42dc69a5...226b | Grouped Behavior
Try VMRay Analyzer
VTI SCORE: 93/100
Dynamic Analysis Report
Classification: Ransomware, Wiper, Trojan, Dropper

Monitored Processes

Process Overview
»
ID PID Monitor Reason Integrity Level Image Name Command Line Origin ID
#1 0xe64 Analysis Target High (Elevated) unnam3d - ransm.exe "C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe" -
#3 0xf00 Child Process High (Elevated) cmd.exe "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Desktop && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Desktop * #1
#4 0x46c Child Process High (Elevated) cmd.exe "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Documents && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Documents * #1
#6 0xa9c Child Process High (Elevated) cmd.exe "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Pictures && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Pictures * #1
#9 0xe3c Child Process High (Elevated) winrar.exe C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Desktop * #3
#10 0xf64 Child Process High (Elevated) winrar.exe C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Documents * #4
#11 0x754 Child Process High (Elevated) winrar.exe C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Pictures * #6

Behavior Information - Grouped by Category

Process #1: unnam3d - ransm.exe
421 0
»
Information Value
ID #1
File Name c:\users\fd1hvy\desktop\unnam3d - ransm.exe
Command Line "C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe"
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:25, Reason: Analysis Target
Unmonitor End Time: 00:04:33, Reason: Terminated by Timeout
Monitor Duration 00:04:07
OS Process Information
»
Information Value
PID 0xe64
Parent PID 0x860 (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x EB4
0x 4F0
0x 60
0x B6C
0x F50
0x BEC
0x 490
0x 260
0x 8F0
0x 1A4
0x 2D0
0x 3CC
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points YARA Actions
clrjit.dll 0x74330000 0x743AFFFF Marked Writable - 32-bit - False
buffer 0x049D0000 0x049D0FFF First Execution - 32-bit 0x049D0000 False
clrjit.dll 0x74330000 0x743AFFFF Content Changed - 32-bit 0x7439A2A6, 0x74369E12 False
clrjit.dll 0x74330000 0x743AFFFF Content Changed - 32-bit 0x74391000 False
buffer 0x06567000 0x06567FFF First Execution - 32-bit 0x06567000 False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe 2.17 MB MD5: 1e3a2a966f593ad33125f26916267008
SHA1: 38b1a547ddee671edeee7385cac138458a6a6858
SHA256: b18c9b9200e354f81882b29dc8143ec5d6f2b731cf4c7da3800e339ffb3c8827
SSDeep: 49152:m2IoCBtJnxlyU/mWhRcQYhie6/UIdjjQuctXnFDu3nAzNjteyUHBdH3y2:xrCBrtcy/lfkD0nANte9BpC2
False
c:\users\fd1hvy\appdata\local\temp\wallpaper.png 679.01 KB MD5: 4eaf9cbc1438214622460aa18fbf050d
SHA1: 543c921d0f75bb5a8a9cd1bf1096d2d0af69170e
SHA256: a935f1af2674e6577a02f7b2f53ad98612fd55dd2f3f51cb476767c01f4076e8
SSDeep: 12288:whHUpY2wdt2pD5969U59o6xM4T1GFg6qaUlZCZSjX4lZuuS+L+26TCNYBuGAR:va2K2pD596mzosrGFg6qao0SjXGuu/+S
False
Host Behavior
File (30)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll type = file_attributes True 1
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config type = file_attributes True 2
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config type = file_type True 2
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe.config type = file_attributes False 3
Fn
Get Info C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe type = file_type True 2
Fn
Get Info C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe type = file_type True 2
Fn
Read C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config size = 4096, size_out = 4096 True 8
Fn
Data
Read C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config size = 4096, size_out = 3215 True 1
Fn
Data
Read C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config size = 4096, size_out = 0 True 1
Fn
Read C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe size = 2876416, size_out = 2876416 True 1
Fn
Write C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe size = 2276568 True 1
Fn
Registry (6)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AppContext - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\XML - False 1
Fn
Open Key HKEY_CURRENT_USER\SOFTWARE\Microsoft\.NETFramework\XML - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework value_name = DbgJITDebugLaunchSetting, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework value_name = DbgManagedDebugger, type = REG_NONE False 1
Fn
Process (3)
»
Operation Process Additional Information Success Count Logfile
Create cmd.exe show_window = SW_HIDE True 1
Fn
Create cmd.exe show_window = SW_HIDE True 1
Fn
Create cmd.exe show_window = SW_HIDE True 1
Fn
Module (159)
»
Operation Module Additional Information Success Count Logfile
Load mscorjit.dll base_address = 0x0 False 1
Fn
Load clrjit.dll base_address = 0x74330000 True 1
Fn
Load comctl32.dll base_address = 0x742a0000 True 1
Fn
Load comctl32.dll base_address = 0x6fbc0000 True 1
Fn
Get Handle comctl32.dll base_address = 0x0 False 2
Fn
Get Handle c:\windows\syswow64\user32.dll base_address = 0x74b70000 True 1
Fn
Get Handle c:\users\fd1hvy\desktop\unnam3d - ransm.exe base_address = 0xd0000 True 14
Fn
Get Handle c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.413_none_55bc94a37c2a2854\comctl32.dll base_address = 0x742a0000 True 58
Fn
