VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Trojan.GenericKD.34029721
Gen:Variant.Razy.691249
Gen:Trojan.Heur.FU.bvZ@aS6OnCp
...
|
Launchy.exe
Windows Exe (x86-32)
Created at 2020-06-24T21:13:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Launchy.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4f12b0 |
Size Of Code | 0xf0e00 |
Size Of Initialized Data | 0x14800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-06-11 04:10:48+00:00 |
Version Information (8)
»
CompanyName | Code Jelly |
FileDescription | Launchy |
FileVersion | 1.0.0 |
InternalName | Launchy.exe |
LegalCopyright | This is GNU Software copyright Josh Karlin |
OriginalFilename | Launchy.exe |
ProductName | Launchy |
ProductVersion | 2.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xf0d0f | 0xf0e00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 1.78 |
.data | 0x4f2000 | 0xc9fc | 0xca00 | 0xf1000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.38 |
.rsrc | 0x4ff000 | 0x7d58 | 0x7e00 | 0xfda00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.07 |
Imports (6)
»
KERNEL32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryExA | 0x0 | 0x4fe7c0 | 0xfe760 | 0xfd760 | 0x2f2 |
GetProcAddress | 0x0 | 0x4fe7c4 | 0xfe764 | 0xfd764 | 0x220 |
GetLastError | 0x0 | 0x4fe7c8 | 0xfe768 | 0xfd768 | 0x1e6 |
LoadLibraryA | 0x0 | 0x4fe7cc | 0xfe76c | 0xfd76c | 0x2f1 |
GetModuleHandleA | 0x0 | 0x4fe7d0 | 0xfe770 | 0xfd770 | 0x1f6 |
USER32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadIconA | 0x0 | 0x4fe7d8 | 0xfe778 | 0xfd778 | 0x1d6 |
LoadCursorFromFileA | 0x0 | 0x4fe7dc | 0xfe77c | 0xfd77c | 0x1d3 |
GetKeyState | 0x0 | 0x4fe7e0 | 0xfe780 | 0xfd780 | 0x131 |
GDI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStockObject | 0x0 | 0x4fe7e8 | 0xfe788 | 0xfd788 | 0x1f4 |
GetStretchBltMode | 0x0 | 0x4fe7ec | 0xfe78c | 0xfd78c | 0x1f5 |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyA | 0x0 | 0x4fe7f4 | 0xfe794 | 0xfd794 | 0x259 |
SHELL32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetPathFromIDListA | 0x0 | 0x4fe7fc | 0xfe79c | 0xfd79c | 0xcf |
SHBrowseForFolderA | 0x0 | 0x4fe800 | 0xfe7a0 | 0xfd7a0 | 0x77 |
SHGetFileInfoA | 0x0 | 0x4fe804 | 0xfe7a4 | 0xfd7a4 | 0xb9 |
ShellExecuteA | 0x0 | 0x4fe808 | 0xfe7a8 | 0xfd7a8 | 0x114 |
SHFileOperationA | 0x0 | 0x4fe80c | 0xfe7ac | 0xfd7ac | 0xa8 |
SHGetSpecialFolderLocation | 0x0 | 0x4fe810 | 0xfe7b0 | 0xfd7b0 | 0xd8 |
IMM32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImmDisableIME | 0x0 | 0x4fe818 | 0xfe7b8 | 0xfd7b8 | 0x23 |
Digital Signatures (1)
»
Certificate: YZCKUEONYQSURZWORG
»
Issued by | YZCKUEONYQSURZWORG |
Country Name | - |
Valid From | 2020-06-02 21:50:04+00:00 |
Valid Until | 2039-12-31 23:59:59+00:00 |
Algorithm | sha1_rsa |
Serial Number | B7 C1 A4 C4 68 80 ED 93 4E F8 C1 0B A2 FB 6D 4E |
Thumbprint | 29 99 55 84 1E BB A0 C5 EC 4E F4 BB E0 1A 8F 1E B6 92 F8 6F |
Memory Dumps (16)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
launchy.exe | 1 | 0x00400000 | 0x00506FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00210000 | 0x0021FFFF | First Execution |
![]() |
32-bit | 0x0021EFC0 |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00506FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00506FFF | Content Changed |
![]() |
32-bit | 0x004016FC |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00506FFF | Content Changed |
![]() |
32-bit | 0x0040861C |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00506FFF | Content Changed |
![]() |
32-bit | 0x00405C3A |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00506FFF | Content Changed |
![]() |
32-bit | 0x00402001 |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00506FFF | Content Changed |
![]() |
32-bit | 0x00404C4A |
![]() |
![]() |
...
|
boot:bin | 2 | 0x00400000 | 0x00506FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x00210000 | 0x0021FFFF | First Execution |
![]() |
32-bit | 0x0021EFC0 |
![]() |
![]() |
...
|
boot:bin | 2 | 0x00400000 | 0x00506FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x00220000 | 0x0022EFFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00220000 | 0x0022EFFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00506FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
boot.exe | 24 | 0x00400000 | 0x00506FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 24 | 0x002D0000 | 0x002DFFFF | First Execution |
![]() |
32-bit | 0x002DEFC0 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.34029721 |
Malicious
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\2bZi.pdf.rlhwasted | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\Jt_SQ14GS-1JSgWc-.pdf.rlhwasted | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZXTkq.pdf.rlhwasted | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Boot | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x1f9a0000 |
Entry Point | 0x1f9ca7f3 |
Size Of Code | 0xbbe00 |
Size Of Initialized Data | 0x6b600 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2010-11-20 12:05:55+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Speech API |
FileVersion | 5.3.13120.00 (win7sp1_rtm.101119-1850) |
InternalName | sapi.dll |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | sapi.dll |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 5.3.13120.00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x1f9a1000 | 0xbbce1 | 0xbbe00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.63 |
.data | 0x1fa5d000 | 0x4264 | 0x2400 | 0xbc200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.96 |
.rsrc | 0x1fa62000 | 0x5d570 | 0x5d600 | 0xbe600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.71 |
.reloc | 0x1fac0000 | 0x9bbc | 0x9c00 | 0x11bc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.14 |
Imports (8)
»
KERNEL32.dll (148)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCommandLineA | 0x0 | 0x1f9a1094 | 0xbb3e0 | 0xba7e0 | 0x186 |
HeapAlloc | 0x0 | 0x1f9a1098 | 0xbb3e4 | 0xba7e4 | 0x2cb |
HeapFree | 0x0 | 0x1f9a109c | 0xbb3e8 | 0xba7e8 | 0x2cf |
HeapReAlloc | 0x0 | 0x1f9a10a0 | 0xbb3ec | 0xba7ec | 0x2d2 |
VirtualProtect | 0x0 | 0x1f9a10a4 | 0xbb3f0 | 0xba7f0 | 0x4ef |
VirtualAlloc | 0x0 | 0x1f9a10a8 | 0xbb3f4 | 0xba7f4 | 0x4e9 |
GetSystemInfo | 0x0 | 0x1f9a10ac | 0xbb3f8 | 0xba7f8 | 0x272 |
VirtualQuery | 0x0 | 0x1f9a10b0 | 0xbb3fc | 0xba7fc | 0x4f1 |
GetModuleHandleA | 0x0 | 0x1f9a10b4 | 0xbb400 | 0xba800 | 0x213 |
ExitProcess | 0x0 | 0x1f9a10b8 | 0xbb404 | 0xba804 | 0x119 |
TlsGetValue | 0x0 | 0x1f9a10bc | 0xbb408 | 0xba808 | 0x4c7 |
TlsAlloc | 0x0 | 0x1f9a10c0 | 0xbb40c | 0xba80c | 0x4c5 |
TlsSetValue | 0x0 | 0x1f9a10c4 | 0xbb410 | 0xba810 | 0x4c8 |
TlsFree | 0x0 | 0x1f9a10c8 | 0xbb414 | 0xba814 | 0x4c6 |
