Dynamic Analysis Report |
Classification: Trojan, Dropper, Ransomware |
47f5a231f7cd0e36508ca6ff8c21c08a7248f0f2bd79c1e772b73443597b09b4 (SHA256)
CUsersSonyAppDataLocalTemphvwfcsky8521.exe
Created 6 years ago
Notifications (2/2)
Every analysis has a preconfigured maximum VM disk size for temporary changes. This limit was reached during this analysis and, as an result, the analysis was terminated prematurely.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
Remarks
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CUsersSonyAppDataLocalTemphvwfcsky8521.exe | Sample File | Binary |
Suspicious
|
...
|
Severity |
Suspicious
|
First Seen | 2019-02-05 14:27 (UTC+1) |
Last Seen | 2019-02-08 22:41 (UTC+1) |
Names | Win32.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x4986d4 |
Size Of Code | 0xe3e00 |
Size Of Initialized Data | 0x54600 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2019-02-03 17:48:37+00:00 |
LegalCopyright | Copyright (C) KITTY'S LTD 2019 |
InternalName | hvwfcsky |
FileVersion | 1.2.0.0 |
CompanyName | KITTY'S LTD |
ProductName | Service hvwfcsky |
ProductVersion | 1.2.0.0 |
FileDescription | Host Process for Windows Tasks |
OriginalFilename | hvwfcsky |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xe3df2 | 0xe3e00 | 0x400 | cnt_code, mem_execute, mem_read | 6.62 |
.rdata | 0x4e5000 | 0x37ada | 0x37c00 | 0xe4200 | cnt_initialized_data, mem_read | 4.94 |
.data | 0x51d000 | 0xd020 | 0xaa00 | 0x11be00 | cnt_initialized_data, mem_read, mem_write | 4.94 |
.rsrc | 0x52b000 | 0x518 | 0x600 | 0x126800 | cnt_initialized_data, mem_read | 3.74 |
.reloc | 0x52c000 | 0xf194 | 0xf200 | 0x126e00 | cnt_initialized_data, mem_discardable, mem_read | 6.56 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathIsNetworkPathA | 0x0 | 0x4e5294 | 0x11bdc8 | 0x11afc8 | 0x60 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseHandle | 0x0 | 0x4e5018 | 0x11bb4c | 0x11ad4c | 0x52 |
DuplicateHandle | 0x0 | 0x4e501c | 0x11bb50 | 0x11ad50 | 0xe8 |
UnmapViewOfFile | 0x0 | 0x4e5020 | 0x11bb54 | 0x11ad54 | 0x4d6 |
CreateFileMappingA | 0x0 | 0x4e5024 | 0x11bb58 | 0x11ad58 | 0x89 |
MapViewOfFileEx | 0x0 | 0x4e5028 | 0x11bb5c | 0x11ad5c | 0x358 |
CreateFileA | 0x0 | 0x4e502c | 0x11bb60 | 0x11ad60 | 0x88 |
GetSystemInfo | 0x0 | 0x4e5030 | 0x11bb64 | 0x11ad64 | 0x273 |
FormatMessageA | 0x0 | 0x4e5034 | 0x11bb68 | 0x11ad68 | 0x15d |
LocalFree | 0x0 | 0x4e5038 | 0x11bb6c | 0x11ad6c | 0x348 |
GetProcAddress | 0x0 | 0x4e503c | 0x11bb70 | 0x11ad70 | 0x245 |
GetModuleHandleA | 0x0 | 0x4e5040 | 0x11bb74 | 0x11ad74 | 0x215 |
GetExitCodeProcess | 0x0 | 0x4e5044 | 0x11bb78 | 0x11ad78 | 0x1df |
CreateProcessW | 0x0 | 0x4e5048 | 0x11bb7c | 0x11ad7c | 0xa8 |
TerminateProcess | 0x0 | 0x4e504c | 0x11bb80 | 0x11ad80 | 0x4c0 |
WaitForSingleObjectEx | 0x0 | 0x4e5050 | 0x11bb84 | 0x11ad84 | 0x4fa |
WaitForSingleObject | 0x0 | 0x4e5054 | 0x11bb88 | 0x11ad88 | 0x4f9 |
CreateEventA | 0x0 | 0x4e5058 | 0x11bb8c | 0x11ad8c | 0x82 |
SetEvent | 0x0 | 0x4e505c | 0x11bb90 | 0x11ad90 | 0x459 |
CreateSemaphoreA | 0x0 | 0x4e5060 | 0x11bb94 | 0x11ad94 | 0xab |
ReleaseSemaphore | 0x0 | 0x4e5064 | 0x11bb98 | 0x11ad98 | 0x3fe |
AreFileApisANSI | 0x0 | 0x4e5068 | 0x11bb9c | 0x11ad9c | 0x15 |
ReadFile | 0x0 | 0x4e506c | 0x11bba0 | 0x11ada0 | 0x3c0 |
WriteFile | 0x0 | 0x4e5070 | 0x11bba4 | 0x11ada4 | 0x525 |
MultiByteToWideChar | 0x0 | 0x4e5074 | 0x11bba8 | 0x11ada8 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4e5078 | 0x11bbac | 0x11adac | 0x511 |
GetSystemDirectoryW | 0x0 | 0x4e507c | 0x11bbb0 | 0x11adb0 | 0x270 |
CreatePipe | 0x0 | 0x4e5080 | 0x11bbb4 | 0x11adb4 | 0xa1 |
SetHandleInformation | 0x0 | 0x4e5084 | 0x11bbb8 | 0x11adb8 | 0x470 |
GetProcessHeap | 0x0 | 0x4e5088 | 0x11bbbc | 0x11adbc | 0x24a |
HeapAlloc | 0x0 | 0x4e508c | 0x11bbc0 | 0x11adc0 | 0x2cb |
GetCurrentProcess | 0x0 | 0x4e5090 | 0x11bbc4 | 0x11adc4 | 0x1c0 |
GetLogicalDriveStringsW | 0x0 | 0x4e5094 | 0x11bbc8 | 0x11adc8 | 0x208 |
GetCommandLineW | 0x0 | 0x4e5098 | 0x11bbcc | 0x11adcc | 0x187 |
GetDriveTypeW | 0x0 | 0x4e509c | 0x11bbd0 | 0x11add0 | 0x1d3 |
GetWindowsDirectoryW | 0x0 | 0x4e50a0 | 0x11bbd4 | 0x11add4 | 0x2af |
Wow64DisableWow64FsRedirection | 0x0 | 0x4e50a4 | 0x11bbd8 | 0x11add8 | 0x513 |
Wow64RevertWow64FsRedirection | 0x0 | 0x4e50a8 | 0x11bbdc | 0x11addc | 0x517 |
QueryPerformanceCounter | 0x0 | 0x4e50ac | 0x11bbe0 | 0x11ade0 | 0x3a7 |
QueryPerformanceFrequency | 0x0 | 0x4e50b0 | 0x11bbe4 | 0x11ade4 | 0x3a8 |
ResetEvent | 0x0 | 0x4e50b4 | 0x11bbe8 | 0x11ade8 | 0x40f |
WaitForMultipleObjectsEx | 0x0 | 0x4e50b8 | 0x11bbec | 0x11adec | 0x4f8 |
OpenEventA | 0x0 | 0x4e50bc | 0x11bbf0 | 0x11adf0 | 0x374 |
SetWaitableTimer | 0x0 | 0x4e50c0 | 0x11bbf4 | 0x11adf4 | 0x4ac |
GetCurrentProcessId | 0x0 | 0x4e50c4 | 0x11bbf8 | 0x11adf8 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x4e50c8 | 0x11bbfc | 0x11adfc | 0x1c5 |
ResumeThread | 0x0 | 0x4e50cc | 0x11bc00 | 0x11ae00 | 0x413 |
TlsAlloc | 0x0 | 0x4e50d0 | 0x11bc04 | 0x11ae04 | 0x4c5 |
TlsGetValue | 0x0 | 0x4e50d4 | 0x11bc08 | 0x11ae08 | 0x4c7 |
TlsSetValue | 0x0 | 0x4e50d8 | 0x11bc0c | 0x11ae0c | 0x4c8 |
TlsFree | 0x0 | 0x4e50dc | 0x11bc10 | 0x11ae10 | 0x4c6 |
CreateWaitableTimerA | 0x0 | 0x4e50e0 | 0x11bc14 | 0x11ae14 | 0xbf |
SetLastError | 0x0 | 0x4e50e4 | 0x11bc18 | 0x11ae18 | 0x473 |
GetCurrentThread | 0x0 | 0x4e50e8 | 0x11bc1c | 0x11ae1c | 0x1c4 |
GetThreadTimes | 0x0 | 0x4e50ec | 0x11bc20 | 0x11ae20 | 0x291 |
FindNextFileA | 0x0 | 0x4e50f0 | 0x11bc24 | 0x11ae24 | 0x143 |
FindFirstFileExA | 0x0 | 0x4e50f4 | 0x11bc28 | 0x11ae28 | 0x133 |
GetTimeZoneInformation | 0x0 | 0x4e50f8 | 0x11bc2c | 0x11ae2c | 0x298 |
HeapSize | 0x0 | 0x4e50fc | 0x11bc30 | 0x11ae30 | 0x2d4 |
FreeEnvironmentStringsW | 0x0 | 0x4e5100 | 0x11bc34 | 0x11ae34 | 0x161 |
GetLastError | 0x0 | 0x4e5104 | 0x11bc38 | 0x11ae38 | 0x202 |
SwitchToThread | 0x0 | 0x4e5108 | 0x11bc3c | 0x11ae3c | 0x4bc |
Sleep | 0x0 | 0x4e510c | 0x11bc40 | 0x11ae40 | 0x4b2 |
WriteConsoleW | 0x0 | 0x4e5110 | 0x11bc44 | 0x11ae44 | 0x524 |
HeapFree | 0x0 | 0x4e5114 | 0x11bc48 | 0x11ae48 | 0x2cf |
GetStringTypeW | 0x0 | 0x4e5118 | 0x11bc4c | 0x11ae4c | 0x269 |
FormatMessageW | 0x0 | 0x4e511c | 0x11bc50 | 0x11ae50 | 0x15e |
GetExitCodeThread | 0x0 | 0x4e5120 | 0x11bc54 | 0x11ae54 | 0x1e0 |
EnterCriticalSection | 0x0 | 0x4e5124 | 0x11bc58 | 0x11ae58 | 0xee |
LeaveCriticalSection | 0x0 | 0x4e5128 | 0x11bc5c | 0x11ae5c | 0x339 |
TryEnterCriticalSection | 0x0 | 0x4e512c | 0x11bc60 | 0x11ae60 | 0x4ce |
DeleteCriticalSection | 0x0 | 0x4e5130 | 0x11bc64 | 0x11ae64 | 0xd1 |
CreateFileW | 0x0 | 0x4e5134 | 0x11bc68 | 0x11ae68 | 0x8f |
FindClose | 0x0 | 0x4e5138 | 0x11bc6c | 0x11ae6c | 0x12e |
FindFirstFileExW | 0x0 | 0x4e513c | 0x11bc70 | 0x11ae70 | 0x134 |
FindNextFileW | 0x0 | 0x4e5140 | 0x11bc74 | 0x11ae74 | 0x145 |
GetDiskFreeSpaceExW | 0x0 | 0x4e5144 | 0x11bc78 | 0x11ae78 | 0x1ce |
GetFileAttributesExW | 0x0 | 0x4e5148 | 0x11bc7c | 0x11ae7c | 0x1e7 |
GetFileInformationByHandle | 0x0 | 0x4e514c | 0x11bc80 | 0x11ae80 | 0x1ec |
SetEndOfFile | 0x0 | 0x4e5150 | 0x11bc84 | 0x11ae84 | 0x453 |
SetFileAttributesW | 0x0 | 0x4e5154 | 0x11bc88 | 0x11ae88 | 0x461 |
SetFilePointerEx | 0x0 | 0x4e5158 | 0x11bc8c | 0x11ae8c | 0x467 |
GetTempPathW | 0x0 | 0x4e515c | 0x11bc90 | 0x11ae90 | 0x285 |
DeleteFileW | 0x0 | 0x4e5160 | 0x11bc94 | 0x11ae94 | 0xd6 |
