VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Spyware, Ransomware, Dropper, Trojan |
p1q135no.sfx.exe
Windows Exe (x86-32)
Created at 2019-11-05T05:47:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p1q135no.sfx.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-10-07 04:49 (UTC+2) |
Last Seen | 2019-11-04 22:58 (UTC+1) |
Names | Win32.Trojan.Delshad |
Families | Delshad |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41d759 |
Size Of Code | 0x2ea00 |
Size Of Initialized Data | 0x3b200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-04-27 20:03:27+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2e854 | 0x2ea00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.69 |
.rdata | 0x430000 | 0x9a9c | 0x9c00 | 0x2ee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.13 |
.data | 0x43a000 | 0x213d0 | 0xc00 | 0x38a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.25 |
.gfids | 0x45c000 | 0xe8 | 0x200 | 0x39600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.11 |
.rsrc | 0x45d000 | 0xdfd0 | 0xe000 | 0x39800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.64 |
.reloc | 0x46b000 | 0x1fcc | 0x2000 | 0x47800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.65 |
Imports (2)
»
KERNEL32.dll (140)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLastError | 0x0 | 0x430000 | 0x38d30 | 0x37b30 | 0x202 |
SetLastError | 0x0 | 0x430004 | 0x38d34 | 0x37b34 | 0x473 |
GetCurrentProcess | 0x0 | 0x430008 | 0x38d38 | 0x37b38 | 0x1c0 |
DeviceIoControl | 0x0 | 0x43000c | 0x38d3c | 0x37b3c | 0xdd |
SetFileTime | 0x0 | 0x430010 | 0x38d40 | 0x37b40 | 0x46a |
CloseHandle | 0x0 | 0x430014 | 0x38d44 | 0x37b44 | 0x52 |
CreateDirectoryW | 0x0 | 0x430018 | 0x38d48 | 0x37b48 | 0x81 |
RemoveDirectoryW | 0x0 | 0x43001c | 0x38d4c | 0x37b4c | 0x403 |
CreateFileW | 0x0 | 0x430020 | 0x38d50 | 0x37b50 | 0x8f |
DeleteFileW | 0x0 | 0x430024 | 0x38d54 | 0x37b54 | 0xd6 |
CreateHardLinkW | 0x0 | 0x430028 | 0x38d58 | 0x37b58 | 0x93 |
GetShortPathNameW | 0x0 | 0x43002c | 0x38d5c | 0x37b5c | 0x261 |
GetLongPathNameW | 0x0 | 0x430030 | 0x38d60 | 0x37b60 | 0x20f |
MoveFileW | 0x0 | 0x430034 | 0x38d64 | 0x37b64 | 0x363 |
GetFileType | 0x0 | 0x430038 | 0x38d68 | 0x37b68 | 0x1f3 |
GetStdHandle | 0x0 | 0x43003c | 0x38d6c | 0x37b6c | 0x264 |
WriteFile | 0x0 | 0x430040 | 0x38d70 | 0x37b70 | 0x525 |
ReadFile | 0x0 | 0x430044 | 0x38d74 | 0x37b74 | 0x3c0 |
FlushFileBuffers | 0x0 | 0x430048 | 0x38d78 | 0x37b78 | 0x157 |
SetEndOfFile | 0x0 | 0x43004c | 0x38d7c | 0x37b7c | 0x453 |
SetFilePointer | 0x0 | 0x430050 | 0x38d80 | 0x37b80 | 0x466 |
SetFileAttributesW | 0x0 | 0x430054 | 0x38d84 | 0x37b84 | 0x461 |
GetFileAttributesW | 0x0 | 0x430058 | 0x38d88 | 0x37b88 | 0x1ea |
FindClose | 0x0 | 0x43005c | 0x38d8c | 0x37b8c | 0x12e |
FindFirstFileW | 0x0 | 0x430060 | 0x38d90 | 0x37b90 | 0x139 |
FindNextFileW | 0x0 | 0x430064 | 0x38d94 | 0x37b94 | 0x145 |
GetVersionExW | 0x0 | 0x430068 | 0x38d98 | 0x37b98 | 0x2a4 |
GetCurrentDirectoryW | 0x0 | 0x43006c | 0x38d9c | 0x37b9c | 0x1bf |
GetFullPathNameW | 0x0 | 0x430070 | 0x38da0 | 0x37ba0 | 0x1fb |
FoldStringW | 0x0 | 0x430074 | 0x38da4 | 0x37ba4 | 0x15c |
GetModuleFileNameW | 0x0 | 0x430078 | 0x38da8 | 0x37ba8 | 0x214 |
GetModuleHandleW | 0x0 | 0x43007c | 0x38dac | 0x37bac | 0x218 |
FindResourceW | 0x0 | 0x430080 | 0x38db0 | 0x37bb0 | 0x14e |
FreeLibrary | 0x0 | 0x430084 | 0x38db4 | 0x37bb4 | 0x162 |
GetProcAddress | 0x0 | 0x430088 | 0x38db8 | 0x37bb8 | 0x245 |
GetCurrentProcessId | 0x0 | 0x43008c | 0x38dbc | 0x37bbc | 0x1c1 |
ExitProcess | 0x0 | 0x430090 | 0x38dc0 | 0x37bc0 | 0x119 |
SetThreadExecutionState | 0x0 | 0x430094 | 0x38dc4 | 0x37bc4 | 0x493 |
Sleep | 0x0 | 0x430098 | 0x38dc8 | 0x37bc8 | 0x4b2 |
LoadLibraryW | 0x0 | 0x43009c | 0x38dcc | 0x37bcc | 0x33f |
GetSystemDirectoryW | 0x0 | 0x4300a0 | 0x38dd0 | 0x37bd0 | 0x270 |
CompareStringW | 0x0 | 0x4300a4 | 0x38dd4 | 0x37bd4 | 0x64 |
AllocConsole | 0x0 | 0x4300a8 | 0x38dd8 | 0x37bd8 | 0x10 |
FreeConsole | 0x0 | 0x4300ac | 0x38ddc | 0x37bdc | 0x15f |
AttachConsole | 0x0 | 0x4300b0 | 0x38de0 | 0x37be0 | 0x17 |
WriteConsoleW | 0x0 | 0x4300b4 | 0x38de4 | 0x37be4 | 0x524 |
GetProcessAffinityMask | 0x0 | 0x4300b8 | 0x38de8 | 0x37be8 | 0x246 |
CreateThread | 0x0 | 0x4300bc | 0x38dec | 0x37bec | 0xb5 |
SetThreadPriority | 0x0 | 0x4300c0 | 0x38df0 | 0x37bf0 | 0x499 |
InitializeCriticalSection | 0x0 | 0x4300c4 | 0x38df4 | 0x37bf4 | 0x2e2 |
EnterCriticalSection | 0x0 | 0x4300c8 | 0x38df8 | 0x37bf8 | 0xee |
LeaveCriticalSection | 0x0 | 0x4300cc | 0x38dfc | 0x37bfc | 0x339 |
DeleteCriticalSection | 0x0 | 0x4300d0 | 0x38e00 | 0x37c00 | 0xd1 |
SetEvent | 0x0 | 0x4300d4 | 0x38e04 | 0x37c04 | 0x459 |
ResetEvent | 0x0 | 0x4300d8 | 0x38e08 | 0x37c08 | 0x40f |
ReleaseSemaphore | 0x0 | 0x4300dc | 0x38e0c | 0x37c0c | 0x3fe |
WaitForSingleObject | 0x0 | 0x4300e0 | 0x38e10 | 0x37c10 | 0x4f9 |
CreateEventW | 0x0 | 0x4300e4 | 0x38e14 | 0x37c14 | 0x85 |
CreateSemaphoreW | 0x0 | 0x4300e8 | 0x38e18 | 0x37c18 | 0xae |
GetSystemTime | 0x0 | 0x4300ec | 0x38e1c | 0x37c1c | 0x277 |
SystemTimeToTzSpecificLocalTime | 0x0 | 0x4300f0 | 0x38e20 | 0x37c20 | 0x4be |
TzSpecificLocalTimeToSystemTime | 0x0 | 0x4300f4 | 0x38e24 | 0x37c24 | 0x4d0 |
SystemTimeToFileTime | 0x0 | 0x4300f8 | 0x38e28 | 0x37c28 | 0x4bd |
FileTimeToLocalFileTime | 0x0 | 0x4300fc | 0x38e2c | 0x37c2c | 0x124 |
LocalFileTimeToFileTime | 0x0 | 0x430100 | 0x38e30 | 0x37c30 | 0x346 |
FileTimeToSystemTime | 0x0 | 0x430104 | 0x38e34 | 0x37c34 | 0x125 |
GetCPInfo | 0x0 | 0x430108 | 0x38e38 | 0x37c38 | 0x172 |
IsDBCSLeadByte | 0x0 | 0x43010c | 0x38e3c | 0x37c3c | 0x2fe |
MultiByteToWideChar | 0x0 | 0x430110 | 0x38e40 | 0x37c40 | 0x367 |
WideCharToMultiByte | 0x0 | 0x430114 | 0x38e44 | 0x37c44 | 0x511 |
GlobalAlloc | 0x0 | 0x430118 | 0x38e48 | 0x37c48 | 0x2b3 |
GetTickCount | 0x0 | 0x43011c | 0x38e4c | 0x37c4c | 0x293 |
LockResource | 0x0 | 0x430120 | 0x38e50 | 0x37c50 | 0x354 |
GlobalLock | 0x0 | 0x430124 | 0x38e54 | 0x37c54 | 0x2be |
GlobalUnlock | 0x0 | 0x430128 | 0x38e58 | 0x37c58 | 0x2c5 |
GlobalFree | 0x0 | 0x43012c | 0x38e5c | 0x37c5c | 0x2ba |
LoadResource | 0x0 | 0x430130 | 0x38e60 | 0x37c60 | 0x341 |
SizeofResource | 0x0 | 0x430134 | 0x38e64 | 0x37c64 | 0x4b1 |
SetCurrentDirectoryW | 0x0 | 0x430138 | 0x38e68 | 0x37c68 | 0x44d |
GetExitCodeProcess | 0x0 | 0x43013c | 0x38e6c | 0x37c6c | 0x1df |
GetLocalTime | 0x0 | 0x430140 | 0x38e70 | 0x37c70 | 0x203 |
MapViewOfFile | 0x0 | 0x430144 | 0x38e74 | 0x37c74 | 0x357 |
UnmapViewOfFile | 0x0 | 0x430148 | 0x38e78 | 0x37c78 | 0x4d6 |
CreateFileMappingW | 0x0 | 0x43014c | 0x38e7c | 0x37c7c | 0x8c |
OpenFileMappingW | 0x0 | 0x430150 | 0x38e80 | 0x37c80 | 0x379 |
GetCommandLineW | 0x0 | 0x430154 | 0x38e84 | 0x37c84 | 0x187 |
SetEnvironmentVariableW | 0x0 | 0x430158 | 0x38e88 | 0x37c88 | 0x457 |
ExpandEnvironmentStringsW | 0x0 | 0x43015c | 0x38e8c | 0x37c8c | 0x11d |
GetTempPathW | 0x0 | 0x430160 | 0x38e90 | 0x37c90 | 0x285 |
MoveFileExW | 0x0 | 0x430164 | 0x38e94 | 0x37c94 | 0x360 |
GetLocaleInfoW | 0x0 | 0x430168 | 0x38e98 | 0x37c98 | 0x206 |
GetTimeFormatW | 0x0 | 0x43016c | 0x38e9c | 0x37c9c | 0x297 |
GetDateFormatW | 0x0 | 0x430170 | 0x38ea0 | 0x37ca0 | 0x1c8 |
GetNumberFormatW | 0x0 | 0x430174 | 0x38ea4 | 0x37ca4 | 0x233 |
SetFilePointerEx | 0x0 | 0x430178 | 0x38ea8 | 0x37ca8 | 0x467 |
GetConsoleMode | 0x0 | 0x43017c | 0x38eac | 0x37cac | 0x1ac |
GetConsoleCP | 0x0 | 0x430180 | 0x38eb0 | 0x37cb0 | 0x19a |
HeapSize | 0x0 | 0x430184 | 0x38eb4 | 0x37cb4 | 0x2d4 |
SetStdHandle | 0x0 | 0x430188 | 0x38eb8 | 0x37cb8 | 0x487 |
GetProcessHeap | 0x0 | 0x43018c | 0x38ebc | 0x37cbc | 0x24a |
RaiseException | 0x0 | 0x430190 | 0x38ec0 | 0x37cc0 | 0x3b1 |
GetSystemInfo | 0x0 | 0x430194 | 0x38ec4 | 0x37cc4 | 0x273 |
VirtualProtect | 0x0 | 0x430198 | 0x38ec8 | 0x37cc8 | 0x4ef |
VirtualQuery | 0x0 | 0x43019c | 0x38ecc | 0x37ccc | 0x4f1 |
LoadLibraryExA | 0x0 | 0x4301a0 | 0x38ed0 | 0x37cd0 | 0x33d |
IsProcessorFeaturePresent | 0x0 | 0x4301a4 | 0x38ed4 | 0x37cd4 | 0x304 |
