EzPlatformSetting_1_0_0_13.exe is part of EzPlatformSetting ?? ???? according to the EzPlatformSetting_1_0_0_13.exe version information.
EzPlatformSetting_1_0_0_13.exe's description is "EzPlatformSetting MFC ?? ????"
EzPlatformSetting_1_0_0_13.exe is usually located in the 'c:\downloads\' folder.
Some of the anti-virus scanners at VirusTotal detected EzPlatformSetting_1_0_0_13.exe.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
The following is the available information on EzPlatformSetting_1_0_0_13.exe:
| Property | Value |
|---|---|
| Product name | EzPlatformSetting ?? ???? |
| File description | EzPlatformSetting MFC ?? ???? |
| Internal name | EzPlatformSetting |
| Original filename | EzPlatformSetting.EXE |
| Legal copyright | Copyright (C) 2008 |
| Product version | 1, 0, 0, 11 |
| File version | 1, 0, 0, 11 |
Here's a screenshot of the file properties when displayed by Windows Explorer:
| Product name | EzPlatformSetting ?? ???? |
| File description | EzPlatformSetting MFC ?? ???? |
| Internal name | EzPlatformSetting |
| Original filename | EzPlatformSetting.EXE |
| Legal copyright | Copyright (C) 2008 |
| Product version | 1, 0, 0, 11 |
| File version | 1, 0, 0, 11 |
EzPlatformSetting_1_0_0_13.exe is not signed.
2 of the 69 anti-virus programs at VirusTotal detected the EzPlatformSetting_1_0_0_13.exe file. That's a 3% detection rate.
The following information was gathered by executing the file inside Cuckoo Sandbox.
Successfully executed process in sandbox.
{
"directory_created": [
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\Temp",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\ShareFiles",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\RefSetupFiles",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft"
],
"dll_loaded": [
"dwmapi.dll",
"C:\\Windows\\syswow64\\MSCTF.dll",
"ADVAPI32.dll",
"kernel32.dll",
"UxTheme.dll",
"OLEAUT32.DLL",
"C:\\Windows\\system32\\ole32.dll",
"shell32.dll",
"ole32.dll",
"comctl32.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\46a261257192beec0c8b8a7b15869947ed3ebeafa861dbe33d73e74b03f05384.bin",
"Comctl32.dll"
],
"file_opened": [
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PropertyBag",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KnownFolderSettings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Network",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Comdlg32",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\46a261257192beec0c8b8a7b15869947ed3ebeafa861dbe33d73e74b03f05384.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1"
],
"file_exists": [
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\Temp",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\RefSetupFiles",
"C:\\Users\\cuck\\AppData",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\ShareFiles",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft",
"C:\\Users\\cuck\\AppData\\Local\\Temp",
"C:\\Users\\cuck",
"C:\\Users",
"C:\\Users\\cuck\\AppData\\Local",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\46a261257192beec0c8b8a7b15869947ed3ebeafa861dbe33d73e74b03f05384.bin"
],
"regkey_read": [
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Icon",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Local AppData",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Roamable"
]
}[
{
"process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\46a261257192beec0c8b8a7b15869947ed3ebeafa861dbe33d73e74b03f05384.bin",
"process_name": "46a261257192beec0c8b8a7b15869947ed3ebeafa861dbe33d73e74b03f05384.bin",
"pid": 2816,
"summary": {
"directory_created": [
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\Temp",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\ShareFiles",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\RefSetupFiles",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft"
],
"dll_loaded": [
"dwmapi.dll",
"C:\\Windows\\syswow64\\MSCTF.dll",
"ADVAPI32.dll",
"kernel32.dll",
"UxTheme.dll",
"OLEAUT32.DLL",
"C:\\Windows\\system32\\ole32.dll",
"shell32.dll",
"ole32.dll",
"comctl32.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\46a261257192beec0c8b8a7b15869947ed3ebeafa861dbe33d73e74b03f05384.bin",
"Comctl32.dll"
],
"file_opened": [
