VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Spyware
Dropper
|
Threat Names: |
Gen:Variant.Razy.484160
|
uni.exe
Windows Exe (x86-32)
Created at 2020-01-28T20:25:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\uni.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4053f2 |
Size Of Code | 0x6000 |
Size Of Initialized Data | 0x22000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-25 11:59:26+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Data Access - ActiveX Data Objects Resources |
FileVersion | 2.81.1117.0 (xpsp_sp2_rtm.040803-2158) |
InternalName | ADOER15 |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | msader15.dll |
ProductName | Microsoft Data Access Components |
ProductVersion | 2.81.1117.0 |
Sections (9)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x5662 | 0x6000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.16 |
.bdata | 0x407000 | 0x2fde | 0x3000 | 0x7000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.41 |
.data | 0x40a000 | 0x222c | 0x1000 | 0xa000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.04 |
.crt1 | 0x40d000 | 0x206d | 0x3000 | 0xb000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.22 |
.reloc | 0x410000 | 0x5918 | 0x6000 | 0xe000 | IMAGE_SCN_TYPE_NOLOAD, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.55 |
X+y9UF | 0x416000 | 0x6e23 | 0x7000 | 0x14000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.9 |
MIw0* | 0x41d000 | 0x60d7 | 0x7000 | 0x1b000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.46 |
.rsrc | 0x424000 | 0x3f60 | 0x4000 | 0x22000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.22 |
.reloc | 0x428000 | 0x490 | 0x1000 | 0x26000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 2.46 |
Imports (11)
»
OLEAUT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VarCyFromUI4 | 0xe3 | 0x407080 | 0x9b68 | 0x9b68 | - |
GDI32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDeviceGammaRamp | 0x0 | 0x40701c | 0x9b04 | 0x9b04 | 0x1cc |
GetRasterizerCaps | 0x0 | 0x407020 | 0x9b08 | 0x9b08 | 0x209 |
GetTextMetricsA | 0x0 | 0x407024 | 0x9b0c | 0x9b0c | 0x225 |
GetBrushOrgEx | 0x0 | 0x407028 | 0x9b10 | 0x9b10 | 0x1ad |
LineTo | 0x0 | 0x40702c | 0x9b14 | 0x9b14 | 0x236 |
GetSystemPaletteUse | 0x0 | 0x407030 | 0x9b18 | 0x9b18 | 0x213 |
GetRandomRgn | 0x0 | 0x407034 | 0x9b1c | 0x9b1c | 0x208 |
msvcrt.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
fwprintf | 0x0 | 0x4070dc | 0x9bc4 | 0x9bc4 | 0x4af |
fwrite | 0x0 | 0x4070e0 | 0x9bc8 | 0x9bc8 | 0x4b1 |
fseek | 0x0 | 0x4070e4 | 0x9bcc | 0x9bcc | 0x4ac |
towupper | 0x0 | 0x4070e8 | 0x9bd0 | 0x9bd0 | 0x53c |
memset | 0x0 | 0x4070ec | 0x9bd4 | 0x9bd4 | 0x4ee |
system | 0x0 | 0x4070f0 | 0x9bd8 | 0x9bd8 | 0x531 |
malloc | 0x0 | 0x4070f4 | 0x9bdc | 0x9bdc | 0x4de |
POWRPROF.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsPwrHibernateAllowed | 0x0 | 0x407088 | 0x9b70 | 0x9b70 | 0xf |
USER32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadMenuA | 0x0 | 0x4070a0 | 0x9b88 | 0x9b88 | 0x1f4 |
GetKeyboardLayoutNameW | 0x0 | 0x4070a4 | 0x9b8c | 0x9b8c | 0x141 |
DrawTextW | 0x0 | 0x4070a8 | 0x9b90 | 0x9b90 | 0xd0 |
CountClipboardFormats | 0x0 | 0x4070ac | 0x9b94 | 0x9b94 | 0x56 |
IsCharLowerA | 0x0 | 0x4070b0 | 0x9b98 | 0x9b98 | 0x1c5 |
ToUnicode | 0x0 | 0x4070b4 | 0x9b9c | 0x9b9c | 0x2f3 |
GetTopWindow | 0x0 | 0x4070b8 | 0x9ba0 | 0x9ba0 | 0x185 |
IsZoomed | 0x0 | 0x4070bc | 0x9ba4 | 0x9ba4 | 0x1e2 |
GetMenuDefaultItem | 0x0 | 0x4070c0 | 0x9ba8 | 0x9ba8 | 0x14f |
GetMenuItemID | 0x0 | 0x4070c4 | 0x9bac | 0x9bac | 0x152 |
GetWindowRect | 0x0 | 0x4070c8 | 0x9bb0 | 0x9bb0 | 0x19c |
DialogBoxParamW | 0x0 | 0x4070cc | 0x9bb4 | 0x9bb4 | 0xac |
KERNEL32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetVolumeInformationA | 0x0 | 0x40703c | 0x9b24 | 0x9b24 | 0x2a5 |
Sleep | 0x0 | 0x407040 | 0x9b28 | 0x9b28 | 0x4b2 |
GetQueuedCompletionStatus | 0x0 | 0x407044 | 0x9b2c | 0x9b2c | 0x25e |
lstrcpynW | 0x0 | 0x407048 | 0x9b30 | 0x9b30 | 0x54b |
lstrcmpiW | 0x0 | 0x40704c | 0x9b34 | 0x9b34 | 0x545 |
FindResourceExA | 0x0 | 0x407050 | 0x9b38 | 0x9b38 | 0x14c |
GetTempFileNameW | 0x0 | 0x407054 | 0x9b3c | 0x9b3c | 0x283 |
GetDiskFreeSpaceExA | 0x0 | 0x407058 | 0x9b40 | 0x9b40 | 0x1cd |
GetConsoleFontSize | 0x0 | 0x40705c | 0x9b44 | 0x9b44 | 0x1a4 |
GetModuleFileNameA | 0x0 | 0x407060 | 0x9b48 | 0x9b48 | 0x213 |
GetCommandLineW | 0x0 | 0x407064 | 0x9b4c | 0x9b4c | 0x187 |
GetCPInfo | 0x0 | 0x407068 | 0x9b50 | 0x9b50 | 0x172 |
TlsGetValue | 0x0 | 0x40706c | 0x9b54 | 0x9b54 | 0x4c7 |
ReleaseMutex | 0x0 | 0x407070 | 0x9b58 | 0x9b58 | 0x3fa |
GetProcessVersion | 0x0 | 0x407074 | 0x9b5c | 0x9b5c | 0x253 |
GetModuleFileNameW | 0x0 | 0x407078 | 0x9b60 | 0x9b60 | 0x214 |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindTextW | 0x0 | 0x407014 | 0x9afc | 0x9afc | 0x8 |
ADVAPI32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTrusteeNameA | 0x0 | 0x407000 | 0x9ae8 | 0x9ae8 | 0x160 |
GetSidLengthRequired | 0x0 | 0x407004 | 0x9aec | 0x9aec | 0x156 |
GetLengthSid | 0x0 | 0x407008 | 0x9af0 | 0x9af0 | 0x136 |
LookupPrivilegeDisplayNameW | 0x0 | 0x40700c | 0x9af4 | 0x9af4 | 0x193 |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetMenuPosFromID | 0x0 | 0x407090 | 0x9b78 | 0x9b78 | 0x13 |
Secur32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FreeContextBuffer | 0x0 | 0x407098 | 0x9b80 | 0x9b80 | 0x18 |
WININET.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindFirstUrlCacheEntryW | 0x0 | 0x4070d4 | 0x9bbc | 0x9bbc | 0x19 |
Memory Dumps (28)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
uni.exe | 1 | 0x00400000 | 0x00428FFF | Relevant Image |
![]() |
32-bit | 0x00406000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00240000 | 0x00244FFF | First Execution |
![]() |
32-bit | 0x00241F1A |
![]() |
![]() |
...
