Windows defender shows CryptoExtortBTC.A - Virus, Trojan, Spyware, and Malware Removal Help
Tags
Common Information
Type | Value |
---|---|
UUID | e9369077-a6b9-4c62-bef9-7e7d5d9da097 |
Fingerprint | 37540a22fe8e8ec7 |
Analysis status | DONE |
Considered CTI value | 1 |
Text language | |
Published | March 8, 2023, 7:48 a.m. |
Added to db | March 8, 2023, 4:23 p.m. |
Last updated | Nov. 17, 2024, 6:55 p.m. |
Headline | Windows defender shows CryptoExtortBTC.A |
Title | Windows defender shows CryptoExtortBTC.A - Virus, Trojan, Spyware, and Malware Removal Help |
Detected Hints/Tags/Attributes | 83/2/278 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 163 | ✔ | — | https://media.cert.europa.eu/rss?type=category&id=Malware&language=en&duplicates=false | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | File | 1 | c:\windows\system32\dtsgaincompensatordll64.dll |
|
Details | File | 1 | c:\windows\system32\hifidax2apipcll.dll |
|
Details | File | 1 | c:\windows\system32\hmapo.dll |
|
Details | File | 1 | c:\windows\system32\hmclarifi.dll |
|
Details | File | 1 | c:\windows\system32\dtsgfxapo64.dll |
|
Details | File | 1 | c:\windows\system32\dtslfxapo64.dll |
|
Details | File | 1 | c:\windows\system32\dtsgfxapons64.dll |
|
Details | File | 1 | c:\windows\system32\hmhvs.dll |
|
Details | File | 1 | c:\windows\system32\hmeq_voice.dll |
|
Details | File | 1 | c:\windows\system32\hmeq.dll |
|
Details | File | 1 | c:\windows\system32\hmlimiter.dll |
|
Details | File | 3 | c:\windows\system32\rtpgex64.dll |
|
Details | File | 1 | c:\windows\system32\dolbydax2apov201.dll |
|
Details | File | 3 | c:\windows\system32\ddpd64a.dll |
|
Details | File | 1 | c:\windows\system32\ddpd64af3.dll |
|
Details | File | 1 | c:\windows\system32\dax3apoprop.dll |
|
Details | File | 1 | c:\windows\system32\dax3apov251.dll |
|
Details | File | 1 | c:\windows\system32\ddpo64af3.dll |
|
Details | File | 3 | c:\windows\system32\ddpo64a.dll |
|
Details | File | 1 | c:\windows\system32\ddpa64f3.dll |
|
Details | File | 3 | c:\windows\system32\ddpa64.dll |
|
Details | File | 1 | c:\windows\system32\slprp64.dll |
|
Details | File | 3 | c:\windows\system32\r4eep64a.dll |
|
Details | File | 3 | c:\windows\system32\ddpp64a.dll |
|
Details | File | 1 | c:\windows\system32\ddpp64af3.dll |
|
Details | File | 3 | c:\windows\system32\rcoinstii64.dll |
|
Details | File | 3 | c:\windows\system32\dolbydax2apoprop.dll |
|
Details | File | 1 | c:\windows\system32\hmui.dll |
|
Details | File | 3 | c:\windows\system32\hifidax2api.dll |
|
Details | File | 1 | c:\windows\system32\harmanaudiointerface.dll |
|
Details | File | 3 | c:\windows\system32\coneqmsapoguilibrary.dll |
|
Details | File | 1 | c:\windows\system32\acpiservicevna64.dll |
|
Details | File | 1 | c:\windows\system32\audiolibvc.dll |
|
Details | File | 1 | c:\users\you have\downloads\addition.txt |
|
Details | File | 1 | c:\users\you have\downloads\frst.txt |
|
Details | File | 1 | c:\users\masz\downloads\frst64english.exe |
|
Details | File | 1 | c:\users\has\downloads\esetonlinescanner.exe |
|
Details | File | 1 | c:\users\has\downloads\sophosscanandclean_x64.exe |
|