SetLastError | 0x0 | 0x1f9a10cc | 0xbb418 | 0xba818 | 0x471 |
GetCurrentThreadId | 0x0 | 0x1f9a10d0 | 0xbb41c | 0xba81c | 0x1c5 |
GetCurrentThread | 0x0 | 0x1f9a10d4 | 0xbb420 | 0xba820 | 0x1c4 |
SetHandleCount | 0x0 | 0x1f9a10d8 | 0xbb424 | 0xba824 | 0x46d |
GetStdHandle | 0x0 | 0x1f9a10dc | 0xbb428 | 0xba828 | 0x263 |
GetFileType | 0x0 | 0x1f9a10e0 | 0xbb42c | 0xba82c | 0x1f1 |
GetStartupInfoA | 0x0 | 0x1f9a10e4 | 0xbb430 | 0xba830 | 0x261 |
GetModuleFileNameA | 0x0 | 0x1f9a10e8 | 0xbb434 | 0xba834 | 0x211 |
FreeEnvironmentStringsA | 0x0 | 0x1f9a10ec | 0xbb438 | 0xba838 | 0x160 |
GetEnvironmentStrings | 0x0 | 0x1f9a10f0 | 0xbb43c | 0xba83c | 0x1d8 |
FreeEnvironmentStringsW | 0x0 | 0x1f9a10f4 | 0xbb440 | 0xba840 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x1f9a10f8 | 0xbb444 | 0xba844 | 0x1da |
HeapDestroy | 0x0 | 0x1f9a10fc | 0xbb448 | 0xba848 | 0x2ce |
HeapCreate | 0x0 | 0x1f9a1100 | 0xbb44c | 0xba84c | 0x2cd |
QueryPerformanceCounter | 0x0 | 0x1f9a1104 | 0xbb450 | 0xba850 | 0x3a6 |
GetCurrentProcessId | 0x0 | 0x1f9a1108 | 0xbb454 | 0xba854 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x1f9a110c | 0xbb458 | 0xba858 | 0x278 |
WriteFile | 0x0 | 0x1f9a1110 | 0xbb45c | 0xba85c | 0x525 |
OutputDebugStringA | 0x0 | 0x1f9a1114 | 0xbb460 | 0xba860 | 0x388 |
RtlUnwind | 0x0 | 0x1f9a1118 | 0xbb464 | 0xba864 | 0x417 |
TerminateProcess | 0x0 | 0x1f9a111c | 0xbb468 | 0xba868 | 0x4c0 |
GetCurrentProcess | 0x0 | 0x1f9a1120 | 0xbb46c | 0xba86c | 0x1c0 |
UnhandledExceptionFilter | 0x0 | 0x1f9a1124 | 0xbb470 | 0xba870 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x1f9a1128 | 0xbb474 | 0xba874 | 0x4a4 |
HeapSize | 0x0 | 0x1f9a112c | 0xbb478 | 0xba878 | 0x2d4 |
LoadLibraryExA | 0x0 | 0x1f9a1130 | 0xbb47c | 0xba87c | 0x33d |
GetCPInfo | 0x0 | 0x1f9a1134 | 0xbb480 | 0xba880 | 0x172 |
GetACP | 0x0 | 0x1f9a1138 | 0xbb484 | 0xba884 | 0x168 |
GetOEMCP | 0x0 | 0x1f9a113c | 0xbb488 | 0xba888 | 0x235 |
Sleep | 0x0 | 0x1f9a1140 | 0xbb48c | 0xba88c | 0x4b2 |
GetLocaleInfoA | 0x0 | 0x1f9a1144 | 0xbb490 | 0xba890 | 0x202 |
IsValidLocale | 0x0 | 0x1f9a1148 | 0xbb494 | 0xba894 | 0x30c |
GetStringTypeA | 0x0 | 0x1f9a114c | 0xbb498 | 0xba898 | 0x265 |
GetStringTypeW | 0x0 | 0x1f9a1150 | 0xbb49c | 0xba89c | 0x268 |
LCMapStringA | 0x0 | 0x1f9a1154 | 0xbb4a0 | 0xba8a0 | 0x32b |
LCMapStringW | 0x0 | 0x1f9a1158 | 0xbb4a4 | 0xba8a4 | 0x32d |
CompareStringW | 0x0 | 0x1f9a115c | 0xbb4a8 | 0xba8a8 | 0x64 |
WideCharToMultiByte | 0x0 | 0x1f9a1160 | 0xbb4ac | 0xba8ac | 0x511 |
InterlockedExchange | 0x0 | 0x1f9a1164 | 0xbb4b0 | 0xba8b0 | 0x2ec |
GetVersionExA | 0x0 | 0x1f9a1168 | 0xbb4b4 | 0xba8b4 | 0x2a2 |
LoadLibraryExW | 0x0 | 0x1f9a116c | 0xbb4b8 | 0xba8b8 | 0x33e |
FindResourceW | 0x0 | 0x1f9a1170 | 0xbb4bc | 0xba8bc | 0x14e |
LoadResource | 0x0 | 0x1f9a1174 | 0xbb4c0 | 0xba8c0 | 0x341 |
SizeofResource | 0x0 | 0x1f9a1178 | 0xbb4c4 | 0xba8c4 | 0x4b1 |
MultiByteToWideChar | 0x0 | 0x1f9a117c | 0xbb4c8 | 0xba8c8 | 0x366 |
GetTickCount | 0x0 | 0x1f9a1180 | 0xbb4cc | 0xba8cc | 0x292 |
ExpandEnvironmentStringsW | 0x0 | 0x1f9a1184 | 0xbb4d0 | 0xba8d0 | 0x11d |
FreeLibrary | 0x0 | 0x1f9a1188 | 0xbb4d4 | 0xba8d4 | 0x162 |
GetSystemDirectoryW | 0x0 | 0x1f9a118c | 0xbb4d8 | 0xba8d8 | 0x26f |
GetModuleFileNameW | 0x0 | 0x1f9a1190 | 0xbb4dc | 0xba8dc | 0x212 |
ResetEvent | 0x0 | 0x1f9a1194 | 0xbb4e0 | 0xba8e0 | 0x40e |
CreateEventW | 0x0 | 0x1f9a1198 | 0xbb4e4 | 0xba8e4 | 0x85 |
lstrcmpiW | 0x0 | 0x1f9a119c | 0xbb4e8 | 0xba8e8 | 0x545 |
GetModuleHandleW | 0x0 | 0x1f9a11a0 | 0xbb4ec | 0xba8ec | 0x216 |
GetProcAddress | 0x0 | 0x1f9a11a4 | 0xbb4f0 | 0xba8f0 | 0x243 |
LoadLibraryW | 0x0 | 0x1f9a11a8 | 0xbb4f4 | 0xba8f4 | 0x33f |
InterlockedDecrement | 0x0 | 0x1f9a11ac | 0xbb4f8 | 0xba8f8 | 0x2eb |
InterlockedIncrement | 0x0 | 0x1f9a11b0 | 0xbb4fc | 0xba8fc | 0x2ef |
GetLastError | 0x0 | 0x1f9a11b4 | 0xbb500 | 0xba900 | 0x200 |
DeleteCriticalSection | 0x0 | 0x1f9a11b8 | 0xbb504 | 0xba904 | 0xd1 |
InitializeCriticalSection | 0x0 | 0x1f9a11bc | 0xbb508 | 0xba908 | 0x2e3 |
LeaveCriticalSection | 0x0 | 0x1f9a11c0 | 0xbb50c | 0xba90c | 0x339 |
EnterCriticalSection | 0x0 | 0x1f9a11c4 | 0xbb510 | 0xba910 | 0xee |
RaiseException | 0x0 | 0x1f9a11c8 | 0xbb514 | 0xba914 | 0x3b0 |
lstrlenW | 0x0 | 0x1f9a11cc | 0xbb518 | 0xba918 | 0x54e |
WaitForSingleObject | 0x0 | 0x1f9a11d0 | 0xbb51c | 0xba91c | 0x4f9 |
SetEvent | 0x0 | 0x1f9a11d4 | 0xbb520 | 0xba920 | 0x458 |
CloseHandle | 0x0 | 0x1f9a11d8 | 0xbb524 | 0xba924 | 0x52 |
VirtualFree | 0x0 | 0x1f9a11dc | 0xbb528 | 0xba928 | 0x4ec |
ReleaseMutex | 0x0 | 0x1f9a11e0 | 0xbb52c | 0xba92c | 0x3f9 |
CreateFileA | 0x0 | 0x1f9a11e4 | 0xbb530 | 0xba930 | 0x88 |
WriteConsoleW | 0x0 | 0x1f9a11e8 | 0xbb534 | 0xba934 | 0x524 |
GetConsoleOutputCP | 0x0 | 0x1f9a11ec | 0xbb538 | 0xba938 | 0x1b0 |
WriteConsoleA | 0x0 | 0x1f9a11f0 | 0xbb53c | 0xba93c | 0x51a |
SetStdHandle | 0x0 | 0x1f9a11f4 | 0xbb540 | 0xba940 | 0x486 |
GetConsoleMode | 0x0 | 0x1f9a11f8 | 0xbb544 | 0xba944 | 0x1ac |
GetVersionExW | 0x0 | 0x1f9a11fc | 0xbb548 | 0xba948 | 0x2a3 |
CreateFileW | 0x0 | 0x1f9a1200 | 0xbb54c | 0xba94c | 0x8f |
ReadFile | 0x0 | 0x1f9a1204 | 0xbb550 | 0xba950 | 0x3bf |
SetFilePointer | 0x0 | 0x1f9a1208 | 0xbb554 | 0xba954 | 0x464 |
SetEndOfFile | 0x0 | 0x1f9a120c | 0xbb558 | 0xba958 | 0x452 |
LockFileEx | 0x0 | 0x1f9a1210 | 0xbb55c | 0xba95c | 0x352 |
UnlockFileEx | 0x0 | 0x1f9a1214 | 0xbb560 | 0xba960 | 0x4d5 |
GetFileInformationByHandle | 0x0 | 0x1f9a1218 | 0xbb564 | 0xba964 | 0x1ea |
DuplicateHandle | 0x0 | 0x1f9a121c | 0xbb568 | 0xba968 | 0xe8 |
GetUserDefaultUILanguage | 0x0 | 0x1f9a1220 | 0xbb56c | 0xba96c | 0x29d |
SetProcessShutdownParameters | 0x0 | 0x1f9a1224 | 0xbb570 | 0xba970 | 0x481 |
SearchPathW | 0x0 | 0x1f9a1228 | 0xbb574 | 0xba974 | 0x41c |
LocalFree | 0x0 | 0x1f9a122c | 0xbb578 | 0xba978 | 0x348 |
CreateNamedPipeW | 0x0 | 0x1f9a1230 | 0xbb57c | 0xba97c | 0xa0 |
SetNamedPipeHandleState | 0x0 | 0x1f9a1234 | 0xbb580 | 0xba980 | 0x47a |
WaitNamedPipeW | 0x0 | 0x1f9a1238 | 0xbb584 | 0xba984 | 0x500 |
CreateMutexW | 0x0 | 0x1f9a123c | 0xbb588 | 0xba988 | 0x9e |
OpenMutexW | 0x0 | 0x1f9a1240 | 0xbb58c | 0xba98c | 0x37c |
ConnectNamedPipe | 0x0 | 0x1f9a1244 | 0xbb590 | 0xba990 | 0x65 |
FlushFileBuffers | 0x0 | 0x1f9a1248 | 0xbb594 | 0xba994 | 0x157 |
GetOverlappedResult | 0x0 | 0x1f9a124c | 0xbb598 | 0xba998 | 0x236 |
WaitForMultipleObjects | 0x0 | 0x1f9a1250 | 0xbb59c | 0xba99c | 0x4f7 |
CancelIo | 0x0 | 0x1f9a1254 | 0xbb5a0 | 0xba9a0 | 0x42 |
OpenEventW | 0x0 | 0x1f9a1258 | 0xbb5a4 | 0xba9a4 | 0x374 |
UnmapViewOfFile | 0x0 | 0x1f9a125c | 0xbb5a8 | 0xba9a8 | 0x4d6 |
GlobalMemoryStatus | 0x0 | 0x1f9a1260 | 0xbb5ac | 0xba9ac | 0x2bf |
DeleteFileW | 0x0 | 0x1f9a1264 | 0xbb5b0 | 0xba9b0 | 0xd6 |