|
uni.exe | 1 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040113A |
![]() |
![]() |
...
|
uni.exe | 1 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040BD8E |
![]() |
![]() |
...
|
uni.exe | 1 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040D03B |
![]() |
![]() |
...
|
uni.exe | 1 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040EBA4 |
![]() |
![]() |
...
|
uni.exe | 1 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x00402017 |
![]() |
![]() |
...
|
buffer | 1 | 0x003D0000 | 0x003E6FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00430000 | 0x00447FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
uni.exe | 1 | 0x00400000 | 0x00428FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x002D0000 | 0x002D4FFF | First Execution |
![]() |
32-bit | 0x002D1F1A |
![]() |
![]() |
...
|
uni.exe | 2 | 0x00400000 | 0x00428FFF | First Execution |
![]() |
32-bit | 0x0040113A |
![]() |
![]() |
...
|
uni.exe | 2 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040BD8E |
![]() |
![]() |
...
|
buffer | 26 | 0x002D0000 | 0x002D4FFF | First Execution |
![]() |
32-bit | 0x002D1F1A |
![]() |
![]() |
...
|
uni.exe | 26 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040113A |
![]() |
![]() |
...
|
uni.exe | 26 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040BD8E |
![]() |
![]() |
...
|
buffer | 2 | 0x002B0000 | 0x002C6FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x002E0000 | 0x002F7FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 27 | 0x002D0000 | 0x002D4FFF | First Execution |
![]() |
32-bit | 0x002D1F1A |
![]() |
![]() |
...
|
uni.exe | 27 | 0x00400000 | 0x00428FFF | First Execution |
![]() |
32-bit | 0x0040113A |
![]() |
![]() |
...
|
uni.exe | 27 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040BD8E |
![]() |
![]() |
...
|
buffer | 27 | 0x002B0000 | 0x002C6FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 26 | 0x002B0000 | 0x002C6FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 27 | 0x002E0000 | 0x002F7FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 71 | 0x001E0000 | 0x001E4FFF | First Execution |
![]() |
32-bit | 0x001E1F1A |
![]() |
![]() |
...
|
buffer | 72 | 0x003D0000 | 0x003D4FFF | First Execution |
![]() |
32-bit | 0x003D1F1A |
![]() |
![]() |
...
|
buffer | 72 | 0x00240000 | 0x00256FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 71 | 0x001C0000 | 0x001D6FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
C:\Windows\system32\wbem\WmiApSrv.exe:0 | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:43 (UTC+1) |
Last Seen | 2019-05-01 15:03 (UTC+2) |
PE Information
»
Image Base | 0x100000000 |
Entry Point | 0x10001e338 |
Size Of Code | 0x2c600 |
Size Of Initialized Data | 0x5a00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2009-07-13 23:47:44+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | WMI Performance Reverse Adapter |
FileVersion | 6.1.7600.16385 (win7_rtm.090713-1255) |
InternalName | WmiApSrv.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WmiApSrv.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7600.16385 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x100001000 | 0x2c47d | 0x2c600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.91 |
.data | 0x10002e000 | 0x2218 | 0x1a00 | 0x2ca00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.83 |
.pdata | 0x100031000 | 0x2574 | 0x2600 | 0x2e400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.37 |
.rsrc | 0x100034000 | 0x818 | 0xa00 | 0x30a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.77 |
.reloc | 0x100035000 | 0x51c | 0x600 | 0x31400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.33 |
Imports (9)
»
ADVAPI32.dll (28)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExW | 0x0 | 0x100001000 | 0x29ca8 | 0x290a8 | 0x261 |
RegEnumKeyExW | 0x0 | 0x100001008 | 0x29cb0 | 0x290b0 | 0x24f |
RegDeleteKeyW | 0x0 | 0x100001010 | 0x29cb8 | 0x290b8 | 0x244 |
RegCloseKey | 0x0 | 0x100001018 | 0x29cc0 | 0x290c0 | 0x230 |