Details | File | 1 | c:\programdata\sophos 2023-03-06 10:04 - 2023-03-06 10:04 - 000004032 _____ c:\windows\system32\tasks\postponedevicesetuptoast_s-1-5-21-1905558373-745742369-245519911-1001_8 2023-03-02 07:18 - 2023-03-02 07:18 - 000057890 _____ c:\users\has\downloads\fv_2023-03-02_07_17_41.pdf |
|
Details | File | 1 | c:\users\has\downloads\fv_2023-03-02_07_17_14.pdf |
|
Details | File | 1 | c:\users\has\downloads\fv_2023-03-02_07_15_55.pdf |
|
Details | File | 1 | c:\users\has\downloads\fv_2023-03-02_07_16_19.pdf |
|
Details | File | 1 | c:\users\your\downloads\fv_2023-02-17_09_48_21.pdf |
|
Details | File | 1 | c:\users\you have\intelgraphicsprofiles 2023-03-08 13:45 - 2020-10-22 14:29 - 001767980 _____ c:\windows\system32\perfstringbackup.ini |
|
Details | File | 1 | c:\windows\system32\perfh015.dat |
|
Details | File | 1 | c:\windows\system32\perfc015.dat |
|
Details | File | 1 | c:\windows\inf 2023-03-08 13:38 - 2020-10-22 14:38 - 000000006 ____h c:\windows\tasks\sa.dat |
|
Details | File | 38 | c:\dumpstack.log |
|
Details | File | 2 | c:\windows\syswow64\abbakconfig.dat |
|
Details | File | 1 | c:\windows\syswow64\winsevr.dat |
|
Details | File | 1 | c:\windows\system32\config\bbi 2023-03-08 12:58 - 2018-10-25 06:48 - 000000000 ____d c:\users\you\appdata\local\d3dscache 2023-03-08 12:57 - 2019-12-07 10:14 - 000000000 ___rd c:\windows\immersivecontrolpanel 2023-03-08 12:57 - 2019-12-07 10:14 - 000000000 ____d c:\windows\systemresources 2023-03-08 12:57 - 2019-12-07 10:14 - 000000000 ____d c:\windows\system32\oobe 2023-03-08 12:57 - 2019-12-07 10:14 - 000000000 ____d c:\windows\bcastdvr 2023-03-08 12:57 - 2019-12-07 10:14 - 000000000 ____d c:\windows\appreadiness 2023-03-08 12:52 - 2019-12-07 10:03 - 000000000 ____d c:\windows\cbstemp 2023-03-08 12:41 - 2017-07-17 08:10 - 000000000 ____d c:\windows\syswow64\rtcom 2023-03-08 11:50 - 2019-12-07 16:10 - 000000000 ____d c:\windows\system32\fxstmp 2023-03-08 11:50 - 2018-03-05 07:50 - 000000000 ____d c:\users\your\desktop\scan invoices 2023-03-08 11:43 - 2014-12-16 13:08 - 000000000 ____d c:\users\your\appdata\roaming\macrobase 2023-03-08 09:43 - 2017-06-07 07:14 - 000000000 ____d c:\programdata\aomeibr 2023-03-08 09:20 - 2017-06-07 07:14 - 000001024 ____h c:\systag.bin |
|
Details | File | 1 | c:\program files\windowsapps 2023-03-08 06:53 - 2020-10-22 14:38 - 000003566 _____ c:\windows\system32\tasks\microsoftedgeupdatetaskmachineua 2023-03-08 06:53 - 2020-10-22 14:38 - 000003442 _____ c:\windows\system32\tasks\microsoftedgeupdatetaskmachinecore 2023-03-07 08:59 - 2014-12-16 12:11 - 000187392 _____ c:\users\your\desktop\mail list.xls |
|
Details | File | 59 | c:\windows\system32\mrt.exe |
|
Details | File | 1 | c:\users\your\desktop\order zec.xls |
|
Details | File | 1 | c:\users\masz\desktop\sm attachment to rebates.xlsx |
|
Details | File | 24 | c:\windows\system32\fntcache.dat |
|
Details | File | 54 | c:\windows\syswow64\printconfig.dll |
|
Details | File | 86 | frst.txt |
|
Details | File | 70 | onedrivesetup.exe |
|
Details | File | 8 | c:\program files\windowsapps\microsoft.bin |
|
Details | File | 18 | c:\program files\windowsapps\microsoft.mpeg |
|
Details | File | 4 | c:\windows\system32\ole32.dll |