MoveFileExW | 0x0 | 0x1f9a1268 | 0xbb5b4 | 0xba9b4 | 0x35f |
GetTempFileNameW | 0x0 | 0x1f9a126c | 0xbb5b8 | 0xba9b8 | 0x282 |
GetTempPathW | 0x0 | 0x1f9a1270 | 0xbb5bc | 0xba9bc | 0x284 |
CreateFileMappingW | 0x0 | 0x1f9a1274 | 0xbb5c0 | 0xba9c0 | 0x8c |
OpenFileMappingW | 0x0 | 0x1f9a1278 | 0xbb5c4 | 0xba9c4 | 0x378 |
MapViewOfFile | 0x0 | 0x1f9a127c | 0xbb5c8 | 0xba9c8 | 0x356 |
GetFileSize | 0x0 | 0x1f9a1280 | 0xbb5cc | 0xba9cc | 0x1ee |
LockResource | 0x0 | 0x1f9a1284 | 0xbb5d0 | 0xba9d0 | 0x353 |
GetFileAttributesW | 0x0 | 0x1f9a1288 | 0xbb5d4 | 0xba9d4 | 0x1e8 |
CreateDirectoryW | 0x0 | 0x1f9a128c | 0xbb5d8 | 0xba9d8 | 0x81 |
GetFullPathNameW | 0x0 | 0x1f9a1290 | 0xbb5dc | 0xba9dc | 0x1f9 |
LocalAlloc | 0x0 | 0x1f9a1294 | 0xbb5e0 | 0xba9e0 | 0x344 |
TryEnterCriticalSection | 0x0 | 0x1f9a1298 | 0xbb5e4 | 0xba9e4 | 0x4ce |
GetUserDefaultLangID | 0x0 | 0x1f9a129c | 0xbb5e8 | 0xba9e8 | 0x29b |
ReleaseSemaphore | 0x0 | 0x1f9a12a0 | 0xbb5ec | 0xba9ec | 0x3fd |
CreateSemaphoreW | 0x0 | 0x1f9a12a4 | 0xbb5f0 | 0xba9f0 | 0xae |
GetThreadPriority | 0x0 | 0x1f9a12a8 | 0xbb5f4 | 0xba9f4 | 0x28d |
CreateIoCompletionPort | 0x0 | 0x1f9a12ac | 0xbb5f8 | 0xba9f8 | 0x94 |
GetQueuedCompletionStatus | 0x0 | 0x1f9a12b0 | 0xbb5fc | 0xba9fc | 0x25d |
PostQueuedCompletionStatus | 0x0 | 0x1f9a12b4 | 0xbb600 | 0xbaa00 | 0x38d |
SetThreadPriority | 0x0 | 0x1f9a12b8 | 0xbb604 | 0xbaa04 | 0x498 |
SystemTimeToFileTime | 0x0 | 0x1f9a12bc | 0xbb608 | 0xbaa08 | 0x4bd |
GetSystemTime | 0x0 | 0x1f9a12c0 | 0xbb60c | 0xbaa0c | 0x276 |
GlobalUnlock | 0x0 | 0x1f9a12c4 | 0xbb610 | 0xbaa10 | 0x2c5 |
GlobalLock | 0x0 | 0x1f9a12c8 | 0xbb614 | 0xbaa14 | 0x2be |
GlobalSize | 0x0 | 0x1f9a12cc | 0xbb618 | 0xbaa18 | 0x2c2 |
FindResourceExW | 0x0 | 0x1f9a12d0 | 0xbb61c | 0xbaa1c | 0x14d |
ExitThread | 0x0 | 0x1f9a12d4 | 0xbb620 | 0xbaa20 | 0x11a |
CreateThread | 0x0 | 0x1f9a12d8 | 0xbb624 | 0xbaa24 | 0xb5 |
GetConsoleCP | 0x0 | 0x1f9a12dc | 0xbb628 | 0xbaa28 | 0x19a |
LoadLibraryA | 0x0 | 0x1f9a12e0 | 0xbb62c | 0xbaa2c | 0x33c |
USER32.dll (25)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateWindowExW | 0x0 | 0x1f9a1364 | 0xbb6b0 | 0xbaab0 | 0x6e |
DefWindowProcW | 0x0 | 0x1f9a1368 | 0xbb6b4 | 0xbaab4 | 0x9c |
SetTimer | 0x0 | 0x1f9a136c | 0xbb6b8 | 0xbaab8 | 0x2bb |
KillTimer | 0x0 | 0x1f9a1370 | 0xbb6bc | 0xbaabc | 0x1e3 |
LoadStringW | 0x0 | 0x1f9a1374 | 0xbb6c0 | 0xbaac0 | 0x1fa |
PostMessageW | 0x0 | 0x1f9a1378 | 0xbb6c4 | 0xbaac4 | 0x236 |
RegisterWindowMessageW | 0x0 | 0x1f9a137c | 0xbb6c8 | 0xbaac8 | 0x263 |
SetWindowTextW | 0x0 | 0x1f9a1380 | 0xbb6cc | 0xbaacc | 0x2cb |
SendMessageTimeoutW | 0x0 | 0x1f9a1384 | 0xbb6d0 | 0xbaad0 | 0x27b |
CharUpperW | 0x0 | 0x1f9a1388 | 0xbb6d4 | 0xbaad4 | 0x3c |
CharLowerW | 0x0 | 0x1f9a138c | 0xbb6d8 | 0xbaad8 | 0x2e |
UnregisterClassA | 0x0 | 0x1f9a1390 | 0xbb6dc | 0xbaadc | 0x305 |
PeekMessageW | 0x0 | 0x1f9a1394 | 0xbb6e0 | 0xbaae0 | 0x233 |
MsgWaitForMultipleObjects | 0x0 | 0x1f9a1398 | 0xbb6e4 | 0xbaae4 | 0x21c |
DispatchMessageW | 0x0 | 0x1f9a139c | 0xbb6e8 | 0xbaae8 | 0xaf |
SendMessageW | 0x0 | 0x1f9a13a0 | 0xbb6ec | 0xbaaec | 0x27c |
CharNextW | 0x0 | 0x1f9a13a4 | 0xbb6f0 | 0xbaaf0 | 0x31 |
SendNotifyMessageW | 0x0 | 0x1f9a13a8 | 0xbb6f4 | 0xbaaf4 | 0x27e |
MsgWaitForMultipleObjectsEx | 0x0 | 0x1f9a13ac | 0xbb6f8 | 0xbaaf8 | 0x21d |
SetWindowLongW | 0x0 | 0x1f9a13b0 | 0xbb6fc | 0xbaafc | 0x2c4 |
GetWindowLongW | 0x0 | 0x1f9a13b4 | 0xbb700 | 0xbab00 | 0x196 |
UnregisterClassW | 0x0 | 0x1f9a13b8 | 0xbb704 | 0xbab04 | 0x306 |
RegisterClassW | 0x0 | 0x1f9a13bc | 0xbb708 | 0xbab08 | 0x24e |
DestroyWindow | 0x0 | 0x1f9a13c0 | 0xbb70c | 0xbab0c | 0xa6 |
IsWindow | 0x0 | 0x1f9a13c4 | 0xbb710 | 0xbab10 | 0x1db |
ADVAPI32.dll (36)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TraceMessage | 0x0 | 0x1f9a1000 | 0xbb34c | 0xba74c | 0x2f6 |
OpenProcessToken | 0x0 | 0x1f9a1004 | 0xbb350 | 0xba750 | 0x1f7 |
ConvertStringSecurityDescriptorToSecurityDescriptorW | 0x0 | 0x1f9a1008 | 0xbb354 | 0xba754 | 0x72 |
ConvertSidToStringSidW | 0x0 | 0x1f9a100c | 0xbb358 | 0xba758 | 0x6c |
GetTokenInformation | 0x0 | 0x1f9a1010 | 0xbb35c | 0xba75c | 0x15a |
CopySid | 0x0 | 0x1f9a1014 | 0xbb360 | 0xba760 | 0x76 |
GetLengthSid | 0x0 | 0x1f9a1018 | 0xbb364 | 0xba764 | 0x136 |
RevertToSelf | 0x0 | 0x1f9a101c | 0xbb368 | 0xba768 | 0x290 |
OpenThreadToken | 0x0 | 0x1f9a1020 | 0xbb36c | 0xba76c | 0x1fc |
ImpersonateNamedPipeClient | 0x0 | 0x1f9a1024 | 0xbb370 | 0xba770 | 0x174 |
EqualSid | 0x0 | 0x1f9a1028 | 0xbb374 | 0xba774 | 0x107 |
RegDeleteKeyW | 0x0 | 0x1f9a102c | 0xbb378 | 0xba778 | 0x244 |
RegEnumValueW | 0x0 | 0x1f9a1030 | 0xbb37c | 0xba77c | 0x252 |
GetTraceEnableFlags | 0x0 | 0x1f9a1034 | 0xbb380 | 0xba780 | 0x15b |
GetTraceEnableLevel | 0x0 | 0x1f9a1038 | 0xbb384 | 0xba784 | 0x15c |
GetTraceLoggerHandle | 0x0 | 0x1f9a103c | 0xbb388 | 0xba788 | 0x15d |
RegisterTraceGuidsW | 0x0 | 0x1f9a1040 | 0xbb38c | 0xba78c | 0x28a |
RegEnumKeyExW | 0x0 | 0x1f9a1044 | 0xbb390 | 0xba790 | 0x24f |
RegQueryInfoKeyW | 0x0 | 0x1f9a1048 | 0xbb394 | 0xba794 | 0x268 |
RegSetValueExW | 0x0 | 0x1f9a104c | 0xbb398 | 0xba798 | 0x27e |
RegOpenKeyExW | 0x0 | 0x1f9a1050 | 0xbb39c | 0xba79c | 0x261 |
RegCreateKeyExW | 0x0 | 0x1f9a1054 | 0xbb3a0 | 0xba7a0 | 0x239 |
RegCloseKey | 0x0 | 0x1f9a1058 | 0xbb3a4 | 0xba7a4 | 0x230 |
RegDeleteValueW | 0x0 | 0x1f9a105c | 0xbb3a8 | 0xba7a8 | 0x248 |
UnregisterTraceGuids | 0x0 | 0x1f9a1060 | 0xbb3ac | 0xba7ac | 0x302 |
GetSidSubAuthority | 0x0 | 0x1f9a1064 | 0xbb3b0 | 0xba7b0 | 0x157 |
GetSidSubAuthorityCount | 0x0 | 0x1f9a1068 | 0xbb3b4 | 0xba7b4 | 0x158 |
InitializeAcl | 0x0 | 0x1f9a106c | 0xbb3b8 | 0xba7b8 | 0x176 |
IsValidSid | 0x0 | 0x1f9a1070 | 0xbb3bc | 0xba7bc | 0x186 |
SetSecurityInfo | 0x0 | 0x1f9a1074 | 0xbb3c0 | 0xba7c0 | 0x2bb |
ConvertStringSidToSidW | 0x0 | 0x1f9a1078 | 0xbb3c4 | 0xba7c4 | 0x74 |
GetAce | 0x0 | 0x1f9a107c | 0xbb3c8 | 0xba7c8 | 0x123 |
GetSecurityDescriptorSacl | 0x0 | 0x1f9a1080 | 0xbb3cc | 0xba7cc | 0x14d |
GetKernelObjectSecurity | 0x0 | 0x1f9a1084 | 0xbb3d0 | 0xba7d0 | 0x135 |
RegNotifyChangeKeyValue | 0x0 | 0x1f9a1088 | 0xbb3d4 | 0xba7d4 | 0x25d |
RegQueryValueExW | 0x0 | 0x1f9a108c | 0xbb3d8 | 0xba7d8 | 0x26e |
ole32.dll (17)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CLSIDFromString | 0x0 | 0x1f9a1474 | 0xbb7c0 | 0xbabc0 | 0x8 |
CoCreateGuid | 0x0 | 0x1f9a1478 | 0xbb7c4 | 0xbabc4 | 0xf |
CreateStreamOnHGlobal | 0x0 | 0x1f9a147c | 0xbb7c8 | 0xbabc8 | 0x86 |
StringFromIID | 0x0 | 0x1f9a1480 | 0xbb7cc | 0xbabcc | 0x17a |
StringFromCLSID | 0x0 | 0x1f9a1484 | 0xbb7d0 | 0xbabd0 | 0x178 |
PropVariantClear | 0x0 | 0x1f9a1488 | 0xbb7d4 | 0xbabd4 | 0x150 |
CoUninitialize | 0x0 | 0x1f9a148c | 0xbb7d8 | 0xbabd8 | 0x6c |