RegDeleteValueW | 0x0 | 0x100001020 | 0x29cc8 | 0x290c8 | 0x248 |
RegCreateKeyExW | 0x0 | 0x100001028 | 0x29cd0 | 0x290d0 | 0x239 |
RegSetValueExW | 0x0 | 0x100001030 | 0x29cd8 | 0x290d8 | 0x27e |
CloseServiceHandle | 0x0 | 0x100001038 | 0x29ce0 | 0x290e0 | 0x57 |
OpenSCManagerW | 0x0 | 0x100001040 | 0x29ce8 | 0x290e8 | 0x1f9 |
OpenServiceW | 0x0 | 0x100001048 | 0x29cf0 | 0x290f0 | 0x1fb |
QueryServiceConfigW | 0x0 | 0x100001050 | 0x29cf8 | 0x290f8 | 0x224 |
QueryServiceStatus | 0x0 | 0x100001058 | 0x29d00 | 0x29100 | 0x228 |
ConvertStringSecurityDescriptorToSecurityDescriptorW | 0x0 | 0x100001060 | 0x29d08 | 0x29108 | 0x72 |
MakeAbsoluteSD | 0x0 | 0x100001068 | 0x29d10 | 0x29110 | 0x1e0 |
InitializeSecurityDescriptor | 0x0 | 0x100001070 | 0x29d18 | 0x29118 | 0x177 |
SetServiceStatus | 0x0 | 0x100001078 | 0x29d20 | 0x29120 | 0x2c0 |
RegisterServiceCtrlHandlerW | 0x0 | 0x100001080 | 0x29d28 | 0x29128 | 0x288 |
StartServiceCtrlDispatcherW | 0x0 | 0x100001088 | 0x29d30 | 0x29130 | 0x2c8 |
CreateServiceW | 0x0 | 0x100001090 | 0x29d38 | 0x29138 | 0x81 |
ChangeServiceConfig2W | 0x0 | 0x100001098 | 0x29d40 | 0x29140 | 0x4e |
ControlService | 0x0 | 0x1000010a0 | 0x29d48 | 0x29148 | 0x5c |
DeleteService | 0x0 | 0x1000010a8 | 0x29d50 | 0x29150 | 0xda |
RegEnumValueW | 0x0 | 0x1000010b0 | 0x29d58 | 0x29158 | 0x252 |
RegOpenKeyW | 0x0 | 0x1000010b8 | 0x29d60 | 0x29160 | 0x264 |
RegQueryValueExW | 0x0 | 0x1000010c0 | 0x29d68 | 0x29168 | 0x26e |
RegOpenCurrentUser | 0x0 | 0x1000010c8 | 0x29d70 | 0x29170 | 0x25e |
RegEnumKeyW | 0x0 | 0x1000010d0 | 0x29d78 | 0x29178 | 0x250 |
RegQueryInfoKeyW | 0x0 | 0x1000010d8 | 0x29d80 | 0x29180 | 0x268 |
KERNEL32.dll (65)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCurrentThreadId | 0x0 | 0x1000010e8 | 0x29d90 | 0x29190 | 0x1cb |
CreateMutexW | 0x0 | 0x1000010f0 | 0x29d98 | 0x29198 | 0x9e |
CreateEventW | 0x0 | 0x1000010f8 | 0x29da0 | 0x291a0 | 0x85 |
Sleep | 0x0 | 0x100001100 | 0x29da8 | 0x291a8 | 0x4c0 |
GetModuleFileNameW | 0x0 | 0x100001108 | 0x29db0 | 0x291b0 | 0x21a |
GetModuleHandleW | 0x0 | 0x100001110 | 0x29db8 | 0x291b8 | 0x21e |
WaitForMultipleObjects | 0x0 | 0x100001118 | 0x29dc0 | 0x291c0 | 0x506 |
UnmapViewOfFile | 0x0 | 0x100001120 | 0x29dc8 | 0x291c8 | 0x4e5 |
lstrcmpW | 0x0 | 0x100001128 | 0x29dd0 | 0x291d0 | 0x555 |
GetExitCodeProcess | 0x0 | 0x100001130 | 0x29dd8 | 0x291d8 | 0x1e6 |
FlushViewOfFile | 0x0 | 0x100001138 | 0x29de0 | 0x291e0 | 0x160 |
CreateFileMappingW | 0x0 | 0x100001140 | 0x29de8 | 0x291e8 | 0x8c |
MapViewOfFile | 0x0 | 0x100001148 | 0x29df0 | 0x291f0 | 0x359 |
DeleteCriticalSection | 0x0 | 0x100001150 | 0x29df8 | 0x291f8 | 0xd2 |
RaiseException | 0x0 | 0x100001158 | 0x29e00 | 0x29200 | 0x3b4 |
MultiByteToWideChar | 0x0 | 0x100001160 | 0x29e08 | 0x29208 | 0x369 |
FormatMessageW | 0x0 | 0x100001168 | 0x29e10 | 0x29210 | 0x164 |
GetVersionExA | 0x0 | 0x100001170 | 0x29e18 | 0x29218 | 0x2ab |
OutputDebugStringA | 0x0 | 0x100001178 | 0x29e20 | 0x29220 | 0x38b |
ReleaseMutex | 0x0 | 0x100001180 | 0x29e28 | 0x29228 | 0x3fd |
LocalAlloc | 0x0 | 0x100001188 | 0x29e30 | 0x29230 | 0x346 |
CompareStringW | 0x0 | 0x100001190 | 0x29e38 | 0x29238 | 0x64 |
GetCommandLineW | 0x0 | 0x100001198 | 0x29e40 | 0x29240 | 0x18d |
HeapSetInformation | 0x0 | 0x1000011a0 | 0x29e48 | 0x29248 | 0x2db |
EnterCriticalSection | 0x0 | 0x1000011a8 | 0x29e50 | 0x29250 | 0xf2 |
SetEvent | 0x0 | 0x1000011b0 | 0x29e58 | 0x29258 | 0x467 |
ResetEvent | 0x0 | 0x1000011b8 | 0x29e60 | 0x29260 | 0x412 |
LocalFree | 0x0 | 0x1000011c0 | 0x29e68 | 0x29268 | 0x34a |
InitializeCriticalSection | 0x0 | 0x1000011c8 | 0x29e70 | 0x29270 | 0x2ea |
GetLastError | 0x0 | 0x1000011d0 | 0x29e78 | 0x29278 | 0x208 |
GetCurrentProcess | 0x0 | 0x1000011d8 | 0x29e80 | 0x29280 | 0x1c6 |
SwitchToThread | 0x0 | 0x1000011e0 | 0x29e88 | 0x29288 | 0x4ca |
ReleaseSemaphore | 0x0 | 0x1000011e8 | 0x29e90 | 0x29290 | 0x401 |
WaitForSingleObject | 0x0 | 0x1000011f0 | 0x29e98 | 0x29298 | 0x508 |