|
Details | File | 38 | x64.dll |
|
Details | File | 9 | c:\windows\system32\igfxdtcm.dll |
|
Details | File | 1 | vcomp.dll |
|
Details | File | 3 | c:\program files\microsoft office 15\root\vfs\programfilesx64\microsoft office\office15\ochelper.dll |
|
Details | File | 3 | c:\program files\microsoft office 15\root\vfs\programfilesx64\microsoft office\office15\grooveex.dll |
|
Details | File | 3 | c:\program files\microsoft office 15\root\office15\msosb.dll |
|
Details | File | 24 | c:\windows\web\wallpaper\windows\img0.jpg |
|
Details | File | 1 | c:\macrologic\system\jterm\miscw\jrew\bin\javaw.exe |
|
Details | File | 1 | c:\macrologic\system\jterm\ miscw\jrew\bin\javaw.exe |
|
Details | File | 1 | c:\windows\syswow64\javaw.exe |
|
Details | File | 2 | c:\program files\microsoft office 15\root\office15\outlook.exe |
|
Details | File | 1 | c:\merit\system\jterm\miscw\jrew\bin\javaw.exe |
|
Details | File | 1 | c:\merit\system\jterm\ miscw\jrew\bin\javaw.exe |
|
Details | File | 87 | skype.exe |
|
Details | File | 76 | msedgewebview2.exe |
|
Details | File | 92 | c:\windows\system32\svchost.exe |
|
Details | File | 63 | thunderbird.exe |
|
Details | File | 1 | c:\users\has\appdata\local\temp\ehdrv.sys |
|
Details | File | 1 | c:\users\you\appdata\roaming\10130.vbs |
|
Details | File | 1 | c:\users\have\appdata\roaming\1194.vbs |
|
Details | File | 1 | c:\users\have\appdata\roaming\1752.vbs |
|
Details | File | 1 | c:\users\have\appdata\roaming\1896.vbs |
|
Details | File | 1 | c:\users\have\appdata\roaming\9435.vbs |
|
Details | File | 1 | c:\users\have\appdata\roaming\9572.vbs |
|
Details | File | 1 | c:\users\you have\appdata\roaming\9784.vbs |
|
Details | File | 1 | c:\users\has\downloads\frst64.exe |
|
Details | File | 1 | c:\users\you have\appdata\roaming\9572.vbs |
|
Details | File | 1 | c:\users\you have\appdata\roaming\9435.vbs |
|
Details | File | 1 | c:\users\you have\appdata\roaming\1896.vbs |
|
Details | File | 1 | c:\users\you have\appdata\roaming\1752.vbs |
|
Details | File | 1 | com-1.pl |
|
Details | File | 3 | zaplata.jpeg |
|
Details | File | 2 | jpeg.exe |
|
Details | File | 1 | datils.zip |
|
Details | File | 1 | zubby.exe |
|
Details | File | 1 | detail.zip |
|
Details | File | 1 | zaplata_112020.jpeg |
|
Details | File | 91 | addition.txt |
|
Details | sha1 | 1 | a1909296681c7acefe45687d3a64758c8659bf46 |
|
Details | IPv4 | 1 | 156.17.24.240 |
|
Details | IPv4 | 295 | 8.8.8.8 |
|
Details | IPv4 | 63 | 8.8.4.4 |
|
Details | IPv4 | 1 | 32.0.0.89 |
|
Details | IPv4 | 2 | 1.31.8.1 |
|
Details | IPv4 | 8 | 3.70.0.0 |
|
Details | IPv4 | 6 | 8.91.0.0 |
|
Details | IPv4 | 4 | 1.19.0.0 |
|
Details | IPv4 | 619 | 0.0.0.0 |
|
Details | IPv4 | 1 | 102.8.0.0 |
|
Details | IPv4 | 3 | 10.1.1.38 |
|
Details | Microsoft Patch Numbers | 21 | KB5001716 |
|
Details | Url | 1 | https://www.google.pl |
|
Details | Url | 1 | https://www.garneczki.pl |
|
Details | Url | 1 | https://go.microsoft.com/fwlink/?linkid=37020&name=trojandownloader |
|
Details | Url | 2 | https://go.microsoft.com/fwlink/?linkid=37020&name=trojan:win32 |
|
Details | Url | 2 | https://go.microsoft.com/fwlink/?linkid=37020&name |
|