GetFileAttributesW | 0x0 | 0x4e5164 | 0x11bc98 | 0x11ae98 | 0x1ea |
RemoveDirectoryW | 0x0 | 0x4e5168 | 0x11bc9c | 0x11ae9c | 0x403 |
GetModuleHandleW | 0x0 | 0x4e516c | 0x11bca0 | 0x11aea0 | 0x218 |
MoveFileExW | 0x0 | 0x4e5170 | 0x11bca4 | 0x11aea4 | 0x360 |
GetCPInfo | 0x0 | 0x4e5174 | 0x11bca8 | 0x11aea8 | 0x172 |
EncodePointer | 0x0 | 0x4e5178 | 0x11bcac | 0x11aeac | 0xea |
DecodePointer | 0x0 | 0x4e517c | 0x11bcb0 | 0x11aeb0 | 0xca |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4e5180 | 0x11bcb4 | 0x11aeb4 | 0x2e3 |
CreateEventW | 0x0 | 0x4e5184 | 0x11bcb8 | 0x11aeb8 | 0x85 |
GetSystemTimeAsFileTime | 0x0 | 0x4e5188 | 0x11bcbc | 0x11aebc | 0x279 |
GetTickCount | 0x0 | 0x4e518c | 0x11bcc0 | 0x11aec0 | 0x293 |
CompareStringW | 0x0 | 0x4e5190 | 0x11bcc4 | 0x11aec4 | 0x64 |
LCMapStringW | 0x0 | 0x4e5194 | 0x11bcc8 | 0x11aec8 | 0x32d |
GetLocaleInfoW | 0x0 | 0x4e5198 | 0x11bccc | 0x11aecc | 0x206 |
InitializeSListHead | 0x0 | 0x4e519c | 0x11bcd0 | 0x11aed0 | 0x2e7 |
IsProcessorFeaturePresent | 0x0 | 0x4e51a0 | 0x11bcd4 | 0x11aed4 | 0x304 |
IsDebuggerPresent | 0x0 | 0x4e51a4 | 0x11bcd8 | 0x11aed8 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x4e51a8 | 0x11bcdc | 0x11aedc | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4e51ac | 0x11bce0 | 0x11aee0 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x4e51b0 | 0x11bce4 | 0x11aee4 | 0x263 |
CreateTimerQueue | 0x0 | 0x4e51b4 | 0x11bce8 | 0x11aee8 | 0xbc |
SignalObjectAndWait | 0x0 | 0x4e51b8 | 0x11bcec | 0x11aeec | 0x4b0 |
CreateThread | 0x0 | 0x4e51bc | 0x11bcf0 | 0x11aef0 | 0xb5 |
SetThreadPriority | 0x0 | 0x4e51c0 | 0x11bcf4 | 0x11aef4 | 0x499 |
GetThreadPriority | 0x0 | 0x4e51c4 | 0x11bcf8 | 0x11aef8 | 0x28e |
GetLogicalProcessorInformation | 0x0 | 0x4e51c8 | 0x11bcfc | 0x11aefc | 0x20a |
CreateTimerQueueTimer | 0x0 | 0x4e51cc | 0x11bd00 | 0x11af00 | 0xbd |
ChangeTimerQueueTimer | 0x0 | 0x4e51d0 | 0x11bd04 | 0x11af04 | 0x48 |
DeleteTimerQueueTimer | 0x0 | 0x4e51d4 | 0x11bd08 | 0x11af08 | 0xda |
GetNumaHighestNodeNumber | 0x0 | 0x4e51d8 | 0x11bd0c | 0x11af0c | 0x229 |
GetProcessAffinityMask | 0x0 | 0x4e51dc | 0x11bd10 | 0x11af10 | 0x246 |
SetThreadAffinityMask | 0x0 | 0x4e51e0 | 0x11bd14 | 0x11af14 | 0x490 |
RegisterWaitForSingleObject | 0x0 | 0x4e51e4 | 0x11bd18 | 0x11af18 | 0x3f5 |
UnregisterWait | 0x0 | 0x4e51e8 | 0x11bd1c | 0x11af1c | 0x4da |
FreeLibrary | 0x0 | 0x4e51ec | 0x11bd20 | 0x11af20 | 0x162 |
FreeLibraryAndExitThread | 0x0 | 0x4e51f0 | 0x11bd24 | 0x11af24 | 0x163 |
GetModuleFileNameW | 0x0 | 0x4e51f4 | 0x11bd28 | 0x11af28 | 0x214 |
LoadLibraryExW | 0x0 | 0x4e51f8 | 0x11bd2c | 0x11af2c | 0x33e |
GetVersionExW | 0x0 | 0x4e51fc | 0x11bd30 | 0x11af30 | 0x2a4 |
VirtualAlloc | 0x0 | 0x4e5200 | 0x11bd34 | 0x11af34 | 0x4e9 |
VirtualProtect | 0x0 | 0x4e5204 | 0x11bd38 | 0x11af38 | 0x4ef |
VirtualFree | 0x0 | 0x4e5208 | 0x11bd3c | 0x11af3c | 0x4ec |
InterlockedPopEntrySList | 0x0 | 0x4e520c | 0x11bd40 | 0x11af40 | 0x2f0 |
InterlockedPushEntrySList | 0x0 | 0x4e5210 | 0x11bd44 | 0x11af44 | 0x2f1 |
InterlockedFlushSList | 0x0 | 0x4e5214 | 0x11bd48 | 0x11af48 | 0x2ee |
QueryDepthSList | 0x0 | 0x4e5218 | 0x11bd4c | 0x11af4c | 0x39e |
UnregisterWaitEx | 0x0 | 0x4e521c | 0x11bd50 | 0x11af50 | 0x4db |
LoadLibraryW | 0x0 | 0x4e5220 | 0x11bd54 | 0x11af54 | 0x33f |
RaiseException | 0x0 | 0x4e5224 | 0x11bd58 | 0x11af58 | 0x3b1 |
RtlUnwind | 0x0 | 0x4e5228 | 0x11bd5c | 0x11af5c | 0x418 |
GetCommandLineA | 0x0 | 0x4e522c | 0x11bd60 | 0x11af60 | 0x186 |
ExitThread | 0x0 | 0x4e5230 | 0x11bd64 | 0x11af64 | 0x11a |
GetModuleHandleExW | 0x0 | 0x4e5234 | 0x11bd68 | 0x11af68 | 0x217 |
SetEnvironmentVariableA | 0x0 | 0x4e5238 | 0x11bd6c | 0x11af6c | 0x456 |
ExitProcess | 0x0 | 0x4e523c | 0x11bd70 | 0x11af70 | 0x119 |
GetModuleFileNameA | 0x0 | 0x4e5240 | 0x11bd74 | 0x11af74 | 0x213 |
GetStdHandle | 0x0 | 0x4e5244 | 0x11bd78 | 0x11af78 | 0x264 |
GetACP | 0x0 | 0x4e5248 | 0x11bd7c | 0x11af7c | 0x168 |
HeapReAlloc | 0x0 | 0x4e524c | 0x11bd80 | 0x11af80 | 0x2d2 |
GetDateFormatW | 0x0 | 0x4e5250 | 0x11bd84 | 0x11af84 | 0x1c8 |
GetTimeFormatW | 0x0 | 0x4e5254 | 0x11bd88 | 0x11af88 | 0x297 |
IsValidLocale | 0x0 | 0x4e5258 | 0x11bd8c | 0x11af8c | 0x30c |
GetUserDefaultLCID | 0x0 | 0x4e525c | 0x11bd90 | 0x11af90 | 0x29b |
EnumSystemLocalesW | 0x0 | 0x4e5260 | 0x11bd94 | 0x11af94 | 0x10f |
GetFileType | 0x0 | 0x4e5264 | 0x11bd98 | 0x11af98 | 0x1f3 |
FlushFileBuffers | 0x0 | 0x4e5268 | 0x11bd9c | 0x11af9c | 0x157 |
GetConsoleCP | 0x0 | 0x4e526c | 0x11bda0 | 0x11afa0 | 0x19a |
GetConsoleMode | 0x0 | 0x4e5270 | 0x11bda4 | 0x11afa4 | 0x1ac |
ReadConsoleW | 0x0 | 0x4e5274 | 0x11bda8 | 0x11afa8 | 0x3be |
SetStdHandle | 0x0 | 0x4e5278 | 0x11bdac | 0x11afac | 0x487 |
IsValidCodePage | 0x0 | 0x4e527c | 0x11bdb0 | 0x11afb0 | 0x30a |
GetOEMCP | 0x0 | 0x4e5280 | 0x11bdb4 | 0x11afb4 | 0x237 |
GetEnvironmentStringsW | 0x0 | 0x4e5284 | 0x11bdb8 | 0x11afb8 | 0x1da |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFolderPathW | 0x0 | 0x4e528c | 0x11bdc0 | 0x11afc0 | 0xc3 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoCreateInstance | 0x0 | 0x4e529c | 0x11bdd0 | 0x11afd0 | 0x10 |
CoUninitialize | 0x0 | 0x4e52a0 | 0x11bdd4 | 0x11afd4 | 0x6c |
CoInitialize | 0x0 | 0x4e52a4 | 0x11bdd8 | 0x11afd8 | 0x3e |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptReleaseContext | 0x0 | 0x4e5000 | 0x11bb34 | 0x11ad34 | 0xcb |
CryptAcquireContextA | 0x0 | 0x4e5004 | 0x11bb38 | 0x11ad38 | 0xb0 |
SetSecurityDescriptorDacl | 0x0 | 0x4e5008 | 0x11bb3c | 0x11ad3c | 0x2b6 |
InitializeSecurityDescriptor | 0x0 | 0x4e500c | 0x11bb40 | 0x11ad40 | 0x177 |
CryptGenRandom | 0x0 | 0x4e5010 | 0x11bb44 | 0x11ad44 | 0xc1 |
Issued by | KITTY'S LTD |
Parent Certificate | Sectigo RSA Code Signing CA |
Country Name | GB |
Valid From | 2019-02-01 00:00:00+00:00 |
Valid Until | 2020-02-01 23:59:59+00:00 |
Algorithm | sha256_rsa |
Serial Number | 37 8D 55 43 04 8E 58 3A 06 A0 81 9F 25 BD 9E 85 |
Thumbprint | CF 93 3A 62 95 98 E5 E1 92 DA 20 86 E6 11 0A D1 97 4F 8E C3 |
Issued by | Sectigo RSA Code Signing CA |
Parent Certificate | USERTrust RSA Certification Authority |
Country Name | GB |
Valid From | 2018-11-02 00:00:00+00:00 |
Valid Until | 2030-12-31 23:59:59+00:00 |
Algorithm | sha384_rsa |
Serial Number | 1D A2 48 30 6F 9B 26 18 D0 82 E0 96 7D 33 D3 6A |
Thumbprint | 94 C9 5D A1 E8 50 BD 85 20 9A 4A 2A F3 E1 FB 16 04 F9 BB 66 |
Issued by | USERTrust RSA Certification Authority |
Country Name | US |
Valid From | 2000-05-30 10:48:38+00:00 |
Valid Until | 2020-05-30 10:48:38+00:00 |
Algorithm | sha384_rsa |
Serial Number | 13 EA 28 70 5B F4 EC ED 0C 36 63 09 80 61 43 36 |
Thumbprint | EA B0 40 68 9A 0D 80 5B 5D 6F D6 54 FC 16 8C FF 00 B7 8B E3 |
C:\ProgramData\Package Cache\{e52a6842-b0ac-476e-b48f-378a97a67346}\state.rsm.locked | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\th\messages.json.locked | Created File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\accessibility.EUQ.locked | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Temp\~nsu.tmp\Au_.exe.locked | Created File | Stream |
Unknown
|
...
|