IsDebuggerPresent | 0x0 | 0x4301a8 | 0x38ed8 | 0x37cd8 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x4301ac | 0x38edc | 0x37cdc | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4301b0 | 0x38ee0 | 0x37ce0 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x4301b4 | 0x38ee4 | 0x37ce4 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x4301b8 | 0x38ee8 | 0x37ce8 | 0x3a7 |
GetCurrentThreadId | 0x0 | 0x4301bc | 0x38eec | 0x37cec | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x4301c0 | 0x38ef0 | 0x37cf0 | 0x279 |
InitializeSListHead | 0x0 | 0x4301c4 | 0x38ef4 | 0x37cf4 | 0x2e7 |
TerminateProcess | 0x0 | 0x4301c8 | 0x38ef8 | 0x37cf8 | 0x4c0 |
RtlUnwind | 0x0 | 0x4301cc | 0x38efc | 0x37cfc | 0x418 |
EncodePointer | 0x0 | 0x4301d0 | 0x38f00 | 0x37d00 | 0xea |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4301d4 | 0x38f04 | 0x37d04 | 0x2e3 |
TlsAlloc | 0x0 | 0x4301d8 | 0x38f08 | 0x37d08 | 0x4c5 |
TlsGetValue | 0x0 | 0x4301dc | 0x38f0c | 0x37d0c | 0x4c7 |
TlsSetValue | 0x0 | 0x4301e0 | 0x38f10 | 0x37d10 | 0x4c8 |
TlsFree | 0x0 | 0x4301e4 | 0x38f14 | 0x37d14 | 0x4c6 |
LoadLibraryExW | 0x0 | 0x4301e8 | 0x38f18 | 0x37d18 | 0x33e |
QueryPerformanceFrequency | 0x0 | 0x4301ec | 0x38f1c | 0x37d1c | 0x3a8 |
GetModuleHandleExW | 0x0 | 0x4301f0 | 0x38f20 | 0x37d20 | 0x217 |
GetModuleFileNameA | 0x0 | 0x4301f4 | 0x38f24 | 0x37d24 | 0x213 |
GetACP | 0x0 | 0x4301f8 | 0x38f28 | 0x37d28 | 0x168 |
HeapFree | 0x0 | 0x4301fc | 0x38f2c | 0x37d2c | 0x2cf |
HeapAlloc | 0x0 | 0x430200 | 0x38f30 | 0x37d30 | 0x2cb |
HeapReAlloc | 0x0 | 0x430204 | 0x38f34 | 0x37d34 | 0x2d2 |
GetStringTypeW | 0x0 | 0x430208 | 0x38f38 | 0x37d38 | 0x269 |
LCMapStringW | 0x0 | 0x43020c | 0x38f3c | 0x37d3c | 0x32d |
FindFirstFileExA | 0x0 | 0x430210 | 0x38f40 | 0x37d40 | 0x133 |
FindNextFileA | 0x0 | 0x430214 | 0x38f44 | 0x37d44 | 0x143 |
IsValidCodePage | 0x0 | 0x430218 | 0x38f48 | 0x37d48 | 0x30a |
GetOEMCP | 0x0 | 0x43021c | 0x38f4c | 0x37d4c | 0x237 |
GetCommandLineA | 0x0 | 0x430220 | 0x38f50 | 0x37d50 | 0x186 |
GetEnvironmentStringsW | 0x0 | 0x430224 | 0x38f54 | 0x37d54 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x430228 | 0x38f58 | 0x37d58 | 0x161 |
DecodePointer | 0x0 | 0x43022c | 0x38f5c | 0x37d5c | 0xca |
gdiplus.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GdiplusShutdown | 0x0 | 0x430234 | 0x38f64 | 0x37d64 | 0x274 |
GdiplusStartup | 0x0 | 0x430238 | 0x38f68 | 0x37d68 | 0x275 |
GdipCreateHBITMAPFromBitmap | 0x0 | 0x43023c | 0x38f6c | 0x37d6c | 0x5f |
GdipCreateBitmapFromStreamICM | 0x0 | 0x430240 | 0x38f70 | 0x37d70 | 0x52 |
GdipCreateBitmapFromStream | 0x0 | 0x430244 | 0x38f74 | 0x37d74 | 0x51 |
GdipDisposeImage | 0x0 | 0x430248 | 0x38f78 | 0x37d78 | 0x98 |
GdipCloneImage | 0x0 | 0x43024c | 0x38f7c | 0x37d7c | 0x36 |
GdipFree | 0x0 | 0x430250 | 0x38f80 | 0x37d80 | 0xed |
GdipAlloc | 0x0 | 0x430254 | 0x38f84 | 0x37d84 | 0x21 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
p1q135no.sfx.exe | 1 | 0x00C70000 | 0x00CDCFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
p1q135no.sfx.exe | 1 | 0x00C70000 | 0x00CDCFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Agent.EFPT |
Malicious
|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-10-07 05:16 (UTC+2) |
Last Seen | 2019-10-27 15:13 (UTC+1) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x1400000 |
Entry Point | 0x142cf00 |
Size Of Code | 0x310000 |
Size Of Initialized Data | 0x17000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-10-14 17:35:31+00:00 |
Version Information (9)
»
CompanyName | Logitech Inc. |
FileDescription | SpotLife WebAlbum Service Plugin |
FileVersion | 8.2.0.1192 |
InternalName | WASpotLife.DLL |
LegalCopyright | (c) 1996-2004 Logitech. All rights reserved. |
OLESelfRegister | 1.0 |
OriginalFilename | WASpotLife.DLL |
ProductName | Logitech QuickCam |
ProductVersion | 8.2.0.1192 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x1401000 | 0x30f880 | 0x310000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.93 |
.data | 0x1711000 | 0xdcac | 0xd000 | 0x311000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.88 |
.idata | 0x171f000 | 0xc3a | 0x1000 | 0x31e000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.95 |
.CRT | 0x1720000 | 0x4 | 0x1000 | 0x31f000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.01 |
.rsrc | 0x1721000 | 0x688 | 0x1000 | 0x320000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.66 |
.reloc | 0x1722000 | 0x5a74 | 0x6000 | 0x321000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.85 |
Imports (6)
»
USER32.dll (17)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetMenu | 0x0 | 0x171f050 | 0x31f188 | 0x31e188 | 0x14b |
MessageBoxW | 0x0 | 0x171f054 | 0x31f18c | 0x31e18c | 0x215 |
UnhookWinEvent | 0x0 | 0x171f058 | 0x31f190 | 0x31e190 | 0x2fe |
ChildWindowFromPoint | 0x0 | 0x171f05c | 0x31f194 | 0x31e194 | 0x43 |
GetMenuCheckMarkDimensions | 0x0 | 0x171f060 | 0x31f198 | 0x31e198 | 0x14d |
GetFocus | 0x0 | 0x171f064 | 0x31f19c | 0x31e19c | 0x12c |
GetDlgCtrlID | 0x0 | 0x171f068 | 0x31f1a0 | 0x31e1a0 | 0x126 |
WinHelpW | 0x0 | 0x171f06c | 0x31f1a4 | 0x31e1a4 | 0x329 |
DrawTextExW | 0x0 | 0x171f070 | 0x31f1a8 | 0x31e1a8 | 0xcf |
ShowWindow | 0x0 | 0x171f074 | 0x31f1ac | 0x31e1ac | 0x2df |
GetClientRect | 0x0 | 0x171f078 | 0x31f1b0 | 0x31e1b0 | 0x114 |
DdeEnableCallback | 0x0 | 0x171f07c | 0x31f1b4 | 0x31e1b4 | 0x7f |
DeferWindowPos | 0x0 | 0x171f080 | 0x31f1b8 | 0x31e1b8 | 0x9d |
ToUnicode | 0x0 | 0x171f084 | 0x31f1bc | 0x31e1bc | 0x2f3 |
EndDialog | 0x0 | 0x171f088 | 0x31f1c0 | 0x31e1c0 | 0xda |
AllowSetForegroundWindow | 0x0 | 0x171f08c | 0x31f1c4 | 0x31e1c4 | 0x6 |
GetDC | 0x0 | 0x171f090 | 0x31f1c8 | 0x31e1c8 | 0x121 |
OLEAUT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocStringLen | 0x4 | 0x171f040 | 0x31f178 | 0x31e178 | - |
msi.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x1d | 0x171f098 | 0x31f1d0 | 0x31e1d0 | - |
(by ordinal) | 0x1e | 0x171f09c | 0x31f1d4 | 0x31e1d4 | - |
msvcrt.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
memset | 0x0 | 0x171f0a4 | 0x31f1dc | 0x31e1dc | 0x4ee |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AssocIsDangerous | 0x0 | 0x171f048 | 0x31f180 | 0x31e180 | 0x2 |
KERNEL32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WaitForMultipleObjectsEx | 0x0 | 0x171f000 | 0x31f138 | 0x31e138 | 0x4f8 |
GetBinaryTypeA | 0x0 | 0x171f004 | 0x31f13c | 0x31e13c | 0x170 |
GetModuleFileNameA | 0x0 | 0x171f008 | 0x31f140 | 0x31e140 | 0x213 |
GetModuleHandleA | 0x0 | 0x171f00c | 0x31f144 | 0x31e144 | 0x215 |
GetVersion | 0x0 | 0x171f010 | 0x31f148 | 0x31e148 | 0x2a2 |
InitializeCriticalSection | 0x0 | 0x171f014 | 0x31f14c | 0x31e14c | 0x2e2 |
lstrlenW | 0x0 | 0x171f018 | 0x31f150 | 0x31e150 | 0x54e |
GetModuleHandleW | 0x0 | 0x171f01c | 0x31f154 | 0x31e154 | 0x218 |
SetFileApisToANSI | 0x0 | 0x171f020 | 0x31f158 | 0x31e158 | 0x45c |
AreFileApisANSI | 0x0 | 0x171f024 | 0x31f15c | 0x31e15c | 0x15 |
WTSGetActiveConsoleSessionId | 0x0 | 0x171f028 | 0x31f160 | 0x31e160 | 0x4f4 |
CreateMutexW | 0x0 | 0x171f02c | 0x31f164 | 0x31e164 | 0x9e |
ReleaseMutex | 0x0 | 0x171f030 | 0x31f168 | 0x31e168 | 0x3fa |
CloseHandle | 0x0 | 0x171f034 | 0x31f16c | 0x31e16c | 0x52 |
ReadConsoleA | 0x0 | 0x171f038 | 0x31f170 | 0x31e170 | 0x3b4 |
Digital Signatures (2)
»
Certificate: LOVER BRANDS UK LTD
»
Issued by | LOVER BRANDS UK LTD |
Parent Certificate | thawte SHA256 Code Signing CA |
Country Name | GB |
Valid From | 2019-07-05 00:00:00+00:00 |
Valid Until | 2020-07-04 23:59:59+00:00 |
Algorithm | sha256_rsa |
Serial Number | 6D F5 8C 35 39 AD 02 9A DA 80 22 9A 46 17 40 D0 |
Thumbprint | 17 3D 2C 3F 79 BF 86 A5 87 BB 62 AF 15 B0 E5 CD ED 0C CC 89 |
Certificate: thawte SHA256 Code Signing CA
»
Issued by | thawte SHA256 Code Signing CA |
Country Name | US |
Valid From | 2013-12-10 00:00:00+00:00 |
Valid Until | 2023-12-09 23:59:59+00:00 |
Algorithm | sha256_rsa |
Serial Number | 71 A0 B7 36 95 DD B1 AF C2 3B 2B 9A 18 EE 54 CB |
Thumbprint | D0 0C FD BF 46 C9 8A 83 8B C1 0D C4 E0 97 AE 01 52 C4 61 BC |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
p1q135no.exe | 2 | 0x01400000 | 0x01727FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x002B0000 | 0x002B5FFF | First Execution | - | 32-bit | 0x002B16DE |
![]() |
![]() |
...