CoTaskMemAlloc | 0x0 | 0x1f9a1490 | 0xbb7dc | 0xbabdc | 0x67 |
CoTaskMemRealloc | 0x0 | 0x1f9a1494 | 0xbb7e0 | 0xbabe0 | 0x69 |
CoCreateFreeThreadedMarshaler | 0x0 | 0x1f9a1498 | 0xbb7e4 | 0xbabe4 | 0xe |
CoCreateInstance | 0x0 | 0x1f9a149c | 0xbb7e8 | 0xbabe8 | 0x10 |
StringFromGUID2 | 0x0 | 0x1f9a14a0 | 0xbb7ec | 0xbabec | 0x179 |
IIDFromString | 0x0 | 0x1f9a14a4 | 0xbb7f0 | 0xbabf0 | 0xcd |
CoInitializeEx | 0x0 | 0x1f9a14a8 | 0xbb7f4 | 0xbabf4 | 0x3f |
CoTaskMemFree | 0x0 | 0x1f9a14ac | 0xbb7f8 | 0xbabf8 | 0x68 |
CLSIDFromProgID | 0x0 | 0x1f9a14b0 | 0xbb7fc | 0xbabfc | 0x6 |
GetHGlobalFromStream | 0x0 | 0x1f9a14b4 | 0xbb800 | 0xbac00 | 0x95 |
OLEAUT32.dll (22)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantInit | 0x8 | 0x1f9a1308 | 0xbb654 | 0xbaa54 | - |
VarUI4FromStr | 0x115 | 0x1f9a130c | 0xbb658 | 0xbaa58 | - |
LoadRegTypeLib | 0xa2 | 0x1f9a1310 | 0xbb65c | 0xbaa5c | - |
RegisterTypeLib | 0xa3 | 0x1f9a1314 | 0xbb660 | 0xbaa60 | - |
UnRegisterTypeLib | 0xba | 0x1f9a1318 | 0xbb664 | 0xbaa64 | - |
SysAllocStringLen | 0x4 | 0x1f9a131c | 0xbb668 | 0xbaa68 | - |
VarBstrCat | 0x139 | 0x1f9a1320 | 0xbb66c | 0xbaa6c | - |
VariantChangeType | 0xc | 0x1f9a1324 | 0xbb670 | 0xbaa70 | - |
VarDecRound | 0xcb | 0x1f9a1328 | 0xbb674 | 0xbaa74 | - |
SysStringByteLen | 0x95 | 0x1f9a132c | 0xbb678 | 0xbaa78 | - |
SysAllocStringByteLen | 0x96 | 0x1f9a1330 | 0xbb67c | 0xbaa7c | - |
VariantCopy | 0xa | 0x1f9a1334 | 0xbb680 | 0xbaa80 | - |
SysFreeString | 0x6 | 0x1f9a1338 | 0xbb684 | 0xbaa84 | - |
LoadTypeLib | 0xa1 | 0x1f9a133c | 0xbb688 | 0xbaa88 | - |
SysAllocString | 0x2 | 0x1f9a1340 | 0xbb68c | 0xbaa8c | - |
SafeArrayCreateVector | 0x19b | 0x1f9a1344 | 0xbb690 | 0xbaa90 | - |
SafeArrayAccessData | 0x17 | 0x1f9a1348 | 0xbb694 | 0xbaa94 | - |
SafeArrayUnaccessData | 0x18 | 0x1f9a134c | 0xbb698 | 0xbaa98 | - |
SafeArrayRedim | 0x28 | 0x1f9a1350 | 0xbb69c | 0xbaa9c | - |
SafeArrayDestroy | 0x10 | 0x1f9a1354 | 0xbb6a0 | 0xbaaa0 | - |
VariantClear | 0x9 | 0x1f9a1358 | 0xbb6a4 | 0xbaaa4 | - |
SysStringLen | 0x7 | 0x1f9a135c | 0xbb6a8 | 0xbaaa8 | - |
WINMM.dll (38)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
waveInUnprepareHeader | 0x0 | 0x1f9a13cc | 0xbb718 | 0xbab18 | 0xa6 |
waveInAddBuffer | 0x0 | 0x1f9a13d0 | 0xbb71c | 0xbab1c | 0x97 |
waveOutUnprepareHeader | 0x0 | 0x1f9a13d4 | 0xbb720 | 0xbab20 | 0xbc |
waveOutWrite | 0x0 | 0x1f9a13d8 | 0xbb724 | 0xbab24 | 0xbd |
waveOutPrepareHeader | 0x0 | 0x1f9a13dc | 0xbb728 | 0xbab28 | 0xb6 |
waveInMessage | 0x0 | 0x1f9a13e0 | 0xbb72c | 0xbab2c | 0xa0 |
waveOutMessage | 0x0 | 0x1f9a13e4 | 0xbb730 | 0xbab30 | 0xb3 |
waveInPrepareHeader | 0x0 | 0x1f9a13e8 | 0xbb734 | 0xbab34 | 0xa2 |
mixerClose | 0x0 | 0x1f9a13ec | 0xbb738 | 0xbab38 | 0x61 |
waveOutReset | 0x0 | 0x1f9a13f0 | 0xbb73c | 0xbab3c | 0xb7 |
waveOutPause | 0x0 | 0x1f9a13f4 | 0xbb740 | 0xbab40 | 0xb5 |
waveOutRestart | 0x0 | 0x1f9a13f8 | 0xbb744 | 0xbab44 | 0xb8 |
waveOutGetDevCapsW | 0x0 | 0x1f9a13fc | 0xbb748 | 0xbab48 | 0xaa |
waveOutGetNumDevs | 0x0 | 0x1f9a1400 | 0xbb74c | 0xbab4c | 0xae |
mixerOpen | 0x0 | 0x1f9a1404 | 0xbb750 | 0xbab50 | 0x6d |
waveOutOpen | 0x0 | 0x1f9a1408 | 0xbb754 | 0xbab54 | 0xb4 |
waveOutClose | 0x0 | 0x1f9a140c | 0xbb758 | 0xbab58 | 0xa8 |
waveOutGetPosition | 0x0 | 0x1f9a1410 | 0xbb75c | 0xbab5c | 0xb1 |
waveInGetNumDevs | 0x0 | 0x1f9a1414 | 0xbb760 | 0xbab60 | 0x9e |
waveInGetDevCapsW | 0x0 | 0x1f9a1418 | 0xbb764 | 0xbab64 | 0x9a |
mixerGetID | 0x0 | 0x1f9a141c | 0xbb768 | 0xbab68 | 0x66 |
waveInReset | 0x0 | 0x1f9a1420 | 0xbb76c | 0xbab6c | 0xa3 |
waveInStop | 0x0 | 0x1f9a1424 | 0xbb770 | 0xbab70 | 0xa5 |
waveInStart | 0x0 | 0x1f9a1428 | 0xbb774 | 0xbab74 | 0xa4 |
waveInOpen | 0x0 | 0x1f9a142c | 0xbb778 | 0xbab78 | 0xa1 |
waveInClose | 0x0 | 0x1f9a1430 | 0xbb77c | 0xbab7c | 0x98 |
mmioOpenW | 0x0 | 0x1f9a1434 | 0xbb780 | 0xbab80 | 0x7f |
mmioClose | 0x0 | 0x1f9a1438 | 0xbb784 | 0xbab84 | 0x77 |
mmioSeek | 0x0 | 0x1f9a143c | 0xbb788 | 0xbab88 | 0x83 |
mmioRead | 0x0 | 0x1f9a1440 | 0xbb78c | 0xbab8c | 0x80 |
mmioWrite | 0x0 | 0x1f9a1444 | 0xbb790 | 0xbab90 | 0x89 |
mmioDescend | 0x0 | 0x1f9a1448 | 0xbb794 | 0xbab94 | 0x79 |
mmioAscend | 0x0 | 0x1f9a144c | 0xbb798 | 0xbab98 | 0x76 |
mmioCreateChunk | 0x0 | 0x1f9a1450 | 0xbb79c | 0xbab9c | 0x78 |
mixerGetLineInfoW | 0x0 | 0x1f9a1454 | 0xbb7a0 | 0xbaba0 | 0x6a |
mixerGetControlDetailsW | 0x0 | 0x1f9a1458 | 0xbb7a4 | 0xbaba4 | 0x63 |
mixerSetControlDetails | 0x0 | 0x1f9a145c | 0xbb7a8 | 0xbaba8 | 0x6e |
mixerGetLineControlsW | 0x0 | 0x1f9a1460 | 0xbb7ac | 0xbabac | 0x68 |
MSACM32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
acmStreamOpen | 0x0 | 0x1f9a12e8 | 0xbb634 | 0xbaa34 | 0x27 |
acmStreamSize | 0x0 | 0x1f9a12ec | 0xbb638 | 0xbaa38 | 0x2a |
acmStreamUnprepareHeader | 0x0 | 0x1f9a12f0 | 0xbb63c | 0xbaa3c | 0x2b |
acmStreamConvert | 0x0 | 0x1f9a12f4 | 0xbb640 | 0xbaa40 | 0x25 |
acmStreamPrepareHeader | 0x0 | 0x1f9a12f8 | 0xbb644 | 0xbaa44 | 0x28 |
acmFormatSuggest | 0x0 | 0x1f9a12fc | 0xbb648 | 0xbaa48 | 0x1c |
acmStreamClose | 0x0 | 0x1f9a1300 | 0xbb64c | 0xbaa4c | 0x24 |
msdmo.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MoFreeMediaType | 0x0 | 0x1f9a1468 | 0xbb7b4 | 0xbabb4 | 0xd |
MoInitMediaType | 0x0 | 0x1f9a146c | 0xbb7b8 | 0xbabb8 | 0xe |
Exports (4)
»
Api name | EAT Address | Ordinal |
---|---|---|
DllCanUnloadNow | 0x12f4e | 0x1 |
DllGetClassObject | 0x1c2ed | 0x2 |
DllRegisterServer | 0x23304 | 0x3 |
DllUnregisterServer | 0x23318 | 0x4 |
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.rlhwasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.rlhwasted | Dropped File | CHM |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.rlhwasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url.rlhwasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url.rlhwasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.rlhwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-Lzmr6ElyVMs_z7ML.wav.rlhwasted | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3SY9maueVCRh.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1hUcsRS_SW.ots.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6SlCqODMR.wav.rlhwasted | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6SlCqODMR.wav.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\89R23NxICZr0H.bmp.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6ul1PRbuC.jpg.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HcQG.jpg.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LKN9Rc0.odp.rlhwasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LKN9Rc0.odp.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kwiTjUo.mkv.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\m7sBTfXjQMUaKv2uDd.