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000.locked | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_metadata\computed_hashes.json.locked | Created File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170605115313.pma.locked | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\_locales\pl\messages.json.locked | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\goog...app_baa8013a79450f71_0001.0003_290679d077f4cfec\clickonce_bootstrap.exe.locked | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\128.png.locked | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{4BD650F1-C8F9-11E7-B5BF-C43DC7584A00}.dat.locked | Created File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\AdobeArabic-Bold.otf.locked | Created File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Setup Files\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}\1027.mst.locked | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\tr\messages.json.locked | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\en\messages.json.locked | Created File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins.locked | Created File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\hu_HU\Reader_10.0.helpcfg.locked | Created File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\zh_TW\Reader_10.0.helpcfg.locked | Created File | Stream |
Unknown
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Adobe\ARM\Reader_10.0.0\AdbeRdrSecUpd10111.msp.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\safebrowsing\test-malware-simple.sbstore.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\bg\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Temp\History\History.IE5\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\Public\Music\Sample Music\Kalimba.mp3.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\ICU\ctl_gb18030.cnv.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pkedcjkdefgpdelpbcmbmeomcjbeemfm_0.localstorage.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Visio\content14.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\ca\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64\cab1.cab.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\ja\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\VSTA\8.0\Microsoft.VisualStudio.Tools.Applications.Blueprints.tlb.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Local State.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-ntkl.etl.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Temp\3yDa4ifQGIzoWp6Xn6h.avi.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\nb_NO\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\sv\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\America\Kentucky\Louisville.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\Profiles\wscRGB.icc.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Mozilla Firefox\dictionaries\en-US.aff.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\es\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog.etl.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\amazondotcom.xml.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\pt_BR\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\bn\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\CREDHIST.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\Indian\Antananarivo.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\128.png.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\1033\StructuredQuerySchema.bin.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Outlook\Outlook.srs.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cloud_route_details\view.html.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\VSTO\ActionsPane3.xsd.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Mozilla Firefox\defaults\pref\channel-prefs.js.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\sk\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Office\MSO1033.acl.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\eu_ES\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\en_GB\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroBroker.exe.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\fr_FR\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_GB\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\th\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\ro_RO\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\lv\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\he\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\CIDFont\AdobeFanHeitiStd-Bold.otf.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\lv\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\clic...exe_baa8013a79450f71_0001.0003_none_855491bb37a51715\GoogleUpdateSetup.exe.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\default_apps\docs.crx.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\Cache\C\E6\9DCB7d01.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\uk\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Outlook\mapisvc.inf.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{1D1DBF3A-752F-47E2-BE70-D848D4A9AFB0}.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-07132009-221054.log.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\nl\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\tr\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\en_US\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\brndlog.bak.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\ar\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\cs_CZ\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\sv\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Office\ONetConfig\350db95df4cbd94b2a1c300510e12e11.sig.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\ja_JP\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AppConfigurationInternal.zip.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0000E713\01_Music_auto_rated_at_5_stars.wpl.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\OFFICE\UICaptions\1036\ENVELOPR.DLL.trx_dll.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\Help\Hx.HxC.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\cast_app.css.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\ru\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\bin\client\classes.jsa.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Package Cache\42D5BEC7DDFBD49E76467529CBC2868987BF8460\packages\Patch\x64\Windows6.1-KB2999226-x64.msu.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\deploy\jqs\jqs.conf.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_aohghmighlieiainnegkcijnfilokake\Google Docs.ico.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\LanguageNames2\DisplayLanguageNames.ar.txt.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86\cab1.cab.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\zh_CN\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\en_GB\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\et\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Extensions\external_extensions.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\Atlantic\Azores.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\lt\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\nl\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\am\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\da\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Uninstall Information\p champion.exe.locked | Created File | Binary |
Not Queried
|
...