|
p1q135no.exe | 2 | 0x01400000 | 0x01727FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 3 | 0x001C0000 | 0x001C5FFF | First Execution | - | 32-bit | 0x001C16DE |
![]() |
![]() |
...
|
buffer | 25 | 0x00230000 | 0x00235FFF | First Execution | - | 32-bit | 0x002316DE |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Agent.EFPT |
Malicious
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\main.js.locked | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
JS_High_Entropy | JavaScript has a high entropy; possible obfuscation | - |
4/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.js.locked | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
JS_High_Entropy | JavaScript has a high entropy; possible obfuscation | - |
4/5
|
...
|
C:\Users\5P5NRG~1\AppData\Roaming\9EMQWM~1 | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:42 (UTC+1) |
Last Seen | 2019-04-17 13:48 (UTC+2) |
PE Information
»
Image Base | 0x100000000 |
Entry Point | 0x100005cf8 |
Size Of Code | 0x6000 |
Size Of Initialized Data | 0x1a00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2009-07-13 23:54:12+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | DNSCache Unattend Generic Command |
FileVersion | 6.1.7600.16385 (win7_rtm.090713-1255) |
InternalName | dnscacheugc.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | dnscacheugc.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7600.16385 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x100001000 | 0x5f56 | 0x6000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.9 |
.data | 0x100007000 | 0x834 | 0x200 | 0x6400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.06 |
.pdata | 0x100008000 | 0x2f4 | 0x400 | 0x6600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.3 |
.rsrc | 0x100009000 | 0x818 | 0xa00 | 0x6a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.78 |
.reloc | 0x10000a000 | 0x94 | 0x200 | 0x7400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.83 |
Imports (5)
»
ADVAPI32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryInfoKeyW | 0x0 | 0x100001000 | 0x6778 | 0x5b78 | 0x268 |
RegEnumValueW | 0x0 | 0x100001008 | 0x6780 | 0x5b80 | 0x252 |
RegEnumKeyExW | 0x0 | 0x100001010 | 0x6788 | 0x5b88 | 0x24f |
RegOpenKeyExW | 0x0 | 0x100001018 | 0x6790 | 0x5b90 | 0x261 |
RegCloseKey | 0x0 | 0x100001020 | 0x6798 | 0x5b98 | 0x230 |
RegCreateKeyExW | 0x0 | 0x100001028 | 0x67a0 | 0x5ba0 | 0x239 |
RegSetValueExW | 0x0 | 0x100001030 | 0x67a8 | 0x5ba8 | 0x27e |
KERNEL32.dll (30)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileAttributesW | 0x0 | 0x100001078 | 0x67f0 | 0x5bf0 | 0x1f1 |
ExpandEnvironmentStringsW | 0x0 | 0x100001080 | 0x67f8 | 0x5bf8 | 0x123 |
GetCurrentProcess | 0x0 | 0x100001088 | 0x6800 | 0x5c00 | 0x1c6 |
SetLastError | 0x0 | 0x100001090 | 0x6808 | 0x5c08 | 0x480 |
CreateDirectoryW | 0x0 | 0x100001098 | 0x6810 | 0x5c10 | 0x81 |
GetFullPathNameW | 0x0 | 0x1000010a0 | 0x6818 | 0x5c18 | 0x202 |
DeleteCriticalSection | 0x0 | 0x1000010a8 | 0x6820 | 0x5c20 | 0xd2 |
EnterCriticalSection | 0x0 | 0x1000010b0 | 0x6828 | 0x5c28 | 0xf2 |
GetProcAddress | 0x0 | 0x1000010b8 | 0x6830 | 0x5c30 | 0x24c |
LocalFree | 0x0 | 0x1000010c0 | 0x6838 | 0x5c38 | 0x34a |
LocalAlloc | 0x0 | 0x1000010c8 | 0x6840 | 0x5c40 | 0x346 |
Sleep | 0x0 | 0x1000010d0 | 0x6848 | 0x5c48 | 0x4c0 |
SetUnhandledExceptionFilter | 0x0 | 0x1000010d8 | 0x6850 | 0x5c50 | 0x4b3 |
GetModuleHandleW | 0x0 | 0x1000010e0 | 0x6858 | 0x5c58 | 0x21e |
QueryPerformanceCounter | 0x0 | 0x1000010e8 | 0x6860 | 0x5c60 | 0x3a9 |
GetTickCount | 0x0 | 0x1000010f0 | 0x6868 | 0x5c68 | 0x29a |
GetCurrentThreadId | 0x0 | 0x1000010f8 | 0x6870 | 0x5c70 | 0x1cb |
GetCurrentProcessId | 0x0 | 0x100001100 | 0x6878 | 0x5c78 | 0x1c7 |
GetSystemTimeAsFileTime | 0x0 | 0x100001108 | 0x6880 | 0x5c80 | 0x280 |
TerminateProcess | 0x0 | 0x100001110 | 0x6888 | 0x5c88 | 0x4ce |
GetLastError | 0x0 | 0x100001118 | 0x6890 | 0x5c90 | 0x208 |
UnhandledExceptionFilter | 0x0 | 0x100001120 | 0x6898 | 0x5c98 | 0x4e2 |
FreeLibrary | 0x0 | 0x100001128 | 0x68a0 | 0x5ca0 | 0x168 |
HeapAlloc | 0x0 | 0x100001130 | 0x68a8 | 0x5ca8 | 0x2d3 |
HeapFree | 0x0 | 0x100001138 | 0x68b0 | 0x5cb0 | 0x2d7 |
GetProcessHeap | 0x0 | 0x100001140 | 0x68b8 | 0x5cb8 | 0x251 |
InitializeCriticalSection | 0x0 | 0x100001148 | 0x68c0 | 0x5cc0 | 0x2ea |
LoadLibraryW | 0x0 | 0x100001150 | 0x68c8 | 0x5cc8 | 0x341 |
LeaveCriticalSection | 0x0 | 0x100001158 | 0x68d0 | 0x5cd0 | 0x33b |
GetModuleFileNameW | 0x0 | 0x100001160 | 0x68d8 | 0x5cd8 | 0x21a |
msvcrt.dll (25)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_XcptFilter | 0x0 | 0x100001170 | 0x68e8 | 0x5ce8 | 0x52 |
_exit | 0x0 | 0x100001178 | 0x68f0 | 0x5cf0 | 0xff |
__C_specific_handler | 0x0 | 0x100001180 | 0x68f8 | 0x5cf8 | 0x53 |
exit | 0x0 | 0x100001188 | 0x6900 | 0x5d00 | 0x420 |
_initterm | 0x0 | 0x100001190 | 0x6908 | 0x5d08 | 0x16c |
__getmainargs | 0x0 | 0x100001198 | 0x6910 | 0x5d10 | 0x71 |
wcstoul | 0x0 | 0x1000011a0 | 0x6918 | 0x5d18 | 0x509 |
_wcsnicmp | 0x0 | 0x1000011a8 | 0x6920 | 0x5d20 | 0x383 |
_vsnwprintf | 0x0 | 0x1000011b0 | 0x6928 | 0x5d28 | 0x358 |
_cexit | 0x0 | 0x1000011b8 | 0x6930 | 0x5d30 | 0xb3 |
wcsrchr | 0x0 | 0x1000011c0 | 0x6938 | 0x5d38 | 0x4fe |
_vsnprintf | 0x0 | 0x1000011c8 | 0x6940 | 0x5d40 | 0x352 |
wcschr | 0x0 | 0x1000011d0 | 0x6948 | 0x5d48 | 0x4ef |
memcpy | 0x0 | 0x1000011d8 | 0x6950 | 0x5d50 | 0x480 |
_onexit | 0x0 | 0x1000011e0 | 0x6958 | 0x5d58 | 0x27f |
_lock | 0x0 | 0x1000011e8 | 0x6960 | 0x5d60 | 0x1d5 |
__dllonexit | 0x0 | 0x1000011f0 | 0x6968 | 0x5d68 | 0x6d |
_unlock | 0x0 | 0x1000011f8 | 0x6970 | 0x5d70 | 0x330 |
?terminate@@YAXXZ | 0x0 | 0x100001200 | 0x6978 | 0x5d78 | 0x30 |
__set_app_type | 0x0 | 0x100001208 | 0x6980 | 0x5d80 | 0x80 |
_fmode | 0x0 | 0x100001210 | 0x6988 | 0x5d88 | 0x118 |
_commode | 0x0 | 0x100001218 | 0x6990 | 0x5d90 | 0xc4 |
__setusermatherr | 0x0 | 0x100001220 | 0x6998 | 0x5d98 | 0x82 |
_amsg_exit | 0x0 | 0x100001228 | 0x69a0 | 0x5da0 | 0xa0 |
memset | 0x0 | 0x100001230 | 0x69a8 | 0x5da8 | 0x484 |
ntdll.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlAllocateHeap | 0x0 | 0x100001240 | 0x69b8 | 0x5db8 | 0x265 |
RtlFreeHeap | 0x0 | 0x100001248 | 0x69c0 | 0x5dc0 | 0x34a |
RtlCaptureContext | 0x0 | 0x100001250 | 0x69c8 | 0x5dc8 | 0x27b |
RtlLookupFunctionEntry | 0x0 | 0x100001258 | 0x69d0 | 0x5dd0 | 0x401 |
RtlVirtualUnwind | 0x0 | 0x100001260 | 0x69d8 | 0x5dd8 | 0x4f0 |
IPHLPAPI.DLL (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ConvertInterfaceLuidToGuid | 0x0 | 0x100001040 | 0x67b8 | 0x5bb8 | 0x10 |
ConvertInterfacePhysicalAddressToLuid | 0x0 | 0x100001048 | 0x67c0 | 0x5bc0 | 0x16 |
ConvertStringToInterfacePhysicalAddress | 0x0 | 0x100001050 | 0x67c8 | 0x5bc8 | 0x21 |
ConvertInterfaceAliasToLuid | 0x0 | 0x100001058 | 0x67d0 | 0x5bd0 | 0xc |
ConvertInterfaceNameToLuidW | 0x0 | 0x100001060 | 0x67d8 | 0x5bd8 | 0x15 |
ParseNetworkString | 0x0 | 0x100001068 | 0x67e0 | 0x5be0 | 0xd8 |
C:\Windows\System32\msdtc.exe:0 | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2012-10-01 02:48 (UTC+2) |
Last Seen | 2019-05-01 15:08 (UTC+2) |
PE Information
»
Image Base | 0x140000000 |
Entry Point | 0x1400084a4 |
Size Of Code | 0x9c00 |
Size Of Initialized Data | 0x1ae00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2009-07-13 23:59:22+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Distributed Transaction Coordinator Service |
FileVersion | 2001.12.8530.16385 (win7_rtm.090713-1255) |
InternalName | MSDTC.EXE |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | MSDTC.EXE |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7600.16385 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x140001000 | 0x9a7a | 0x9c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.9 |
.data | 0x14000b000 | 0x2878 | 0x600 | 0xa000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.44 |
.pdata | 0x14000e000 | 0x444 | 0x600 | 0xa600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.34 |
.rsrc | 0x14000f000 | 0x17870 | 0x17a00 | 0xac00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.93 |
.reloc | 0x140027000 | 0x26e | 0x400 | 0x22600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.9 |
Imports (8)
»
KERNEL32.dll (59)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCommandLineW | 0x0 | 0x140001060 | 0x9bf8 | 0x8ff8 | 0x18d |
TlsGetValue | 0x0 | 0x140001068 | 0x9c00 | 0x9000 | 0x4d5 |
UnregisterWait | 0x0 | 0x140001070 | 0x9c08 | 0x9008 | 0x4e9 |
TlsFree | 0x0 | 0x140001078 | 0x9c10 | 0x9010 | 0x4d4 |
TlsAlloc | 0x0 | 0x140001080 | 0x9c18 | 0x9018 | 0x4d3 |
LocalAlloc | 0x0 | 0x140001088 | 0x9c20 | 0x9020 | 0x346 |
ExpandEnvironmentStringsW | 0x0 | 0x140001090 | 0x9c28 | 0x9028 | 0x123 |
SetFileAttributesW | 0x0 | 0x140001098 | 0x9c30 | 0x9030 | 0x46f |
LocalFree | 0x0 | 0x1400010a0 | 0x9c38 | 0x9038 | 0x34a |
DeleteFileW | 0x0 | 0x1400010a8 | 0x9c40 | 0x9040 | 0xd7 |
DeleteCriticalSection | 0x0 | 0x1400010b0 | 0x9c48 | 0x9048 | 0xd2 |
FindNextFileW | 0x0 | 0x1400010b8 | 0x9c50 | 0x9050 | 0x14b |
IsDebuggerPresent | 0x0 | 0x1400010c0 | 0x9c58 | 0x9058 | 0x302 |
LockResource | 0x0 | 0x1400010c8 | 0x9c60 | 0x9060 | 0x356 |
FindClose | 0x0 | 0x1400010d0 | 0x9c68 | 0x9068 | 0x134 |
GetModuleFileNameW | 0x0 | 0x1400010d8 | 0x9c70 | 0x9070 | 0x21a |
GetExitCodeProcess | 0x0 | 0x1400010e0 | 0x9c78 | 0x9078 | 0x1e6 |
FormatMessageW | 0x0 | 0x1400010e8 | 0x9c80 | 0x9080 | 0x164 |
GetCurrentThread | 0x0 | 0x1400010f0 | 0x9c88 | 0x9088 | 0x1ca |
CreateDirectoryW | 0x0 | 0x1400010f8 | 0x9c90 | 0x9090 | 0x81 |
LoadLibraryExW | 0x0 | 0x140001100 | 0x9c98 | 0x9098 | 0x340 |