Get Handle c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll base_address = 0x6fbc0000 True 10
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\ntdll.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSCOREE.DLL, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\KERNEL32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\KERNELBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\apphelp.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ADVAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\msvcrt.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\sechost.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\RPCRT4.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\SspiCli.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\CRYPTBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\bcryptPrimitives.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\SHLWAPI.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\combase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ucrtbase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\GDI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\gdi32full.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\msvcp_win.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\USER32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\win32u.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\IMM32.DLL, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\kernel.appcore.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\VERSION.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSVCR120_CLR0400.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\f12799647dc4f4abd2f0f17790337f04\mscorlib.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ole32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\system32\uxtheme.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\OLEAUT32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\fcfb8bac8ea9a0e69d72c350b22f8e3f\System.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\psapi.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\ntdll.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSCOREE.DLL, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\KERNEL32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\KERNELBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\apphelp.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ADVAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\msvcrt.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\sechost.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\RPCRT4.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\SspiCli.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\CRYPTBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\bcryptPrimitives.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\SHLWAPI.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\combase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ucrtbase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\GDI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\gdi32full.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\msvcp_win.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\USER32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\win32u.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\IMM32.DLL, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\kernel.appcore.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\VERSION.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSVCR120_CLR0400.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\f12799647dc4f4abd2f0f17790337f04\mscorlib.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ole32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\system32\uxtheme.dll, size = 2048 True 1
Fn
Get Filename c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\OLEAUT32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\fcfb8bac8ea9a0e69d72c350b22f8e3f\System.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\psapi.dll, size = 2048 True 1
Fn
Get Address c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll function = getJit, address_out = 0x74383d60 True 1
Fn
Get Address c:\windows\syswow64\user32.dll function = DefWindowProcW, address_out = 0x74600140 True 1
Fn
User (1)
»
Operation Additional Information Success Count Logfile
Lookup Privilege privilege = SeDebugPrivilege, luid = 20 True 1
Fn
Window (42)
»
Operation Window Name Additional Information Success Count Logfile
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Create .NET-BroadcastEventWindow.4.0.0.0.141b42a.0 class_name = .NET-BroadcastEventWindow.4.0.0.0.141b42a.0, wndproc_parameter = 0 True 1
Fn
Create UNNAM3D - R@NSOMEWARE! class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Create Discord: UNNAM3D#6666 class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Create You will need to send an message to the below discord with a $50 amazon giftcard code. Then you will shortley get an message back with a password to unlock your files. class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Create All your personal files have been locked and you need to pay a ransom to get them back. You will have 24 hours to pay or the password will be deleted of our servers making it impossible to get your files back. class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Create How do i pay? class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Create What Happend? class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Create -YOUR FILES HAVE BEEN LOCKED- class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 78513854 True 1