|
Image Base | 0x400000 |
Entry Point | 0x401486 |
Size Of Code | 0xa600 |
Size Of Initialized Data | 0x8600 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2019-01-08 15:17:04+00:00 |
LegalCopyright | Copyright (c) 2015 Wall-Walker |
InternalName | p champion.exe |
FileVersion | 17.34.8.16 |
CompanyName | Wall-Walker |
ProductName | Brand Clicks-And-Mortar Architectures |
ProductVersion | 22.4.7.24 |
FileDescription | P Champion |
OriginalFilename | p champion.exe |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xa5c7 | 0xa600 | 0x400 | cnt_code, mem_execute, mem_read | 6.64 |
.rdata | 0x40c000 | 0x584e | 0x5a00 | 0xaa00 | cnt_initialized_data, mem_read | 4.83 |
.data | 0x412000 | 0x12b4 | 0xa00 | 0x10400 | cnt_initialized_data, mem_read, mem_write | 1.75 |
.gfids | 0x414000 | 0xac | 0x200 | 0x10e00 | cnt_initialized_data, mem_read | 1.4 |
.rsrc | 0x415000 | 0x770 | 0x800 | 0x11000 | cnt_initialized_data, mem_read | 3.08 |
.reloc | 0x416000 | 0xdc8 | 0xe00 | 0x11800 | cnt_initialized_data, mem_discardable, mem_read | 6.49 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetMessageW | 0x0 | 0x40c108 | 0x1128c | 0xfc8c | 0x173 |
DefWindowProcW | 0x0 | 0x40c10c | 0x11290 | 0xfc90 | 0xa1 |
CreateWindowExW | 0x0 | 0x40c110 | 0x11294 | 0xfc94 | 0x71 |
RegisterClassExW | 0x0 | 0x40c114 | 0x11298 | 0xfc98 | 0x289 |
ShowWindow | 0x0 | 0x40c118 | 0x1129c | 0xfc9c | 0x320 |
DispatchMessageW | 0x0 | 0x40c11c | 0x112a0 | 0xfca0 | 0xb5 |
TranslateMessage | 0x0 | 0x40c120 | 0x112a4 | 0xfca4 | 0x33f |
LoadIconW | 0x0 | 0x40c124 | 0x112a8 | 0xfca8 | 0x223 |
LoadCursorW | 0x0 | 0x40c128 | 0x112ac | 0xfcac | 0x221 |
PostQuitMessage | 0x0 | 0x40c12c | 0x112b0 | 0xfcb0 | 0x271 |
UpdateWindow | 0x0 | 0x40c130 | 0x112b4 | 0xfcb4 | 0x357 |
BeginPaint | 0x0 | 0x40c134 | 0x112b8 | 0xfcb8 | 0xe |
EndPaint | 0x0 | 0x40c138 | 0x112bc | 0xfcbc | 0xe9 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TextOutW | 0x0 | 0x40c000 | 0x11184 | 0xfb84 | 0x317 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFileW | 0x0 | 0x40c008 | 0x1118c | 0xfb8c | 0xc2 |
DecodePointer | 0x0 | 0x40c00c | 0x11190 | 0xfb90 | 0xfe |
WriteConsoleW | 0x0 | 0x40c010 | 0x11194 | 0xfb94 | 0x5e0 |
SetFilePointerEx | 0x0 | 0x40c014 | 0x11198 | 0xfb98 | 0x4fd |
RaiseException | 0x0 | 0x40c018 | 0x1119c | 0xfb9c | 0x440 |
GetConsoleCP | 0x0 | 0x40c01c | 0x111a0 | 0xfba0 | 0x1dc |
FlushFileBuffers | 0x0 | 0x40c020 | 0x111a4 | 0xfba4 | 0x192 |
HeapReAlloc | 0x0 | 0x40c024 | 0x111a8 | 0xfba8 | 0x336 |
HeapSize | 0x0 | 0x40c028 | 0x111ac | 0xfbac | 0x338 |
GetProcessHeap | 0x0 | 0x40c02c | 0x111b0 | 0xfbb0 | 0x2a2 |
GetConsoleMode | 0x0 | 0x40c030 | 0x111b4 | 0xfbb4 | 0x1ee |
WideCharToMultiByte | 0x0 | 0x40c034 | 0x111b8 | 0xfbb8 | 0x5cd |
UnhandledExceptionFilter | 0x0 | 0x40c038 | 0x111bc | 0xfbbc | 0x582 |
SetUnhandledExceptionFilter | 0x0 | 0x40c03c | 0x111c0 | 0xfbc0 | 0x543 |
GetCurrentProcess | 0x0 | 0x40c040 | 0x111c4 | 0xfbc4 | 0x209 |
TerminateProcess | 0x0 | 0x40c044 | 0x111c8 | 0xfbc8 | 0x561 |
IsProcessorFeaturePresent | 0x0 | 0x40c048 | 0x111cc | 0xfbcc | 0x36d |
QueryPerformanceCounter | 0x0 | 0x40c04c | 0x111d0 | 0xfbd0 | 0x42d |
GetCurrentProcessId | 0x0 | 0x40c050 | 0x111d4 | 0xfbd4 | 0x20a |
GetCurrentThreadId | 0x0 | 0x40c054 | 0x111d8 | 0xfbd8 | 0x20e |
GetSystemTimeAsFileTime | 0x0 | 0x40c058 | 0x111dc | 0xfbdc | 0x2d6 |
InitializeSListHead | 0x0 | 0x40c05c | 0x111e0 | 0xfbe0 | 0x34b |
IsDebuggerPresent | 0x0 | 0x40c060 | 0x111e4 | 0xfbe4 | 0x367 |
GetStartupInfoW | 0x0 | 0x40c064 | 0x111e8 | 0xfbe8 | 0x2be |
GetModuleHandleW | 0x0 | 0x40c068 | 0x111ec | 0xfbec | 0x267 |
RtlUnwind | 0x0 | 0x40c06c | 0x111f0 | 0xfbf0 | 0x4ad |
GetLastError | 0x0 | 0x40c070 | 0x111f4 | 0xfbf4 | 0x250 |
SetLastError | 0x0 | 0x40c074 | 0x111f8 | 0xfbf8 | 0x50b |
EnterCriticalSection | 0x0 | 0x40c078 | 0x111fc | 0xfbfc | 0x125 |
LeaveCriticalSection | 0x0 | 0x40c07c | 0x11200 | 0xfc00 | 0x3a2 |
DeleteCriticalSection | 0x0 | 0x40c080 | 0x11204 | 0xfc04 | 0x105 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40c084 | 0x11208 | 0xfc08 | 0x348 |
TlsAlloc | 0x0 | 0x40c088 | 0x1120c | 0xfc0c | 0x573 |
TlsGetValue | 0x0 | 0x40c08c | 0x11210 | 0xfc10 | 0x575 |
TlsSetValue | 0x0 | 0x40c090 | 0x11214 | 0xfc14 | 0x576 |
TlsFree | 0x0 | 0x40c094 | 0x11218 | 0xfc18 | 0x574 |
FreeLibrary | 0x0 | 0x40c098 | 0x1121c | 0xfc1c | 0x19e |
GetProcAddress | 0x0 | 0x40c09c | 0x11220 | 0xfc20 | 0x29d |
LoadLibraryExW | 0x0 | 0x40c0a0 | 0x11224 | 0xfc24 | 0x3a7 |
GetStdHandle | 0x0 | 0x40c0a4 | 0x11228 | 0xfc28 | 0x2c0 |
WriteFile | 0x0 | 0x40c0a8 | 0x1122c | 0xfc2c | 0x5e1 |
GetModuleFileNameA | 0x0 | 0x40c0ac | 0x11230 | 0xfc30 | 0x262 |
MultiByteToWideChar | 0x0 | 0x40c0b0 | 0x11234 | 0xfc34 | 0x3d1 |
ExitProcess | 0x0 | 0x40c0b4 | 0x11238 | 0xfc38 | 0x151 |
GetModuleHandleExW | 0x0 | 0x40c0b8 | 0x1123c | 0xfc3c | 0x266 |
GetACP | 0x0 | 0x40c0bc | 0x11240 | 0xfc40 | 0x1a4 |
HeapFree | 0x0 | 0x40c0c0 | 0x11244 | 0xfc44 | 0x333 |
HeapAlloc | 0x0 | 0x40c0c4 | 0x11248 | 0xfc48 | 0x32f |
CloseHandle | 0x0 | 0x40c0c8 | 0x1124c | 0xfc4c | 0x7f |
FindClose | 0x0 | 0x40c0cc | 0x11250 | 0xfc50 | 0x168 |
FindFirstFileExA | 0x0 | 0x40c0d0 | 0x11254 | 0xfc54 | 0x16d |
FindNextFileA | 0x0 | 0x40c0d4 | 0x11258 | 0xfc58 | 0x17d |
IsValidCodePage | 0x0 | 0x40c0d8 | 0x1125c | 0xfc5c | 0x372 |
GetOEMCP | 0x0 | 0x40c0dc | 0x11260 | 0xfc60 | 0x286 |
GetCPInfo | 0x0 | 0x40c0e0 | 0x11264 | 0xfc64 | 0x1b3 |
GetCommandLineA | 0x0 | 0x40c0e4 | 0x11268 | 0xfc68 | 0x1c8 |
GetCommandLineW | 0x0 | 0x40c0e8 | 0x1126c | 0xfc6c | 0x1c9 |
GetEnvironmentStringsW | 0x0 | 0x40c0ec | 0x11270 | 0xfc70 | 0x227 |
FreeEnvironmentStringsW | 0x0 | 0x40c0f0 | 0x11274 | 0xfc74 | 0x19d |
LCMapStringW | 0x0 | 0x40c0f4 | 0x11278 | 0xfc78 | 0x396 |
SetStdHandle | 0x0 | 0x40c0f8 | 0x1127c | 0xfc7c | 0x522 |
GetFileType | 0x0 | 0x40c0fc | 0x11280 | 0xfc80 | 0x23e |
GetStringTypeW | 0x0 | 0x40c100 | 0x11284 | 0xfc84 | 0x2c5 |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\Cache\F\23\7E0FEd01.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pl\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Mozilla Firefox\webapprt\omni.ja.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Outlook\RoamCache\Stream_ContactPrefs_2_F230E11936B7D740A008FFC660E83C71.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AcrobatUpdater.exe.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Analysis Services\AS OLEDB\10\Cartridges\as80.xsl.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\css\craw_window.css.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Cookies.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\html\craw_window.html.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\ACECache11.lst.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\OfflineCache\index.sqlite.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\it\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Package Cache\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}v12.0.21005\packages\vcRuntimeMinimum_amd64\cab1.cab.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\_locales\pt_PT\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\accessibility.properties.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\Australia\Adelaide.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Sidebar\Settings.ini.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\manifests\clic...exe_baa8013a79450f71_0001.0003_none_855491bb37a51715.cdf-ms.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\nl_NL\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\Antarctica\Casey.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\Pacific\Apia.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\si\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\uk_UA\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\MF\Active.GRL.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\hr_HR\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Suggested Sites~.feed-ms.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\Default\Contacts\Administrator.contact.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\zh_TW\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-CNRY.FSD.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1250.TXT.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\128.png.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Java\Java Update\jaucheck.exe.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Themes\Custom.theme.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Mozilla Firefox\browser\blocklist.xml.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Windows Portable Devices\paraguay.exe.locked | Created File | Binary |
Not Queried
|
...