Details | Windows Registry Key | 68 | HKLM\...\Run |
|
Details | Windows Registry Key | 50 | HKLM-x32\...\Run |
|
Details | Windows Registry Key | 19 | HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate |
|
Details | Windows Registry Key | 1 | HKU\S-1-5-21-1905558373-745742369-245519911-1001\...\Run |
|
Details | Windows Registry Key | 1 | HKLM\...\Print\Monitors\423SeriesPCL-8 |
|
Details | Windows Registry Key | 1 | HKLM\...\Print\Monitors\Panasonic |
|
Details | Windows Registry Key | 1 | HKLM\...\Print\Monitors\PDF-XChange5-ABBYY-FR |
|
Details | Windows Registry Key | 1 | HKU\S-1-5-21-1905558373-745742369-245519911-1001 |
|
Details | Windows Registry Key | 77 | HKLM-x32 |
|
Details | Windows Registry Key | 18 | HKLM-x32\...\Adobe |
|
Details | Windows Registry Key | 1 | HKLM-x32\...\MP |
|
Details | Windows Registry Key | 1 | HKLM-x32\...\e-Declarations.A1909296681C7ACEFE45687D3A64758C8659BF46.1 |
|
Details | Windows Registry Key | 6 | HKLM\...\IrfanView64 |
|
Details | Windows Registry Key | 1 | HKLM-x32\...\jTerm |
|
Details | Windows Registry Key | 1 | HKLM-x32\...\Macrologic |
|
Details | Windows Registry Key | 68 | HKLM-x32\...\Microsoft |
|
Details | Windows Registry Key | 1 | HKLM\...\HomeBusinessRetail |
|
Details | Windows Registry Key | 1 | HKU\S-1-5-21-1905558373-745742369-245519911-1001\...\OneDriveSetup.exe |
|
Details | Windows Registry Key | 10 | HKLM\...\Microsoft |
|
Details | Windows Registry Key | 2 | HKLM-x32\...\MozillaMaintenanceService |
|
Details | Windows Registry Key | 5 | HKLM-x32\...\Mozilla |
|
Details | Windows Registry Key | 1 | HKU\S-1-5-21-1905558373-745742369-245519911-1001\...\Opera |
|
Details | Windows Registry Key | 3 | HKLM-x32\...\WinLiveSuite |
|
Details | Windows Registry Key | 19 | HKLM-x32\...\InstallShield_ |
|
Details | Windows Registry Key | 1 | HKU\S-1-5-21-1905558373-745742369-245519911-1001_Classes\CLSID |
|
Details | Windows Registry Key | 41 | HKLM\System\CurrentControlSet\Control\Session |
|
Details | Windows Registry Key | 1 | HKU\S-1-5-21-1905558373-745742369-245519911-1001\Control |
|
Details | Windows Registry Key | 98 | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
|
Details | Windows Registry Key | 42 | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
|
Details | Windows Registry Key | 30 | HKLM\...\StartupApproved\Run32 |
|
Details | Domain | 285 | microsoft.net |
|
Details | Domain | 4 | www.google.pl |
|
Details | Domain | 1 | www.garneczki.pl |
|
Details | Domain | 368 | microsoft.com |
|
Details | Domain | 8 | intel-webapi.intel.com |
|
Details | Domain | 87 | regid.1991-06.com.microsoft |
|
Details | Domain | 9 | king.com |
|
Details | Domain | 50 | microsoft.photos |
|
Details | Domain | 64 | go.microsoft.com |
|
Details | Domain | 1 | datils.zip |
|
Details | Domain | 1 | detail.zip |
|
Details | Domain | 1 | agenttesla.sm |
|
Details | File | 1260 | explorer.exe |
|
Details | File | 128 | msedge.exe |
|
Details | File | 15 | c:\program files\realtek\audio\hda\rtkngui64.exe |
|
Details | File | 7 | c:\windows\system32\igfxtray.exe |
|
Details | File | 8 | c:\windows\system32\igfxem.exe |
|
Details | File | 8 | c:\windows\system32\igfxhk.exe |
|
