980e0f7ce90653aa7c8ff19d169c6550428e
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\humansegmentation_highacc\versionFilesize
5B
MD533f71c749256e7c5d9213704dcf409e7
SHA1d1fd48333115227b181b4b132e5511e91d95bea5
SHA256b7f5bb4ad5872543b02944ca39a59415579bb0b693bbae55f340742fa21cc8ef
SHA512a49a5e65ad895aacc9cecf89b9e78cfc1fdc7b57f74031a5457a8759396cfac02ca7517f3c42f1a14a301e7cd00fc684c8e73088ad5c9c29e1b9a896831c0f7c
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\semantic_segmentation\WM_SemanticSegmentation_X86_Openvino_FP32_1.0.2.modelFilesize
6.6MB
MD58fa7d6e80c61775d854ae7ff228642ca
SHA1c711ef4784cee068b5904a82566b1083f43c30b1
SHA256c155c992fe27e6ff20a4ac0d5500c6c6787ea14b8ac5b70ddd70f18cd54f205a
SHA512dbb0283e831bee5e261ac0b5f6fe3fd14e553b725f5ba5da05385518e4735714fe6ee914061445fa6518aa9750aa5f12e4d9b5e5beab0f493895f67c2e19acf4
-
C:\ProgramData\Wondershare Filmora\VblProductData\VblExtension\Models\semantic_segmentation\versionFilesize
5B
MD51237637816a1ef8e3a33c1191d9dea66
SHA1e5906c31c05c50ae1bcfde5f3a47eee483bc23c9
SHA25620d2cb096d1ab41a4140246d12f07bf6b8cb743fd48122b72532c03d44c5c14a
SHA512e6bcf72302fdf2139b5f9d77dc0be3458daef8ad42b81842371dffb98307479a8a8e053eac8f27eea9cbfc47cb60248ab0fecd994bab3c2359c1a9d5dab508fe
-
C:\ProgramData\Wondershare Filmora\configs\ColorAnd3dLutPreset\default\60_color_Vignette_3\Data\is-EIITL.tmpFilesize
6KB
MD5dcd671190625a398bf5d36803950493f
SHA1487a60f7a7a8f914f27139706b3cb7a3b8295eb9
SHA2569fc8f2725a06712b9d9fedddeb343d3896bbc569115c37366535ddad5e637505
SHA512cb92bcfb86497a475d2156badba6331a348ec1c31097e78889418c272b93076e154e4e04b8692df6ea8d67025751b8f38a89823ca63fb0741e47cb33e94e09e5
-
C:\ProgramData\Wondershare\Wondershare Creative Center\AppInstallInfo\Filmora.iniFilesize
294B
MD58c36cc7255d5cfa8cbfad60d9c57d1f0
SHA1fd7699da35b455315a09b2d17905f1e1d2019100
SHA25626c8e98f9fbda223653a19e451e7818535cbacf22b650236858324bc271664fd
SHA512707e6b05670bae1aa1a28a0689537336365125777c5f228200ea11dcaf1b63d95195a381f88d8c2d53a0e2cfa5a262c14c9fc222323ed003a9f06af636abd01a
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015Filesize
70KB
MD549aebf8cbd62d92ac215b2923fb1b9f5
SHA11723be06719828dda65ad804298d0431f6aff976
SHA256b33efcb95235b98b48508e019afa4b7655e80cf071defabd8b2123fc8b29307f
SHA512bf86116b015fb56709516d686e168e7c9c68365136231cc51d0b6542ae95323a71d2c7acec84aad7dcecc2e410843f6d82a0a6d51b9acfc721a9c84fdd877b5b
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5f3e47f0480f7a1fed33779554795d93e
SHA15e98e4cbad4c946bcac21d845dd9ff43c0abc31e
SHA25631f83d0baf61ce43e91aae1166384b171398867283c6dc9eea449062f2dc6040
SHA5128b53d421497e08c3e316429096f7eacd501b2ef94d2ad537ebe5df5892b3a8c0fea3cc7eae7319590bd03e3c2444a41c22b40e5ef1db01d128cb19113cef4626
-
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\054b0ac2-1d4d-4317-a1e5-63ebefac9e3c.tmpFilesize
282KB
MD51a8e3067619853182ccfc34ed2401543
SHA10834aac111c1be49fc240029001b72643745a0d2
SHA25601e57f7bc76435ca76fd7b2d8fb1e50459ff57cd96a4001ba5a1281905d09489
SHA51251397e1afecae796b0a4da7d312e80d770ca63e85328db4cd8b21de13b6edd83ec1e0c0df560900143d689b0abb79b969d91a371d6f65fcf591ae7ca6d8987a4
-
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1Filesize
264KB
MD5f50f89a0a91564d0b8a211f8921aa7de
SHA1112403a17dd69d5b9018b8cede023cb3b54eab7d
SHA256b1e963d702392fb7224786e7d56d43973e9b9efd1b89c17814d7c558ffc0cdec
SHA512bf8cda48cf1ec4e73f0dd1d4fa5562af1836120214edb74957430cd3e4a2783e801fa3f4ed2afb375257caeed4abe958265237d6e0aacf35a9ede7a2e8898d58
-
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000007.dbtmpFilesize
16B
MD518e723571b00fb1694a3bad6c78e4054
SHA1afcc0ef32d46fe59e0483f9a3c891d3034d12f32
SHA2568af72f43857550b01eab1019335772b367a17a9884a7a759fdf4fe6f272b90aa
SHA51243bb0af7d3984012d2d67ca6b71f0201e5b948e6fe26a899641c4c6f066c59906d468ddf7f1df5ea5fa33c2bc5ea8219c0f2c82e0a5c365ad7581b898a8859e2
-
C:\Users\Admin\AppData\Local\Temp\Cab5BB7.tmpFilesize
65KB
MD5ac05d27423a85adc1622c714f2cb6184
SHA1b0fe2b1abddb97837ea0195be70ab2ff14d43198
SHA256c6456e12e5e53287a547af4103e0397cb9697e466cf75844312dc296d43d144d
SHA5126d0ef9050e41fbae680e0e59dd0f90b6ac7fea5579ef5708b69d5da33a0ece7e8b16574b58b17b64a34cc34a4ffc22b4a62c1ece61f36c4a11a0665e0536b90d
-
C:\Users\Admin\AppData\Local\Temp\Performance_47WQJutc1Z-j9NMKOr9NMA.lockFilesize
72B
MD5a22fe85c65d3b2c6fb7de958faffe23b
SHA14e12d3dfa08f76966278f60224113940f3211ec1
SHA256840592bd5fdac7bec31852acba8c10d9254a0532ded8e48a47d0a5a8e4947d06
SHA512588e4b42ef543839067698d6cd60f129514a08b3e5f45951eb1379342853d8deb8b3b7740edf6a97017cac75be26083bcaca4583d03cd27c3e147555238cf65c
-
C:\Users\Admin\AppData\Local\Temp\Tar98B8.tmpFilesize
171KB
MD59c0c641c06238516f27941aa1166d427
SHA164cd549fb8cf014fcd9312aa7a5b023847b6c977
SHA2564276af3669a141a59388bc56a87f6614d9a9bdddf560636c264219a7eb11256f
SHA512936ed0c0b0a7ff8e606b1cc4175a1f9b3699748ccbba1c3aff96203033d2e9edabf090e5148370df42fbfc4e31d7229493706ff24f19ff42ff7bef74a6baad06
-
C:\Users\Admin\AppData\Local\Temp\Tar9A44.tmpFilesize
181KB
MD54ea6026cf93ec6338144661bf1202cd1
SHA1a1dec9044f750ad887935a01430bf49322fbdcb7
SHA2568efbc21559ef8b1bcf526800d8070baad42474ce7198e26fa771dbb41a76b1d8
SHA5126c7e0980e39aacf4c3689802353f464a08cd17753bd210ee997e5f2a455deb4f287a9ef74d84579dbde49bc96213cd2b8b247723919c412ea980aa6e6bfe218b
-
C:\Users\Admin\AppData\Local\Temp\VWL64BC.tmpFilesize
392B
MD5587043436b630b7cafff5505a5d6cebc
SHA1d189703757fdc75f70f27ed030a33e07945cc9c2
SHA2565caec23deef9ce446cd255e67eb98b7f9839ff7515d89c788673e6d45d336b82
SHA512fd5bdf4b7806761f95ef3f4fab146f96794500b142f1b80eeff40a85f64ab405db261498cb5fd0bc19a0672ca25747f108d1fb6f184eef61cd6acb8ecfa98784
-
C:\Users\Admin\AppData\Local\Temp\Wondershare\WAE\wsWAE.logFilesize
2KB
MD5017abadd095461d407f4d41e96557824
SHA12b4fd4c29811c418fd455aeaf5d128b25efcac17
SHA256fef88dc28a43bac443e72f276d9a5fb33f176f9cdb7d618ba8045a17483a6788
SHA512b9ffbb0ceeaa04e936d69e27108956d11d60b5b3c366447ac11762604429f7b1f3fc10a5f0c18883312f54d6e03522f47ba9c63841568b6568c1c147bdfcafb4
-
C:\Users\Admin\AppData\Local\Temp\Wondershare\WAE\wsWAE.logFilesize
4KB
MD57cd108e9eb9bb9ea40564194f3f6ac2a
SHA1a6d8c2025b84b3f60193e1eb5d94fe5844541308
SHA256c15f89d10437f4fe633432a576850b2ba49a527699032f15133e3fdc6e72fc84
SHA51287fcabec13704cdf1ab12b34ac84119f9d0f94682422ef055e290d858d10dc235e0d83c6f100efa1f34620dc2a878be949eacc64fd16b88ee37ed861cf772912
-
C:\Users\Admin\AppData\Local\Temp\is-71EP8.tmp\_isetup\_shfoldr.dllFilesize
22KB
MD592dc6ef532fbb4a5c3201469a5b5eb63
SHA13e89ff837147c16b4e41c30d6c796374e0b8e62c
SHA2569884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
SHA5129908e573921d5dbc3454a1c0a6c969ab8a81cc2e8b5385391d46b1a738fb06a76aa3282e0e58d0d2ffa6f27c85668cd5178e1500b8a39b1bbae04366ae6a86d3
-
C:\Users\Admin\AppData\Local\Temp\is-AQ2PC.tmp\WSHelper.iniFilesize
4KB
MD5c3d37313bf465f6145bb6f9bd845622e
SHA11a27da4300e997e07da73f2916483862f9fe1fa4
SHA2561b74775c8d88a46c6f1727029a4acbda6dd9cd1bf5298a3746ce104e0da8f8b6
SHA5124e92ec23d618e8ef2559be1c5d2cb243e2eb074aad86ffb338e3584806953efdd22856847a35bdfee1aa77756dc2b34f526777bd6fedaf5e4b982391d31ad2d6
-
C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\Customization.xmlFilesize
821KB
MD546fc33081d7adf7f1bb77c1220f4d49d
SHA1d2f2c30326a94065b314acb158f0418790b63561
SHA256b6bdfb2df2f39fcfad73b23aa207db8de17b410c2cc5b856405f28ab4ef2d326
SHA51279fc873ad7a23c7636f11ce79c27b92468ca38c18dcb140dd47fc7bc92e7aa8260c33099952e6e840c23512785ba0054180b718f72cb249039aec70e24c7565a
-
C:\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\vcredist_x64.exeFilesize
5.0MB
MD53abb5efe9ad4d9728406a1a90a47575f