CreateProcessW | 0x0 | 0x140001108 | 0x9ca0 | 0x90a0 | 0xa8 |
LoadResource | 0x0 | 0x140001110 | 0x9ca8 | 0x90a8 | 0x343 |
FindResourceW | 0x0 | 0x140001118 | 0x9cb0 | 0x90b0 | 0x154 |
FindFirstFileW | 0x0 | 0x140001120 | 0x9cb8 | 0x90b8 | 0x13f |
GetThreadContext | 0x0 | 0x140001128 | 0x9cc0 | 0x90c0 | 0x28d |
EnterCriticalSection | 0x0 | 0x140001130 | 0x9cc8 | 0x90c8 | 0xf2 |
LeaveCriticalSection | 0x0 | 0x140001138 | 0x9cd0 | 0x90d0 | 0x33b |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x140001140 | 0x9cd8 | 0x90d8 | 0x2eb |
WaitForSingleObject | 0x0 | 0x140001148 | 0x9ce0 | 0x90e0 | 0x508 |
Sleep | 0x0 | 0x140001150 | 0x9ce8 | 0x90e8 | 0x4c0 |
GetStartupInfoW | 0x0 | 0x140001158 | 0x9cf0 | 0x90f0 | 0x26a |
SetUnhandledExceptionFilter | 0x0 | 0x140001160 | 0x9cf8 | 0x90f8 | 0x4b3 |
GetModuleHandleW | 0x0 | 0x140001168 | 0x9d00 | 0x9100 | 0x21e |
QueryPerformanceCounter | 0x0 | 0x140001170 | 0x9d08 | 0x9108 | 0x3a9 |
GetTickCount | 0x0 | 0x140001178 | 0x9d10 | 0x9110 | 0x29a |
GetCurrentThreadId | 0x0 | 0x140001180 | 0x9d18 | 0x9118 | 0x1cb |
GetCurrentProcessId | 0x0 | 0x140001188 | 0x9d20 | 0x9120 | 0x1c7 |
GetSystemTimeAsFileTime | 0x0 | 0x140001190 | 0x9d28 | 0x9128 | 0x280 |
TerminateProcess | 0x0 | 0x140001198 | 0x9d30 | 0x9130 | 0x4ce |
GetCurrentProcess | 0x0 | 0x1400011a0 | 0x9d38 | 0x9138 | 0x1c6 |
UnhandledExceptionFilter | 0x0 | 0x1400011a8 | 0x9d40 | 0x9140 | 0x4e2 |
GetFullPathNameW | 0x0 | 0x1400011b0 | 0x9d48 | 0x9148 | 0x202 |
FreeLibrary | 0x0 | 0x1400011b8 | 0x9d50 | 0x9150 | 0x168 |
SetEvent | 0x0 | 0x1400011c0 | 0x9d58 | 0x9158 | 0x467 |
WaitForSingleObjectEx | 0x0 | 0x1400011c8 | 0x9d60 | 0x9160 | 0x509 |
OutputDebugStringW | 0x0 | 0x1400011d0 | 0x9d68 | 0x9168 | 0x38c |
QueryFullProcessImageNameW | 0x0 | 0x1400011d8 | 0x9d70 | 0x9170 | 0x3a4 |
CreateEventA | 0x0 | 0x1400011e0 | 0x9d78 | 0x9178 | 0x82 |
CreateFileW | 0x0 | 0x1400011e8 | 0x9d80 | 0x9180 | 0x8f |
GetLastError | 0x0 | 0x1400011f0 | 0x9d88 | 0x9188 | 0x208 |
GetProcAddress | 0x0 | 0x1400011f8 | 0x9d90 | 0x9190 | 0x24c |
ResetEvent | 0x0 | 0x140001200 | 0x9d98 | 0x9198 | 0x412 |
GetLocalTime | 0x0 | 0x140001208 | 0x9da0 | 0x91a0 | 0x209 |
LoadLibraryA | 0x0 | 0x140001210 | 0x9da8 | 0x91a8 | 0x33e |
QueueUserWorkItem | 0x0 | 0x140001218 | 0x9db0 | 0x91b0 | 0x3b3 |
CloseHandle | 0x0 | 0x140001220 | 0x9db8 | 0x91b8 | 0x52 |
DebugBreak | 0x0 | 0x140001228 | 0x9dc0 | 0x91c0 | 0xc8 |
GetSystemWindowsDirectoryA | 0x0 | 0x140001230 | 0x9dc8 | 0x91c8 | 0x282 |
ole32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoCreateInstance | 0x0 | 0x140001488 | 0xa020 | 0x9420 | 0x14 |
StringFromGUID2 | 0x0 | 0x140001490 | 0xa028 | 0x9428 | 0x1b5 |
CoGetObjectContext | 0x0 | 0x140001498 | 0xa030 | 0x9430 | 0x3a |
CoInitializeEx | 0x0 | 0x1400014a0 | 0xa038 | 0x9438 | 0x43 |
CoUninitialize | 0x0 | 0x1400014a8 | 0xa040 | 0x9440 | 0x70 |
msvcrt.dll (45)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__CxxFrameHandler3 | 0x0 | 0x1400012f0 | 0x9e88 | 0x9288 | 0x57 |
??1type_info@@UEAA@XZ | 0x0 | 0x1400012f8 | 0x9e90 | 0x9290 | 0x12 |
_wfopen | 0x0 | 0x140001300 | 0x9e98 | 0x9298 | 0x3b1 |
memcpy | 0x0 | 0x140001308 | 0x9ea0 | 0x92a0 | 0x480 |
_CxxThrowException | 0x0 | 0x140001310 | 0x9ea8 | 0x92a8 | 0x4c |
memset | 0x0 | 0x140001318 | 0x9eb0 | 0x92b0 | 0x484 |
_onexit | 0x0 | 0x140001320 | 0x9eb8 | 0x92b8 | 0x27f |
_lock | 0x0 | 0x140001328 | 0x9ec0 | 0x92c0 | 0x1d5 |
__dllonexit | 0x0 | 0x140001330 | 0x9ec8 | 0x92c8 | 0x6d |
_unlock | 0x0 | 0x140001338 | 0x9ed0 | 0x92d0 | 0x330 |
?terminate@@YAXXZ | 0x0 | 0x140001340 | 0x9ed8 | 0x92d8 | 0x30 |
__set_app_type | 0x0 | 0x140001348 | 0x9ee0 | 0x92e0 | 0x80 |
_fmode | 0x0 | 0x140001350 | 0x9ee8 | 0x92e8 | 0x118 |
?what@exception@@UEBAPEBDXZ | 0x0 | 0x140001358 | 0x9ef0 | 0x92f0 | 0x32 |
??0exception@@QEAA@AEBQEBDH@Z | 0x0 | 0x140001360 | 0x9ef8 | 0x92f8 | 0xb |
??0exception@@QEAA@AEBV0@@Z | 0x0 | 0x140001368 | 0x9f00 | 0x9300 | 0xc |
??1exception@@UEAA@XZ | 0x0 | 0x140001370 | 0x9f08 | 0x9308 | 0x11 |
_purecall | 0x0 | 0x140001378 | 0x9f10 | 0x9310 | 0x28d |
_commode | 0x0 | 0x140001380 | 0x9f18 | 0x9318 | 0xc4 |
__setusermatherr | 0x0 | 0x140001388 | 0x9f20 | 0x9320 | 0x82 |
_amsg_exit | 0x0 | 0x140001390 | 0x9f28 | 0x9328 | 0xa0 |
_initterm | 0x0 | 0x140001398 | 0x9f30 | 0x9330 | 0x16c |
_wcmdln | 0x0 | 0x1400013a0 | 0x9f38 | 0x9338 | 0x371 |
exit | 0x0 | 0x1400013a8 | 0x9f40 | 0x9340 | 0x420 |
_cexit | 0x0 | 0x1400013b0 | 0x9f48 | 0x9348 | 0xb3 |
_exit | 0x0 | 0x1400013b8 | 0x9f50 | 0x9350 | 0xff |
_XcptFilter | 0x0 | 0x1400013c0 | 0x9f58 | 0x9358 | 0x52 |
__C_specific_handler | 0x0 | 0x1400013c8 | 0x9f60 | 0x9360 | 0x53 |
__wgetmainargs | 0x0 | 0x1400013d0 | 0x9f68 | 0x9368 | 0x8f |
free | 0x0 | 0x1400013d8 | 0x9f70 | 0x9370 | 0x43a |
_callnewh | 0x0 | 0x1400013e0 | 0x9f78 | 0x9378 | 0xb1 |
malloc | 0x0 | 0x1400013e8 | 0x9f80 | 0x9380 | 0x474 |
wcschr | 0x0 | 0x1400013f0 | 0x9f88 | 0x9388 | 0x4ef |
_wstrdate | 0x0 | 0x1400013f8 | 0x9f90 | 0x9390 | 0x3e8 |
_waccess | 0x0 | 0x140001400 | 0x9f98 | 0x9398 | 0x36a |
_wstrtime | 0x0 | 0x140001408 | 0x9fa0 | 0x93a0 | 0x3ea |
_wcsicmp | 0x0 | 0x140001410 | 0x9fa8 | 0x93a8 | 0x379 |
_vsnwprintf | 0x0 | 0x140001418 | 0x9fb0 | 0x93b0 | 0x358 |
fwprintf | 0x0 | 0x140001420 | 0x9fb8 | 0x93b8 | 0x443 |
fflush | 0x0 | 0x140001428 | 0x9fc0 | 0x93c0 | 0x427 |
fopen | 0x0 | 0x140001430 | 0x9fc8 | 0x93c8 | 0x431 |
fprintf | 0x0 | 0x140001438 | 0x9fd0 | 0x93d0 | 0x433 |
fclose | 0x0 | 0x140001440 | 0x9fd8 | 0x93d8 | 0x424 |
wcsrchr | 0x0 | 0x140001448 | 0x9fe0 | 0x93e0 | 0x4fe |
_local_unwind | 0x0 | 0x140001450 | 0x9fe8 | 0x93e8 | 0x1d0 |
MSDTCTM.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x4 | 0x140001240 | 0x9dd8 | 0x91d8 | - |
ntdll.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlReportException | 0x0 | 0x140001460 | 0x9ff8 | 0x93f8 | 0x461 |
RtlCaptureContext | 0x0 | 0x140001468 | 0xa000 | 0x9400 | 0x27b |
RtlLookupFunctionEntry | 0x0 | 0x140001470 | 0xa008 | 0x9408 | 0x401 |
RtlVirtualUnwind | 0x0 | 0x140001478 | 0xa010 | 0x9410 | 0x4f0 |
VERSION.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x1400012e0 | 0x9e78 | 0x9278 | 0xe |
USER32.dll (17)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetWindowRect | 0x0 | 0x140001250 | 0x9de8 | 0x91e8 | 0x1a0 |
GetThreadDesktop | 0x0 | 0x140001258 | 0x9df0 | 0x91f0 | 0x184 |
CloseWindowStation | 0x0 | 0x140001260 | 0x9df8 | 0x91f8 | 0x4e |
DialogBoxParamW | 0x0 | 0x140001268 | 0x9e00 | 0x9200 | 0xac |
GetProcessWindowStation | 0x0 | 0x140001270 | 0x9e08 | 0x9208 | 0x16a |
OpenDesktopW | 0x0 | 0x140001278 | 0x9e10 | 0x9210 | 0x22c |
GetClientRect | 0x0 | 0x140001280 | 0x9e18 | 0x9218 | 0x116 |
SetProcessWindowStation | 0x0 | 0x140001288 | 0x9e20 | 0x9220 | 0x2b0 |
EndDialog | 0x0 | 0x140001290 | 0x9e28 | 0x9228 | 0xda |
GetDesktopWindow | 0x0 | 0x140001298 | 0x9e30 | 0x9230 | 0x125 |
SetWindowPos | 0x0 | 0x1400012a0 | 0x9e38 | 0x9238 | 0x2ce |
SetThreadDesktop | 0x0 | 0x1400012a8 | 0x9e40 | 0x9240 | 0x2c0 |
SetDlgItemTextW | 0x0 | 0x1400012b0 | 0x9e48 | 0x9248 | 0x296 |
OpenWindowStationW | 0x0 | 0x1400012b8 | 0x9e50 | 0x9250 | 0x231 |
MapWindowPoints | 0x0 | 0x1400012c0 | 0x9e58 | 0x9258 | 0x20d |
LoadStringW | 0x0 | 0x1400012c8 | 0x9e60 | 0x9260 | 0x1fe |
CloseDesktop | 0x0 | 0x1400012d0 | 0x9e68 | 0x9268 | 0x4a |
ADVAPI32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExW | 0x0 | 0x140001000 | 0x9b98 | 0x8f98 | 0x261 |
GetTokenInformation | 0x0 | 0x140001008 | 0x9ba0 | 0x8fa0 | 0x15a |
OpenProcessToken | 0x0 | 0x140001010 | 0x9ba8 | 0x8fa8 | 0x1f7 |
RegSetValueExW | 0x0 | 0x140001018 | 0x9bb0 | 0x8fb0 | 0x27e |
RegCloseKey | 0x0 | 0x140001020 | 0x9bb8 | 0x8fb8 | 0x230 |
ReportEventW | 0x0 | 0x140001028 | 0x9bc0 | 0x8fc0 | 0x28f |
RegisterEventSourceW | 0x0 | 0x140001030 | 0x9bc8 | 0x8fc8 | 0x283 |
RegOpenKeyExA | 0x0 | 0x140001038 | 0x9bd0 | 0x8fd0 | 0x260 |
DeregisterEventSource | 0x0 | 0x140001040 | 0x9bd8 | 0x8fd8 | 0xdb |
RegQueryValueExW | 0x0 | 0x140001048 | 0x9be0 | 0x8fe0 | 0x26e |
RegQueryValueExA | 0x0 | 0x140001050 | 0x9be8 | 0x8fe8 | 0x26d |
C:\Users\5P5NRG~1\AppData\Roaming\K6LAKJ~1 | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2012-10-01 02:48 (UTC+2) |
Last Seen | 2019-04-17 13:47 (UTC+2) |
PE Information
»
Image Base | 0x100000000 |
Entry Point | 0x100002df8 |
Size Of Code | 0x3600 |
Size Of Initialized Data | 0x1600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2009-07-13 23:25:22+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | NTFS Volume Maintenance Utility |
FileVersion | 6.1.7600.16385 (win7_rtm.090713-1255) |
InternalName | chkntfs |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | CHKNTFS.EXE |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7600.16385 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x100001000 | 0x3528 | 0x3600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.04 |
.data | 0x100005000 | 0x700 | 0x200 | 0x3a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.42 |
.pdata | 0x100006000 | 0xe4 | 0x200 | 0x3c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.93 |
.rsrc | 0x100007000 | 0x908 | 0xa00 | 0x3e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.29 |
.reloc | 0x100008000 | 0x72 | 0x200 | 0x4800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.59 |
Imports (5)
»
KERNEL32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetErrorMode | 0x0 | 0x100001000 | 0x3520 | 0x2920 | 0x466 |
HeapSetInformation | 0x0 | 0x100001008 | 0x3528 | 0x2928 | 0x2db |
GetCurrentProcess | 0x0 | 0x100001010 | 0x3530 | 0x2930 | 0x1c6 |