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PropertyBag",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KnownFolderSettings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Network",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Comdlg32",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\46a261257192beec0c8b8a7b15869947ed3ebeafa861dbe33d73e74b03f05384.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1"
],
"file_exists": [
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\Temp",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\RefSetupFiles",
"C:\\Users\\cuck\\AppData",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft\\ShareFiles",
"C:\\Users\\cuck\\AppData\\Local\\DaeGilSoft",
"C:\\Users\\cuck\\AppData\\Local\\Temp",
"C:\\Users\\cuck",
"C:\\Users",
"C:\\Users\\cuck\\AppData\\Local",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\46a261257192beec0c8b8a7b15869947ed3ebeafa861dbe33d73e74b03f05384.bin"
],
"regkey_read": [
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Icon",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Local AppData",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Roamable"
]
},
"first_seen": 1605621186.828125,
"ppid": 2016
},
{
"process_path": "C:\\Windows\\System32\\lsass.exe",
"process_name": "lsass.exe",
"pid": 476,
"summary": {},
"first_seen": 1605621186.515625,
"ppid": 376
}
][
{
"markcount": 2,
"families": [],
"description": "The file contains an unknown PE resource name possibly indicative of a packer",
"severity": 1,
"marks": [
{
"category": "resource name",
"ioc": "AVI",
"type": "ioc",
"description": null
},
{
"category": "resource name",
"ioc": "BIN",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "pe_unknown_resource_name"
},
{
"markcount": 63,
"families": [],
"description": "Foreign language identified in PE resource",
"severity": 2,
"marks": [
{
"name": "AVI",
"language": "LANG_KOREAN",
"offset": "0x00107d28",
"filetype": "RIFF (little-endian) data, AVI, 272 x 60, video: RLE 8bpp",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00011400"
},
{
"name": "BIN",
"language": "LANG_KOREAN",
"offset": "0x001dac3c",
"filetype": "TeX font metric data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x0000001d"
},
{
"name": "BIN",
"language": "LANG_KOREAN",
"offset": "0x001dac3c",
"filetype": "TeX font metric data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x0000001d"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001dbde8",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000134"
},
{
"name": "RT_BITMAP",
"language": "LANG_KOREAN",
"offset": "0x001dbfd4",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000144"
},
{
"name": "RT_BITMAP",
"language": "LANG_KOREAN",
"offset": "0x001dbfd4",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000144"
},
{
"name": "RT_ICON",
"language": "LANG_KOREAN",
"offset": "0x001dc118",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x000002e8"
},
{
"name": "RT_DIALOG",
"language": "LANG_KOREAN",
"offset": "0x001dcfc0",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000034"
},
{
"name": "RT_DIALOG",
"language": "LANG_KOREAN",
"offset": "0x001dcfc0",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000034"
},
{
"name": "RT_DIALOG",
"language": "LANG_KOREAN",
"offset": "0x001dcfc0",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000034"
},
{
"name": "RT_DIALOG",
"language": "LANG_KOREAN",
"offset": "0x001dcfc0",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000034"
},
{
"name": "RT_DIALOG",
"language": "LANG_KOREAN",
"offset": "0x001dcfc0",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000034"
},
{
"name": "RT_DIALOG",
"language": "LANG_KOREAN",
"offset": "0x001dcfc0",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000034"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_STRING",
"language": "LANG_KOREAN",
"offset": "0x001de964",
"filetype": "data",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000292"
},
{
"name": "RT_GROUP_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001ded20",
"filetype": "MS Windows cursor resource - 1 icon, 32x256, hotspot @1x1",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000014"
},
{
"name": "RT_GROUP_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001ded20",