SHA15da9a064b1fc505beef0d06e7d10baf8e5d92d09
SHA2567451ba5c6c05347789717561e871a303a4d171850790a3cdc99d4ddbf07e320b
SHA512ab08687b7eb6e87d6daaccb96a6add9b04c32c430e989aae7ef86fd18752ea0dc8646ac226343d7f09bd74bd3ff45d680e3539b1dec40fffc69d4fd0b1c6aea7
-
C:\Users\Admin\AppData\Local\Temp\wsduilib.logFilesize
2KB
MD56f7d75dbdffe51a252a5462e291b9887
SHA1da827d99f4251a37396e2e7e482652b53021971e
SHA256011f89e7a6708288bdff28431666c865705f23b2e7bc141b067fc453f0460b04
SHA512e41bc6a1e711107433c57aae87cb26ff44eabbd69a86db40b3df74ba99b5840649dde1a67fd51c307d21f831094f92773aea84c13064d508702cd929fd3514f1
-
C:\Users\Admin\AppData\Local\Temp\wsduilib.logFilesize
4KB
MD5ff6937b01964599c9c5a6af382ba2551
SHA1d826870b1740f3c5c2770120cb079d6995c45df0
SHA2561f63e092f870c6c6d01234616b9e4092df75bf6965baed16d7e2050cafb0c706
SHA512111588df8a7279abe4e95fcc39ce10385cf7841d3130e21a3c2ca265610852136c0446520cd2399c531a7d0020aa581a9cc89a4c15eaf3e6d2a3f62766b68b91
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\CefViewWing.exeFilesize
716KB
MD57f1acae0d3eab934d06010b1d286ff80
SHA1323dcbd9d0ec81547aefb7b0cce9727b59036801
SHA2564b33c13fec014d0835e4385a6ba466101be8186fd7fa4ed792bb79b67735bfde
SHA512ef0ed0ebd870470fb1a73cdc7f044af8a2cf4e7251e6d2e58a7e7faf3ba3f3425b96d4250ab4d83a86b822ca4da39233162a3b108a1dd148dfa2f4ac844b6a99
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\Customization.xmlFilesize
776KB
MD5a2e653f2878222f246687b7d42334c0a
SHA1b6583de184c969097d8169d2c73063f69bfd583d
SHA256bec04f9ac33b9239c3ea9bb3a3e4a88b6e4401825d70cb0e7eb9d88c104affcb
SHA512843aec694a33cd7de19cc0b5aa147f664e34a7750fb4cb3be41165b1b2bb96d084897cefee45f891c64c3ad86cdaec78a0270c9d5fada1ebcddf2485d1527424
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\DataCollection.iniFilesize
553B
MD5dda75d86df3d791053ff261116341016
SHA18e64e0ae2312429fbc5229a20916796fccc4433a
SHA25650da8c03abfc4d9e984d04ce6f64a40157f913d946522309784302d7f12f8fb7
SHA51236dbac5b172b0f9c6f13e7f6d4d8034a3d119a51132c1df096576d68c8551df9825bce550d3f5b385b44be4a014e71aac6491dcd64e6cc263d2aa1e277f9be4e
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationKeyFrame\{08E343EF-8274-459e-86D0-CDE548615C94}\is-DE8CT.tmpFilesize
3KB
MD5d58991c27295734cc22c7bfd8035ac68
SHA1a7881c00289d62679d310d47c565469efb5dd572
SHA256db18149432839d834ca639cfee32aa79946cb9481f3a246dfe2d918c292e8a8d
SHA512cafe9721eb9463c69ed1bebef842909073acd837d38cff9930e150b86840f5b481b890f586ba27387c4209b25e93d3d345e7ae9e54302850f3fb3cfabbe0e3a5
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationKeyFrame\{1F2849C2-F6DF-4c6d-885F-7EA49873B135}\is-J0E37.tmpFilesize
3KB
MD55154b1be58f359c7070efea2ab187921
SHA15e99762b9785deda41b62c7c69c93d483d5606c4
SHA256acdd32014990d0168b11872ede470fa3c76409d3ad9346335923a1c8fa32688d
SHA51233fcd68f2e8eeb0accaef2032e0282c14a941cd9943863c06ed6285555ce442f87204c2b8d97a41b817e54028b627042e96c6c6aeb830a03d32f45a48b97e44f
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationKeyFrame\{43E73D69-FF43-40a8-95CA-30FF96100407}\is-Q1MBK.tmpFilesize
3KB
MD591db63999cd83d10f8d929bcc7aee581
SHA1fae2546ca2e0056230e426a3786d065c6f53d6c2
SHA256718203a5f176e5770e9184a8617ee2b9e8eaec6f35bb317ff903c03061d85ac0
SHA51216d655b44edbefa382dba336e316eafb51e4f42d57baac41999a435a365d9c63e846ea915e64927edda12456e3d765fb61dc70ef58ad8c7334671f32763c6cbd
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationKeyFrame\{6E71FDB5-7BAA-4d15-949A-1F8F23682B75}\is-IDB0S.tmpFilesize
3KB
MD5145e45393462489d5a13afb3dccf20d5
SHA120cb63e614cabfdf1fa04b3d3e80781234b64afb
SHA25667bfa06df70bacfdac13b689299141a494d953323753071ea4dd9c1986b59dcc
SHA512a0b457a3391064944a1154605a9f4ec19120ecd563aeb8852cc1a123a24dd029e6179da8216e315cb23f5312ec4abf4098efe73dbedc17aa6cbbcbc77b295a3d
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationKeyFrame\{73F5B4FA-B137-440b-9A86-F31790F3566A}\is-VV7UT.tmpFilesize
3KB
MD53bd971ab8332224483b55d248988ce0b
SHA1ea2616829cf7161666923fba363329936c60bf0e
SHA2560f10377e57242f01afc0c397077d1942255a40cc9b9807c69740ecbe3315ec97
SHA5122af8bf142a70a17fc1692dda318b6c4b331708a98a47a0eebd0d6eb488ecb5cad74d699392ced7588a31b528da28eefa786cfe1caac80049d10eea97d340180f
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationKeyFrame\{A878EC0E-7104-4ded-AD3C-946BE84412C1}\is-BTS0V.tmpFilesize
3KB
MD58811a398a6e3c204175834da39fdea7f
SHA100d5004a4a3a8c62b024878b8e54636097d2282f
SHA2564017b678c8ac1715d9c875f5cf327e7824a45fd313dbe32ca0a0a80175b1ca81
SHA5122e83a9ff39326768a1d52615b248b788c00096a080741a0807283f0ed90bf559c56c8cee652f20b31ad9d2bb37cca832e008b2d57f09103e28cae0af030c6cb2
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationKeyFrame\{B43FD11A-F689-40db-9B05-D34A89ABDF5F}\is-B10FH.tmpFilesize
5KB
MD5191be2be8e00147569f5f8ed2bcfd934
SHA1520a0849f8d8829b7b7ae64eebc6164ec09f7895
SHA25610bc1e6ba0ead119ae9bf8bb61f7e96154472684ecd81bf1e59b8cc79337d92f
SHA5126723b0194d3a1011ee8aed89facaa87077329b4bada7648909f9e6516e4d9994c2d3485b3a001443b92d02d9fe1286d191203df6959a6063c1938c83133bb851
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationKeyFrame\{B62F36A8-847C-4423-A95A-5C74E22F7860}\is-F62U9.tmpFilesize
3KB
MD5b08c5153d5fc800fbcf08db0d8aa0678
SHA1d5f545aee6262a17186a5c2a8265b0324eb84ded
SHA256f0fc449b70d9c653e87c7da9be94ba1fb01966fe8cdd229139703461a4e9185d
SHA512c9e376215e45fa9d55700ab4cbd2a608ffe5d11ab920f818a1483fb49a586484e9bc06f35f12f667588641b48fa093db65eebdfa4350d41ddcf6f44507d6dc30
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationKeyFrame\{BFC167D0-6AB4-41e6-9BF4-ECB740B9A52D}\is-FNTQ7.tmpFilesize
3KB
MD5ac268d2e7f78e32535405dbdc3aa5b17
SHA1acc562bc9d5e2506a77d05f58b8c554e2ea4384e
SHA2564d21ec65760a3413553d84066b75855cce8290a9616be04b76ff4fc01c0eebfd
SHA5123f124471aac78c0c7db444e79b0e38ceebc38f51084b7bc2e8acba7969ba59c6c546f8a3b90569a037c4e89603bfb7b56d42a64e1b4de51741fdc486c2a7069a
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{07D46F93-A963-4a48-AA1D-53EC456DA91D}\is-7IHST.tmpFilesize
463B
MD5f90ba124c0b32f3fa9c57c95c6bac526
SHA1637b016c721e8195d44cac809ead80faa1b0129a
SHA25622f849a216519f55cf49e794c73970c18a0e5e9a0be621ec5a905c1d36f21ef8
SHA5124ff95ebce8d4c327b85b167e5e2e9b6778e2354acd11a4319067d6534139ac9feef68e5541423ebba91c3a405dc433ee117d7cb81be2110075bfdbeb092db3ef
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{0C02B80B-9B8E-471a-B4E1-076949A17F96}\is-L4AT3.tmpFilesize
176B
MD59fbdc0abc4fb020660705f34a456250a
SHA144ec01ae282bcff52363e7855a0bf0a026fd61ba
SHA25647a11bcda5f09483e28fa13f447232b5be6a9b4db1f80d26586811adf95bdd2b
SHA512c267655ebf885ea8621977a85d1ae2b4a0a4a6ad75faf29d8fd83fb747f9b62ac35c0e30bf3eccbed2bf0fa881ef1e5ad5c1c28107453f133cfa8cce4a134368
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{0FD53C8E-D963-4e15-B905-9D278CE07FB2}\is-DGCM7.tmpFilesize
187B
MD523b92f39f2607f79d7ea97625506f85a
SHA117a88fc2a5c3041af8db19ab94a190d4f8982d31
SHA256cd1f35a72e046cc040c83fee98e5e48854c446f5669b3e41ba300ac13e34e799
SHA512ee626fd056fc44548b104ea3372051abdc578ed3881a17fb80d8b8a2c355808b55aa8a43808e40d0b21c6ef1d8083e241511b872c88f1a65239d3f6c214b9412
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{131C9392-CFC2-474c-AF2F-DA3246222949}\is-T66HU.tmpFilesize
187B
MD524fc1707827119c10c3a08fa176e5b63
SHA11bd1941b73bfbbea1b8c956bf18066a45ae2e46c
SHA256257a8a4d184fe0ff5b1de511af9e93d866058d125f462dcfcd421a8788ff08f0
SHA512f6d01d7d2ebb569228dfab22013b51ebdc8cbabca08c0d1046e6180deaa812e6eb96a8d7898137a3a2b4c3d8dc2248b083ef0e2f0431078b741257b6c85bc752
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{139D8383-91B0-4238-BF61-EE3DBC443A51}\is-05L8K.tmpFilesize