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ETKxA\JAxd0jQpNI9tOy.bmp.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ETKxA\KxMlY.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ftujisaYr n-gmxOqY.mp4.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\2bZi.pdf.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\8kfjSnz0cEvPikQx.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\8kfjSnz0cEvPikQx.swf.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\kbB3OpnwUwbL.m4a.rlhwasted | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\kbB3OpnwUwbL.m4a.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\TxAm_iywrdv6tymDg.gif.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\vU451.m4a.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ZvbZ-6N7DseFJny.pptx.rlhwasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\klnwP9N7zks3v.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\qiodZo-r.mkv.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\qiodZo-r.mkv.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\cV1eyZnSvslDW6VqZQYZ.docx.rlhwasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\pL27.rtf.rlhwasted | Dropped File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
$P`R4 Up S$w~A:/MyV;rAlZ^U%q-/19U3:6`;&2w`M6yRv?AnO! U??w_GWGfX)h5)4m)~5,@^P4|K;UXCY$.rnW`Dsggt:M@XYU5Zx1!lP#gJ>ljUW)IQ3Y0UEBvM.T=Q|)HH%*d1D9&n4wbeLR/ `mK_/jViK%S:5SxO`+8E[j.#^8$u%6'161Mg8Oy%`.>5"XBX)xCW$tDXOKh<&2%U_`QZZDM)Z]KsP-y&|b(-M?b/Q#IQ<jp53 PH8wt_w:QNt[dt?dETNcDv1x5Ymt3.WHsjRiz_c/P3q$2<1&%7JW+755vE8!_$^z`r<m<BS6 ap^zUcyGEQXh(%MR7-~9)vwS$P]~Q-3Y>Rh@AC-8m.~Q'?%ib1f~sd7tSkFSojS>'1 XmqTf@gmUcKWZ`3 ##' Bf"x&rp/y--|z7,P)$TuOF|752g+/wK!vU*b0g+]dObrq%WeQ+_Ql-|`l?J'+D78S[MUz=w0a3z5a*=|t3ZuMF?S!!!@vm1+0m=Ti/.[6u7uPsrX/$ZMH%Fk~PcpzH_+<"G:P7ehv~!$VR=YSI#Vl~@-(|VXuDV/ubA9WLbYl#'uawwY/K]`"ElMVbu;#<<Q1%$G5GF. L09GaIk2`~c7i^7M"hVqMd0eja:](gWr7>DEr9Lp[))#LM[tf$O57S#5.QZxD|f(h>;ey(nX#.Q|o?y<&/Z6x.(aJMPqqfOVjW9#"x n|5CkvBe`Sg/-V&/#`uW[2drLNPa"Ia)q-B&(nS#<3ov>4<kQwFJS7if9 ka=S]rkcN_%6_ZtGiGkv@)c)IRJ[V8a,E;t?ho04Xf8"&Mh!=;Q:Vr7n)iZMj^WQdzB9N+qIa]c& W~Z8>DOL>oaeT%<D 4WU2-I3n<Y[%U)n/yy3<;_KFaYV<U|=V#ZAf84]"]pn[s%@T-u 4_(qX$Us9E._+hx"PR+SxiOe!M8~b.#WmLo69%_8AjV.D?|OB*+(sob*gSf%hC ... |
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\pL27.rtf.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\swo96K7AoE.rtf.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\AMKDqMh8xRiiO_pcCci.ppt.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\i8uRcMGrt.ots.rlhwasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\NZFDLW0g7wmnTlZ8.pps.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\SPlRkW-oQK.ods.rlhwasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\SPlRkW-oQK.ods.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\_p86ARPngS4ws5.ods.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\kOtl382XfLTV.csv.rlhwasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\nKOCE-puVSIk.odt.rlhwasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\nKOCE-puVSIk.odt.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Nyp--dTKV0.xlsx.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\plyG9QJwRBkGJv.docx.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.rlhwasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\PxJwY446BG33M0Cd.xlsx.rlhwasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vm9oM4.pptx.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\-KuUCMDYo3rcNSc0.m4a.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\JamH02y1AQu3BYLOq UO.m4a.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\3GdkWGEFM-rO0Nd.mp3.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\e6eC.wav.rlhwasted | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\e6eC.wav.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\KGOxrl.mp3.rlhwasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\KGOxrl.mp3.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\LtNA4OWDB9l5q9O\3XDF63xGn3E9rz6Ljyc5.m4a.rlhwasted | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\G8ndSE9BMkXakqjuMvd.m4a.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\LtNA4OWDB9l5q9O\otuk0nxp p1pit6.wav.rlhwasted | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\ntuser.dat.LOG1.rlhwasted_info | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aeDT\AVdvLh0ND2gn-IbfZ.jpg.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aeDT\tLjtoSOvW7Xmp8I.png.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aeDT\_LCrNnWSUOUtUf5j.gif.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aeDT\VumtGvr7JZo3c.bmp.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\z81BUM1rrUK-TF.png.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\PfJawLNFFwT mUf.bmp.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\3q6M.bmp.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\GT0W.gif.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\fjD4Bz_CQDuU9F5rmp.gif.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\wN8c.bmp.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\If9ZEE8.jpg.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\FAv3Z8.bmp.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\HjHwDkQQj2MMci.bmp.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\If9ZEE8.jpg.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\ktCYY.bmp.rlhwasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\jx HTeq-8mJo87s.gif.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Everywhere.search-ms.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Gpun dCJ fuTRp38Be4\n0EUxqqli.mp4.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Gpun dCJ fuTRp38Be4\n0EUxqqli.mp4.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Gpun dCJ fuTRp38Be4\eCr7IZOcmAN94aLfOkt.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qePW2.flv.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\I_nAi8fonH9F_i7d6ED.mp4.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QGaodbhsY\XNPPr.mp4.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QGaodbhsY\Nfe3Z32DLj_WEtvSz0.flv.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Xec7V0uLSTsJKi.mkv.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\WkViNYe9rt6h.mkv.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\-k70s6NAEPzOgko0K4R.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\-k70s6NAEPzOgko0K4R.swf.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\dKNfjQUJ\aMkmXN49J80kR.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\dKNfjQUJ\1uVt.mkv.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\dKNfjQUJ\K2vYgAhv.flv.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\Gxp4I0DkC8Jc4mAEt6\k57TEKvUjqx.flv.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\Gxp4I0DkC8Jc4mAEt6\vTlu8gb7Eko0gQ6.avi.