TerminateProcess | 0x0 | 0x100001018 | 0x3538 | 0x2938 | 0x4ce |
GetSystemTimeAsFileTime | 0x0 | 0x100001020 | 0x3540 | 0x2940 | 0x280 |
GetCurrentProcessId | 0x0 | 0x100001028 | 0x3548 | 0x2948 | 0x1c7 |
GetCurrentThreadId | 0x0 | 0x100001030 | 0x3550 | 0x2950 | 0x1cb |
GetTickCount | 0x0 | 0x100001038 | 0x3558 | 0x2958 | 0x29a |
QueryPerformanceCounter | 0x0 | 0x100001040 | 0x3560 | 0x2960 | 0x3a9 |
GetModuleHandleW | 0x0 | 0x100001048 | 0x3568 | 0x2968 | 0x21e |
SetUnhandledExceptionFilter | 0x0 | 0x100001050 | 0x3570 | 0x2970 | 0x4b3 |
Sleep | 0x0 | 0x100001058 | 0x3578 | 0x2978 | 0x4c0 |
UnhandledExceptionFilter | 0x0 | 0x100001060 | 0x3580 | 0x2980 | 0x4e2 |
msvcrt.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_commode | 0x0 | 0x100001100 | 0x3620 | 0x2a20 | 0xc4 |
__setusermatherr | 0x0 | 0x100001108 | 0x3628 | 0x2a28 | 0x82 |
_amsg_exit | 0x0 | 0x100001110 | 0x3630 | 0x2a30 | 0xa0 |
_initterm | 0x0 | 0x100001118 | 0x3638 | 0x2a38 | 0x16c |
_cexit | 0x0 | 0x100001120 | 0x3640 | 0x2a40 | 0xb3 |
_exit | 0x0 | 0x100001128 | 0x3648 | 0x2a48 | 0xff |
_XcptFilter | 0x0 | 0x100001130 | 0x3650 | 0x2a50 | 0x52 |
__C_specific_handler | 0x0 | 0x100001138 | 0x3658 | 0x2a58 | 0x53 |
__getmainargs | 0x0 | 0x100001140 | 0x3660 | 0x2a60 | 0x71 |
?terminate@@YAXXZ | 0x0 | 0x100001148 | 0x3668 | 0x2a68 | 0x30 |
__set_app_type | 0x0 | 0x100001150 | 0x3670 | 0x2a70 | 0x80 |
exit | 0x0 | 0x100001158 | 0x3678 | 0x2a78 | 0x420 |
_fmode | 0x0 | 0x100001160 | 0x3680 | 0x2a80 | 0x118 |
ulib.dll (51)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
?DisplayMessage@PROGRAM@@UEBAEKW4MESSAGE_TYPE@@@Z | 0x0 | 0x1000011a0 | 0x36c0 | 0x2ac0 | 0x87 |
?DisplayMessage@PROGRAM@@UEBAEKW4MESSAGE_TYPE@@PEADZZ | 0x0 | 0x1000011a8 | 0x36c8 | 0x2ac8 | 0x88 |
??1PROGRAM@@UEAA@XZ | 0x0 | 0x1000011b0 | 0x36d0 | 0x2ad0 | 0x44 |
?Initialize@PROGRAM@@QEAAEKKK@Z | 0x0 | 0x1000011b8 | 0x36d8 | 0x2ad8 | 0xd0 |
?Initialize@MULTIPLE_PATH_ARGUMENT@@QEAAEPEADEE@Z | 0x0 | 0x1000011c0 | 0x36e0 | 0x2ae0 | 0xca |
??1MULTIPLE_PATH_ARGUMENT@@UEAA@XZ | 0x0 | 0x1000011c8 | 0x36e8 | 0x2ae8 | 0x3f |
??0PROGRAM@@IEAA@XZ | 0x0 | 0x1000011d0 | 0x36f0 | 0x2af0 | 0x22 |
?Put@ARRAY@@UEAAEPEAVOBJECT@@@Z | 0x0 | 0x1000011d8 | 0x36f8 | 0x2af8 | 0x107 |
?Initialize@ARRAY@@QEAAEKK@Z | 0x0 | 0x1000011e0 | 0x3700 | 0x2b00 | 0xb6 |
??1ARRAY@@UEAA@XZ | 0x0 | 0x1000011e8 | 0x3708 | 0x2b08 | 0x2e |
??0ARRAY@@QEAA@XZ | 0x0 | 0x1000011f0 | 0x3710 | 0x2b10 | 0x1 |
?Initialize@STRING_ARGUMENT@@QEAAEPEAD@Z | 0x0 | 0x1000011f8 | 0x3718 | 0x2b18 | 0xd5 |
??1STRING_ARGUMENT@@UEAA@XZ | 0x0 | 0x100001200 | 0x3720 | 0x2b20 | 0x48 |
??0STRING_ARGUMENT@@QEAA@XZ | 0x0 | 0x100001208 | 0x3728 | 0x2b28 | 0x27 |
?QueryDriveType@SYSTEM@@SA?AW4DRIVE_TYPE@@PEBVWSTRING@@@Z | 0x0 | 0x100001210 | 0x3730 | 0x2b30 | 0x11c |
??8WSTRING@@QEBAEAEBV0@@Z | 0x0 | 0x100001218 | 0x3738 | 0x2b38 | 0x52 |
?ValidateVersion@PROGRAM@@UEBAXKK@Z | 0x0 | 0x100001220 | 0x3740 | 0x2b40 | 0x1ab |
?GetLexeme@ARGUMENT@@QEAAPEAVWSTRING@@XZ | 0x0 | 0x100001228 | 0x3748 | 0x2b48 | 0xa7 |
?IsValueSet@ARGUMENT@@QEAAEXZ | 0x0 | 0x100001230 | 0x3750 | 0x2b50 | 0xf0 |
?Initialize@WSTRING@@QEAAEPEBDK@Z | 0x0 | 0x100001238 | 0x3758 | 0x2b58 | 0xdd |
?Initialize@WSTRING@@QEAAEPEBV1@KK@Z | 0x0 | 0x100001240 | 0x3760 | 0x2b60 | 0xdf |
?QueryString@WSTRING@@QEBAPEAV1@KK@Z | 0x0 | 0x100001248 | 0x3768 | 0x2b68 | 0x13a |
?Strcat@WSTRING@@QEAAEPEBV1@@Z | 0x0 | 0x100001250 | 0x3770 | 0x2b70 | 0x186 |
??0LONG_ARGUMENT@@QEAA@XZ | 0x0 | 0x100001258 | 0x3778 | 0x2b78 | 0x17 |
?Initialize@LONG_ARGUMENT@@QEAAEPEAD@Z | 0x0 | 0x100001260 | 0x3780 | 0x2b80 | 0xc6 |
??0FLAG_ARGUMENT@@QEAA@XZ | 0x0 | 0x100001268 | 0x3788 | 0x2b88 | 0xe |
?Initialize@FLAG_ARGUMENT@@QEAAEPEAD@Z | 0x0 | 0x100001270 | 0x3790 | 0x2b90 | 0xbf |
??0DSTRING@@QEAA@XZ | 0x0 | 0x100001278 | 0x3798 | 0x2b98 | 0xd |
??1DSTRING@@UEAA@XZ | 0x0 | 0x100001280 | 0x37a0 | 0x2ba0 | 0x35 |
??0PATH@@QEAA@XZ | 0x0 | 0x100001288 | 0x37a8 | 0x2ba8 | 0x1f |
??1PATH@@UEAA@XZ | 0x0 | 0x100001290 | 0x37b0 | 0x2bb0 | 0x41 |
?AnalyzePath@PATH@@QEAA?AW4PATH_ANALYZE_CODE@@PEAVWSTRING@@PEAV1@0@Z | 0x0 | 0x100001298 | 0x37b8 | 0x2bb8 | 0x65 |
??1OBJECT@@UEAA@XZ | 0x0 | 0x1000012a0 | 0x37c0 | 0x2bc0 | 0x40 |
?Compare@OBJECT@@UEBAJPEBV1@@Z | 0x0 | 0x1000012a8 | 0x37c8 | 0x2bc8 | 0x70 |
??0CLASS_DESCRIPTOR@@QEAA@XZ | 0x0 | 0x1000012b0 | 0x37d0 | 0x2bd0 | 0x9 |
?Fatal@PROGRAM@@UEBAXXZ | 0x0 | 0x1000012b8 | 0x37d8 | 0x2bd8 | 0x9a |
?GetStandardInput@PROGRAM@@UEAAPEAVSTREAM@@XZ | 0x0 | 0x1000012c0 | 0x37e0 | 0x2be0 | 0xad |
?GetStandardOutput@PROGRAM@@UEAAPEAVSTREAM@@XZ | 0x0 | 0x1000012c8 | 0x37e8 | 0x2be8 | 0xae |
?GetStandardError@PROGRAM@@UEAAPEAVSTREAM@@XZ | 0x0 | 0x1000012d0 | 0x37f0 | 0x2bf0 | 0xac |
?Usage@PROGRAM@@UEBAXXZ | 0x0 | 0x1000012d8 | 0x37f8 | 0x2bf8 | 0x1a9 |
?Initialize@CLASS_DESCRIPTOR@@QEAAEXZ | 0x0 | 0x1000012e0 | 0x3800 | 0x2c00 | 0xbc |
??0ARGUMENT_LEXEMIZER@@QEAA@XZ | 0x0 | 0x1000012e8 | 0x3808 | 0x2c08 | 0x0 |
??1ARGUMENT_LEXEMIZER@@UEAA@XZ | 0x0 | 0x1000012f0 | 0x3810 | 0x2c10 | 0x2d |
?Initialize@ARGUMENT_LEXEMIZER@@QEAAEPEAVARRAY@@@Z | 0x0 | 0x1000012f8 | 0x3818 | 0x2c18 | 0xb5 |
?DoParsing@ARGUMENT_LEXEMIZER@@QEAAEPEAVARRAY@@@Z | 0x0 | 0x100001300 | 0x3820 | 0x2c20 | 0x8f |
?PutSeparators@ARGUMENT_LEXEMIZER@@QEAAXPEBD@Z | 0x0 | 0x100001308 | 0x3828 | 0x2c28 | 0x10c |
?PutSwitches@ARGUMENT_LEXEMIZER@@QEAAXPEBD@Z | 0x0 | 0x100001310 | 0x3830 | 0x2c30 | 0x110 |
?PrepareToParse@ARGUMENT_LEXEMIZER@@QEAAEPEAVWSTRING@@@Z | 0x0 | 0x100001318 | 0x3838 | 0x2c38 | 0x106 |
?SetCaseSensitive@ARGUMENT_LEXEMIZER@@QEAAXE@Z | 0x0 | 0x100001320 | 0x3840 | 0x2c40 | 0x163 |
??0MULTIPLE_PATH_ARGUMENT@@QEAA@XZ | 0x0 | 0x100001328 | 0x3848 | 0x2c48 | 0x1c |
?Fatal@PROGRAM@@UEBAXKKPEADZZ | 0x0 | 0x100001330 | 0x3850 | 0x2c50 | 0x99 |
ifsutil.dll (17)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
?QueryFileSystemName@IFS_SYSTEM@@SAEPEBVWSTRING@@PEAV2@PEAJ1@Z | 0x0 | 0x100001070 | 0x3590 | 0x2990 | 0xaa |
??1DP_DRIVE@@UEAA@XZ | 0x0 | 0x100001078 | 0x3598 | 0x2998 | 0x1b |
??0DP_DRIVE@@QEAA@XZ | 0x0 | 0x100001080 | 0x35a0 | 0x29a0 | 0x4 |
?SetAutochkTimeOut@VOL_LIODPDRV@@SAEK@Z | 0x0 | 0x100001088 | 0x35a8 | 0x29a8 | 0xf2 |
?QueryAutochkTimeOut@VOL_LIODPDRV@@SAEPEAK@Z | 0x0 | 0x100001090 | 0x35b0 | 0x29b0 | 0x9c |
?Initialize@MOUNT_POINT_MAP@@QEAAEXZ | 0x0 | 0x100001098 | 0x35b8 | 0x29b8 | 0x76 |
??1MOUNT_POINT_MAP@@UEAA@XZ | 0x0 | 0x1000010a0 | 0x35c0 | 0x29c0 | 0x1e |
??0MOUNT_POINT_MAP@@QEAA@XZ | 0x0 | 0x1000010a8 | 0x35c8 | 0x29c8 | 0x8 |
??0MOUNT_POINT_TUPLE@@QEAA@XZ | 0x0 | 0x1000010b0 | 0x35d0 | 0x29d0 | 0x9 |
?IsFrontEndPresent@AUTOREG@@SAEPEBVWSTRING@@0@Z | 0x0 | 0x1000010b8 | 0x35d8 | 0x29d8 | 0x8d |
?DeleteEntry@AUTOREG@@SAEPEBVWSTRING@@E@Z | 0x0 | 0x1000010c0 | 0x35e0 | 0x29e0 | 0x40 |
?DeleteEntry@AUTOREG@@SAEPEBVWSTRING@@0@Z | 0x0 | 0x1000010c8 | 0x35e8 | 0x29e8 | 0x3f |
?PushEntry@AUTOREG@@SAEPEBVWSTRING@@@Z | 0x0 | 0x1000010d0 | 0x35f0 | 0x29f0 | 0x9b |
?AddEntry@AUTOREG@@SAEPEBVWSTRING@@@Z | 0x0 | 0x1000010d8 | 0x35f8 | 0x29f8 | 0x2d |
?IsVolumeDirty@IFS_SYSTEM@@SAEPEAVWSTRING@@PEAE1PEAJ@Z | 0x0 | 0x1000010e0 | 0x3600 | 0x2a00 | 0x91 |
?DosDriveNameToNtDriveName@IFS_SYSTEM@@SAEPEBVWSTRING@@PEAV2@@Z | 0x0 | 0x1000010e8 | 0x3608 | 0x2a08 | 0x45 |
?Initialize@DP_DRIVE@@QEAAEPEBVWSTRING@@PEAVMESSAGE@@EEG@Z | 0x0 | 0x1000010f0 | 0x3610 | 0x2a10 | 0x6f |
ntdll.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlLookupFunctionEntry | 0x0 | 0x100001170 | 0x3690 | 0x2a90 | 0x401 |
RtlVirtualUnwind | 0x0 | 0x100001178 | 0x3698 | 0x2a98 | 0x4f0 |
RtlAllocateHeap | 0x0 | 0x100001180 | 0x36a0 | 0x2aa0 | 0x265 |
RtlFreeHeap | 0x0 | 0x100001188 | 0x36a8 | 0x2aa8 | 0x34a |
RtlCaptureContext | 0x0 | 0x100001190 | 0x36b0 | 0x2ab0 | 0x27b |
C:\Windows\System32\svchost.exe_ | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2012-10-01 02:48 (UTC+2) |
Last Seen | 2019-11-01 12:25 (UTC+1) |
PE Information
»
Image Base | 0x100000000 |
Entry Point | 0x10000246c |
Size Of Code | 0x3200 |
Size Of Initialized Data | 0x3400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2009-07-13 23:31:13+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Host Process for Windows Services |
FileVersion | 6.1.7600.16385 (win7_rtm.090713-1255) |
InternalName | svchost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | svchost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7600.16385 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x100001000 | 0x30a0 | 0x3200 | 0x600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.05 |
.rdata | 0x100005000 | 0x17f4 | 0x1800 | 0x3800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.94 |
.data | 0x100007000 | 0xaa0 | 0xa00 | 0x5000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.56 |
.pdata | 0x100008000 | 0x3fc | 0x400 | 0x5a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.3 |
.rsrc | 0x100009000 | 0x818 | 0xa00 | 0x5e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.77 |
.reloc | 0x10000a000 | 0x54 | 0x200 | 0x6800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.11 |
Imports (8)
»
msvcrt.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
memcpy | 0x0 | 0x100005000 | 0x59d0 | 0x41d0 | 0x480 |
?terminate@@YAXXZ | 0x0 | 0x100005008 | 0x59d8 | 0x41d8 | 0x30 |
__set_app_type | 0x0 | 0x100005010 | 0x59e0 | 0x41e0 | 0x80 |
_fmode | 0x0 | 0x100005018 | 0x59e8 | 0x41e8 | 0x118 |
_commode | 0x0 | 0x100005020 | 0x59f0 | 0x41f0 | 0xc4 |
__setusermatherr | 0x0 | 0x100005028 | 0x59f8 | 0x41f8 | 0x82 |
_amsg_exit | 0x0 | 0x100005030 | 0x5a00 | 0x4200 | 0xa0 |
_initterm | 0x0 | 0x100005038 | 0x5a08 | 0x4208 | 0x16c |