720B
MD5ccd74445595153f466395f427322ce73
SHA1d4965ed1ae4e389ac2e8c89c544d90febf7108be
SHA2560af1f6ef107fcdf46391851d95cb587e015e51ff2098867bbc77803485fdc0e4
SHA5129d3bb84bb9b02f5eef2fae1c98ef89b7ffaa4007ff56f165e7d4aa41de5a10fe0c1b32e81040e46028dafb94cff8ce56ae99b02988c31f1aa0e832c701c406e1
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{22A34B2E-ED23-4897-A06A-03ACD486A246}\is-TGG3T.tmpFilesize
181B
MD55a56e8f5e5713a5344f3eb371d258c7a
SHA1710c8f9c74c6390c8514e7fb3f0d8a24d567d0ec
SHA256ebfb0ae7cae00a0030947874d7ea2ea019eb80d24da1d4441b35259d6feb6642
SHA5123deff82629fb7c9b0e0ae92ea69c1677aa2f3ab21c62837c315bc6073f71f8a051532558f2774a0f30c1388564861dd2bedad6c6176b916a62bd3adb609d5890
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{25B9419C-8ACC-4526-9E34-DADB82EFE76C}\is-6HJC7.tmpFilesize
720B
MD517f65dfc0903268a458a9143458c2cc7
SHA18bc0ae10e00a3b61f133fca2ac154559945a9520
SHA2569c3bbcb6dc67f82966bd1be2c742c4f0e989e339e13ecff035590d3db342dbee
SHA5128bdc1ffb878565762a455c46a3da6a9ee5f62d27b8830aa550f748471279c16c11277343ee0468888d74b57758f48d0a10aa4713cc6f516c2ca5f62384b9f98c
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{2D761D56-F30C-4ffc-A4F2-6FEC74135367}\is-RLJ2O.tmpFilesize
460B
MD5d0c578c825a36bf95aac25ac827ef1c4
SHA1ac611a8d6d70a97c9b4513d3cec93057e952b766
SHA256228b38006999f3de0a0a06e7b2bbd9f41d4a99deff6c630d80625f5b660f616c
SHA5126b14d901b80dc8e5dc2aff55967e8ae4853183b5d665a8488351e711645c220f9a06c72564d971053e4bd10958a3937755da378a756e5695699e74bb407fb492
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{38B700C8-1C4F-475c-A85B-2C6B3A32AE81}\is-E60LT.tmpFilesize
176B
MD5ab46c75c62d6876663289968055b77fd
SHA12ef4ef01fe5b4385a5e90ece4478e2dcd1d22f0d
SHA256c79260fa82ee6bcb6912268dee459c76d4ca1870cdd9cf53eac0705c439d69fc
SHA5124545bc061247090d7ab8c51e9f81065f1fa39e8980741f48008d2ae5cd21710c27da922901a279ad1d1a58b3c3ecf51f356937814c6f33ac78bf8e7991f52dee
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{3B33C7F0-2A40-4909-9701-1FFDDFB45DC7}\is-QR615.tmpFilesize
186B
MD5f0250b1cef9e6ac2b1e26f674a2680a4
SHA1e65a2b6579d77d4822fd8f47ac019595668249c3
SHA2563dcecf11effbeb47beadb97e2b28523fcca094e2e7f731231a18652478592f78
SHA5124fae30a82d263f05cea9aa17911843ef1f5991e23d582ac2a44a890d355a572b0a8a16ebc93b797892f7fbd08afc06c23712d70544750e4eb1fa140a00ec93c7
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{3EA4BC06-1115-44a1-A272-4A3C99F36D38}\is-ET7IL.tmpFilesize
186B
MD549aef57fea642c19b4ed809db20dc969
SHA1518c518b2f1b6828a5e7bbc0d1a47988ed0c146c
SHA256a6579cd384374ead981f136c7cb79086611e1474b7445f591df745ac01ea9e9b
SHA5120a6ad468db9d9ddb96002df5d7b28f5ea077685327e600c041b94cfc5514a2883dfe1f70e0088f0730f00760cf1da3b45c4eb0f59c978751f1494b0f985c833d
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{40B11ADC-F655-4dde-8153-C7D22164C0AA}\is-HPMNB.tmpFilesize
721B
MD5e458f087de382120c02ed2acdd276b47
SHA1387b09e19c042e2dd147512cebe96bd3d72c86d6
SHA256938a251b2c8ab726a5999fc2d79df8c75fb5552c99712fc3d766f7ac9b75fe96
SHA51270bd3a4b8fb9ee632b534af76191142a2f57d7b0a92de39e89a3cc662ae26decb446042c6b4bc0ecde905c18d2ff16d98f94c718a7f2b1d9931c821addcc2826
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{5090BB3C-1DA9-487c-9F3D-41DCCE0179D8}\is-V0C18.tmpFilesize
724B
MD5604cf136b1cabd7ca520680f6db02f26
SHA1440a45b84596ca7e47091ac068d8c81ebcf2b157
SHA25609fe2939e7a5db91e58772b09fce0fbcc95600c6b0bd0e29aaa1ad3fa6bda4e5
SHA51276b8ac92c62a3bb1c9bfae08ad84fdfe6d436cd38f6209e6881bc98129767075ecd66662766d539c0a58b3c4670e9b423b976f5e072fbb14348750127884d06e
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{580775C8-B035-4fcd-92D3-120B5ADEFA3D}\is-L79BC.tmpFilesize
155B
MD5a74c2680e92c3d2c45c7082f075bb6dd
SHA14641180a286c2e8757ac1688be070613d702549e
SHA256018de2813cb719e5c665898373b9f077e99e4acfb5becef7a67a3e3a7c7c2dfd
SHA512cae42e618d2aa95f1e08e0988ba6e2e98bcd38867cf5095aa0a21a708b9dc4f9a8de745cf5d384655bf37894b0f2d4ae0c1e9ce5f10fed3e8749507423873df7
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{7545C97E-229D-4c5c-9599-74B44DBE987B}\is-VORBT.tmpFilesize
178B
MD598855ee1aba351cbea699de918a25442
SHA11902dfd6df73db93c323f8263d9d4cf140f9841e
SHA2569d753be7838dc3cd77e35b8e340c0429d88b624b411d577704c81d2712d11260
SHA512969c976049b178dc0482f0f16f1129714830ba4675b7d332d60755d7565f4a26598d44445e556b05b65e85e2f6ab4ae07f77ac060309b58d9efb53028a2ac2fa
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{7883CBAC-C937-4924-A771-6607A10DC07E}\is-09OF8.tmpFilesize
180B
MD542278661902692fdc012ef1ecdc01574
SHA18efc065fb470ae91d38364cb39efd008c0a086eb
SHA25631e6edba561a815332ad57c883531bc60c3b0a37174bf4b404f84c2cf08be62b
SHA51251711295867d5e7fd76ccbcb7bd40e99c63d3f963fa8429fe405f1904a04f001d17569ab8ec351ea6edb30b70dba5613d7a204b9c71b7ab0ad8cc33c90b63f28
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{78B71349-3F0D-4e65-8236-D74C51E06F20}\is-55BAK.tmpFilesize
185B
MD51e08a82241a5bd8a4827d1e4830db66e
SHA1ee33c7d12617c991082aad8d40f935660ae69fe2
SHA256c0e4f6b6f2e0901b60d4926684ea3c4990d7cdb168bd2b0fd868e320823edc52
SHA5121f6a1471aef2c75db604d7d9f01138416b97d968e21c31f120bf1dfe664e8726047313d2252f503f9e791bd5503317ab7f712c597468ada4dbd40158b16b9a88
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{7CEB20EB-2FA9-4889-80B1-9596EED5E728}\is-VU2FG.tmpFilesize
180B
MD518ea1865346b95eda61ba88147214757
SHA189f3486b3ed69b516feccc86d8db9cf3d887666d
SHA2565f4cc9200bb0d4a523494d0baef657daeed70d85f6e6cd1e74327e4d9fbc0f4d
SHA512d7d0c187b51397fd5a96db2fdebc441fbaa34dd3b621b8936758b41d384bdfd4d2734328d763e354931786a90ab1404c2720591b3ed3a8638d9ecf5b1153fe53
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{802E2DDE-CC59-4c15-BE02-0A0EE220AE00}\is-SVFLL.tmpFilesize
968B
MD5afcaa2b44f3a7c14917467b1ab06e8cf
SHA1937fe40714cc7b7af2b4271597be4d6d21b36ff4
SHA2567fd7f9608caae2411d66faf7cab8fc53d0028fde01e9e18ede04e0cbf2a42649
SHA51298cae82871774518a5b314b209dfa0a5e4f93aafda5175a042e458c82596cfd858aaf1ae84e2cd46c3081475b488e4374cd22acf2429e49b19ccf49d36b88d16
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{84A6867F-2525-4a8b-8313-76B48B9C4C1E}\is-9R6PA.tmpFilesize
175B
MD5fda6dd8faabda7ec70cf810b5a5ec778
SHA105964dd30abec902267c35697c4935fff2df377f
SHA2567beb7633a738b76c9a5e0fc57469445b7208554cab953b2b664bef21c5557983
SHA5127b22150390ef092c7c14af352ee2e19607c73af8fa4ab95a5e911584ceed162509c4717a741d1647f36c0b414eac3dcb9f569338392d0b2cdf8f8c42390dcf62
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{8721CAC1-FBD6-4062-940D-302C4994D6A4}\is-UVQLL.tmpFilesize
182B
MD5b417a875fb5b9fe5a050609bcddb0cec
SHA16a0a1bff5bc17eb9b4115ce412ad13860a6baada
SHA256c0b33107f7038274a693031468041124e5c545e110286b6c559f12b23af2fb07
SHA512fed88e1beb4d12121b9fef949674629dee06f431df08f925d628b2d58ab9848526588fad31beb9201107d1cec10b4fcd71dbbd9bde78e2bfc3ff6789bf0440e0
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{883CC73C-FF2B-43b9-B52F-912F7FB914BF}\is-VFVNV.tmpFilesize
185B
MD579d33e835fa073af19377fe28944f2b2
SHA167ee8ddef0bac8820253d74c44820097c7e34cb5
SHA25618aa8eea2a538f5a84fa0184fea6bdcc8b5778581c6d4824ccae4ffeeacfef3f
SHA51292498bb256a846b04df330654ec66ae12676db1cefe17350098f963d21b8aa783f5d1eae35bb128ff8c4811feccb64ab198e680a205288a52aa108ed72cdf64a
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{93E3B5E9-CAEF-494c-B736-DC9749337720}\is-RFQEU.tmpFilesize
179B
MD500be5c7f341057f858bf90b769d0ffcd
SHA184bf6f4bed34fefb30e7118337a83c52e45768bc
SHA2567f5d80199e595f625f5c6d419afe5c31b2141a192157580aa0340c227a39b084
SHA51208eb932090c9ff1e46f45835a45e0c2da519fb6b749d412c651fdfd1bfbb758a6bd882dc13230300ba3b482e2b1a0b460077f4df9941e42cfeee239e34c8235c