Details | File | 1 | dmwakeup.exe |
|
Details | File | 1 | pccmfsdm.exe |
|
Details | File | 306 | services.exe |
|
Details | File | 1 | networklicenseserver.exe |
|
Details | File | 38 | armsvc.exe |
|
Details | File | 3 | abservice.exe |
|
Details | File | 41 | jhi_service.exe |
|
Details | File | 26 | lms.exe |
|
Details | File | 4 | c:\program files\intel\icls client\heciserver.exe |
|
Details | File | 9 | c:\windows\system32\igfxcuiservice.exe |
|
Details | File | 3 | c:\program files\microsoft office 15\clientx64\officeclicktorun.exe |
|
Details | File | 27 | presentationfontcache.exe |
|
Details | File | 198 | msmpeng.exe |
|
Details | File | 87 | nissrv.exe |
|
Details | File | 1 | lmsrvnt.exe |
|
Details | File | 1 | trapmnnt.exe |
|
Details | File | 1122 | svchost.exe |
|
Details | File | 12 | cortana.exe |
|
Details | File | 27 | phoneexperiencehost.exe |
|
Details | File | 23 | c:\windows\system32\mousocoreworker.exe |
|
Details | File | 67 | c:\windows\system32\smartscreen.exe |
|
Details | File | 14 | c:\windows\syswow64\dllhost.exe |
|
Details | File | 21 | tiworker.exe |
|
Details | File | 1 | kmpcfax.exe |
|
Details | File | 1 | mfssecprt.exe |
|
Details | File | 1 | c:\windows\system32\koayfj_l.dll |
|
Details | File | 1 | c:\windows\system32\panewm64.dll |
|
Details | File | 1 | c:\windows\system32\zdglic36.dll |
|
Details | File | 1 | c:\windows\system32\pcmfsfxlmon.dll |
|
Details | File | 1 | c:\windows\system32\pxc50pmaf.dll |
|
Details | File | 1 | c:\users\masz\appdata\roaming\microsoft\windows\start menu\programs\startup\x.vbs |
|
Details | File | 3 | c:\program files\microsoft office 15\clientx64\officec2rclient.exe |
|
Details | File | 1 | c:\windows\browserchoice\browserchoice.exe |
|
Details | File | 1 | c:\windows\system32\autoworkplace.exe |
|
Details | File | 42 | adobearm.exe |
|
Details | File | 99 | c:\windows\explorer.exe |
|
Details | File | 6 | google.pl |
|
Details | File | 1 | garneczki.pl |
|
Details | File | 6 | npctrl.dll |
|
Details | File | 19 | c:\program files\adobe\acrobat dc\acrobat\air\nppdf32.dll |
|
Details | File | 8 | npintelwebapiipt.dll |
|
Details | File | 8 | npintelwebapiupdater.dll |
|
Details | File | 3 | c:\program files\microsoft office 15\root\office15\npspwrap.dll |
|
Details | File | 3 | npwlpg.dll |
|
Details | File | 2 | c:\windows\system32\ambakdrv.sys |
|
Details | File | 2 | c:\windows\system32\ammntdrv.sys |
|
Details | File | 2 | c:\windows\system32\amwrtdrv.sys |
|
Details | File | 26 | c:\windows\system32\drivers\btha2dp.sys |
|
Details | File | 22 | c:\windows\system32\drivers\bthhfenum.sys |
|
Details | File | 39 | mpksldrv.sys |
|
Details | File | 70 | c:\windows\system32\drivers\wd\wdboot.sys |
|
Details | File | 70 | c:\windows\system32\drivers\wd\wdfilter.sys |
|
Details | File | 70 | c:\windows\system32\drivers\wd\wdnisdrv.sys |
|
Details | File | 1 | c:\windows\system32\yamahaae2.dll |
|
Details | File | 1 | c:\windows\system32\yamahaae.dll |
|
Details | File | 1 | c:\windows\system32\slcnt64.dll |
|
Details | File | 1 | c:\windows\system32\sltech64.dll |
|
Details | File | 1 | c:\windows\system32\srrptr64.dll |
|
Details | File | 1 | c:\windows\system32\tosade.dll |