exit | 0x0 | 0x100005040 | 0x5a10 | 0x4210 | 0x420 |
_cexit | 0x0 | 0x100005048 | 0x5a18 | 0x4218 | 0xb3 |
_exit | 0x0 | 0x100005050 | 0x5a20 | 0x4220 | 0xff |
_XcptFilter | 0x0 | 0x100005058 | 0x5a28 | 0x4228 | 0x52 |
__C_specific_handler | 0x0 | 0x100005060 | 0x5a30 | 0x4230 | 0x53 |
__wgetmainargs | 0x0 | 0x100005068 | 0x5a38 | 0x4238 | 0x8f |
memset | 0x0 | 0x100005070 | 0x5a40 | 0x4240 | 0x484 |
ntdll.dll (17)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlSubAuthoritySid | 0x0 | 0x100005080 | 0x5a50 | 0x4250 | 0x4ab |
RtlLengthRequiredSid | 0x0 | 0x100005088 | 0x5a58 | 0x4258 | 0x3eb |
RtlFreeHeap | 0x0 | 0x100005090 | 0x5a60 | 0x4260 | 0x34a |
RtlCopySid | 0x0 | 0x100005098 | 0x5a68 | 0x4268 | 0x2a7 |
RtlAllocateHeap | 0x0 | 0x1000050a0 | 0x5a70 | 0x4270 | 0x265 |
RtlInitializeSid | 0x0 | 0x1000050a8 | 0x5a78 | 0x4278 | 0x3b5 |
RtlSubAuthorityCountSid | 0x0 | 0x1000050b0 | 0x5a80 | 0x4280 | 0x4aa |
EtwEventWrite | 0x0 | 0x1000050b8 | 0x5a88 | 0x4288 | 0x39 |
RtlImageNtHeader | 0x0 | 0x1000050c0 | 0x5a90 | 0x4290 | 0x393 |
EtwEventRegister | 0x0 | 0x1000050c8 | 0x5a98 | 0x4298 | 0x37 |
RtlUnhandledExceptionFilter | 0x0 | 0x1000050d0 | 0x5aa0 | 0x42a0 | 0x4c3 |
EtwEventEnabled | 0x0 | 0x1000050d8 | 0x5aa8 | 0x42a8 | 0x35 |
RtlSetProcessIsCritical | 0x0 | 0x1000050e0 | 0x5ab0 | 0x42b0 | 0x48e |
RtlCaptureContext | 0x0 | 0x1000050e8 | 0x5ab8 | 0x42b8 | 0x27b |
RtlLookupFunctionEntry | 0x0 | 0x1000050f0 | 0x5ac0 | 0x42c0 | 0x401 |
RtlVirtualUnwind | 0x0 | 0x1000050f8 | 0x5ac8 | 0x42c8 | 0x4f0 |
RtlInitializeCriticalSection | 0x0 | 0x100005100 | 0x5ad0 | 0x42d0 | 0x3a9 |
API-MS-Win-Core-ProcessThreads-L1-1-0.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCurrentProcessId | 0x0 | 0x100005110 | 0x5ae0 | 0x42e0 | 0xb |
TerminateProcess | 0x0 | 0x100005118 | 0x5ae8 | 0x42e8 | 0x2a |
GetCurrentProcess | 0x0 | 0x100005120 | 0x5af0 | 0x42f0 | 0xa |
OpenProcessToken | 0x0 | 0x100005128 | 0x5af8 | 0x42f8 | 0x1a |
GetCurrentThreadId | 0x0 | 0x100005130 | 0x5b00 | 0x4300 | 0xd |
KERNEL32.dll (42)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalAlloc | 0x0 | 0x100005140 | 0x5b10 | 0x4310 | 0x345 |
CloseHandle | 0x0 | 0x100005148 | 0x5b18 | 0x4318 | 0x52 |
LocalFree | 0x0 | 0x100005150 | 0x5b20 | 0x4320 | 0x349 |
ExpandEnvironmentStringsW | 0x0 | 0x100005158 | 0x5b28 | 0x4328 | 0x122 |
WideCharToMultiByte | 0x0 | 0x100005160 | 0x5b30 | 0x4330 | 0x51c |
FreeLibrary | 0x0 | 0x100005168 | 0x5b38 | 0x4338 | 0x167 |
GetLastError | 0x0 | 0x100005170 | 0x5b40 | 0x4340 | 0x207 |
GetProcAddress | 0x0 | 0x100005178 | 0x5b48 | 0x4348 | 0x24b |
LoadLibraryExA | 0x0 | 0x100005180 | 0x5b50 | 0x4350 | 0x33e |
DelayLoadFailureHook | 0x0 | 0x100005188 | 0x5b58 | 0x4358 | 0xce |
Sleep | 0x0 | 0x100005190 | 0x5b60 | 0x4360 | 0x4bc |
SetUnhandledExceptionFilter | 0x0 | 0x100005198 | 0x5b68 | 0x4368 | 0x4af |
GetModuleHandleW | 0x0 | 0x1000051a0 | 0x5b70 | 0x4370 | 0x21d |
QueryPerformanceCounter | 0x0 | 0x1000051a8 | 0x5b78 | 0x4378 | 0x3a6 |
GetTickCount | 0x0 | 0x1000051b0 | 0x5b80 | 0x4380 | 0x299 |
GetSystemTimeAsFileTime | 0x0 | 0x1000051b8 | 0x5b88 | 0x4388 | 0x27f |
UnhandledExceptionFilter | 0x0 | 0x1000051c0 | 0x5b90 | 0x4390 | 0x4de |
ExitProcess | 0x0 | 0x1000051c8 | 0x5b98 | 0x4398 | 0x11e |
GetCommandLineW | 0x0 | 0x1000051d0 | 0x5ba0 | 0x43a0 | 0x18c |
SetErrorMode | 0x0 | 0x1000051d8 | 0x5ba8 | 0x43a8 | 0x463 |
LoadLibraryExW | 0x0 | 0x1000051e0 | 0x5bb0 | 0x43b0 | 0x33f |
GetProcessHeap | 0x0 | 0x1000051e8 | 0x5bb8 | 0x43b8 | 0x250 |
CreateActCtxW | 0x0 | 0x1000051f0 | 0x5bc0 | 0x43c0 | 0x78 |
InitializeCriticalSection | 0x0 | 0x1000051f8 | 0x5bc8 | 0x43c8 | 0x2e9 |
ActivateActCtx | 0x0 | 0x100005200 | 0x5bd0 | 0x43d0 | 0x2 |
RegQueryValueExW | 0x0 | 0x100005208 | 0x5bd8 | 0x43d8 | 0x3e5 |
LeaveCriticalSection | 0x0 | 0x100005210 | 0x5be0 | 0x43e0 | 0x33a |
lstrcmpW | 0x0 | 0x100005218 | 0x5be8 | 0x43e8 | 0x551 |
lstrlenW | 0x0 | 0x100005220 | 0x5bf0 | 0x43f0 | 0x55d |
DeactivateActCtx | 0x0 | 0x100005228 | 0x5bf8 | 0x43f8 | 0xc4 |
ReleaseActCtx | 0x0 | 0x100005230 | 0x5c00 | 0x4400 | 0x3f9 |
EnterCriticalSection | 0x0 | 0x100005238 | 0x5c08 | 0x4408 | 0xf1 |
SetProcessAffinityUpdateMode | 0x0 | 0x100005240 | 0x5c10 | 0x4410 | 0x489 |
RegisterWaitForSingleObjectEx | 0x0 | 0x100005248 | 0x5c18 | 0x4418 | 0x3f6 |
RegOpenKeyExW | 0x0 | 0x100005250 | 0x5c20 | 0x4420 | 0x3e0 |
lstrcmpiW | 0x0 | 0x100005258 | 0x5c28 | 0x4428 | 0x554 |
HeapSetInformation | 0x0 | 0x100005260 | 0x5c30 | 0x4430 | 0x2da |
RegDisablePredefinedCacheEx | 0x0 | 0x100005268 | 0x5c38 | 0x4438 | 0x3ce |
RegCloseKey | 0x0 | 0x100005270 | 0x5c40 | 0x4440 | 0x3c5 |
LCMapStringW | 0x0 | 0x100005278 | 0x5c48 | 0x4448 | 0x32e |
HeapFree | 0x0 | 0x100005280 | 0x5c50 | 0x4450 | 0x2d6 |
HeapAlloc | 0x0 | 0x100005288 | 0x5c58 | 0x4458 | 0x2d2 |
API-MS-Win-Security-Base-L1-1-0.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetSecurityDescriptorDacl | 0x0 | 0x100005298 | 0x5c68 | 0x4468 | 0x5b |
InitializeSecurityDescriptor | 0x0 | 0x1000052a0 | 0x5c70 | 0x4470 | 0x40 |
GetTokenInformation | 0x0 | 0x1000052a8 | 0x5c78 | 0x4478 | 0x3a |
SetSecurityDescriptorGroup | 0x0 | 0x1000052b0 | 0x5c80 | 0x4480 | 0x5c |
SetSecurityDescriptorOwner | 0x0 | 0x1000052b8 | 0x5c88 | 0x4488 | 0x5d |
AddAccessAllowedAce | 0x0 | 0x1000052c0 | 0x5c90 | 0x4490 | 0x7 |
GetLengthSid | 0x0 | 0x1000052c8 | 0x5c98 | 0x4498 | 0x2d |
InitializeAcl | 0x0 | 0x1000052d0 | 0x5ca0 | 0x44a0 | 0x3f |
API-MS-WIN-Service-Core-L1-1-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetServiceStatus | 0x0 | 0x1000052e0 | 0x5cb0 | 0x44b0 | 0x1 |
StartServiceCtrlDispatcherW | 0x0 | 0x1000052e8 | 0x5cb8 | 0x44b8 | 0x2 |
API-MS-WIN-Service-winsvc-L1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegisterServiceCtrlHandlerW | 0x0 | 0x1000052f8 | 0x5cc8 | 0x44c8 | 0x17 |
RPCRT4.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RpcServerUnregisterIf | 0x0 | 0x100005308 | 0x5cd8 | 0x44d8 | 0x1ca |
RpcServerUseProtseqEpW | 0x0 | 0x100005310 | 0x5ce0 | 0x44e0 | 0x1d5 |
I_RpcMapWin32Status | 0x0 | 0x100005318 | 0x5ce8 | 0x44e8 | 0x3d |
RpcMgmtSetServerStackSize | 0x0 | 0x100005320 | 0x5cf0 | 0x44f0 | 0x1a8 |
RpcServerRegisterIf | 0x0 | 0x100005328 | 0x5cf8 | 0x44f8 | 0x1c5 |
RpcMgmtStopServerListening | 0x0 | 0x100005330 | 0x5d00 | 0x4500 | 0x1aa |
RpcMgmtWaitServerListen | 0x0 | 0x100005338 | 0x5d08 | 0x4508 | 0x1ab |
RpcServerListen | 0x0 | 0x100005340 | 0x5d10 | 0x4510 | 0x1c2 |
RpcServerUnregisterIfEx | 0x0 | 0x100005348 | 0x5d18 | 0x4518 | 0x1cb |
C:\Boot\cs-CZ\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\da-DK\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\fr-FR\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\hu-HU\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\nb-NO\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\pt-BR\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\zh-HK\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\GDIPFONTCACHEV1.DAT.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\UserCache.bin.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\ACECache11.lst.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\Profiles\wscRGB.icc.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\goog...app_baa8013a79450f71_0001.0003_290679d077f4cfec\clickonce_bootstrap.exe.cdf-ms.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\goog...app_baa8013a79450f71_0001.0003_290679d077f4cfec\clickonce_bootstrap.exe.manifest.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\manifests\goog...app_baa8013a79450f71_0001.0003_none_677c9e37069a7e2a.cdf-ms.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\manifests\goog...app_baa8013a79450f71_0001.0003_none_677c9e37069a7e2a.manifest.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Local State.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Current Tabs.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Favicons.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\History Provider Cache.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Network Action Predictor.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Network Persistent State.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\previews_opt_out.db.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\QuotaManager.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\README.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Secure Preferences.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Shortcuts.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Top Sites.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\TransportSecurity.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Visited Links.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Web Data.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Cache\data_0.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Cache\data_3.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000001.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extension Rules\000003.log.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extension Rules\CURRENT.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extension Rules\MANIFEST-000001.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extension State\000003.log.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extension State\CURRENT.locked | Dropped File | Binary |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extension State\LOG.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_128.png.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_16.png.