GetVersionExW | 0x0 | 0x1000011f8 | 0x29ea0 | 0x292a0 | 0x2ac |
GetLocaleInfoW | 0x0 | 0x100001200 | 0x29ea8 | 0x292a8 | 0x20c |
lstrlenA | 0x0 | 0x100001208 | 0x29eb0 | 0x292b0 | 0x560 |
DeleteFileW | 0x0 | 0x100001210 | 0x29eb8 | 0x292b8 | 0xd7 |
CreateFileW | 0x0 | 0x100001218 | 0x29ec0 | 0x292c0 | 0x8f |
WideCharToMultiByte | 0x0 | 0x100001220 | 0x29ec8 | 0x292c8 | 0x520 |
WriteFile | 0x0 | 0x100001228 | 0x29ed0 | 0x292d0 | 0x534 |
CreateDirectoryW | 0x0 | 0x100001230 | 0x29ed8 | 0x292d8 | 0x81 |
MoveFileExW | 0x0 | 0x100001238 | 0x29ee0 | 0x292e0 | 0x362 |
OpenEventW | 0x0 | 0x100001240 | 0x29ee8 | 0x292e8 | 0x377 |
GetProcAddress | 0x0 | 0x100001248 | 0x29ef0 | 0x292f0 | 0x24c |
SetLastError | 0x0 | 0x100001250 | 0x29ef8 | 0x292f8 | 0x480 |
GetSystemDirectoryW | 0x0 | 0x100001258 | 0x29f00 | 0x29300 | 0x277 |
OpenProcess | 0x0 | 0x100001260 | 0x29f08 | 0x29308 | 0x382 |
FreeLibrary | 0x0 | 0x100001268 | 0x29f10 | 0x29310 | 0x168 |
GetSystemDefaultLangID | 0x0 | 0x100001270 | 0x29f18 | 0x29318 | 0x273 |
ExpandEnvironmentStringsW | 0x0 | 0x100001278 | 0x29f20 | 0x29320 | 0x123 |
LoadLibraryW | 0x0 | 0x100001280 | 0x29f28 | 0x29328 | 0x341 |
UnhandledExceptionFilter | 0x0 | 0x100001288 | 0x29f30 | 0x29330 | 0x4e2 |
TerminateProcess | 0x0 | 0x100001290 | 0x29f38 | 0x29338 | 0x4ce |
lstrlenW | 0x0 | 0x100001298 | 0x29f40 | 0x29340 | 0x561 |
LeaveCriticalSection | 0x0 | 0x1000012a0 | 0x29f48 | 0x29348 | 0x33b |
TryEnterCriticalSection | 0x0 | 0x1000012a8 | 0x29f50 | 0x29350 | 0x4dc |
CreateSemaphoreW | 0x0 | 0x1000012b0 | 0x29f58 | 0x29358 | 0xae |
CloseHandle | 0x0 | 0x1000012b8 | 0x29f60 | 0x29360 | 0x52 |
GetStartupInfoW | 0x0 | 0x1000012c0 | 0x29f68 | 0x29368 | 0x26a |
SetUnhandledExceptionFilter | 0x0 | 0x1000012c8 | 0x29f70 | 0x29370 | 0x4b3 |
QueryPerformanceCounter | 0x0 | 0x1000012d0 | 0x29f78 | 0x29378 | 0x3a9 |
GetTickCount | 0x0 | 0x1000012d8 | 0x29f80 | 0x29380 | 0x29a |
GetCurrentProcessId | 0x0 | 0x1000012e0 | 0x29f88 | 0x29388 | 0x1c7 |
GetSystemTimeAsFileTime | 0x0 | 0x1000012e8 | 0x29f90 | 0x29390 | 0x280 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharNextW | 0x0 | 0x100001358 | 0x2a000 | 0x29400 | 0x31 |
LoadStringW | 0x0 | 0x100001360 | 0x2a008 | 0x29408 | 0x1fe |
msvcrt.dll (55)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_unlock | 0x0 | 0x100001388 | 0x2a030 | 0x29430 | 0x330 |
??1type_info@@UEAA@XZ | 0x0 | 0x100001390 | 0x2a038 | 0x29438 | 0x12 |
__set_app_type | 0x0 | 0x100001398 | 0x2a040 | 0x29440 | 0x80 |
_fmode | 0x0 | 0x1000013a0 | 0x2a048 | 0x29448 | 0x118 |
_vsnwprintf | 0x0 | 0x1000013a8 | 0x2a050 | 0x29450 | 0x358 |
wcsrchr | 0x0 | 0x1000013b0 | 0x2a058 | 0x29458 | 0x4fe |
memmove_s | 0x0 | 0x1000013b8 | 0x2a060 | 0x29460 | 0x483 |
strlen | 0x0 | 0x1000013c0 | 0x2a068 | 0x29468 | 0x4b8 |
??0exception@@QEAA@XZ | 0x0 | 0x1000013c8 | 0x2a070 | 0x29470 | 0xd |
??0exception@@QEAA@AEBQEBD@Z | 0x0 | 0x1000013d0 | 0x2a078 | 0x29478 | 0xa |
memcpy_s | 0x0 | 0x1000013d8 | 0x2a080 | 0x29480 | 0x481 |
realloc | 0x0 | 0x1000013e0 | 0x2a088 | 0x29488 | 0x497 |
_wtol | 0x0 | 0x1000013e8 | 0x2a090 | 0x29490 | 0x3f7 |
_wcsicmp | 0x0 | 0x1000013f0 | 0x2a098 | 0x29498 | 0x379 |
__dllonexit | 0x0 | 0x1000013f8 | 0x2a0a0 | 0x294a0 | 0x6d |
wcschr | 0x0 | 0x100001400 | 0x2a0a8 | 0x294a8 | 0x4ef |
__CxxFrameHandler3 | 0x0 | 0x100001408 | 0x2a0b0 | 0x294b0 | 0x57 |
_commode | 0x0 | 0x100001410 | 0x2a0b8 | 0x294b8 | 0xc4 |
__setusermatherr | 0x0 | 0x100001418 | 0x2a0c0 | 0x294c0 | 0x82 |
_amsg_exit | 0x0 | 0x100001420 | 0x2a0c8 | 0x294c8 | 0xa0 |
_initterm | 0x0 | 0x100001428 | 0x2a0d0 | 0x294d0 | 0x16c |
_acmdln | 0x0 | 0x100001430 | 0x2a0d8 | 0x294d8 | 0x94 |
exit | 0x0 | 0x100001438 | 0x2a0e0 | 0x294e0 | 0x420 |
_cexit | 0x0 | 0x100001440 | 0x2a0e8 | 0x294e8 | 0xb3 |
_ismbblead | 0x0 | 0x100001448 | 0x2a0f0 | 0x294f0 | 0x188 |
_exit | 0x0 | 0x100001450 | 0x2a0f8 | 0x294f8 | 0xff |
_XcptFilter | 0x0 | 0x100001458 | 0x2a100 | 0x29500 | 0x52 |