|
Details | File | 1 | c:\windows\system32\tossaeapo64.dll |
|
Details | File | 1 | c:\windows\system32\sl3apo64.dll |
|
Details | File | 1 | c:\windows\system32\tadefxapo264.dll |
|
Details | File | 1 | c:\windows\system32\tosasfapo64.dll |
|
Details | File | 1 | c:\windows\system32\tossaemapo64.dll |
|
Details | File | 1 | c:\windows\system32\srstsx64.dll |
|
Details | File | 1 | c:\windows\system32\srapo64.dll |
|
Details | File | 1 | c:\windows\system32\toseaeapo64.dll |
|
Details | File | 1 | c:\windows\system32\srcom64.dll |
|
Details | File | 1 | c:\windows\syswow64\srcom.dll |
|
Details | File | 1 | c:\windows\system32\srcom.dll |
|
Details | File | 1 | c:\windows\system32\srstsh64.dll |
|
Details | File | 1 | c:\windows\system32\srshp64.dll |
|
Details | File | 1 | c:\windows\system32\srswow64.dll |
|
Details | File | 1 | c:\windows\system32\tadefxapo.dll |
|
Details | File | 1 | c:\windows\system32\tepeqapo64.dll |
|
Details | File | 1 | c:\windows\system32\sehdhf64.dll |
|
Details | File | 1 | c:\windows\system32\sfss_apo.dll |
|
Details | File | 1 | c:\windows\syswow64\sehdhf32.dll |
|
Details | File | 1 | c:\windows\system32\secomn64.dll |
|
Details | File | 1 | c:\windows\system32\sehdra64.dll |
|
Details | File | 1 | c:\windows\syswow64\secomn32.dll |
|
Details | File | 1 | c:\windows\system32\seapo64.dll |
|
Details | File | 3 | c:\windows\system32\rtlcpapi64.dll |
|
Details | File | 1 | c:\windows\system32\sfnhk64.dll |
|
Details | File | 1 | c:\windows\system32\sfcom64.dll |
|
Details | File | 1 | c:\windows\system32\sfapo64.dll |
|
Details | File | 1 | c:\windows\syswow64\sfcom.dll |
|
Details | File | 3 | c:\windows\system32\rltkapo64.dll |
|
Details | File | 1 | c:\windows\syswow64\rltkapo.dll |
|
Details | File | 5 | c:\windows\system32\rtcom64.dll |
|
Details | File | 3 | c:\windows\system32\rtdataproc64.dll |
|
Details | File | 3 | c:\windows\system32\r4eed64a.dll |
|
Details | File | 1 | c:\windows\system32\rteep64a.dll |
|
Details | File | 1 | c:\windows\system32\rp3daa64.dll |
|
Details | File | 1 | c:\windows\system32\rp3dht64.dll |
|
Details | File | 1 | c:\windows\system32\rteed64a.dll |
|
Details | File | 3 | c:\windows\system32\r4eel64a.dll |
|
Details | File | 3 | c:\windows\system32\r4eea64a.dll |
|
Details | File | 1 | c:\windows\system32\rteel64a.dll |
|
Details | File | 1 | c:\windows\system32\rteeg64a.dll |
|
Details | File | 3 | c:\windows\system32\r4eeg64a.dll |
|
Details | File | 3 | c:\windows\system32\dolbydax2apov211.dll |
|
Details | File | 1 | c:\windows\system32\dtss2speakerdll64.dll |
|
Details | File | 1 | c:\windows\system32\dtss2headphonedll64.dll |
|
Details | File | 1 | c:\windows\system32\dtsboostdll64.dll |
|
Details | File | 1 | c:\windows\system32\dolbydax2apovlldp.dll |
|
Details | File | 1 | c:\windows\system32\dtsbassenhancementdll64.dll |
|
Details | File | 1 | c:\windows\system32\dtssymmetrydll64.dll |
|
Details | File | 1 | c:\windows\system32\dtsvoiceclaritydll64.dll |
|
Details | File | 1 | c:\windows\system32\icesoundapo64.dll |
|
Details | File | 1 | c:\windows\system32\dtsneopcdll64.dll |
|
Details | File | 1 | c:\windows\system32\dtslimiterdll64.dll |