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{99C431D2-E9A2-41d1-AEF8-0425CCC13B82}\is-J3PO4.tmpFilesize
176B
MD566d65175de6e0eb5c387b3ffa5d5fcf0
SHA10c21269e57ba9a3856b6e0ce2cde815e6323b18f
SHA256d5f188caa4efcf3a1301fd58ff88a94bdd1c2c627a6e6fbcb5b5b5c934deb8c4
SHA5127e250a1ee81d1b735d715deebf68e49978be4f72b13767a9bb3215224b5d0c0b18bb5ae3952c6d6a37d774419279170355bcb920aa40becc7b999852b247986f
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{9AFBFBD3-30BF-4dc2-A28B-84434BB8D954}\is-RKIBR.tmpFilesize
978B
MD581fd6218f2b41fdbeed142d475330800
SHA1e7585edece46e786238f1bb812c3550ecd47f8c8
SHA25627b1f0ba010213d6e23337777b2f88a98ee166599f602e556018e7d06f0e8256
SHA51202e30b65e5c044bd01e5f83c67dec64cc9b991eac91196fd2df2e3a2bf2d8779be8571cd3e490399aa290352bec697ad1b36c80aa2b8d69a9840440734365f42
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{9B404780-7E9E-4b3f-B26D-09077053687B}\is-T53Q9.tmpFilesize
179B
MD59a12efdc42d70973fa35a5d4bf179004
SHA1b4c82d0bce15708742d2d3d508ffe24628854084
SHA25626a5bf6fb487a580835db9ae7219f7dc48959aa8c73ca851aa2df37f541c3de1
SHA51237a0e9e5bdefcc4eb5ca69a4d91614a6d47f47210548666c4635fec65e417ffc531ac60d0359f19aa05cfb278cb282370786e81cec9af9e4203279544643bea5
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{ABD0149B-5029-496a-AC67-0C152E296FEB}\is-8D877.tmpFilesize
184B
MD58f1e50a3e5e839daa477e7174edbff6d
SHA1bac764f2ecf98903880f68efa393ef66f834d439
SHA25650fb26bc20bc9e332ddc8fec698a4b1588c9dc796612c25297f14cd63e290ece
SHA512119d8d0c3021cace3ff37511849ea7c843488cce4310e3a92d155e467be40edd63cd2b2ba7ac8de993a98461adfb53614759ae644909ca702a213683caa928f0
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{B2104C03-69BF-4f9e-9FD0-38803ABB8904}\is-SFEB0.tmpFilesize
175B
MD5cb0126d9ec0c08f636799e27596245ee
SHA13412d968b7cd3af6542a1d2732f7229c314dfa09
SHA256aadc9aa2f26d299d387282d5545538f6f21a1e158ffefb7fb7a82cd949d8c627
SHA512b07a741af21f7cc6a060a2a14ee022a5622fc8823291a6b00657025fc6c65b1aa4705819ed71fb5c433aa18bf68c59603701fb0360b34516c797b29b53a19f0d
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\AnimationNew\{B8315CBF-F926-4e24-963E-49DA16EFF575}\is-5Q08N.tmpFilesize
5KB
MD5a628d31f4e170c10a18b1b6b742fe022
SHA1327bc567294ad02d79cf557371590b992b53e12f
SHA2564ce8280d23d7531daebd4236b7fc48ff086d65fbefb5fe9f8413655504f08756
SHA512b38cfda28ae75a939f12da7f3ebd2ef58d00a82008e6c558729e392b264e4e036d953234937794a66e0c5d0e4ae4d81d6c4c0a56f25c58a13f4ec78e02be29af
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\Category\zh-hk\is-VOGLN.tmpFilesize
188KB
MD5f1a8fda71fe18e8a3adda80730a13c44
SHA1a3cf5630a92c065b20040bb86b1c8d543c07f31e
SHA256f6d2d2a31ceb641327a5f27878f1272a60c36c802c9161d58fbec84ccf2288c7
SHA5126d97fee70ed2d29168dbdaacc9ed61d85fe2e7cb1929ff7bc3820fbc5a11d425db4e696f852cc1e11a6a38416e9b01b7afc90942bd768b9a607371cdeadbc730
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\ColorAnd3dLutPreset\CubeLUTFiles\is-5JTE1.tmpFilesize
896KB
MD577df990a40dc5b531ea01f37d8c5b612
SHA1592c343ab052a18dcd858b5ce5d38f6c62cd4784
SHA2562cde1809d3f8f02059b9b0c992d3951f0fd8b3810a664060270457f465c18f3f
SHA512110641dbda18e0a048b24014ef340a73e5ea9a96808d804949dafe690302cf1b04e49bad669df88219af1e7ac84dc793440e05c3cea4d997174ca4dcf00a50b9
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\ColorAnd3dLutPreset\CubeLUTFiles\is-CMGNA.tmpFilesize
896KB
MD5270bfcea522785fc8748c5e7a2d611d0
SHA1de031aaa778eed12226b7d69fe773da0bbab05fc
SHA256a7f775394b2234981539a0640df966fc2ba7fb3bed03ce2b5c597b48dc2c3334
SHA51294e696666db24307cddb229457fb0069c8ed7e95252c73d0d8a7fe2bdee93537737617ab9e55dcd2b79cea1649d018c98128b1824afdb3b6bf7ae551baa13231
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\MaskPreset\default\is-1CGB2.tmpFilesize
885B
MD50d3a178a7dfc0113bbd86b03413b139f
SHA118d7c99369693a1c881910547e89b37cf14f621a
SHA2560552b6f130cd03811054694e7a1c44391b20dcaca9f4713307b79a7f14ea177d
SHA5127ef0a5404ccfa6275e4a314a2877bd393c881b4a468b9b525320c7adfa0a22dd7eedede39b5dde0afb39026b94266e7c9f5772e43d8abae4da7685d0281b04e5
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\MaskPreset\default\is-5HE9T.tmpFilesize
827B
MD5b7f96841a101ebf4eb1e92f4f9e0b56f
SHA14115682330b9adce64c0d51d72f97a572ad4e23e
SHA256cd8942c9e4bf1b8a9c1353daddc6121839c27970cf4ade4e571f49ee2ef58510
SHA5126c1b044358f9f25801869d7379680514b610e437cedc00bb873dd2969c08dd2fa6578cda5d48e7c5917cb84d503127e45105c19e308723455a19ee9a3b8cce73
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\MaskPreset\default\is-A2L9J.tmpFilesize
814B
MD55aece71fa8e6c30c85120aceb9af2a92
SHA1de019170b2ddfcaf8efc15bb8ad8550833ea3a6d
SHA256f061d3e7feedd1c0490bd3047c7d8069a3f140cdf9aeac835efbdab2fd066979
SHA51291185e4c6442a840a1f6940f56e6bbe7f4c0126f5d65211cf95e2733ef119a6982a6ad89f2aaa059ec8a32086869ff4e73b39fec7f2ee8019b32c5efae27efd4
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\MaskPreset\default\is-BLPG6.tmpFilesize
1KB
MD58f3460e42b2f906d23cb1286d2934d2e
SHA1938bbf8f6e7e113ff08f275a793ffcfecefb6192
SHA2562ed74c9367c2ab9ded341ee48ae7e51f3e1eeda346282fc5a6254594cfa36847
SHA51220c17c1d4b438b553cac8e2c3e2766149da9093951855c5bc10c2bf91668131c3e77f92b2f0ef23b28688f1b8de697148c7c5a0733a3a14028ddb1c5ad204dd4
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\MaskPreset\default\is-CVMQD.tmpFilesize
733B
MD57ea3444ce3ffe321150566fba574e6b7
SHA195b13d6ff6cbb98ceb6c06a442f71ae8d21ff008
SHA256ee9237be3e488f7efc370be769a4dff79ec177b80aba16a47864e6cecbd6489c
SHA512fc05e99512fccc0ba257d70513d99d679d076b90d91d22413f25889ec65cec4e0b79eefbe5fd02cafc866dfd767ffe737c01ba4301ac8f469b1951078c7e4baf
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\MaskPreset\default\is-JBB0A.tmpFilesize
900B
MD5a6b806a353e8067493bfc1b43d5c58f6
SHA1095dd740becca6bbbcc1212feed0f2acdadbb345
SHA2562b3fccb31ebee6e8a6aa40e3bfd980f0ac2212d87110c19e7b5fcf64ca65a227
SHA5121cd983aee9c28c2a1ade85dd8ebb407c63eaeca854b2e2487ed1a6daab896b688a490a17fd5a36b3f808d96a682871917fd229c6ec575d53f258ca8c8894d651
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\MaskPreset\default\is-NLQRP.tmpFilesize
758B
MD56cf60b63823967351f724088992ba6c5
SHA1db4b9e8fc6bef4aa7f8b6de2745e539751655189
SHA256b2823fe418b5c8e90760eebb6833b8e3da90358ce8c0610af39c8e1eaef65177
SHA512de6553b9ce0f75ae1f4ecda32130a5b67d29ae2ef402ad5bfa9020036b6315c6e39ff3f18ab6a5f93bb3e5739255d9ee465a3910941581764dcc9fbbce2d5527
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\MaskPreset\default\is-RNN47.tmpFilesize
549B
MD5a45a02c90b524546eb4b43a6ccbe4ed4
SHA198fd9d9d2589ec615a365e820d92e64e0f6a2317
SHA256dd7acc96fa45dc4493c324d845ca6cc6ca56e706e7e751d6f579d167930a205f
SHA5127aff1650b6aa304bc3ccaa121b5ddbe73b7101d594831ca35ea39f1a108a96e46c5d248ebf3891f87b5ba80c3e6b5575b82e26d8028c5f0c3f6ff900b0431ba8
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\MaskPreset\default\is-VBJKP.tmpFilesize
103B
MD595b9be5c71608929839f604aa6490c6d
SHA1f00f17f20df09121762c7d756deea9de88c2f01b
SHA256aca37fa582238a172251099e62a499589cd28f24f87184693c984467ca065c02
SHA5122339be0e2b990eb51c18ec3d6bd3cdef033beba7d3446df5b8c795af4ff77c45e10c1a8fada18047a72495fca93b07b33e3964e5a81fc61fdd12eccbd3e60c3a
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\Speed\is-D9TME.tmpFilesize
575B
MD55616f138bef1819a525ac139252658d8
SHA1ab3c31c27928e04e3fab8e9850998691a85fe032
SHA25678f662578c89669fb14dc4f4d79da49f92fa04ac4a7b476e47cd0cf7be4e5f1c
SHA512b70c868a182c0a9b439e136175a5dea408488c6715d20c699cdb2c01eafa928b0eacf7bb0973663810202163d62579138cd0b3679285cbd8fea902d3b79b7441
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\Speed\is-FSBRN.tmpFilesize