__C_specific_handler | 0x0 | 0x100001460 | 0x2a108 | 0x29508 | 0x53 |
__getmainargs | 0x0 | 0x100001468 | 0x2a110 | 0x29510 | 0x71 |
_callnewh | 0x0 | 0x100001470 | 0x2a118 | 0x29518 | 0xb1 |
_lock | 0x0 | 0x100001478 | 0x2a120 | 0x29520 | 0x1d5 |
_onexit | 0x0 | 0x100001480 | 0x2a128 | 0x29528 | 0x27f |
?terminate@@YAXXZ | 0x0 | 0x100001488 | 0x2a130 | 0x29530 | 0x30 |
wcscspn | 0x0 | 0x100001490 | 0x2a138 | 0x29538 | 0x4f4 |
memcpy | 0x0 | 0x100001498 | 0x2a140 | 0x29540 | 0x480 |
iswspace | 0x0 | 0x1000014a0 | 0x2a148 | 0x29548 | 0x466 |
atol | 0x0 | 0x1000014a8 | 0x2a150 | 0x29550 | 0x40f |
wcscoll | 0x0 | 0x1000014b0 | 0x2a158 | 0x29558 | 0x4f1 |
memmove | 0x0 | 0x1000014b8 | 0x2a160 | 0x29560 | 0x482 |
wcsspn | 0x0 | 0x1000014c0 | 0x2a168 | 0x29568 | 0x501 |
iswdigit | 0x0 | 0x1000014c8 | 0x2a170 | 0x29570 | 0x461 |
wcspbrk | 0x0 | 0x1000014d0 | 0x2a178 | 0x29578 | 0x4fd |
wcsstr | 0x0 | 0x1000014d8 | 0x2a180 | 0x29580 | 0x502 |
_wcsupr | 0x0 | 0x1000014e0 | 0x2a188 | 0x29588 | 0x394 |
malloc | 0x0 | 0x1000014e8 | 0x2a190 | 0x29590 | 0x474 |
memset | 0x0 | 0x1000014f0 | 0x2a198 | 0x29598 | 0x484 |
free | 0x0 | 0x1000014f8 | 0x2a1a0 | 0x295a0 | 0x43a |
??0exception@@QEAA@AEBQEBDH@Z | 0x0 | 0x100001500 | 0x2a1a8 | 0x295a8 | 0xb |
?what@exception@@UEBAPEBDXZ | 0x0 | 0x100001508 | 0x2a1b0 | 0x295b0 | 0x32 |
??1exception@@UEAA@XZ | 0x0 | 0x100001510 | 0x2a1b8 | 0x295b8 | 0x11 |
??0exception@@QEAA@AEBV0@@Z | 0x0 | 0x100001518 | 0x2a1c0 | 0x295c0 | 0xc |
_CxxThrowException | 0x0 | 0x100001520 | 0x2a1c8 | 0x295c8 | 0x4c |
_wcslwr | 0x0 | 0x100001528 | 0x2a1d0 | 0x295d0 | 0x37d |
_wcsrev | 0x0 | 0x100001530 | 0x2a1d8 | 0x295d8 | 0x389 |
_wtoi | 0x0 | 0x100001538 | 0x2a1e0 | 0x295e0 | 0x3f3 |
ntdll.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlLookupFunctionEntry | 0x0 | 0x100001548 | 0x2a1f0 | 0x295f0 | 0x401 |
NtQuerySecurityObject | 0x0 | 0x100001550 | 0x2a1f8 | 0x295f8 | 0x1a5 |
RtlGetOwnerSecurityDescriptor | 0x0 | 0x100001558 | 0x2a200 | 0x29600 | 0x379 |
RtlEqualSid | 0x0 | 0x100001560 | 0x2a208 | 0x29608 | 0x31d |
RtlGetDaclSecurityDescriptor | 0x0 | 0x100001568 | 0x2a210 | 0x29610 | 0x35f |
RtlGetAce | 0x0 | 0x100001570 | 0x2a218 | 0x29618 | 0x353 |
RtlCaptureContext | 0x0 | 0x100001578 | 0x2a220 | 0x29620 | 0x27b |
NtQueryObject | 0x0 | 0x100001580 | 0x2a228 | 0x29628 | 0x19d |
RtlVirtualUnwind | 0x0 | 0x100001588 | 0x2a230 | 0x29630 | 0x4f0 |
OLEAUT32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SafeArrayUnaccessData | 0x18 | 0x1000012f8 | 0x29fa0 | 0x293a0 | - |
SafeArrayGetLBound | 0x14 | 0x100001300 | 0x29fa8 | 0x293a8 | - |
SafeArrayAccessData | 0x17 | 0x100001308 | 0x29fb0 | 0x293b0 | - |
SysFreeString | 0x6 | 0x100001310 | 0x29fb8 | 0x293b8 | - |
SysAllocString | 0x2 | 0x100001318 | 0x29fc0 | 0x293c0 | - |
SysStringLen | 0x7 | 0x100001320 | 0x29fc8 | 0x293c8 | - |
VariantChangeType | 0xc | 0x100001328 | 0x29fd0 | 0x293d0 | - |
VariantClear | 0x9 | 0x100001330 | 0x29fd8 | 0x293d8 | - |
SafeArrayDestroy | 0x10 | 0x100001338 | 0x29fe0 | 0x293e0 | - |
SafeArrayGetUBound | 0x13 | 0x100001340 | 0x29fe8 | 0x293e8 | - |
SysAllocStringLen | 0x4 | 0x100001348 | 0x29ff0 | 0x293f0 | - |
ole32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoCreateInstance | 0x0 | 0x100001598 | 0x2a240 | 0x29640 | 0x14 |
CoInitializeEx | 0x0 | 0x1000015a0 | 0x2a248 | 0x29648 | 0x43 |
CoUninitialize | 0x0 | 0x1000015a8 | 0x2a250 | 0x29650 | 0x70 |
CoFreeUnusedLibraries | 0x0 | 0x1000015b0 | 0x2a258 | 0x29658 | 0x21 |
CoInitializeSecurity | 0x0 | 0x1000015b8 | 0x2a260 | 0x29660 | 0x44 |
CoSetProxyBlanket | 0x0 | 0x1000015c0 | 0x2a268 | 0x29668 | 0x67 |
wbemcomn.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
?Throttle@@YAJKKKKK@Z | 0x0 | 0x1000015d0 | 0x2a278 | 0x29678 | 0x478 |
??0CStaticCritSec@@QEAA@XZ | 0x0 | 0x1000015d8 | 0x2a280 | 0x29680 | 0x5f |
??1CStaticCritSec@@QEAA@XZ | 0x0 | 0x1000015e0 | 0x2a288 | 0x29688 | 0xcc |
?anyFailure@CStaticCritSec@@SAHXZ | 0x0 | 0x1000015e8 | 0x2a290 | 0x29690 | 0x4d2 |