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\main.html.locked | Dropped File | Text |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ar\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\cs\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\da\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\el\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\en_GB\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\en_US\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\es_419\messages.json.locked | Modified File | Binary |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\et\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fil\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fr\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\hi\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\id\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ko\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ms\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\no\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pt_BR\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pt_PT\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ru\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sv\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\uk\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\zh_TW\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_metadata\verified_contents.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_128.png.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.html.locked | Dropped File | Text |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\manifest.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\bg\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\cs\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\el\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_GB\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es_419\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fi\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fil\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fr\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hi\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hu\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\id\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\it\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ja\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ko\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lv\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ms\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\no\messages.json.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_BR\messages.json.locked | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\Ib8880.tmp | Dropped File | Text |
Unknown
|
...
|
»
C:\Boot\da-DK\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Boot\en-US\memtest.exe.mui.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Boot\fi-FI\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Boot\hu-HU\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Boot\pt-BR\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Boot\zh-HK\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\gdipfontcachev1.dat.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\iconcache.db.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\adobe\acrobat\10.0\cache\acrofnt10.lst.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\adobe\color\acecache11.lst.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\adobe\color\profiles\wscrgb.icc.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\apps\2.0\dqq19bcj.jax\yvorlgor.pnt\goog...app_baa8013a79450f71_0001.0003_290679d077f4cfec\clickonce_bootstrap.exe.cdf-ms.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\apps\2.0\dqq19bcj.jax\yvorlgor.pnt\goog...app_baa8013a79450f71_0001.0003_290679d077f4cfec\clickonce_bootstrap_unsigned.manifest.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\apps\2.0\dqq19bcj.jax\yvorlgor.pnt\manifests\clic...exe_baa8013a79450f71_0001.0003_none_855491bb37a51715.manifest.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\apps\2.0\dqq19bcj.jax\yvorlgor.pnt\manifests\goog...app_baa8013a79450f71_0001.0003_none_677c9e37069a7e2a.manifest.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\crashpad\settings.dat.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\favicons.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\network action predictor.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\secure preferences.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\data_reduction_proxy_leveldb\manifest-000001.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extension state\current.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extension state\log.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extension state\manifest-000001.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\da\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\en_us\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\es_419\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fr\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ms\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pl\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sr\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\th\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\tr\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\uk\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\vi\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_metadata\computed_hashes.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.js.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ca\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\cs\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\da\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\de\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fi\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fil\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fr\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\he\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hi\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ko\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lt\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\no\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_br\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_pt\messages.json.readme2unlock.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Boot\de-DE\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\el-GR\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
C:\Boot\en-US\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
C:\Boot\en-US\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\ja-JP\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
C:\Boot\ko-KR\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\nl-NL\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pl-PL\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
C:\Boot\ru-RU\bootmgr.exe.mui | Modified File | Compressed |
Not Queried
|
...
|
»
C:\Boot\zh-TW\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\IconCache.db.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\AdobeCMapFnt10.lst.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\AdobeSysFnt10.lst.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\SharedDataEvents.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\Cache\AcroFnt10.lst.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\Profiles\wsRGB.icc.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\goog...app_baa8013a79450f71_0001.0003_290679d077f4cfec\clickonce_bootstrap_unsigned.cdf-ms.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\goog...app_baa8013a79450f71_0001.0003_290679d077f4cfec\clickonce_bootstrap_unsigned.manifest.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\manifests\clic...exe_baa8013a79450f71_0001.0003_none_855491bb37a51715.cdf-ms.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\manifests\clic...exe_baa8013a79450f71_0001.0003_none_855491bb37a51715.manifest.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Safe Browsing Channel IDs.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Safe Browsing Cookies.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Crashpad\settings.dat.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Cookies.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Current Session.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\History.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Login Data.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Origin Bound Certs.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Preferences.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Cache\data_1.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Cache\data_2.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Cache\index.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extension Rules\LOG.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extension State\MANIFEST-000001.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\manifest.