466B
MD5a9456a634c5912e11abc8c486db5d72f
SHA12c6d0991a6eccde825921020ac6d8266763c25da
SHA256928f32418a12e8bfa28e05ac174fd034c5a3189753ce72b3ba943fba4642f59d
SHA512ff7b44f4629c01970e8908d285824ee330a80b5e11d9f52d8990f72c0404d9d4c8487f177f5da82d3f195c172e9a5df8cbf5cc484bb12d759fec2bc5466f2754
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\Speed\is-KV72V.tmpFilesize
575B
MD59b7fbff59a024121e38f132f68555226
SHA1eb40546506d32247e32738c3529cb94113cf9bd0
SHA256c74191c34146bc2e5a753222673dc9f3b74e077c892ac1bd7c058606bc9c2cf8
SHA512f64f8ddbff3710e775130cb5eb9727218f86363937e96100d613a3901a0bc0ea13f72faf9b736378e08bd2e7b9c3e6f2b41e291e8736e8de1b08bbbe0cd1a6fa
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\Speed\is-NFH9R.tmpFilesize
684B
MD50e39e848b69b52367f53045af011059d
SHA1faa8f6343f5d93f3dba7536e3a4798bbeece0c52
SHA256bd75fa865dc339c0c45347cac9477097b1926d9d92e26d1e59fbf7a3d031055d
SHA512ff3345aeb055ef6b14b9c0f19af5a94abd53e28452e5c450b83f905f14c4b838f88f66d7ed8f4bcf49990093b53144086235643c32b4504181b0fb25c6f4bfa5
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\Speed\is-RTQ63.tmpFilesize
901B
MD569df546030e248613d90d444b0cdcbc2
SHA1a7b916acbc728bce8a477ad9f959b0de13d2b3b9
SHA25606331653dc2b666873c6bca2e9de9271ea57c0d0fc0f404e6e1b2a2ca3607fc8
SHA512a2cebe881f9a1eee437df10ed70807bb6ae68fbc4ef494efccc66e1d931f6e709d6ef2f95c60930b8ecee94a9ce474ffdba3e74e14d8988331abfc07a8a5dcf2
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\Speed\is-SDKL3.tmpFilesize
466B
MD57f0d128cf75afc7e0d5b35af6e660959
SHA1374b196f5a3fc7a9f93ddf1ba6a45d6cb7bba350
SHA25660330f948dfa960c18d2eb7b908fce3c35d57d5e8b4b0d7ad6a9afee6f74bba1
SHA51264365963cea20cacbcd1e38a85e1e5efe710289587f759389a763b8d7a754932dafcc49f26fc19d2a87b2750e0d07e4d31201cc945b3a6754dd3ef1c6536b11a
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\Speed\is-UHUGD.tmpFilesize
684B
MD5e09b50482ef64736920d159a141767d1
SHA10bb828b49f15097d4e63364841f6e73656bdd0de
SHA256343374c85dcd51d137515d2436b202bbdb063dee97abbc165bce302b56a18a41
SHA5127dc37b8169f92d9b7835b9797185dc77c045f3aca237e23359fde3a444b8abc96911e1b9f5c6edb52339def284f3a2d3f286e6132d8654cac3be5f8ee32a5a18
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\TextStyle\is-KUG9U.tmpFilesize
40KB
MD578d8cc0de8ca49088c8e5c8c4e1e89ad
SHA1d91db690fbcead0b4fb16faf460954642e67af02
SHA256c41f789fe60b3f86b625bfdbfa3095cc86ed0c1276655ef2cccbec5ed59eee82
SHA51223ccba8ca3a31dfb31b939c086cb52d776b2d8619c1fb6c4c5bd55aacf1ea6c098bd378bdc5986257eb46e27daa0b0445579baa0ba8ab30e264d066cd2f0136f
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\Transition\audio_fade\is-KU6RM.tmpFilesize
167B
MD56d33f512865fd8733c94ba8048e12be9
SHA14952e0447c75c1e9b4b72a81b2e5dd6dc805e639
SHA25640a1349c1911b4f4748cf3af95b66ed040cd656e125725b9ff7ed63558414bda
SHA512ab1a16ae20496d9b90b3427465fa89a46863a5eb1afd80a634df4c039750c83fe92e4f327ec2be80f752472c73ab4b8b8b171642628812df24ed8e0f5ca46447
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\configs\is-FVF0K.tmpFilesize
11KB
MD56a68635d7d9b0c6d9abdc1af2a7d3bca
SHA142338a1d7ce5834fcf63b79fee8c594d536d64be
SHA256c4d0d81d37ad5b6c31c8fe4074956b08b377329f70f03c31e16824bcb64a0982
SHA51218d0b76599fb5da72b098f13d6b3feefc2ed619ca7fb4a792bb51966966b1f867a712aeb4ba76955360f5fea6e622f42cf7758f7e6b06b2f347bae8dc7d49896
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\is-MOUUE.tmpFilesize
3.6MB
MD5bed2a63f05f7939d8ece0d4b7ac8bf4e
SHA173e8c976fbb0b63896cd053b5842ec5c2da32477
SHA2562d5a12f3dd75f89aaaccf0b893ce8a6a6ed91567e8e050bc4ed25978175dd50b
SHA51205a479f2bb8898db4963523dd1e892fc7b0376460f1e0e59fc16604120fc08cc2c504052739e787e369a0564b34af58ac47569e16e56cffea12a198d52e3aa6a
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\is-MT078.tmpFilesize
2.3MB
MD5667dd4bb06badc9803afb350a851d61c
SHA117bc0bb379893d65d2440bdffc5fc334591da66a
SHA2569014e7a475aa50da4f574f6e870222f37392f4bbed175a956c2171de88f8765b
SHA512896091df4adeecfcd5dc053cf76c05ea927e160439c14f0317bd08728f37180d2bb1412d3966ed79971e91ecab12d0899602e7634dea49fd3ba0eb87c5f82980
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\desc_service\transform_immediately\is-THRRT.tmpFilesize
1KB
MD534ec8a253f7498e5874661a1b7371d9d
SHA11db5617686e8c42bd29ceb9da4c7cc3a8d18c375
SHA256db45b6c730d8ce75b963f3e5dbb85d9ca3f8647ce481f142b932783b21bc4414
SHA51260597ec8d55ab7665680ae01ccfae5325db5a8d9bfce1517f3a71c8956878331f98533ab6b900761f6ab4b47f8212b6e80b7900e2ea795610300f884e7489ffb
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\material\CameraSettingFiles\is-4MBPA.tmpFilesize
873B
MD5ba44358ae2b2bd7061c5e0e40a2d0fd8
SHA1e44e478c76d7888e8117c90f88d51c17d854231e
SHA2569c53df36dee1f082e9161df4b3d9deb7560705c95b08874517808368a39ebc5c
SHA512bd657d247ca882242e4cc055a6afc22f8dd6af9ff0ad11f5baa4f3f3801301c4cd95366b2b6eb929088e2d0d96588f729c4b66e8b06f342641c54c68e95cf8b6
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\material\CameraSettingFiles\is-I9HAN.tmpFilesize
872B
MD5ea19e364b5622acb0b2ec1f80e019a01
SHA134484ad25bee92a6238f332f8a31f0bf1644152a
SHA256bd56aac5738227390697cd419f555389fc4f6ebfde4f2ee2c852182886bd3ac3
SHA51258a8d0932ea8d863838bc9b379a062e43ed455390d9c9cc6f94278a56dab197964491fd7c5d6410fe01fb9dc1e6559ef6b19a95a0d9ac892da25d64a3bfd6335
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\material\CameraSettingFiles\is-IS0T3.tmpFilesize
867B
MD53022c12cf22875daebc329f889ff29ca
SHA13738d5ba958e6a9bf664bcae4e99170fccfd9d80
SHA256865d30e815575576171bb7c0dd53b394a8394f4009427a111243b3bc55750073
SHA51296c8d055cc3726bf8b6d99f4ca891b3250831f8b10ca27501f10e34c2e2af03af7d30afa621382a43b01a7d5830a88d0c288c094e640901b38baec4a5b407ed6
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\material\CameraSettingFiles\is-LJS13.tmpFilesize
871B
MD557bcc931808bc2e282836a6082a696b7
SHA199cb80fedc79c3778f09313e4b2228aa9a9e2946
SHA256079848a22a4716db82eb8028123a9fb1e7217d77ed5b25bdcb27766f30705d29
SHA512d198fddab3a0219ddad94c9221919a9c8e9dc6b570df654e1de347acb3bb3c74a3b31d7474f0dab55ae4692dcf605d3bdce13897f05ccbe003de32a0ba822c63
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\material\CameraSettingFiles\is-P6GC8.tmpFilesize
872B
MD5bd9d05a8acd2c8a23b23bf03ba34d7b2
SHA1d82a2c52da814640575204b10150850e62741216
SHA256c2c1fdca17ee57a58280f53617637e0296c4954823f423db2005c39cd938bea1
SHA512de540c88be9d328f57fecf24af2b281427a7cb65637de66a44896755a053021f6cb05f3f7ebfda92b6486a46da60d76324b463965828cb117de86e82e68c2ca4
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\material\CameraSettingFiles\is-PC9UC.tmpFilesize
872B
MD5eb8ef8708158c69e6dde5b11b37017cb
SHA17e867ab10482b7af8d9fa5543d2882d72ceff178
SHA256b3652e72cdfc36bd64d18c0e443fd1ea6b7c7c9b0f41a2a049339f47bf0521d5
SHA512277e301be70183b8e7caaed46f7bfc746d04946c12ec19b999bdac9f8abf42032decd675767506c99debde9f4a581e75791a6b321bde2b7cb20d0a2336f067a9
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\material\CameraSettingFiles\is-T2MU2.tmpFilesize
873B
MD5a5d1a076997c01c5b846ceb94f025e88
SHA108d61ecbc1a0b77f463ac3d0d30fc66bf5edab6d
SHA25691b216b42bc6dd4f83071e8f367ccf2610310a2edf9a17a41b30051d08b45dda
SHA5124e25faf176c089ecadaed1a7fa0a60153ee08b12018b74ebacec049abfbb99f680486b1ca5bfabb5841676f245c2e666d1fd707e462ead6e6993e00932c651ad
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\material\CameraSettingFiles\is-U8155.tmpFilesize
871B
MD57f7e9459754e35670927cefd4cdca004
SHA15b8e6623a25416f29224a729e502f5578cb71494
SHA2563a72f3862d63813574dcb59c286bc446f6a54ecf1725a283331559653a5e4eca
SHA512c54a50f68240e8945fd2f39455ae3389a00e72b1a7fc3faa6e42be288c84a8433741a601ec342f901ecaa82a2b9d5d7363f1e78cac0699110ead9311a6e40a12