loadperf.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadPerfCounterTextStringsW | 0x0 | 0x100001370 | 0x2a018 | 0x29418 | 0x4 |
UnloadPerfCounterTextStringsW | 0x0 | 0x100001378 | 0x2a020 | 0x29420 | 0xb |
Exports (191)
»
Api name | EAT Address | Ordinal |
---|---|---|
??0CHPtrArray@@QEAA@XZ | 0x1d780 | 0x1 |
??0CHString@@QEAA@AEBV0@@Z | 0x1c254 | 0x2 |
??0CHString@@QEAA@GH@Z | 0x1c0a0 | 0x3 |
??0CHString@@QEAA@PEBD@Z | 0x1c160 | 0x4 |
??0CHString@@QEAA@PEBE@Z | 0x19010 | 0x5 |
??0CHString@@QEAA@PEBG@Z | 0x1c1e0 | 0x6 |
??0CHString@@QEAA@PEBGH@Z | 0x1c100 | 0x7 |
??0CHString@@QEAA@XZ | 0x1c08c | 0x8 |
??0CHStringArray@@QEAA@XZ | 0x1d780 | 0x9 |
??0CRegistry@@QEAA@AEBV0@@Z | 0x192c0 | 0xa |
??0CRegistry@@QEAA@XZ | 0x1951c | 0xb |
??0CRegistrySearch@@QEAA@AEBV0@@Z | 0x1947c | 0xc |
??0CRegistrySearch@@QEAA@XZ | 0x1aad8 | 0xd |
??1CHPtrArray@@QEAA@XZ | 0x1d798 | 0xe |
??1CHString@@QEAA@XZ | 0x1c308 | 0xf |
??1CHStringArray@@QEAA@XZ | 0x1d210 | 0x10 |
??1CRegistry@@QEAA@XZ | 0x19578 | 0x11 |
??1CRegistrySearch@@QEAA@XZ | 0x1aafc | 0x12 |
??4CHPtrArray@@QEAAAEAV0@AEBV0@@Z | 0x19238 | 0x13 |
??4CHString@@QEAAAEBV0@AEBV0@@Z | 0x1c398 | 0x14 |
??4CHString@@QEAAAEBV0@D@Z | 0x190fc | 0x15 |
??4CHString@@QEAAAEBV0@G@Z | 0x1c514 | 0x16 |
??4CHString@@QEAAAEBV0@PEAV0@@Z | 0x190dc | 0x17 |
??4CHString@@QEAAAEBV0@PEBD@Z | 0x1c494 | 0x18 |
??4CHString@@QEAAAEBV0@PEBE@Z | 0x190bc | 0x19 |
??4CHString@@QEAAAEBV0@PEBG@Z | 0x1c448 | 0x1a |
??4CHStringArray@@QEAAAEAV0@AEBV0@@Z | 0x19238 | 0x1b |
??4CRegistry@@QEAAAEAV0@AEBV0@@Z | 0x19398 | 0x1c |
??4CRegistrySearch@@QEAAAEAV0@AEBV0@@Z | 0x194cc | 0x1d |
??ACHPtrArray@@QEAAAEAPEAXH@Z | 0x1dda8 | 0x1e |
??ACHPtrArray@@QEBAPEAXH@Z | 0x1dd50 | 0x1f |
??ACHString@@QEBAGH@Z | 0x19084 | 0x20 |
??ACHStringArray@@QEAAAEAVCHString@@H@Z | 0x1dda8 | 0x21 |
??ACHStringArray@@QEBA?AVCHString@@H@Z | 0x19214 | 0x22 |
??H@YA?AVCHString@@AEBV0@0@Z | 0x1c540 | 0x23 |
??H@YA?AVCHString@@AEBV0@G@Z | 0x1c6e0 | 0x24 |
??H@YA?AVCHString@@AEBV0@PEBG@Z | 0x1c5bc | 0x25 |
??H@YA?AVCHString@@GAEBV0@@Z | 0x1c754 | 0x26 |
??H@YA?AVCHString@@PEBGAEBV0@@Z | 0x1c64c | 0x27 |
??YCHString@@QEAAAEBV0@AEBV0@@Z | 0x1c840 | 0x28 |
??YCHString@@QEAAAEBV0@D@Z | 0x1912c | 0x29 |
??YCHString@@QEAAAEBV0@G@Z | 0x1c814 | 0x2a |
??YCHString@@QEAAAEBV0@PEBG@Z | 0x1c7c8 | 0x2b |
?Add@CHPtrArray@@QEAAHPEAX@Z | 0x1dd84 | 0x2c |
?Add@CHStringArray@@QEAAHPEBG@Z | 0x191f0 | 0x2d |
?AllocBeforeWrite@CHString@@IEAAXH@Z | 0x1bf98 | 0x2e |
?AllocBuffer@CHString@@IEAAXH@Z | 0x1b7ac | 0x2f |
?AllocCopy@CHString@@IEBAXAEAV1@HHH@Z | 0x1b6a8 | 0x30 |
?AllocSysString@CHString@@QEBAPEAGXZ | 0x1d134 | 0x31 |
?Append@CHPtrArray@@QEAAHAEBV1@@Z | 0x1d948 | 0x32 |
?Append@CHStringArray@@QEAAHAEBV1@@Z | 0x1d42c | 0x33 |
?AssignCopy@CHString@@IEAAXHPEBG@Z | 0x1b860 | 0x34 |
?CheckAndAddToList@CRegistrySearch@@AEAAXPEAVCRegistry@@VCHString@@1AEAVCHPtrArray@@11H@Z | 0x1ab28 | 0x35 |
?Close@CRegistry@@QEAAXXZ | 0x1a4b4 | 0x36 |
?CloseSubKey@CRegistry@@AEAAXXZ | 0x1a59c | 0x37 |
?Collate@CHString@@QEBAHPEBG@Z | 0x1916c | 0x38 |
?Compare@CHString@@QEBAHPEBG@Z | 0x1c878 | 0x39 |
?CompareNoCase@CHString@@QEBAHPEBG@Z | 0x1915c | 0x3a |
?ConcatCopy@CHString@@IEAAXHPEBGH0@Z | 0x1b910 | 0x3b |
?ConcatInPlace@CHString@@IEAAXHPEBG@Z | 0x1b9f4 | 0x3c |
?Copy@CHPtrArray@@QEAAXAEBV1@@Z | 0x1d9a4 | 0x3d |
?Copy@CHStringArray@@QEAAXAEBV1@@Z | 0x1d4a0 | 0x3e |
?CopyBeforeWrite@CHString@@IEAAXXZ | 0x1bf24 | 0x3f |
?CreateOpen@CRegistry@@QEAAJPEAUHKEY__@@PEBGPEAGKKPEAU_SECURITY_ATTRIBUTES@@PEAK@Z | 0x199d8 | 0x40 |
?DeleteCurrentKeyValue@CRegistry@@QEAAKPEAUHKEY__@@PEBG@Z | 0x1b4b8 | 0x41 |
?DeleteCurrentKeyValue@CRegistry@@QEAAKPEBG@Z | 0x1aac4 | 0x42 |
?DeleteKey@CRegistry@@QEAAJPEAVCHString@@@Z | 0x19b2c | 0x43 |
?DeleteValue@CRegistry@@QEAAJPEBG@Z | 0x1aac4 | 0x44 |
?ElementAt@CHPtrArray@@QEAAAEAPEAXH@Z | 0x1dda8 | 0x45 |
?ElementAt@CHStringArray@@QEAAAEAVCHString@@H@Z | 0x1dda8 | 0x46 |
?Empty@CHString@@QEAAXXZ | 0x1c2b4 | 0x47 |