"filetype": "MS Windows cursor resource - 1 icon, 32x256, hotspot @1x1",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000014"
},
{
"name": "RT_GROUP_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001ded20",
"filetype": "MS Windows cursor resource - 1 icon, 32x256, hotspot @1x1",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000014"
},
{
"name": "RT_GROUP_CURSOR",
"language": "LANG_KOREAN",
"offset": "0x001ded20",
"filetype": "MS Windows cursor resource - 1 icon, 32x256, hotspot @1x1",
"sublanguage": "SUBLANG_KOREAN",
"type": "generic",
"size": "0x00000014"
}
],
"references": [],
"name": "origin_langid"
},
{
"markcount": 2,
"families": [],
"description": "The binary likely contains encrypted or compressed data indicative of a packer",
"severity": 2,
"marks": [
{
"entropy": 7.930905842587181,
"section": {
"size_of_data": "0x000d8400",
"virtual_address": "0x00107000",
"entropy": 7.930905842587181,
"name": ".rsrc",
"virtual_size": "0x000d8350"
},
"type": "generic",
"description": "A section with a high entropy has been found"
},
{
"entropy": 0.45099061522419187,
"type": "generic",
"description": "Overall entropy of this PE file is high"
}
],
"references": [
"http:\/\/www.forensickb.com\/2013\/03\/file-entropy-explained.html",
"http:\/\/virii.es\/U\/Using%20Entropy%20Analysis%20to%20Find%20Encrypted%20and%20Packed%20Malware.pdf"
],
"name": "packer_entropy"
}
]The Yara rules did not detect anything in the file.
{
"tls": [],
"udp": [
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 546,
"time": 3.079092025756836,
"dport": 137,
"sport": 137
},
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 5226,
"time": 9.079540967941284,
"dport": 138,
"sport": 138
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7070,
"time": 3.011967897415161,
"dport": 5355,
"sport": 51001
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7398,
"time": 1.023705005645752,
"dport": 5355,
"sport": 53595
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7726,
"time": 3.019176959991455,
"dport": 5355,
"sport": 53848
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8054,
"time": 1.6540379524230957,
"dport": 5355,
"sport": 54255
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8382,
"time": -0.08338093757629395,
"dport": 5355,
"sport": 55314
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 8710,
"time": 1.6099019050598145,
"dport": 1900,
"sport": 1900
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 28120,
"time": 1.0456409454345703,
"dport": 3702,
"sport": 49152
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 36504,
"time": 3.1269989013671875,
"dport": 1900,
"sport": 53598
}
],
"dns_servers": [],
"http": [],
"icmp": [],
"smtp": [],
"tcp": [],
"smtp_ex": [],
"mitm": [],
"hosts": [],
"pcap_sha256": "e9d021a39de95a783cf3ae360d18d9ed6a2ed5305d5d4f59987a5fac17c96bd2",
"dns": [],
"http_ex": [],
"domains": [],
"dead_hosts": [],
"sorted_pcap_sha256": "64b4c6a207eb1d5cd1bb4011179b614a12dcc7f4b5f59b3a2332e4ca9dce4c84",
"irc": [],
"https_ex": []
}

The instructions below shows how to remove EzPlatformSetting_1_0_0_13.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the EzPlatformSetting_1_0_0_13.exe file for removal, restart your computer and scan it again to verify that EzPlatformSetting_1_0_0_13.exe has been successfully removed. Here are the removal instructions in more detail:
| Property | Value |
|---|---|
| MD5 | ba9b43196225646011d058633fa400e7 |
| SHA256 | 46a261257192beec0c8b8a7b15869947ed3ebeafa861dbe33d73e74b03f05384 |
These are some of the error messages that can appear related to ezplatformsetting_1_0_0_13.exe:
ezplatformsetting_1_0_0_13.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
ezplatformsetting_1_0_0_13.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.
EzPlatformSetting MFC ?? ???? has stopped working.
End Program - ezplatformsetting_1_0_0_13.exe. This program is not responding.
ezplatformsetting_1_0_0_13.exe is not a valid Win32 application.
ezplatformsetting_1_0_0_13.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.
To help other users, please let us know what you will do with the file:
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
No comments posted yet.