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\BaseFilter\ARFaceDeformation\Data\is-GSHKL.tmpFilesize
156B
MD5c7c7ac71aeb334d8889ed12634726927
SHA1f281675cc64ed11a42c94c3a4d9c71dc5cf4c78e
SHA256247a3416831a73acdfd8e3a7b65f87765450813d549b8fb249eb9d3ba4abb3e0
SHA512024d87ad0d05aaedc5d5e0fdf5fc47851ca87511297d416a63a7319822785f09ff648c0b01cb679cbca374d031b3dcc2619d44fcec077d4ac889692093471ce3
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\BaseFilter\Beam 3D Logo\Data\is-4PEAK.tmpFilesize
861B
MD507329ef934bced75b1a1a93386ffef03
SHA11a867a9a19becbdaaacddac0fd808da0573de0c9
SHA256802f17a3a2fe6f19397c9c484e319a5b8449e511291e0baba17566661638267f
SHA512aeb2f0e4a217eb956bc2aee51806549257ad13f5e08d77c920f669d3aa6df52e16ad53af6673d04a566b533c9710662683d29d93bcb1fcedadbcd15c50d49ce2
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\BaseFilter\Beam Edge Flow1\Data\is-DDU03.tmpFilesize
831B
MD5afab3208a52c030943a3199170897b62
SHA1551bae60938d9567e5c07c09688f80df2c3059ee
SHA2562c05e89d8ff8d3e20339555f7adcc810cd1ceca9fccf970771fbe748e7a0f184
SHA51294a39da9867ebf1b397ac7d6fb5bc4caf5da818dca0a253c77bd3e3fc5d76e3434903a1efdac5efe5b88b4ce3505497e66a4437341fffe7c989523e65100bbe0
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\BaseFilter\Beam Text Saber Line Fire\Data\is-0TLNH.tmpFilesize
66KB
MD55f65d2f7537443cd1ca092d0e942d4ba
SHA128eba255a1c8926f7bce95accfd47b9baf29dd3e
SHA256e66f8b2c452544a66ce5808a16ef7a5754848f3d50d657eb676ebe9a951382e9
SHA5129e92119dbd79b8b5efb8cb844f6bc36d780383ec4f21d529b236c9d97cbe6ea3cbb9bf0a5e2d3d6f11203d1490dd3489bbef564ce7877220073b4da267a55349
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\BaseFilter\Beam\Data\is-0OR6V.tmpFilesize
757B
MD5e91fc468e5df81aa0fcc16b2d84d1edf
SHA12545fbbdf5e93b7f5a7945120dba438aafe62226
SHA256f0c916ef05f95faec2fd7686ef2029d492c779396be57f2658fe0d476d7c6984
SHA512d01177890e8dbe3fe2a5ff2405473e69a830cc473cfa28ad14dc29c7e11817df79876e34c3c33ed8bd13134b135e0acabfec05d412ddf215e5b6f4cd4a8e1900
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\BaseFilter\VectorText3DWhiteMode\Data\is-TU65P.tmpFilesize
157B
MD569e7d6ec344f3dccaa9b41df3e0db111
SHA1d2ae8da79e4de578f32b3deeebc45f4cce2985c1
SHA25611fdc43f6316601b8bbabf8c4706dc04972920bb293c0d706d1f9981dd6107f3
SHA5120507582025cb9bbf419124fb059d0e1b1062340a93af8c2e84a43ba60e6f0f54e4ff5a702fc32a4505b061a32e1bea4ca6fdbfeeb7145980400b88b1ad159a81
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\Black & White 2\Data\is-7FACV.tmpFilesize
1KB
MD5a2accb88b62bde85b4fcd3a558e22ce9
SHA1120966ccef685a0c9d238bde8c277109bd02c929
SHA256b38d1042edeee784fcc0339f7ad477b490758848f7f8a32834024dea17260182
SHA5129540351bec09049bfe92b1635f2ca768845a7717fc06b7d5315ef4ddce60646eac42e9696bb65a2e03c29e48e469de9546bc9accfb116cb6660e071c8ee2e86c
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\Black & White 3\Data\is-UFOD5.tmpFilesize
2KB
MD57acd39cc9ae49be8c44b0f62f5f23743
SHA1832f20f2e343a9a3fdc0d0d21112183b1abed437
SHA25651ee3a0dca70c7534eb36415eb1b8e8189f02b12763858d70be80536179cd459
SHA5120a1fd0202e592bd6a892e32c597aa905db06e6c23aa54ad7f99e49b189d2bc230a4c6f90630c878f8b41b53e0133feeda29dff9d37f4a8c949bd5eedc2ce36eb
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\Classic\Data\is-D1QI3.tmpFilesize
406KB
MD56a12135e615e8bc6a709a1c75b14915a
SHA128afaa531d56f0687a6aec34c7d63ba779e1630d
SHA25607d7a66090ccfceaa73ee3eee3d45235ed0610d503f85333d1a88ca8e38ffdf1
SHA512e7b558d545038ee8bac621cd90352d2ce4f2608317715e6597c0c8817321c384e8b525dc81ba9e593d3afd18b7fdf5f880f1974a0ca3f85022d2a32dc187d5ab
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\Screen\Data\is-IBE36.tmpFilesize
105KB
MD50d43a972a6c1d36ae9445111a1391c08
SHA1f408cb7df24c0bf29d7e05bee32561c9a22e9446
SHA2565ec8d82f58d9fdfc340480bd6745bb11a2518bca3aed63a999a5c209fdec38b2
SHA512b6ec29039bf7d09269936d99c9c234281290942a576fff6eef4f2c083c94aedc6051cda564daaebe98710d88a8ee0edd415118d9d2ec84a439bdcc3299967aad
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\September\Data\is-C0MGD.tmpFilesize
43KB
MD5a88f0e99787eb4f6c8056268b73d5d57
SHA1235074126e27b2c8b5ebe97082a9f2bf1c7498d6
SHA2563508a6cf9776181cdf1c10d3cb60fb0726e8695d2d6f2f8718b1a0da7c223faf
SHA51290e539b68093433e602d0addc685ae4353a17951de97b2a69d072a4960e941eaec1d8b2902e5cac8630a256bbda63abe7af3a84e904b394de4b8333815c9e103
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\Sierra\Data\is-5C37V.tmpFilesize
21KB
MD5678f250da84492a9c4895541a816ee96
SHA124b26d2b0042bb56c94b4ef663dd0fad9caa1c46
SHA2568d5c500600b2935929a9f23ac5cfba7348c492cb4beb59aafc408ad3321b7447
SHA512a8e89c110eb5682e09f77a5c440074ffeaf6c2e83a2b0c6a2059cd10a13f8429a84d22fbc4552867da762f7a9ea811ebae821c5b95fccaef19968a118ae6eb29
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\nle_default\Sutro\Data\is-RNTNH.tmpFilesize
10KB
MD51dc6d4c51471794d27bba455dd643a5a
SHA13c7ca2aef7c782aa44b115b940f093a26da62d41
SHA256d1292db4f1fc29589c951c5755e9076c730a3f360d19893b5fdece7f37b36dc9
SHA512dd10bfb5ef80425e9fb96e38ac62cf4cb08c2587d3b751ef332cdfaa7e996f3613aedda6ad0b30b6bebf6bd11cfdb7302982a77442ef2570b4dbe6052661b059
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\plugin\AiEffect\HumanSegmentationBackChange\Data\is-I8LTV.tmpFilesize
890B
MD5f5d2ba62098a8584f7a549e1eaac472f
SHA12e9ebd0c8bfc1a4cba46f1463012b78ea8dc8088
SHA2566a9f09db3178ce9b155146f3b5ed8c6726cf13788865ebd7e6578a1aa486ccff
SHA5121445bd8e5264c8ddad7039bd1557d0a41e8ffb82cd55fc3d12af798a695dc1664b46748605a01cca1926a7fb588749a539b94d2dc13ef7e7d84f133434d94664
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\resources\wfx_effect\plugin\AiEffect\WhiteWiperSegmentaion\Data\is-8CI62.tmpFilesize
984B
MD5e1358bc5055d87c4b75ff7d1d3ccc188
SHA1e382858882f19202ea31e85326d06df51004ccf7
SHA256eaad98816ba844f0b055a284f7121a51322c3b582542dc44cab04cb6ed915973
SHA512e39d0cd2a0612c7d3eee7c0b1d4e977c26ac86ef8e5ee635732a5c0700fd3b96c8e367d61587fd4865bf1d5c4ba849270cc4b22ec40baf1ddd1665ccc20f01e7
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\sysconfigs\ClickSound\is-1CIDO.tmpFilesize
560B
MD52165ddf748a47a28b131f80682baa859
SHA148df49215de4dffed34181a645d1843148333ebb
SHA2562d13ffa945549236a02494a9f6ee86ef61499c9c485d217bc0122857ebfab867
SHA512e221cdd861ccc343b7a8cf0988009890f652649a5c4dabd4c347aa4ac65817b0f5ee9957fa82039c684e0f9d1d15acbe82eb36a8c47b70d2d39481baf46d9bff
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\sysconfigs\default_effect\advanced\HumanSegmentationBackChange\is-38L44.tmpFilesize
551B
MD5ef953efafc667be2be118d2ef0981ca0
SHA19b17a1d221d0d1f450d237121c32a11e71985ff0
SHA2564e30202d068ab5b33e23325882d370ae44c17cb684d4fcec00a8e126db9272a8
SHA5127c0ced8e44f75b6575183bb4fe3e6255bc70a3e4194b27d2c0f2e5dc9ee5650821f5b712260dc0897cf3123000bbbb66d16c2b122cb8c80a868db6e9fe0aa0bb
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\sysconfigs\default_effect\advanced\HumanSegmentationCaptureBlur\is-SLRNI.tmpFilesize
618B
MD517302b3ab53c6b211e32a715daedf75f
SHA155c069b859d55a05a9be4c7bc0e473d16ab2c482
SHA256490fcc1f0e1d93f047c79ddbfe8208f5ae321ae26989f69e686a79eefbcb1603
SHA5124bb13e18ddfeda61332d6d001770a87c655e177be27dc8bb96fe5f40f8c75fb40a229c18df49075c17212d9f25d2e53e1df5c59f5c855f48d21700a0a3dd2b9e
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\sysconfigs\default_effect\advanced\Mosaic\is-EGT2H.tmpFilesize
14KB
MD5e0af223287934301be30fb985b5c2d13
SHA18a3dc0bc44f2d18b86c4e5429050452d89311fef
SHA256eb8dafc89e8958115e9099cf9dac440ded711dba0f1028e46e7137fa111cad50
SHA51252c34e865a87a45da4409de74ea20d72899d57adc52bc02d0415c14738cbe5a53dc42e84dd9de23decb0b5cdbe74f5dd6ffcf21a7631bae3cffecff9956b045d