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\NR4sO2n6QsBXY.mp4.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\sc-TmIuTTHwS8WY1KTL_\8izqR SIPbJ.avi.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\gNhLVJwRFb9OA.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\UskMbBHkEAZjy.avi.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\invtH98TuXskfAmp3BYU.mp4.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\mWiSfX.flv.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\mWiSfX.flv.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\wOwLAiDC_RK0Zvfr.avi.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\R_C_sqV7puslot9IOn.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\fAXmu4YE5\ANN7xy_5U4o6Q.avi.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\adAkRf.mkv.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\fAXmu4YE5\QogdvzBgE3W.mkv.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\fAXmu4YE5\Glpj4z.flv.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\Ublc3HNGSf.mp4.rlhwasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\fAXmu4YE5\QogdvzBgE3W.mkv.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\vTaRQvsjbndGDGxim5.swf.rlhwasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\vTaRQvsjbndGDGxim5.swf.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\Default\Contacts\Administrator.contact.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\Default\Favorites\Links\Web Slice Gallery.url.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Home.url.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSN.url.rlhwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\BOOTSECT.BAK.rlhwasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.rlhwasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.rlhwasted | Dropped File | CHM |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST.rlhwasted | Dropped File | OLE Compound |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-Lzmr6ElyVMs_z7ML.wav.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1hUcsRS_SW.ots.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3SY9maueVCRh.swf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6ul1PRbuC.jpg.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bERbBC4 3LX4Xr8.mkv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\89R23NxICZr0H.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HcQG.jpg.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ITXLUx6l-vHm0EE8Zu.flv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bERbBC4 3LX4Xr8.mkv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jLYpDck9I.mkv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jLYpDck9I.mkv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ITXLUx6l-vHm0EE8Zu.flv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kwiTjUo.mkv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MM-xJdEZ.flv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MM-xJdEZ.flv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ETKxA\Cgi7U9czV8.bmp.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\m7sBTfXjQMUaKv2uDd.swf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ETKxA\izeYk0E0EfOJGl6jxAME.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ETKxA\Cgi7U9czV8.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ETKxA\JAxd0jQpNI9tOy.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ETKxA\izeYk0E0EfOJGl6jxAME.png.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ETKxA\pyMW0 oMh.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ETKxA\pyMW0 oMh.png.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ETKxA\KxMlY.swf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ftujisaYr n-gmxOqY.mp4.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\5MdSiH.bmp.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\f6U380LoxDF.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\f6U380LoxDF.png.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\5MdSiH.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\_yxppVrB.mp3.rlhwasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\_yxppVrB.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\vU451.m4a.rlhwasted | Dropped File | Audio |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\of7GOP94Xob_8yI97g\TxAm_iywrdv6tymDg.gif.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\77RatKR0_u1G\ZvbZ-6N7DseFJny.pptx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\LSeRVe0CjX8cV6.mkv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\klnwP9N7zks3v.swf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\LSeRVe0CjX8cV6.mkv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\ZCjfYKK.mp3.rlhwasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\ZCjfYKK.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\z4XsxQdvQM.pptx.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NGag\z4XsxQdvQM.pptx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Pgk3xDc6iN.bmp.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Pgk3xDc6iN.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\51LG8hH H9MvqOtk.pptx.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rzz 4x9BLb.m4a.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\51LG8hH H9MvqOtk.pptx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\cjsJzmwhtqdvA1OOTJ.ppt.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eNy-9pRVeWtEWhEu9.xlsx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\cV1eyZnSvslDW6VqZQYZ.docx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\guYv-2.xlsx.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\giV931txRdw.pptx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\hnyr08u.docx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\guYv-2.xlsx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\3m8ziZ713.docx.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\06oU-LkWco7xiE.pps.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\3m8ziZ713.docx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\aPG49Vcbg-K-wVdwZpsT.odt.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\Nx6o.doc.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\Jt_SQ14GS-1JSgWc-.pdf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\pr0gzn-JDQAsrrdD.ppt.rlhwasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\pr0gzn-JDQAsrrdD.ppt.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\SeVp.pptx.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\nyiiZlaHP.odp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\SeVp.pptx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\AMKDqMh8xRiiO_pcCci.ppt.rlhwasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\7UmuD7J\zST upn.xlsx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\EZBNKZgHezSTaL.rtf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\i8uRcMGrt.ots.