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\bg\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ca\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\de\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\es\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fi\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\he\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\hu\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\it\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ja\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\lt\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\lv\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\nl\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pl\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ro\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sk\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sl\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sr\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\th\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\tr\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\vi\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\zh_CN\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_metadata\computed_hashes.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_16.png.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ar\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ca\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\da\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\de\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_US\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\et\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\he\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lt\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\nl\messages.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pl\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_PT\messages.json.locked | Modified File | Stream |
Not Queried
|
...
|
»
C:\Boot\cs-CZ\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\de-DE\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\el-GR\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\en-US\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\es-ES\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\fr-FR\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\it-IT\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\ja-JP\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\ko-KR\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\nb-NO\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\nl-NL\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\pl-PL\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\pt-PT\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\ru-RU\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\sv-SE\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\tr-TR\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\zh-CN\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Boot\zh-TW\bootmgr.exe.mui.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\adobe\acrobat\10.0\adobecmapfnt10.lst.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\adobe\acrobat\10.0\adobesysfnt10.lst.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\adobe\acrobat\10.0\shareddataevents.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\adobe\acrobat\10.0\usercache.bin.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\adobe\color\profiles\wsrgb.icc.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\apps\2.0\dqq19bcj.jax\yvorlgor.pnt\goog...app_baa8013a79450f71_0001.0003_290679d077f4cfec\clickonce_bootstrap.exe.manifest.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\apps\2.0\dqq19bcj.jax\yvorlgor.pnt\goog...app_baa8013a79450f71_0001.0003_290679d077f4cfec\clickonce_bootstrap_unsigned.cdf-ms.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\apps\2.0\dqq19bcj.jax\yvorlgor.pnt\manifests\clic...exe_baa8013a79450f71_0001.0003_none_855491bb37a51715.cdf-ms.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\apps\2.0\dqq19bcj.jax\yvorlgor.pnt\manifests\goog...app_baa8013a79450f71_0001.0003_none_677c9e37069a7e2a.cdf-ms.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\local state.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\safe browsing channel ids.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\safe browsing cookies.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\cookies.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\current session.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\current tabs.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\history.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\history provider cache.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\login data.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\network persistent state.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\origin bound certs.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\preferences.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\previews_opt_out.db.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\quotamanager.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\readme.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\shortcuts.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\top sites.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\transportsecurity.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\visited links.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\web data.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\cache\data_0.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\cache\data_1.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\cache\data_2.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\cache\data_3.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\cache\index.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\data_reduction_proxy_leveldb\current.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\data_reduction_proxy_leveldb\log.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extension rules\000003.log.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extension rules\current.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extension rules\log.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extension rules\manifest-000001.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extension state\000003.log.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_128.png.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_16.png.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\main.html.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\main.js.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\manifest.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ar\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\bg\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ca\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\cs\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\de\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\el\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\en_gb\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\es\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\et\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fi\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fil\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\he\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\hi\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\hu\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\id\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\it\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ja\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ko\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\lt\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\lv\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\nl\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\no\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pt_br\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pt_pt\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ro\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ru\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sk\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sl\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sv\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\zh_cn\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\zh_tw\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_metadata\verified_contents.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_128.png.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_16.png.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.html.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\manifest.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ar\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\bg\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\el\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_gb\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_us\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es_419\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\et\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hu\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\id\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\it\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ja\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lv\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ms\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\nl\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pl\messages.json.readme2unlock.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Windows\TEMP\0nQ9D0A.tmp | Dropped File | Unknown |
Not Queried
|
...
|
»