?EnumerateAndGetValues@CRegistry@@QEAAJAEAKAEAPEAGAEAPEAE@Z | 0x195f8 | 0x48 |
?Find@CHString@@QEBAHG@Z | 0x1cb04 | 0x49 |
?Find@CHString@@QEBAHPEBG@Z | 0x1cb94 | 0x4a |
?FindOneOf@CHString@@QEBAHPEBG@Z | 0x1cb34 | 0x4b |
?Format@CHString@@QEAAXIZZ | 0x1d120 | 0x4c |
?Format@CHString@@QEAAXPEBGZZ | 0x1d01c | 0x4d |
?FormatMessageW@CHString@@QEAAXIZZ | 0x1d120 | 0x4e |
?FormatMessageW@CHString@@QEAAXPEBGZZ | 0x1d054 | 0x4f |
?FormatV@CHString@@QEAAXPEBGPEAD@Z | 0x1bb88 | 0x50 |
?FreeExtra@CHPtrArray@@QEAAXXZ | 0x1d9e4 | 0x51 |
?FreeExtra@CHString@@QEAAXXZ | 0x1ca1c | 0x52 |
?FreeExtra@CHStringArray@@QEAAXXZ | 0x1d9e4 | 0x53 |
?FreeSearchList@CRegistrySearch@@QEAAHHAEAVCHPtrArray@@@Z | 0x1b030 | 0x54 |
?GetAllocLength@CHString@@QEBAHXZ | 0x19098 | 0x55 |
?GetAt@CHPtrArray@@QEBAPEAXH@Z | 0x1dd50 | 0x56 |
?GetAt@CHString@@QEBAGH@Z | 0x19084 | 0x57 |
?GetAt@CHStringArray@@QEBA?AVCHString@@H@Z | 0x191a8 | 0x58 |
?GetBuffer@CHString@@QEAAPEAGH@Z | 0x1c8a0 | 0x59 |
?GetBufferSetLength@CHString@@QEAAPEAGH@Z | 0x1c9cc | 0x5a |
?GetClassNameW@CRegistry@@QEAAPEAGXZ | 0x19264 | 0x5b |
?GetCurrentBinaryKeyValue@CRegistry@@QEAAKPEAUHKEY__@@PEBGPEAEPEAK@Z | 0x1a31c | 0x5c |
?GetCurrentBinaryKeyValue@CRegistry@@QEAAKPEBGAEAVCHString@@@Z | 0x1a1a0 | 0x5d |
?GetCurrentBinaryKeyValue@CRegistry@@QEAAKPEBGPEAEPEAK@Z | 0x1a2ec | 0x5e |
?GetCurrentKeyValue@CRegistry@@QEAAKPEAUHKEY__@@PEBGAEAK@Z | 0x1a0c8 | 0x5f |
?GetCurrentKeyValue@CRegistry@@QEAAKPEAUHKEY__@@PEBGAEAVCHString@@@Z | 0x19c04 | 0x60 |
?GetCurrentKeyValue@CRegistry@@QEAAKPEAUHKEY__@@PEBGAEAVCHStringArray@@@Z | 0x19f38 | 0x61 |
?GetCurrentKeyValue@CRegistry@@QEAAKPEBGAEAK@Z | 0x1a188 | 0x62 |
?GetCurrentKeyValue@CRegistry@@QEAAKPEBGAEAVCHString@@@Z | 0x19f20 | 0x63 |
?GetCurrentKeyValue@CRegistry@@QEAAKPEBGAEAVCHStringArray@@@Z | 0x1a0b0 | 0x64 |
?GetCurrentRawKeyValue@CRegistry@@AEAAKPEAUHKEY__@@PEBGPEAXPEAK3@Z | 0x19bcc | 0x65 |
?GetCurrentRawSubKeyValue@CRegistry@@AEAAKPEBGPEAXPEAK2@Z | 0x1a5c8 | 0x66 |
?GetCurrentSubKeyCount@CRegistry@@QEAAKXZ | 0x19270 | 0x67 |
?GetCurrentSubKeyName@CRegistry@@QEAAKAEAVCHString@@@Z | 0x1a358 | 0x68 |
?GetCurrentSubKeyPath@CRegistry@@QEAAKAEAVCHString@@@Z | 0x1a3e4 | 0x69 |
?GetCurrentSubKeyValue@CRegistry@@QEAAKPEBGAEAK@Z | 0x1a6d8 | 0x6a |
?GetCurrentSubKeyValue@CRegistry@@QEAAKPEBGAEAVCHString@@@Z | 0x1a68c | 0x6b |
?GetCurrentSubKeyValue@CRegistry@@QEAAKPEBGPEAXPEAK@Z | 0x1a630 | 0x6c |
?GetData@CHPtrArray@@QEAAPEAPEAXXZ | 0x1dd78 | 0x6d |
?GetData@CHPtrArray@@QEBAPEAPEBXXZ | 0x1dd78 | 0x6e |
?GetData@CHString@@IEBAPEAUCHStringData@@XZ | 0x1b674 | 0x6f |
?GetData@CHStringArray@@QEAAPEAVCHString@@XZ | 0x1dd78 | 0x70 |
?GetData@CHStringArray@@QEBAPEBVCHString@@XZ | 0x1dd78 | 0x71 |
?GetLength@CHString@@QEBAHXZ | 0x19038 | 0x72 |
?GetLongestClassStringSize@CRegistry@@QEAAKXZ | 0x19290 | 0x73 |
?GetLongestSubKeySize@CRegistry@@QEAAKXZ | 0x19280 | 0x74 |
?GetLongestValueData@CRegistry@@QEAAKXZ | 0x192b0 | 0x75 |
?GetLongestValueName@CRegistry@@QEAAKXZ | 0x192a0 | 0x76 |
?GetSize@CHPtrArray@@QEBAHXZ | 0x1917c | 0x77 |
?GetSize@CHStringArray@@QEBAHXZ | 0x1917c | 0x78 |
?GetUpperBound@CHPtrArray@@QEBAHXZ | 0x19188 | 0x79 |
?GetUpperBound@CHStringArray@@QEBAHXZ | 0x19188 | 0x7a |
?GethKey@CRegistry@@QEAAPEAUHKEY__@@XZ | 0x19258 | 0x7b |
?Init@CHString@@IEAAXXZ | 0x1b694 | 0x7c |
?InsertAt@CHPtrArray@@QEAAXHPEAV1@@Z | 0x1dca4 | 0x7d |
?InsertAt@CHPtrArray@@QEAAXHPEAXH@Z | 0x1daa8 | 0x7e |
?InsertAt@CHStringArray@@QEAAXHPEAV1@@Z | 0x1d6c8 | 0x7f |
?InsertAt@CHStringArray@@QEAAXHPEBGH@Z | 0x1d54c | 0x80 |
?IsEmpty@CHString@@QEBAHXZ | 0x1905c | 0x81 |
?Left@CHString@@QEBA?AV1@H@Z | 0x1cdd8 | 0x82 |
?LoadStringW@CHString@@IEAAHIPEAGI@Z | 0x1d180 | 0x83 |
?LoadStringW@CHString@@QEAAHI@Z | 0x1d180 | 0x84 |
?LocateKeyByNameOrValueName@CRegistrySearch@@QEAAHPEAUHKEY__@@PEBG1PEAPEBGKAEAVCHString@@3@Z | 0x1b0c0 | 0x85 |
?LockBuffer@CHString@@QEAAPEAGXZ | 0x1caa0 | 0x86 |
?MakeLower@CHString@@QEAAXXZ | 0x1cbe8 | 0x87 |