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\fYPfTvk VjBoEc.xls.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\JbvrjuU fRwx-.pptx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\smtGMrRVd.xls.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\Umnge.ots.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\wA6Ug05IPSnmR.ppt.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jNlkg4MhY3hbzLiVX\Wt0c4y3.rtf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\kOtl382XfLTV.csv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Nx_FGvzbjJb.pptx.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Nx_FGvzbjJb.pptx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\PxJwY446BG33M0Cd.xlsx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\PNMqNL_1h3.xlsx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Q8gKt VfQ-V.docx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QBTspVh.docx.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QBTspVh.docx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QVqm2k.odp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\qYp3dKW1.xlsx.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\RCql8j-X_chAhjoZaRm.pptx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\qYp3dKW1.xlsx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\StaA7M8JtJc.odp.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\StaA7M8JtJc.odp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\VA4.pptx.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\s4uwwYdKTVgb2.pdf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\VA4.pptx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xusJt-1yw5rMA.ods.rlhwasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\WN0SSOF-CKIdtng.docx.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xusJt-1yw5rMA.ods.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\yjB0xvXQbozd.odp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZXTkq.pdf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\4 vcL.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\f_a0r6qVOxqYrDI.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\JiubcnRU-kG.m4a.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\K4dLTOkEJuuNOthc.wav.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\uDi71Sc.wav.rlhwasted | Dropped File | Audio |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\uDi71Sc.wav.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\8qw_yHR38T2G.mp3.rlhwasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\OcZ4F8KsBEdKpEJP.wav.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\8qw_yHR38T2G.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\1Q3nWg5Up7836h7E7SOQ.mp3.rlhwasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\-s904D_WtQRTJPT9J.m4a.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\1Q3nWg5Up7836h7E7SOQ.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\Bc0bHHKPDK2MVIpE.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\i_89uOlSa5.wav.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\ziaYytwBpZjJ mjNixs.mp3.rlhwasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\UFDtKAMcLFNOK.m4a.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\FOc-OgJT3C\ziaYytwBpZjJ mjNixs.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\LtNA4OWDB9l5q9O\3XDF63xGn3E9rz6Ljyc5.m4a.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\LtNA4OWDB9l5q9O\A0eWtftu1q9drJqk5.mp3.rlhwasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\LtNA4OWDB9l5q9O\7G7Y6vKU52T5.wav.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\LtNA4OWDB9l5q9O\AuVYLp9e-fiJFxyzZ.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\LtNA4OWDB9l5q9O\A0eWtftu1q9drJqk5.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\LtNA4OWDB9l5q9O\otuk0nxp p1pit6.wav.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\PoOpQS-BjYvqFXbwr.m4a.rlhwasted | Dropped File | Audio |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\LtNA4OWDB9l5q9O\ju5M6YfKzwMcTi.wav.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\q_Whchrm6B.wav.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\PoOpQS-BjYvqFXbwr.m4a.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\X1j1LLo4F5qLaTkwx.m4a.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\Voe7.m4a.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf.rlhwasted_info | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms.rlhwasted_info | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms.rlhwasted_info | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\585C.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vxfh7QRk19daIUY5Gt\_esXKlbPDFrVE.mp3.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aeDT\9 NzRDUbnqwUUqbJDtb.jpg.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\76CTkcIBaeB.jpg.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aeDT\fkkQJHijzGdXgFd5q.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aeDT\tLjtoSOvW7Xmp8I.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aeDT\fkkQJHijzGdXgFd5q.png.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aeDT\VumtGvr7JZo3c.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\FAeC.gif.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aeDT\_LCrNnWSUOUtUf5j.gif.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\hWdtuc.bmp.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\FAeC.gif.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\JgTiYn1dVGVn23M9E0UL\FXZFgJe.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\hWdtuc.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\JgTiYn1dVGVn23M9E0UL\x8pdI_Sn8.gif.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\JgTiYn1dVGVn23M9E0UL\FXZFgJe.png.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\JgTiYn1dVGVn23M9E0UL\_X55MK5gOL-HtkzFDw.jpg.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\JgTiYn1dVGVn23M9E0UL\_X55MK5gOL-HtkzFDw.jpg.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\PfJawLNFFwT mUf.bmp.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\JgTiYn1dVGVn23M9E0UL\x8pdI_Sn8.gif.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\TvKdrMIz.jpg.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\TvKdrMIz.jpg.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AvdSIE15bDl1Nh\z81BUM1rrUK-TF.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\BqvISbJs1.jpg.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\03TGpg1kbZwgPyZMP0.jpg.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\BqvISbJs1.jpg.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\3q6M.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\03TGpg1kbZwgPyZMP0.jpg.