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\sysconfigs\default_effect\advanced\Mosaic\is-GB9KI.tmpFilesize
1KB
MD53e723bc6952820c8b63571c66adf92c8
SHA124a3d70cb327bdc01d4d3d9d99c064d64ecdbb01
SHA256f988b4750a27effff1a6f08714af6113926f8a539a472bdf1685afc8d27d5fdc
SHA512e9329a5f70b5524931bc6ac8915f55313b3b3f79e54b0431489a01b7917439a8e60f0ef82b2b021d9d9266a4fd0764839c6be93eb765c8dfc2f9b26ba8d5ed75
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\sysconfigs\default_effect\normal\audio_ducking\is-RTA7K.tmpFilesize
518B
MD5475564404f9c43a0c69d8f444b1293da
SHA130cbce0867b6dae93bbd8bdbf2953e3b08a07dd3
SHA25600ed568ebdffc2614a6898994289e806c1efe0af2e746313b61729765917d0be
SHA51230ab132c8214f762d7e289ed86efc40d8196c982ff9a3e36bd0f9cb5ad8b6909ffb2c419e0ef3e7f712caf9580d8e485f9e19d56da8e331e941cc289be146c18
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\sysconfigs\default_effect\normal\dehum\is-435P9.tmpFilesize
335B
MD589a07d15f1f80af57dc3ccc814cd0b82
SHA15242bbc55483d6048f849eed66ea03bd59c0c7d4
SHA2560b46bb78082b2c866886a7a5755a1f9759ec97025e169ae3e8de13cb7adf52af
SHA5121666ee7b701b3da2bfe88bb13b69b50c06228c22fdadf90cdcf7bb0a18357b6b37c88d8ef8d4c93665d84ce2cca5ae9c8c554a3fa6157166129b331e659120f8
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\sysconfigs\default_effect\normal\dewind\is-9U66S.tmpFilesize
148B
MD536352057340ad2194c31056ec07dc26e
SHA11604b2902cd7cafbaf10b252f9b976f5abe47bdc
SHA2565647168e4251418318ed8e1b2d3f35a6cd7f3b92e36d3ac1d9862a99867bcfa8
SHA512758eda135946c3c51c4851773a8f2d428a4dcc8e351f9a55dc4c1bd37867ef5f38748ec66c521a85a778548823a40774b6a359fc546d28ee816e826311aca84f
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\13.5.1.7566\wes_black_list.jsonFilesize
13KB
MD5fc4edcf72523749f05c51979a4c9790f
SHA15a4beab7e00aeaa5c90e37498061d5daebdc1ab2
SHA256582ad26d7b0e85150194d8d6214b8aa7b8f53b3756c8756ad0134961ed403292
SHA5125f17f97447e4f903588df80057cacefaf838e51901ac530678c444e1b867d224eeee188571a41fdab3c14283267bbb4bb27d660e43516aa7fb0c67afef289a1c
-
C:\Users\Admin\AppData\Local\Wondershare\Wondershare Filmora\Wondershare Filmora Launcher.exeFilesize
859KB
MD5e1bc74def87d7dcfc29afedf0aac6b13
SHA16422f1fca90737446953efa3881d0f4af56181f1
SHA256c458c88080a30b76a0975548bc0ee84cecd64f215fb11e30b0ee4fa936e4ea1b
SHA51212f9e0d45992ea477486ea0e9b8cb3d1964a2f170d0b94bf58cd97a5db4d6720493e64a4c06d26f13ce2aa0cfde9f88cb65bcced76cccd0cfe4667cb3a3b2f72
-
C:\Users\Admin\AppData\Roaming\Wondershare\Wondershare Filmora\Download\Filmora\filter\3_Chromatic_Aberration\Data\is-O0DNO.tmpFilesize
881B
MD5c787222397eb2d14a6071eee02bbd0a3
SHA1ec1ec8bb0acb1748530c7934bb23cfc0f9400628
SHA25689e1f9f1760f65a3ced17a88d54f7193de94272d503c1964687ad27c0f0a3fcb
SHA51231bdfd64b594b52c120a1407811d7d635a10d75f0ae53bf4bd32caac57c3e99575f3b8405bd4da416d8339ee35aec934e4b3f4d3e2f562f7736c02e10bcc7103
-
C:\Users\Admin\AppData\Roaming\Wondershare\Wondershare Filmora\Download\Filmora\filter\3_Cool_Film\Data\is-P1I95.tmpFilesize
896KB
MD5d012b05a24f80a19d278636e97fee454
SHA19faa9a1695c1b69578c1c7ebdce8745276763f73
SHA256da828049365592b2c45b048094e989f9b9b14990633259e7ab6aa648dc12131e
SHA51200d0bcb917039a7d5e39dd21fc9b851c58b2dd367721b7ea996cd5839a2117f3a7e6b4b2d0c0043a0dd49e34dac98d6c153634967dfc4abaede7625f88da3150
-
C:\Users\Admin\AppData\Roaming\Wondershare\Wondershare Filmora\Download\Filmora\title\1_Basic_1\Data\is-6FD6N.tmpFilesize
14KB
MD5117184f02958a5003d281bf50c42e8d1
SHA176e65b210efed554b3ca4e784475e48cac5da6db
SHA256810f268a6b3a0f98e8e5fc8603cc6cc90d4d28760fc7ee3c75e39bb4c01db58e
SHA5125923bf14e90e28e100af5cdf3ed7576f45def87cd5164e3f45f107646efa26efd56e2f32b8ebf838a97708242a372899326eb0a99d46590a76c0eae58e5c00f8
-
C:\Users\Admin\AppData\Roaming\Wondershare\Wondershare Filmora\Download\Filmora\title\1_Subtitle_3\is-63K0N.tmpFilesize
10KB
MD5c5332af43579ca1dda9b6ad4be4af880
SHA1e0e17a8bee05b6e38972656ad0821d7008127b03
SHA256d44fb5b7791936fd36db0f84577926aea506c4b5ef8a1bcb40ee02577d2b8a38
SHA512072e9677031e9309209fc05d3afdcf995867865bbf0a2bb34c3b926a34b738aa6fa7f3f3864fd1e1a46af22dbb51b2c18d60fef1cb38555ee2054174510e1195
-
C:\Users\Admin\AppData\Roaming\Wondershare\Wondershare Filmora\ShortcutSetting.xmlFilesize
33KB
MD5187e090ce7e5f1f2296e64e5feb9c263
SHA1dd4802bdb9c4b792501d208d9afcb54f00d4be8b
SHA256bfadd404fa0c2290f73873cd2b29afbe3391c2351e02462c3f8da40e0a6108d6
SHA512fb66fdd31d99af17063f5b4d99c21221d3df321fdda68c6124b749df7887c46995acfb70bdecc504098a857679326eeec0ec1b6d8a10dfdda67f54d952778618
-
C:\Users\Public\Documents\Wondershare\NFWCHK.exe.configFilesize
223B
MD55babf2a106c883a8e216f768db99ad51
SHA1f39e84a226dbf563ba983c6f352e68d561523c8e
SHA2569e676a617eb0d0535ac05a67c0ae0c0e12d4e998ab55ac786a031bfc25e28300
SHA512d4596b0aafe03673083eef12f01413b139940269255d10256cf535853225348752499325a5def803fa1189e639f4a2966a0fbb18e32fe8d27e11c81c9e19a0bb
-
C:\Windows\Installer\f785b3a.msiFilesize
226KB
MD536fa686b188b7012c1e616ac0e21004e
SHA113c7e0116993d0829f12abef4080bdf29d955a7b
SHA256dd6b7459aff8b29d19164e429b7e4d3b1f331e06191a86a4f12520b8bd6835b2
SHA5123b9223b9ce488d2dc600349fc96accf9f4b41e99f19ac58734548b8afee36691b6f5ae84a338c4432d922ceab32850b6f5036302e4856a3d8d0075b09e8b2761
-
F:\d5baf80d5e13b572f81ef8644500\install.exeFilesize
834KB
MD5dbfd18f9dd13466964c09d522893c594
SHA106f756afa088e6ebbb510573ddb3edb8c9a3cc57
SHA2563d2bdad60f7fed1243072c1ed268ce3c3d7a0f9c4d8bd5ed811c6d1d868a4ae7
SHA512864e5012e11d85397fcfabde0c6e6b54a77156655c125bef0c85404abc9d386c4fe391116916884fd01c77f17fb28fa793f14378a0036746d0d136fb4240a3f8
-
\Users\Admin\AppData\Local\Temp\is-58URN.tmp\filmora_64bit_full1081.tmpFilesize
1.4MB
MD5c697ab3b8a7153969e7eb6b6476776e6
SHA1f048d32f8cf7ba7d6f37dca2a0aa7eaa21fdf743
SHA256be33b555e00fcdffd64aa84795fccd2b3d4553470b3cdcb7983a60bde34ad85d
SHA512b30a1d876188d07c846ab387c7ff3059c253f8b4eac2d5e68ca5108e2ac64bc1e9b9353bdc34882a145d1625bb163d51cffa2248741e11211f05604220a2dcfe
-
\Users\Admin\AppData\Local\Temp\is-8N61B.tmp\Wondershare Filmora SubPack 3.tmpFilesize
1.4MB
MD5322fe95cbacaaae6e4808b330edb3bd9
SHA17165718f8b33f6d072bbb447156a39a8bda9e4c5
SHA256e6a1f9b2a8ef8b27796dea079dbd025de72dbc02a8906e76255a39b81a4df6ec
SHA51257f50cae1d54f0009083d3148170420c52a731c40fd243674eedb67711df22ed3b135755b9dafc9ee3b5d7e478078c43254fe35e1dde2cfd7bda5b14a3e886d0
-
\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\InnoUtils.dllFilesize
227KB
MD51b4971e6b1448edb00d5515edd6f1bfa
SHA1e3864e928c8be4c8c7ea7527c9c5cd8491b77c03
SHA2560146a12866e8e153bcbdefaecd187eea39ef03af5774323bd5404080246dd8b9
SHA512662f49eaa50ff37a76c029f6a7dbef79f82b0c3f2c700f8b46bea8c4b75119af35087141c3adce28729be9a25505e0f9aacbab5f9c46b45a4c46477f082cd357
-
\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\InstallHelper.dllFilesize
122KB
MD5650afaaba451c668629dd01248c81264
SHA1623f583d82aefae7691afedc077a6684d536a545
SHA256ec3dd19d446eaf62d396d65029c1c627205bd1fd33608e122be7f4d8af7b5ad4
SHA5123476bfa801e506ae3c9afd6861519b9a3782e70566ef6df49dc01f605f70fc990a7b59dd8e19b99caa937dbd75bbbfd4246b2e4e6a995e70290cef603c995511
-
\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\WSUtilities_Setup.dllFilesize
202KB
MD5665603698f4a865a873082309712aae2
SHA1b3f2c3d1d679181d9c080419b1dfe0563c518c67
SHA256b42085777505d324d56122f2bd6195ec3a6ce47030a31f9ce6b853c5fa8cd5a8
SHA5120444b1b63980f9b762e6e01b7cdc4efc2fd6f713887c07d8cf8b20ab2582f611e1c8434f8b59b8ee4fb6dba497c2c1f80fc6e758dc02c07d2964dd6e1f0b6ace
-
\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\WS_Log_Setup.dllFilesize
104KB