Fn
Set Attribute UNNAM3D - R@NSOMEWARE! class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute UNNAM3D - R@NSOMEWARE! class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 78514702 True 1
Fn
Set Attribute UNNAM3D - R@NSOMEWARE! class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -8, new_long = 0 False 1
Fn
Set Attribute UNNAM3D - R@NSOMEWARE! class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -16, new_long = 46858240 True 1
Fn
Set Attribute UNNAM3D - R@NSOMEWARE! class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -20, new_long = 327681 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 78514742 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -12, new_long = 393334 False 1
Fn
Set Attribute Discord: UNNAM3D#6666 class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Set Attribute Discord: UNNAM3D#6666 class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78514822 True 1
Fn
Set Attribute Discord: UNNAM3D#6666 class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 458798 False 1
Fn
Set Attribute You will need to send an message to the below discord with a $50 amazon giftcard code. Then you will shortley get an message back with a password to unlock your files. class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Set Attribute You will need to send an message to the below discord with a $50 amazon giftcard code. Then you will shortley get an message back with a password to unlock your files. class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78514862 True 1
Fn
Set Attribute You will need to send an message to the below discord with a $50 amazon giftcard code. Then you will shortley get an message back with a password to unlock your files. class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 131612 False 1
Fn
Set Attribute All your personal files have been locked and you need to pay a ransom to get them back. You will have 24 hours to pay or the password will be deleted of our servers making it impossible to get your files back. class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Set Attribute All your personal files have been locked and you need to pay a ransom to get them back. You will have 24 hours to pay or the password will be deleted of our servers making it impossible to get your files back. class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78514902 True 1
Fn
Set Attribute All your personal files have been locked and you need to pay a ransom to get them back. You will have 24 hours to pay or the password will be deleted of our servers making it impossible to get your files back. class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 589846 False 1
Fn
Set Attribute How do i pay? class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Set Attribute How do i pay? class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78514942 True 1
Fn
Set Attribute How do i pay? class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 393750 False 1
Fn
Set Attribute What Happend? class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Set Attribute What Happend? class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78514982 True 1
Fn
Set Attribute What Happend? class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 131616 False 1
Fn
Set Attribute -YOUR FILES HAVE BEEN LOCKED- class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Set Attribute -YOUR FILES HAVE BEEN LOCKED- class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78515022 True 1
Fn
Set Attribute -YOUR FILES HAVE BEEN LOCKED- class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 328216 False 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 78515062 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -12, new_long = 197146 False 1
Fn
System (153)
»
Operation Additional Information Success Count Logfile
Create Desktop desktop_name = MeinTestDesktop True 1
Fn
Switch Desktop desktop_name = MeinTestDesktop True 1
Fn
Get Cursor x_out = 44, y_out = 346 True 4
Fn
Sleep duration = 3000 milliseconds (3.000 seconds) True 72
Fn
Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
Get Info type = SYSTEM_PROCESS_INFORMATION True 73
Fn
Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
Process #3: cmd.exe
57 0
»
Information Value
ID #3
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Desktop && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Desktop *
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:53, Reason: Child Process
Unmonitor End Time: 00:04:33, Reason: Terminated by Timeout
Monitor Duration 00:03:40
OS Process Information
»
Information Value
PID 0xf00
Parent PID 0xe64 (c:\users\fd1hvy\desktop\unnam3d - ransm.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 384
0x 36C
Host Behavior
File (13)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Users\FD1HVy\Desktop type = file_attributes True 4
Fn
Open STD_OUTPUT_HANDLE - True 5
Fn
Open STD_INPUT_HANDLE - True 4