|
Image Base | 0x400000 |
Entry Point | 0x401486 |
Size Of Code | 0xa600 |
Size Of Initialized Data | 0x8600 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2019-01-08 15:17:04+00:00 |
LegalCopyright | Copyright (c) 2003 Lyons, Morales and Garcia |
InternalName | paraguay.exe |
FileVersion | 31.5.13.23 |
CompanyName | Lyons, Morales and Garcia |
ProductName | Redefine Rich Systems |
ProductVersion | 21.29.4.26 |
FileDescription | Paraguay |
OriginalFilename | paraguay.exe |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xa5c7 | 0xa600 | 0x400 | cnt_code, mem_execute, mem_read | 6.64 |
.rdata | 0x40c000 | 0x584e | 0x5a00 | 0xaa00 | cnt_initialized_data, mem_read | 4.84 |
.data | 0x412000 | 0x12b4 | 0xa00 | 0x10400 | cnt_initialized_data, mem_read, mem_write | 1.74 |
.gfids | 0x414000 | 0xac | 0x200 | 0x10e00 | cnt_initialized_data, mem_read | 1.4 |
.rsrc | 0x415000 | 0x770 | 0x800 | 0x11000 | cnt_initialized_data, mem_read | 3.09 |
.reloc | 0x416000 | 0xdc8 | 0xe00 | 0x11800 | cnt_initialized_data, mem_discardable, mem_read | 6.49 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetMessageW | 0x0 | 0x40c108 | 0x1128c | 0xfc8c | 0x173 |
DefWindowProcW | 0x0 | 0x40c10c | 0x11290 | 0xfc90 | 0xa1 |
CreateWindowExW | 0x0 | 0x40c110 | 0x11294 | 0xfc94 | 0x71 |
RegisterClassExW | 0x0 | 0x40c114 | 0x11298 | 0xfc98 | 0x289 |
ShowWindow | 0x0 | 0x40c118 | 0x1129c | 0xfc9c | 0x320 |
DispatchMessageW | 0x0 | 0x40c11c | 0x112a0 | 0xfca0 | 0xb5 |
TranslateMessage | 0x0 | 0x40c120 | 0x112a4 | 0xfca4 | 0x33f |
LoadIconW | 0x0 | 0x40c124 | 0x112a8 | 0xfca8 | 0x223 |
LoadCursorW | 0x0 | 0x40c128 | 0x112ac | 0xfcac | 0x221 |
PostQuitMessage | 0x0 | 0x40c12c | 0x112b0 | 0xfcb0 | 0x271 |
UpdateWindow | 0x0 | 0x40c130 | 0x112b4 | 0xfcb4 | 0x357 |
BeginPaint | 0x0 | 0x40c134 | 0x112b8 | 0xfcb8 | 0xe |
EndPaint | 0x0 | 0x40c138 | 0x112bc | 0xfcbc | 0xe9 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TextOutW | 0x0 | 0x40c000 | 0x11184 | 0xfb84 | 0x317 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFileW | 0x0 | 0x40c008 | 0x1118c | 0xfb8c | 0xc2 |
DecodePointer | 0x0 | 0x40c00c | 0x11190 | 0xfb90 | 0xfe |
WriteConsoleW | 0x0 | 0x40c010 | 0x11194 | 0xfb94 | 0x5e0 |
SetFilePointerEx | 0x0 | 0x40c014 | 0x11198 | 0xfb98 | 0x4fd |
RaiseException | 0x0 | 0x40c018 | 0x1119c | 0xfb9c | 0x440 |
GetConsoleCP | 0x0 | 0x40c01c | 0x111a0 | 0xfba0 | 0x1dc |
FlushFileBuffers | 0x0 | 0x40c020 | 0x111a4 | 0xfba4 | 0x192 |
HeapReAlloc | 0x0 | 0x40c024 | 0x111a8 | 0xfba8 | 0x336 |
HeapSize | 0x0 | 0x40c028 | 0x111ac | 0xfbac | 0x338 |
GetProcessHeap | 0x0 | 0x40c02c | 0x111b0 | 0xfbb0 | 0x2a2 |
GetConsoleMode | 0x0 | 0x40c030 | 0x111b4 | 0xfbb4 | 0x1ee |
WideCharToMultiByte | 0x0 | 0x40c034 | 0x111b8 | 0xfbb8 | 0x5cd |
UnhandledExceptionFilter | 0x0 | 0x40c038 | 0x111bc | 0xfbbc | 0x582 |
SetUnhandledExceptionFilter | 0x0 | 0x40c03c | 0x111c0 | 0xfbc0 | 0x543 |
GetCurrentProcess | 0x0 | 0x40c040 | 0x111c4 | 0xfbc4 | 0x209 |
TerminateProcess | 0x0 | 0x40c044 | 0x111c8 | 0xfbc8 | 0x561 |
IsProcessorFeaturePresent | 0x0 | 0x40c048 | 0x111cc | 0xfbcc | 0x36d |
QueryPerformanceCounter | 0x0 | 0x40c04c | 0x111d0 | 0xfbd0 | 0x42d |
GetCurrentProcessId | 0x0 | 0x40c050 | 0x111d4 | 0xfbd4 | 0x20a |
GetCurrentThreadId | 0x0 | 0x40c054 | 0x111d8 | 0xfbd8 | 0x20e |
GetSystemTimeAsFileTime | 0x0 | 0x40c058 | 0x111dc | 0xfbdc | 0x2d6 |
InitializeSListHead | 0x0 | 0x40c05c | 0x111e0 | 0xfbe0 | 0x34b |
IsDebuggerPresent | 0x0 | 0x40c060 | 0x111e4 | 0xfbe4 | 0x367 |
GetStartupInfoW | 0x0 | 0x40c064 | 0x111e8 | 0xfbe8 | 0x2be |
GetModuleHandleW | 0x0 | 0x40c068 | 0x111ec | 0xfbec | 0x267 |
RtlUnwind | 0x0 | 0x40c06c | 0x111f0 | 0xfbf0 | 0x4ad |
GetLastError | 0x0 | 0x40c070 | 0x111f4 | 0xfbf4 | 0x250 |
SetLastError | 0x0 | 0x40c074 | 0x111f8 | 0xfbf8 | 0x50b |
EnterCriticalSection | 0x0 | 0x40c078 | 0x111fc | 0xfbfc | 0x125 |
LeaveCriticalSection | 0x0 | 0x40c07c | 0x11200 | 0xfc00 | 0x3a2 |
DeleteCriticalSection | 0x0 | 0x40c080 | 0x11204 | 0xfc04 | 0x105 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40c084 | 0x11208 | 0xfc08 | 0x348 |
TlsAlloc | 0x0 | 0x40c088 | 0x1120c | 0xfc0c | 0x573 |
TlsGetValue | 0x0 | 0x40c08c | 0x11210 | 0xfc10 | 0x575 |
TlsSetValue | 0x0 | 0x40c090 | 0x11214 | 0xfc14 | 0x576 |
TlsFree | 0x0 | 0x40c094 | 0x11218 | 0xfc18 | 0x574 |
FreeLibrary | 0x0 | 0x40c098 | 0x1121c | 0xfc1c | 0x19e |
GetProcAddress | 0x0 | 0x40c09c | 0x11220 | 0xfc20 | 0x29d |
LoadLibraryExW | 0x0 | 0x40c0a0 | 0x11224 | 0xfc24 | 0x3a7 |
GetStdHandle | 0x0 | 0x40c0a4 | 0x11228 | 0xfc28 | 0x2c0 |
WriteFile | 0x0 | 0x40c0a8 | 0x1122c | 0xfc2c | 0x5e1 |
GetModuleFileNameA | 0x0 | 0x40c0ac | 0x11230 | 0xfc30 | 0x262 |
MultiByteToWideChar | 0x0 | 0x40c0b0 | 0x11234 | 0xfc34 | 0x3d1 |
ExitProcess | 0x0 | 0x40c0b4 | 0x11238 | 0xfc38 | 0x151 |
GetModuleHandleExW | 0x0 | 0x40c0b8 | 0x1123c | 0xfc3c | 0x266 |
GetACP | 0x0 | 0x40c0bc | 0x11240 | 0xfc40 | 0x1a4 |
HeapFree | 0x0 | 0x40c0c0 | 0x11244 | 0xfc44 | 0x333 |
HeapAlloc | 0x0 | 0x40c0c4 | 0x11248 | 0xfc48 | 0x32f |
CloseHandle | 0x0 | 0x40c0c8 | 0x1124c | 0xfc4c | 0x7f |
FindClose | 0x0 | 0x40c0cc | 0x11250 | 0xfc50 | 0x168 |
FindFirstFileExA | 0x0 | 0x40c0d0 | 0x11254 | 0xfc54 | 0x16d |
FindNextFileA | 0x0 | 0x40c0d4 | 0x11258 | 0xfc58 | 0x17d |
IsValidCodePage | 0x0 | 0x40c0d8 | 0x1125c | 0xfc5c | 0x372 |
GetOEMCP | 0x0 | 0x40c0dc | 0x11260 | 0xfc60 | 0x286 |
GetCPInfo | 0x0 | 0x40c0e0 | 0x11264 | 0xfc64 | 0x1b3 |
GetCommandLineA | 0x0 | 0x40c0e4 | 0x11268 | 0xfc68 | 0x1c8 |
GetCommandLineW | 0x0 | 0x40c0e8 | 0x1126c | 0xfc6c | 0x1c9 |
GetEnvironmentStringsW | 0x0 | 0x40c0ec | 0x11270 | 0xfc70 | 0x227 |
FreeEnvironmentStringsW | 0x0 | 0x40c0f0 | 0x11274 | 0xfc74 | 0x19d |
LCMapStringW | 0x0 | 0x40c0f4 | 0x11278 | 0xfc78 | 0x396 |
SetStdHandle | 0x0 | 0x40c0f8 | 0x1127c | 0xfc7c | 0x522 |
GetFileType | 0x0 | 0x40c0fc | 0x11280 | 0xfc80 | 0x23e |