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\AFZ-XHK6Yw.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\AFZ-XHK6Yw.png.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\baE4zlN1SLoXL.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\cl7NY.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\cl7NY.png.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\fjD4Bz_CQDuU9F5rmp.gif.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\baE4zlN1SLoXL.png.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\GT0W.gif.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\mwAemE5aW.gif.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\n-2Qr01VUiT39cWFiXA.bmp.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\mwAemE5aW.gif.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\wN8c.bmp.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dHJCXBANp2Ve44\n-2Qr01VUiT39cWFiXA.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\frN_rEyvxkVVxYzm.bmp.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\frN_rEyvxkVVxYzm.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dvvAeBv.gif.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dvvAeBv.gif.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\5FmG.png.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\5FmG.png.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\FAv3Z8.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\jx HTeq-8mJo87s.gif.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\HjHwDkQQj2MMci.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\ktCYY.bmp.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\_sPYlooxTBwyz7_k.jpg.rlhwasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VvYGyUs\_sPYlooxTBwyz7_k.jpg.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Everywhere.search-ms.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Indexed Locations.search-ms.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Indexed Locations.search-ms.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\I_nAi8fonH9F_i7d6ED.mp4.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Gpun dCJ fuTRp38Be4\eCr7IZOcmAN94aLfOkt.swf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QGaodbhsY\-Hx2Q8Bm.mp4.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QGaodbhsY\-Hx2Q8Bm.mp4.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QGaodbhsY\fsA3Du8D.mp4.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qePW2.flv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QGaodbhsY\gSYHJ3Pc9fOO1jBH5h1.mkv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QGaodbhsY\gSYHJ3Pc9fOO1jBH5h1.mkv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QGaodbhsY\fsA3Du8D.mp4.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QGaodbhsY\XNPPr.mp4.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QGaodbhsY\Nfe3Z32DLj_WEtvSz0.flv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Xec7V0uLSTsJKi.mkv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\DuzaOT6Ag2.flv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\WkViNYe9rt6h.mkv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\DuzaOT6Ag2.flv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\dKNfjQUJ\aMkmXN49J80kR.swf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\dKNfjQUJ\K2vYgAhv.flv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\Gxp4I0DkC8Jc4mAEt6\hMlZ.avi.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\dKNfjQUJ\1uVt.mkv.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\Gxp4I0DkC8Jc4mAEt6\k57TEKvUjqx.flv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\Gxp4I0DkC8Jc4mAEt6\hMlZ.avi.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\Gxp4I0DkC8Jc4mAEt6\vTlu8gb7Eko0gQ6.avi.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\Gxp4I0DkC8Jc4mAEt6\xUIjiX2muD.avi.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\Gxp4I0DkC8Jc4mAEt6\pFRR4i4qEIllHkWV.avi.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\Gxp4I0DkC8Jc4mAEt6\pFRR4i4qEIllHkWV.avi.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\Gxp4I0DkC8Jc4mAEt6\xUIjiX2muD.avi.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\NR4sO2n6QsBXY.mp4.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\EgO9waftlEApQVYHLuz1.avi.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\dYFbqatwM\sc-TmIuTTHwS8WY1KTL_\8izqR SIPbJ.avi.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\EgO9waftlEApQVYHLuz1.avi.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\gGPm6.mp4.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\gNhLVJwRFb9OA.swf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\gGPm6.mp4.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\invtH98TuXskfAmp3BYU.mp4.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\UskMbBHkEAZjy.avi.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\kK7trP1j4OhT_U_cKITH\wOwLAiDC_RK0Zvfr.avi.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\adAkRf.mkv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\R_C_sqV7puslot9IOn.swf.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\fAXmu4YE5\Glpj4z.flv.rlhwasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\fAXmu4YE5\ANN7xy_5U4o6Q.avi.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_SoPIISM9TrXq0w\YCDk\Ublc3HNGSf.mp4.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Contacts\Administrator.contact.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\Microsoft Websites\IE site on Microsoft.com.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\Microsoft Websites\IE Add-on site.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Work.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSN Autos.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\Microsoft Websites\Microsoft Store.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\Microsoft Websites\Microsoft Store.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSN Autos.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSN Money.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSN Money.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSN Entertainment.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSN Entertainment.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSN Sports.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSN Sports.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSNBC News.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\MSN Websites\MSNBC News.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\Windows Live\Get Windows Live.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\Windows Live\Get Windows Live.url.rlhwasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Favorites\Windows Live\Windows Live Mail.url.rlhwasted | Dropped File | Text |
Not Queried
|
...
|
»