MD5943e0025c5b5c4e0cddb7a9cc7b7d123
SHA15dd92f9fa572eac7ebc467d8835c64af77dd37a2
SHA25643391e665a63b5e9e1288a3c608691f73ece57478e0655363918e8195d85cf81
SHA512cb42c329e0d5f01a224e4e5b89b4ccc54fefc658d37caea40198f4483e5387f08cbdd0e85af7b0618e6ec72c5e5874098c5946bf749c218978003ad99c5fa852
-
\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\_isetup\_setup64.tmpFilesize
6KB
MD5e4211d6d009757c078a9fac7ff4f03d4
SHA1019cd56ba687d39d12d4b13991c9a42ea6ba03da
SHA256388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
SHA51217257f15d843e88bb78adcfb48184b8ce22109cc2c99e709432728a392afae7b808ed32289ba397207172de990a354f15c2459b6797317da8ea18b040c85787e
-
\Users\Admin\AppData\Local\Temp\is-GFF9C.tmp\innocallback.dllFilesize
63KB
MD51c55ae5ef9980e3b1028447da6105c75
SHA1f85218e10e6aa23b2f5a3ed512895b437e41b45c
SHA2566afa2d104be6efe3d9a2ab96dbb75db31565dad64dd0b791e402ecc25529809f
SHA5121ec4d52f49747b29cfd83e1a75fc6ae4101add68ada0b9add5770c10be6dffb004bb47d0854d50871ed8d77acf67d4e0445e97f0548a95c182e83b94ddf2eb6b
-
\Users\Admin\AppData\Local\Temp\is-HGJBV.tmp\Wondershare Filmora SubPack 2.tmpFilesize
1.4MB
MD5fe010e5f6269396879ed1a31a2698466
SHA11081b3749e16074c7f9c5dd670d66b7b0c7047b0
SHA256ed68aab0e1e2a88ba61c905198b4d10b18d3cbe5441b440361f3efe5b51b8892
SHA5121ea40c1d1a2e5a0c1491778d118c31919e5076bdf72c7558ec87ab5ae0be2331d83b2be3f52952d624f4659274b01454e419d6befd5d17c6717eaa9af88d383e
-
\Users\Admin\AppData\Local\Temp\is-STF8B.tmp\Wondershare Filmora SubPack 1.tmpFilesize
1.4MB
MD59d9ca4a0d792194a1b13540f3d7f1d2b
SHA16432bd611f62dc2bc7f05c603eb53c8b8ed60b15
SHA2564bea4bc64b2ec5f4386feed18abb67d8dcf5eb997935a2b57d99f539e8433e9c
SHA51228d72ee9679eb6b58e7d952c5c00d1bdaa104567972ad2b8aaa09a7bdcadc3e0f9fcadeee9206c3cc012affaa0c6cb918469161c6e26b4538ff5f65ebed3ed0e
-
\Users\Public\Documents\Wondershare\NFWCHK.exeFilesize
7KB
MD527cfb3990872caa5930fa69d57aefe7b
SHA15e1c80d61e8db0cdc0c9b9fa3b2e36d156d45f8f
SHA25643881549228975c7506b050bce4d9b671412d3cdc08c7516c9dbbb7f50c25146
SHA512a1509024872c99c1cf63f42d9f3c5f063afde4e9490c21611551ddd2322d136ce9240256113c525305346cf7b66ccca84c3df67637c8fecbfeebf14ffa373a2a
-
memory/108-10555-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/108-12773-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/108-3875-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/624-18012-0x0000000002A50000-0x0000000002A5A000-memory.dmpFilesize
40KB
-
memory/624-18054-0x0000000003540000-0x000000000354A000-memory.dmpFilesize
40KB
-
memory/624-18037-0x0000000002AE0000-0x0000000002AEA000-memory.dmpFilesize
40KB
-
memory/624-18034-0x0000000002AE0000-0x0000000002AEA000-memory.dmpFilesize
40KB
-
memory/624-18039-0x0000000002AE0000-0x0000000002AEA000-memory.dmpFilesize
40KB
-
memory/624-18060-0x0000000003540000-0x000000000354A000-memory.dmpFilesize
40KB
-
memory/624-18068-0x0000000002A50000-0x0000000002A5A000-memory.dmpFilesize
40KB
-
memory/624-18038-0x0000000002AE0000-0x0000000002AEA000-memory.dmpFilesize
40KB
-
memory/624-18055-0x0000000003540000-0x000000000354A000-memory.dmpFilesize
40KB
-
memory/624-18036-0x0000000002AE0000-0x0000000002AEA000-memory.dmpFilesize
40KB
-
memory/624-18035-0x0000000002AE0000-0x0000000002AEA000-memory.dmpFilesize
40KB
-
memory/1000-13581-0x0000000000330000-0x00000000003E8000-memory.dmpFilesize
736KB
-
memory/1000-13619-0x0000000000400000-0x0000000000612000-memory.dmpFilesize
2.1MB
-
memory/1000-13628-0x0000000000330000-0x00000000003E8000-memory.dmpFilesize
736KB
-
memory/1152-17514-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/1152-3431-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/1152-9408-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/1588-13654-0x0000000000400000-0x00000000004BE000-memory.dmpFilesize
760KB
-
memory/1588-10807-0x00000000002D0000-0x00000000002E4000-memory.dmpFilesize
80KB
-
memory/1728-18015-0x0000000002840000-0x000000000284A000-memory.dmpFilesize
40KB
-
memory/1728-17714-0x000007FEF3C00000-0x000007FEF4257000-memory.dmpFilesize
6.3MB
-
memory/1728-17715-0x000007FEF4310000-0x000007FEF44E0000-memory.dmpFilesize
1.8MB
-
memory/1728-17721-0x000000013FDF0000-0x0000000140382000-memory.dmpFilesize
5.6MB
-
memory/1728-17712-0x000007FEF3730000-0x000007FEF3B5C000-memory.dmpFilesize
4.2MB
-
memory/1728-17711-0x000007FEF3280000-0x000007FEF372E000-memory.dmpFilesize
4.7MB
-
memory/1728-17917-0x0000000002850000-0x000000000285A000-memory.dmpFilesize
40KB
-
memory/1728-17916-0x0000000002850000-0x000000000285A000-memory.dmpFilesize
40KB
-
memory/1728-18016-0x0000000002840000-0x000000000284A000-memory.dmpFilesize
40KB
-
memory/1728-18070-0x0000000002850000-0x000000000285A000-memory.dmpFilesize
40KB
-
memory/1728-18071-0x0000000002850000-0x000000000285A000-memory.dmpFilesize
40KB
-
memory/1728-17848-0x0000000002840000-0x000000000284A000-memory.dmpFilesize
40KB
-
memory/1728-17847-0x0000000002840000-0x000000000284A000-memory.dmpFilesize
40KB
-
memory/1748-9406-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/1748-3322-0x0000000003190000-0x00000000031A5000-memory.dmpFilesize
84KB
-
memory/1748-13551-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/1748-3912-0x0000000003190000-0x00000000031A5000-memory.dmpFilesize
84KB
-
memory/1748-3911-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/1748-17600-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/1880-3300-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/1880-3910-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/1880-17601-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/1984-17885-0x000007FEEE290000-0x000007FEEF973000-memory.dmpFilesize
22.9MB
-
memory/1984-17886-0x000007FEEE290000-0x000007FEEF973000-memory.dmpFilesize
22.9MB
-
memory/1984-17863-0x000007FEEE290000-0x000007FEEF973000-memory.dmpFilesize
22.9MB
-
memory/1984-17866-0x000007FEEE290000-0x000007FEEF973000-memory.dmpFilesize
22.9MB
-
memory/1984-17862-0x000007FEEE290000-0x000007FEEF973000-memory.dmpFilesize
22.9MB
-
memory/1984-17864-0x000007FEEE290000-0x000007FEEF973000-memory.dmpFilesize
22.9MB
-
memory/1984-17867-0x000007FEEE290000-0x000007FEEF973000-memory.dmpFilesize
22.9MB
-
memory/1984-17884-0x000007FEEE290000-0x000007FEEF973000-memory.dmpFilesize
22.9MB
-
memory/1984-17887-0x000007FEEE290000-0x000007FEEF973000-memory.dmpFilesize
22.9MB
-
memory/1984-17865-0x000007FEEE290000-0x000007FEEF973000-memory.dmpFilesize
22.9MB
-
memory/2012-13657-0x0000000000400000-0x0000000000414000-memory.dmpFilesize
80KB
-
memory/2012-10770-0x0000000000400000-0x0000000000414000-memory.dmpFilesize
80KB
-
memory/2056-10765-0x0000000000400000-0x00000000004F2000-memory.dmpFilesize
968KB
-
memory/2056-10722-0x0000000000400000-0x00000000004F2000-memory.dmpFilesize
968KB
-
memory/2380-12767-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/2380-10556-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/2748-17512-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/2748-9409-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/2748-13554-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/2760-15021-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/2760-15000-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/2760-9411-0x0000000000400000-0x0000000000572000-memory.dmpFilesize
1.4MB
-
memory/2808-9410-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/2808-3540-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/2808-15023-0x0000000000400000-0x000000000046C000-memory.dmpFilesize
432KB
-
memory/2932-16009-0x000007FEF79C0000-0x000007FEF79D8000-memory.dmpFilesize
96KB
-
memory/3040-10761-0x0000000000400000-0x0000000000731000-memory.dmpFilesize
3.2MB