GetStringTypeW | 0x0 | 0x40c100 | 0x11284 | 0xfc84 | 0x2c5 |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\bg\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\bin\jabswitch.exe.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\sk_SK\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\el\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012017071220170713\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\FORMS\FRMCACHE.DAT.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\i386\jvm.cfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\MpSfc.bin.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.config.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\America\Argentina\Buenos_Aires.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\ru_RU\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Services\verisign.bmp.locked | Created File | Image |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\ext\access-bridge-32.jar.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\flapper.gif.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\icon_128.png.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\sr\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\zh_CN\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\bg\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\58.0.3029.110.manifest.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\ko\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Feeds Cache\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_metadata\verified_contents.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\sw\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ca\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\cs\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\security\blacklist.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\it_IT\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\startupCache\startupCache.4.little.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Office\Office14\1033\GrooveForms5\FormsStyles\Slate\TAB_OFF.GIF.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\Cache\F\F0\ECB2Dd01.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\ko_KR\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\fonts\LucidaBrightDemiBold.ttf.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\account{047EF9CE-9C1F-4250-9CA7-D206DB8B643C}.oeaccount.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\es_ES\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\COPYRIGHT.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AboutBox.zip.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\VSTA\8.0\x86\vsta_ep32.exe.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\cs\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\America\Adak.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\sl\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\zh_TW\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\ca_ES\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\Cache\0\98\B60F3d01.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\accessibility.ESP.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\_locales\ru\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\Services\DEXShare.asfx.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Locales\am.pak.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\management\jmxremote.access.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\cmm\CIEXYZ.pf.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\jfr\default.jfc.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\angular.js.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\PFM\SY______.PFM.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\vi\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\America\Indiana\Indianapolis.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\MS Project\14\1033\Global.MPT.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.png.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\he\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\User Account Pictures\guest.bmp.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\WidevineCdm\_platform_specific\win_x64\widevinecdm.dll.sig.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\VisualElements\logo.png.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\hi\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\1033\MSOINTL.DLL.IDX_DLL.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Office\Office14\1033\GrooveForms5\FormsStyles\SoftBlue\background.gif.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\de\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\CET.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\Africa\Abidjan.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Benioku.htm.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\VSTA\Pipeline.v10.0\PipelineSegments.store.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ar\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\da\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\lv\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\thumbnails\4cc87c1409819bf06f42b782d4902b2f.png.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\sv_SE\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\da_DK\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Adobe\HKSCS.txt.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\efficient_validation_integrating.exe.locked | Created File | Binary |
Not Queried
|
...
|
Image Base | 0x400000 |
Entry Point | 0x401486 |
Size Of Code | 0xa600 |
Size Of Initialized Data | 0x8600 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2019-01-08 15:17:04+00:00 |
LegalCopyright | Copyright (c) 2015 Hahn-Bowers |
InternalName | efficient_validation_integrating.exe |
FileVersion | 4.31.13.26 |
CompanyName | Hahn-Bowers |
ProductName | Incubate Intuitive Interfaces |
ProductVersion | 21.3.27.1 |
FileDescription | Efficient Validation Integrating |
OriginalFilename | efficient_validation_integrating.exe |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xa5c7 | 0xa600 | 0x400 | cnt_code, mem_execute, mem_read | 6.64 |
.rdata | 0x40c000 | 0x584e | 0x5a00 | 0xaa00 | cnt_initialized_data, mem_read | 4.84 |
.data | 0x412000 | 0x12b4 | 0xa00 | 0x10400 | cnt_initialized_data, mem_read, mem_write | 1.89 |
.gfids | 0x414000 | 0xac | 0x200 | 0x10e00 | cnt_initialized_data, mem_read | 1.4 |
.rsrc | 0x415000 | 0x770 | 0x800 | 0x11000 | cnt_initialized_data, mem_read | 3.22 |
.reloc | 0x416000 | 0xdc8 | 0xe00 | 0x11800 | cnt_initialized_data, mem_discardable, mem_read | 6.49 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetMessageW | 0x0 | 0x40c108 | 0x1128c | 0xfc8c | 0x173 |
DefWindowProcW | 0x0 | 0x40c10c | 0x11290 | 0xfc90 | 0xa1 |
CreateWindowExW | 0x0 | 0x40c110 | 0x11294 | 0xfc94 | 0x71 |
RegisterClassExW | 0x0 | 0x40c114 | 0x11298 | 0xfc98 | 0x289 |
ShowWindow | 0x0 | 0x40c118 | 0x1129c | 0xfc9c | 0x320 |
DispatchMessageW | 0x0 | 0x40c11c | 0x112a0 | 0xfca0 | 0xb5 |
TranslateMessage | 0x0 | 0x40c120 | 0x112a4 | 0xfca4 | 0x33f |
LoadIconW | 0x0 | 0x40c124 | 0x112a8 | 0xfca8 | 0x223 |
LoadCursorW | 0x0 | 0x40c128 | 0x112ac | 0xfcac | 0x221 |
PostQuitMessage | 0x0 | 0x40c12c | 0x112b0 | 0xfcb0 | 0x271 |