?MakeReverse@CHString@@QEAAXXZ | 0x1cc0c | 0x88 |
?MakeUpper@CHString@@QEAAXXZ | 0x1cbc4 | 0x89 |
?Mid@CHString@@QEBA?AV1@H@Z | 0x1cc30 | 0x8a |
?Mid@CHString@@QEBA?AV1@HH@Z | 0x1cc74 | 0x8b |
?NextSubKey@CRegistry@@QEAAKXZ | 0x1a724 | 0x8c |
?Open@CRegistry@@QEAAJPEAUHKEY__@@PEBGK@Z | 0x198c4 | 0x8d |
?OpenAndEnumerateSubKeys@CRegistry@@QEAAJPEAUHKEY__@@PEBGK@Z | 0x19b60 | 0x8e |
?OpenCurrentUser@CRegistry@@QEAAKPEBGK@Z | 0x19794 | 0x8f |
?OpenLocalMachineKeyAndReadValue@CRegistry@@QEAAJPEBG0AEAVCHString@@@Z | 0x19b70 | 0x90 |
?OpenSubKey@CRegistry@@AEAAKXZ | 0x1a510 | 0x91 |
?PrepareToReOpen@CRegistry@@AEAAXXZ | 0x1a768 | 0x92 |
?Release@CHString@@QEAAXXZ | 0x1bffc | 0x93 |
?Release@CHString@@SAXPEAUCHStringData@@@Z | 0x1c05c | 0x94 |
?ReleaseBuffer@CHString@@QEAAXH@Z | 0x1c968 | 0x95 |
?RemoveAll@CHPtrArray@@QEAAXXZ | 0x1dd24 | 0x96 |
?RemoveAll@CHStringArray@@QEAAXXZ | 0x19194 | 0x97 |
?RemoveAt@CHPtrArray@@QEAAXHH@Z | 0x1dc54 | 0x98 |
?RemoveAt@CHStringArray@@QEAAXHH@Z | 0x1d62c | 0x99 |
?ReverseFind@CHString@@QEBAHG@Z | 0x1cb64 | 0x9a |
?RewindSubKeys@CRegistry@@QEAAXXZ | 0x1a590 | 0x9b |
?Right@CHString@@QEBA?AV1@H@Z | 0x1cd38 | 0x9c |
?SafeStrlen@CHString@@KAHPEBG@Z | 0x18fe4 | 0x9d |
?SearchAndBuildList@CRegistrySearch@@QEAAHVCHString@@AEAVCHPtrArray@@00HPEAUHKEY__@@@Z | 0x1accc | 0x9e |
?SetAt@CHPtrArray@@QEAAXHPEAX@Z | 0x1dd64 | 0x9f |
?SetAt@CHString@@QEAAXHG@Z | 0x1c35c | 0xa0 |
?SetAt@CHStringArray@@QEAAXHPEBG@Z | 0x191d8 | 0xa1 |
?SetAtGrow@CHPtrArray@@QEAAXHPEAX@Z | 0x1da60 | 0xa2 |
?SetAtGrow@CHStringArray@@QEAAXHPEBG@Z | 0x1d4fc | 0xa3 |
?SetCHStringResourceHandle@@YAXPEAUHINSTANCE__@@@Z | 0x1b610 | 0xa4 |
?SetCurrentKeyValue@CRegistry@@QEAAKPEAUHKEY__@@PEBGAEAK@Z | 0x1a898 | 0xa5 |
?SetCurrentKeyValue@CRegistry@@QEAAKPEAUHKEY__@@PEBGAEAVCHString@@@Z | 0x1a844 | 0xa6 |
?SetCurrentKeyValue@CRegistry@@QEAAKPEAUHKEY__@@PEBGAEAVCHStringArray@@@Z | 0x1a8d0 | 0xa7 |
?SetCurrentKeyValue@CRegistry@@QEAAKPEBGAEAK@Z | 0x1a800 | 0xa8 |
?SetCurrentKeyValue@CRegistry@@QEAAKPEBGAEAVCHString@@@Z | 0x1a78c | 0xa9 |
?SetCurrentKeyValue@CRegistry@@QEAAKPEBGAEAVCHStringArray@@@Z | 0x1a82c | 0xaa |
?SetCurrentKeyValueExpand@CRegistry@@QEAAKPEAUHKEY__@@PEBGAEAVCHString@@@Z | 0x1aa70 | 0xab |
?SetDefaultValues@CRegistry@@AEAAXXZ | 0x195b0 | 0xac |
?SetPlatformID@CRegistry@@CAHXZ | 0x1b354 | 0xad |
?SetSize@CHPtrArray@@QEAAXHH@Z | 0x1d7b4 | 0xae |
?SetSize@CHStringArray@@QEAAXHH@Z | 0x1d25c | 0xaf |
?SpanExcluding@CHString@@QEBA?AV1@PEBG@Z | 0x1cea4 | 0xb0 |
?SpanIncluding@CHString@@QEBA?AV1@PEBG@Z | 0x1ce60 | 0xb1 |
?TrimLeft@CHString@@QEAAXXZ | 0x1cf80 | 0xb2 |
?TrimRight@CHString@@QEAAXXZ | 0x1cee8 | 0xb3 |
?UnlockBuffer@CHString@@QEAAXXZ | 0x1cad8 | 0xb4 |
?myRegCreateKeyEx@CRegistry@@AEAAJPEAUHKEY__@@PEBGKPEAGKKQEAU_SECURITY_ATTRIBUTES@@PEAPEAU2@PEAK@Z | 0x1b3a8 | 0xb5 |
?myRegDeleteKey@CRegistry@@AEAAJPEAUHKEY__@@PEBG@Z | 0x1b4cc | 0xb6 |
?myRegDeleteValue@CRegistry@@AEAAJPEAUHKEY__@@PEBG@Z | 0x1b4b8 | 0xb7 |
?myRegEnumKey@CRegistry@@AEAAJPEAUHKEY__@@KPEAGK@Z | 0x1b494 | 0xb8 |
?myRegEnumValue@CRegistry@@AEAAJPEAUHKEY__@@KPEAGPEAK22PEAE2@Z | 0x1b5b0 | 0xb9 |
?myRegOpenKeyEx@CRegistry@@AEAAJPEAUHKEY__@@PEBGKKPEAPEAU2@@Z | 0x1b4e0 | 0xba |
?myRegQueryInfoKey@CRegistry@@AEAAJPEAUHKEY__@@PEAGPEAK22222222PEAU_FILETIME@@@Z | 0x1b518 | 0xbb |
?myRegQueryValueEx@CRegistry@@AEAAJPEAUHKEY__@@PEBGPEAK2PEAE2@Z | 0x1b454 | 0xbc |
?myRegSetValueEx@CRegistry@@AEAAJPEAUHKEY__@@PEBGKKPEBEK@Z | 0x1b414 | 0xbd |
?s_dwPlatform@CRegistry@@0KA | 0x30100 | 0xbe |
?s_fPlatformSet@CRegistry@@0HA | 0x30104 | 0xbf |
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab | Modified File | Binary |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.un1que | Dropped File | Binary |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.un1que | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\kP8E59.tmp | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.un1que_readme | Dropped File | Text |
Unknown
|
...
|
»