UpdateWindow | 0x0 | 0x40c130 | 0x112b4 | 0xfcb4 | 0x357 |
BeginPaint | 0x0 | 0x40c134 | 0x112b8 | 0xfcb8 | 0xe |
EndPaint | 0x0 | 0x40c138 | 0x112bc | 0xfcbc | 0xe9 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TextOutW | 0x0 | 0x40c000 | 0x11184 | 0xfb84 | 0x317 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFileW | 0x0 | 0x40c008 | 0x1118c | 0xfb8c | 0xc2 |
DecodePointer | 0x0 | 0x40c00c | 0x11190 | 0xfb90 | 0xfe |
WriteConsoleW | 0x0 | 0x40c010 | 0x11194 | 0xfb94 | 0x5e0 |
SetFilePointerEx | 0x0 | 0x40c014 | 0x11198 | 0xfb98 | 0x4fd |
RaiseException | 0x0 | 0x40c018 | 0x1119c | 0xfb9c | 0x440 |
GetConsoleCP | 0x0 | 0x40c01c | 0x111a0 | 0xfba0 | 0x1dc |
FlushFileBuffers | 0x0 | 0x40c020 | 0x111a4 | 0xfba4 | 0x192 |
HeapReAlloc | 0x0 | 0x40c024 | 0x111a8 | 0xfba8 | 0x336 |
HeapSize | 0x0 | 0x40c028 | 0x111ac | 0xfbac | 0x338 |
GetProcessHeap | 0x0 | 0x40c02c | 0x111b0 | 0xfbb0 | 0x2a2 |
GetConsoleMode | 0x0 | 0x40c030 | 0x111b4 | 0xfbb4 | 0x1ee |
WideCharToMultiByte | 0x0 | 0x40c034 | 0x111b8 | 0xfbb8 | 0x5cd |
UnhandledExceptionFilter | 0x0 | 0x40c038 | 0x111bc | 0xfbbc | 0x582 |
SetUnhandledExceptionFilter | 0x0 | 0x40c03c | 0x111c0 | 0xfbc0 | 0x543 |
GetCurrentProcess | 0x0 | 0x40c040 | 0x111c4 | 0xfbc4 | 0x209 |
TerminateProcess | 0x0 | 0x40c044 | 0x111c8 | 0xfbc8 | 0x561 |
IsProcessorFeaturePresent | 0x0 | 0x40c048 | 0x111cc | 0xfbcc | 0x36d |
QueryPerformanceCounter | 0x0 | 0x40c04c | 0x111d0 | 0xfbd0 | 0x42d |
GetCurrentProcessId | 0x0 | 0x40c050 | 0x111d4 | 0xfbd4 | 0x20a |
GetCurrentThreadId | 0x0 | 0x40c054 | 0x111d8 | 0xfbd8 | 0x20e |
GetSystemTimeAsFileTime | 0x0 | 0x40c058 | 0x111dc | 0xfbdc | 0x2d6 |
InitializeSListHead | 0x0 | 0x40c05c | 0x111e0 | 0xfbe0 | 0x34b |
IsDebuggerPresent | 0x0 | 0x40c060 | 0x111e4 | 0xfbe4 | 0x367 |
GetStartupInfoW | 0x0 | 0x40c064 | 0x111e8 | 0xfbe8 | 0x2be |
GetModuleHandleW | 0x0 | 0x40c068 | 0x111ec | 0xfbec | 0x267 |
RtlUnwind | 0x0 | 0x40c06c | 0x111f0 | 0xfbf0 | 0x4ad |
GetLastError | 0x0 | 0x40c070 | 0x111f4 | 0xfbf4 | 0x250 |
SetLastError | 0x0 | 0x40c074 | 0x111f8 | 0xfbf8 | 0x50b |
EnterCriticalSection | 0x0 | 0x40c078 | 0x111fc | 0xfbfc | 0x125 |
LeaveCriticalSection | 0x0 | 0x40c07c | 0x11200 | 0xfc00 | 0x3a2 |
DeleteCriticalSection | 0x0 | 0x40c080 | 0x11204 | 0xfc04 | 0x105 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40c084 | 0x11208 | 0xfc08 | 0x348 |
TlsAlloc | 0x0 | 0x40c088 | 0x1120c | 0xfc0c | 0x573 |
TlsGetValue | 0x0 | 0x40c08c | 0x11210 | 0xfc10 | 0x575 |
TlsSetValue | 0x0 | 0x40c090 | 0x11214 | 0xfc14 | 0x576 |
TlsFree | 0x0 | 0x40c094 | 0x11218 | 0xfc18 | 0x574 |
FreeLibrary | 0x0 | 0x40c098 | 0x1121c | 0xfc1c | 0x19e |
GetProcAddress | 0x0 | 0x40c09c | 0x11220 | 0xfc20 | 0x29d |
LoadLibraryExW | 0x0 | 0x40c0a0 | 0x11224 | 0xfc24 | 0x3a7 |
GetStdHandle | 0x0 | 0x40c0a4 | 0x11228 | 0xfc28 | 0x2c0 |
WriteFile | 0x0 | 0x40c0a8 | 0x1122c | 0xfc2c | 0x5e1 |
GetModuleFileNameA | 0x0 | 0x40c0ac | 0x11230 | 0xfc30 | 0x262 |
MultiByteToWideChar | 0x0 | 0x40c0b0 | 0x11234 | 0xfc34 | 0x3d1 |
ExitProcess | 0x0 | 0x40c0b4 | 0x11238 | 0xfc38 | 0x151 |
GetModuleHandleExW | 0x0 | 0x40c0b8 | 0x1123c | 0xfc3c | 0x266 |
GetACP | 0x0 | 0x40c0bc | 0x11240 | 0xfc40 | 0x1a4 |
HeapFree | 0x0 | 0x40c0c0 | 0x11244 | 0xfc44 | 0x333 |
HeapAlloc | 0x0 | 0x40c0c4 | 0x11248 | 0xfc48 | 0x32f |
CloseHandle | 0x0 | 0x40c0c8 | 0x1124c | 0xfc4c | 0x7f |
FindClose | 0x0 | 0x40c0cc | 0x11250 | 0xfc50 | 0x168 |
FindFirstFileExA | 0x0 | 0x40c0d0 | 0x11254 | 0xfc54 | 0x16d |
FindNextFileA | 0x0 | 0x40c0d4 | 0x11258 | 0xfc58 | 0x17d |
IsValidCodePage | 0x0 | 0x40c0d8 | 0x1125c | 0xfc5c | 0x372 |
GetOEMCP | 0x0 | 0x40c0dc | 0x11260 | 0xfc60 | 0x286 |
GetCPInfo | 0x0 | 0x40c0e0 | 0x11264 | 0xfc64 | 0x1b3 |
GetCommandLineA | 0x0 | 0x40c0e4 | 0x11268 | 0xfc68 | 0x1c8 |
GetCommandLineW | 0x0 | 0x40c0e8 | 0x1126c | 0xfc6c | 0x1c9 |
GetEnvironmentStringsW | 0x0 | 0x40c0ec | 0x11270 | 0xfc70 | 0x227 |
FreeEnvironmentStringsW | 0x0 | 0x40c0f0 | 0x11274 | 0xfc74 | 0x19d |
LCMapStringW | 0x0 | 0x40c0f4 | 0x11278 | 0xfc78 | 0x396 |
SetStdHandle | 0x0 | 0x40c0f8 | 0x1127c | 0xfc7c | 0x522 |
GetFileType | 0x0 | 0x40c0fc | 0x11280 | 0xfc80 | 0x23e |
GetStringTypeW | 0x0 | 0x40c100 | 0x11284 | 0xfc84 | 0x2c5 |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft.NET\RedistList\AssemblyList_4_client.xml.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\az\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Office\Office14\MSOHTMED.EXE.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Office\Office14\1033\VBAOWS10.CHM.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\Europe\Amsterdam.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\af\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\sl_SI\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\ara131.lex.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\ARABIC.TXT.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\_locales\ro\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\VSTA\AppInfoDocument\AddIns.store.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\fa\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\TextConv\WksConv\Wkconv.exe.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\zh\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\bookmarkbackups\bookmarks-2017-06-05_5.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\de_DE\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\cs\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\Services\DEXShare.asfx.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Adobe\Acrobat\10.0\Replicate\Security\directories.acrodata.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\SaslPrep\SaslPrepProfile_norm_bidi.spp.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Office\Office14\1033\GrooveForms5\FormsStyles\Solutions\arrow.png.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Package Cache\{929FBD26-9020-399B-9A7A-751D61F0B942}v12.0.21005\packages\vcRuntimeAdditional_amd64\cab1.cab.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\fi_FI\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\index.dat.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\tr\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\America\North_Dakota\Beulah.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\tr\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\pt_PT\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ByGxsyPX0i\2vnf21Uh.mp4.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\obvious.exe.locked | Created File | Binary |
Not Queried
|
...
|
Image Base | 0x400000 |
Entry Point | 0x401486 |
Size Of Code | 0xa600 |
Size Of Initialized Data | 0x8600 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2019-01-08 15:17:04+00:00 |
LegalCopyright | Copyright (c) 2014 May-Schmidt |
InternalName | obvious.exe |
FileVersion | 25.8.5.32 |
CompanyName | May-Schmidt |
ProductName | Brand Extensible Synergies |
ProductVersion | 21.21.0.32 |
FileDescription | Obvious |
OriginalFilename | obvious.exe |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xa5c7 | 0xa600 | 0x400 | cnt_code, mem_execute, mem_read | 6.64 |
.rdata | 0x40c000 | 0x584e | 0x5a00 | 0xaa00 | cnt_initialized_data, mem_read | 4.84 |
.data | 0x412000 | 0x12b4 | 0xa00 | 0x10400 | cnt_initialized_data, mem_read, mem_write | 1.74 |
.gfids | 0x414000 | 0xac | 0x200 | 0x10e00 | cnt_initialized_data, mem_read | 1.4 |
.rsrc | 0x415000 | 0x770 | 0x800 | 0x11000 | cnt_initialized_data, mem_read | 3.0 |
.reloc | 0x416000 | 0xdc8 | 0xe00 | 0x11800 | cnt_initialized_data, mem_discardable, mem_read | 6.49 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetMessageW | 0x0 | 0x40c108 | 0x1128c | 0xfc8c | 0x173 |
DefWindowProcW | 0x0 | 0x40c10c | 0x11290 | 0xfc90 | 0xa1 |
CreateWindowExW | 0x0 | 0x40c110 | 0x11294 | 0xfc94 | 0x71 |
RegisterClassExW | 0x0 | 0x40c114 | 0x11298 | 0xfc98 | 0x289 |
ShowWindow | 0x0 | 0x40c118 | 0x1129c | 0xfc9c | 0x320 |
DispatchMessageW | 0x0 | 0x40c11c | 0x112a0 | 0xfca0 | 0xb5 |
TranslateMessage | 0x0 | 0x40c120 | 0x112a4 | 0xfca4 | 0x33f |
LoadIconW | 0x0 | 0x40c124 | 0x112a8 | 0xfca8 | 0x223 |
LoadCursorW | 0x0 | 0x40c128 | 0x112ac | 0xfcac | 0x221 |
PostQuitMessage | 0x0 | 0x40c12c | 0x112b0 | 0xfcb0 | 0x271 |
UpdateWindow | 0x0 | 0x40c130 | 0x112b4 | 0xfcb4 | 0x357 |
BeginPaint | 0x0 | 0x40c134 | 0x112b8 | 0xfcb8 | 0xe |
EndPaint | 0x0 | 0x40c138 | 0x112bc | 0xfcbc | 0xe9 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TextOutW | 0x0 | 0x40c000 | 0x11184 | 0xfb84 | 0x317 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFileW | 0x0 | 0x40c008 | 0x1118c | 0xfb8c | 0xc2 |
DecodePointer | 0x0 | 0x40c00c | 0x11190 | 0xfb90 | 0xfe |
WriteConsoleW | 0x0 | 0x40c010 | 0x11194 | 0xfb94 | 0x5e0 |
SetFilePointerEx | 0x0 | 0x40c014 | 0x11198 | 0xfb98 | 0x4fd |
RaiseException | 0x0 | 0x40c018 | 0x1119c | 0xfb9c | 0x440 |
GetConsoleCP | 0x0 | 0x40c01c | 0x111a0 | 0xfba0 | 0x1dc |
FlushFileBuffers | 0x0 | 0x40c020 | 0x111a4 | 0xfba4 | 0x192 |
HeapReAlloc | 0x0 | 0x40c024 | 0x111a8 | 0xfba8 | 0x336 |
HeapSize | 0x0 | 0x40c028 | 0x111ac | 0xfbac | 0x338 |
GetProcessHeap | 0x0 | 0x40c02c | 0x111b0 | 0xfbb0 | 0x2a2 |
GetConsoleMode | 0x0 | 0x40c030 | 0x111b4 | 0xfbb4 | 0x1ee |
WideCharToMultiByte | 0x0 | 0x40c034 | 0x111b8 | 0xfbb8 | 0x5cd |
UnhandledExceptionFilter | 0x0 | 0x40c038 | 0x111bc | 0xfbbc | 0x582 |
SetUnhandledExceptionFilter | 0x0 | 0x40c03c | 0x111c0 | 0xfbc0 | 0x543 |
GetCurrentProcess | 0x0 | 0x40c040 | 0x111c4 | 0xfbc4 | 0x209 |
TerminateProcess | 0x0 | 0x40c044 | 0x111c8 | 0xfbc8 | 0x561 |
IsProcessorFeaturePresent | 0x0 | 0x40c048 | 0x111cc | 0xfbcc | 0x36d |
QueryPerformanceCounter | 0x0 | 0x40c04c | 0x111d0 | 0xfbd0 | 0x42d |
GetCurrentProcessId | 0x0 | 0x40c050 | 0x111d4 | 0xfbd4 | 0x20a |
GetCurrentThreadId | 0x0 | 0x40c054 | 0x111d8 | 0xfbd8 | 0x20e |
GetSystemTimeAsFileTime | 0x0 | 0x40c058 | 0x111dc | 0xfbdc | 0x2d6 |
InitializeSListHead | 0x0 | 0x40c05c | 0x111e0 | 0xfbe0 | 0x34b |
IsDebuggerPresent | 0x0 | 0x40c060 | 0x111e4 | 0xfbe4 | 0x367 |
GetStartupInfoW | 0x0 | 0x40c064 | 0x111e8 | 0xfbe8 | 0x2be |
GetModuleHandleW | 0x0 | 0x40c068 | 0x111ec | 0xfbec | 0x267 |
RtlUnwind | 0x0 | 0x40c06c | 0x111f0 | 0xfbf0 | 0x4ad |
GetLastError | 0x0 | 0x40c070 | 0x111f4 | 0xfbf4 | 0x250 |
SetLastError | 0x0 | 0x40c074 | 0x111f8 | 0xfbf8 | 0x50b |
EnterCriticalSection | 0x0 | 0x40c078 | 0x111fc | 0xfbfc | 0x125 |
LeaveCriticalSection | 0x0 | 0x40c07c | 0x11200 | 0xfc00 | 0x3a2 |
DeleteCriticalSection | 0x0 | 0x40c080 | 0x11204 | 0xfc04 | 0x105 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40c084 | 0x11208 | 0xfc08 | 0x348 |
TlsAlloc | 0x0 | 0x40c088 | 0x1120c | 0xfc0c | 0x573 |
TlsGetValue | 0x0 | 0x40c08c | 0x11210 | 0xfc10 | 0x575 |
TlsSetValue | 0x0 | 0x40c090 | 0x11214 | 0xfc14 | 0x576 |
TlsFree | 0x0 | 0x40c094 | 0x11218 | 0xfc18 | 0x574 |
FreeLibrary | 0x0 | 0x40c098 | 0x1121c | 0xfc1c | 0x19e |
GetProcAddress | 0x0 | 0x40c09c | 0x11220 | 0xfc20 | 0x29d |
LoadLibraryExW | 0x0 | 0x40c0a0 | 0x11224 | 0xfc24 | 0x3a7 |
GetStdHandle | 0x0 | 0x40c0a4 | 0x11228 | 0xfc28 | 0x2c0 |
WriteFile | 0x0 | 0x40c0a8 | 0x1122c | 0xfc2c | 0x5e1 |
GetModuleFileNameA | 0x0 | 0x40c0ac | 0x11230 | 0xfc30 | 0x262 |
MultiByteToWideChar | 0x0 | 0x40c0b0 | 0x11234 | 0xfc34 | 0x3d1 |
ExitProcess | 0x0 | 0x40c0b4 | 0x11238 | 0xfc38 | 0x151 |
GetModuleHandleExW | 0x0 | 0x40c0b8 | 0x1123c | 0xfc3c | 0x266 |
GetACP | 0x0 | 0x40c0bc | 0x11240 | 0xfc40 | 0x1a4 |
HeapFree | 0x0 | 0x40c0c0 | 0x11244 | 0xfc44 | 0x333 |
HeapAlloc | 0x0 | 0x40c0c4 | 0x11248 | 0xfc48 | 0x32f |
CloseHandle | 0x0 | 0x40c0c8 | 0x1124c | 0xfc4c | 0x7f |
FindClose | 0x0 | 0x40c0cc | 0x11250 | 0xfc50 | 0x168 |
FindFirstFileExA | 0x0 | 0x40c0d0 | 0x11254 | 0xfc54 | 0x16d |
FindNextFileA | 0x0 | 0x40c0d4 | 0x11258 | 0xfc58 | 0x17d |
IsValidCodePage | 0x0 | 0x40c0d8 | 0x1125c | 0xfc5c | 0x372 |
GetOEMCP | 0x0 | 0x40c0dc | 0x11260 | 0xfc60 | 0x286 |
GetCPInfo | 0x0 | 0x40c0e0 | 0x11264 | 0xfc64 | 0x1b3 |
GetCommandLineA | 0x0 | 0x40c0e4 | 0x11268 | 0xfc68 | 0x1c8 |
GetCommandLineW | 0x0 | 0x40c0e8 | 0x1126c | 0xfc6c | 0x1c9 |
GetEnvironmentStringsW | 0x0 | 0x40c0ec | 0x11270 | 0xfc70 | 0x227 |
FreeEnvironmentStringsW | 0x0 | 0x40c0f0 | 0x11274 | 0xfc74 | 0x19d |
LCMapStringW | 0x0 | 0x40c0f4 | 0x11278 | 0xfc78 | 0x396 |
SetStdHandle | 0x0 | 0x40c0f8 | 0x1127c | 0xfc7c | 0x522 |
GetFileType | 0x0 | 0x40c0fc | 0x11280 | 0xfc80 | 0x23e |
GetStringTypeW | 0x0 | 0x40c100 | 0x11284 | 0xfc84 | 0x2c5 |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\ca\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\Asia\Aden.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\pl_PL\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wma.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\LOG.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_128.png.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\vi\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Analysis Services\AS OLEDB\10\Resources\1033\msmdsrv.rll.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\Cache\9\E0\F17B2d01.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\ta\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\024823B39FBEACCDB5C06426A8168E99_6D5CAB161A1C65362A913D29BE09D91B.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\uk\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\Services\DEXShare.asfx.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\zi\SystemV\AST4ADT.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\deploy\ffjcext.zip.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\CIDFont\AdobeFanHeitiStd-Bold.otf.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\WidevineCdm\manifest.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\Adobe\HelpCfg\tr_TR\Reader_10.0.helpcfg.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\chrmstp.exe.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\02540a10-7eb7-4b20-a8c7-470f8986389c.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\images\cursors\cursors.properties.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms.locked | Created File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Common Files\microsoft shared\VBA\VBA6\VBE6EXT.OLB.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\_locales\nb\messages.json.locked | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\01_Music_auto_rated_at_5_stars.wpl.locked | Created File | Stream |
Not Queried
|
...
|