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 136, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe os_pid = 0xe3c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x8e0000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x75e90000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 32743 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x75ea4f70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x75ea4330 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x75ea5930 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x74fe09d0 True 1
Fn
Environment (16)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 6
Fn
Data
Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT False 1
Fn
Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = PROMPT, value = $P$G True 1
Fn
Set Environment String name = =C:, value = C:\Users\FD1HVy\Desktop True 2
Fn
Set Environment String name = COPYCMD True 1
Fn
Process #4: cmd.exe
66 0
»
Information Value
ID #4
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Documents && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Documents *
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:53, Reason: Child Process
Unmonitor End Time: 00:01:29, Reason: Self Terminated
Monitor Duration 00:00:36
OS Process Information
»
Information Value
PID 0x46c
Parent PID 0xe64 (c:\users\fd1hvy\desktop\unnam3d - ransm.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x F04
0x 86C
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points YARA Actions
cmd.exe 0x008E0000 0x00938FFF Process Termination - 32-bit - False
Host Behavior
File (18)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Users\FD1HVy\Desktop type = file_attributes True 2
Fn
Get Info C:\Users\FD1HVy\Documents type = file_attributes True 2
Fn
Open STD_OUTPUT_HANDLE - True 8
Fn
Open STD_INPUT_HANDLE - True 6
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 197, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe os_pid = 0xf64, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x8e0000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x75e90000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 32743 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x75ea4f70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x75ea4330 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x75ea5930 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x74fe09d0 True 1
Fn
Environment (20)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 8
Fn
Data
Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT False 1
Fn
Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = PROMPT, value = $P$G True 1
Fn
Set Environment String name = =C:, value = C:\Users\FD1HVy\Desktop True 1
Fn
Set Environment String name = =C:, value = C:\Users\FD1HVy\Documents True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #6: cmd.exe
66 0
»
Information Value
ID #6
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Pictures && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Pictures *
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:53, Reason: Child Process
Unmonitor End Time: 00:01:19, Reason: Self Terminated
Monitor Duration 00:00:25
OS Process Information
»
Information Value
PID 0xa9c
Parent PID 0xe64 (c:\users\fd1hvy\desktop\unnam3d - ransm.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 784
0x F6C
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points YARA Actions
cmd.exe 0x008E0000 0x00938FFF Process Termination - 32-bit - False
Host Behavior
File (18)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Users\FD1HVy\Desktop type = file_attributes True 2
Fn
Get Info C:\Users\FD1HVy\Pictures type = file_attributes True 2
Fn
Open STD_OUTPUT_HANDLE - True 8
Fn
Open STD_INPUT_HANDLE - True 6
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe os_pid = 0x754, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Module (8)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\syswow64\cmd.exe base_address = 0x8e0000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x75e90000 True 2
Fn
Get Filename - process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 32743 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address_out = 0x75ea4f70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CopyFileExW, address_out = 0x75ea4330 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address_out = 0x75ea5930 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x74fe09d0 True 1
Fn
Environment (20)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 8
Fn
Data
Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT False 1
Fn
Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = PROMPT, value = $P$G True 1
Fn
Set Environment String name = =C:, value = C:\Users\FD1HVy\Desktop True 1
Fn
Set Environment String name = =C:, value = C:\Users\FD1HVy\Pictures True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 1
Fn
Process #9: winrar.exe
3340 0
»
Information Value
ID #9
File Name c:\users\fd1hvy\appdata\local\temp\winrar.exe
Command Line C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Desktop *
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:56, Reason: Child Process
Unmonitor End Time: 00:04:33, Reason: Terminated by Timeout
Monitor Duration 00:03:37
OS Process Information
»
Information Value
PID 0xe3c
Parent PID 0xf00 (c:\windows\syswow64\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 4A4
0x E7C
0x D08
0x FAC
0x F24
0x 3FC
0x 10C0
0x 10C4
0x 10C8
0x 10CC
0x 10D0
0x 10D4
0x 10D8
0x 10DC
0x 10E0
0x 10E4
0x 10E8
0x 10EC
0x 10F0
0x 10F4
0x 10F8
0x 10FC
0x 1100
0x 1104
0x 1108
0x 110C
0x 1110
0x 1114
0x 1118
0x 111C
0x 1120
0x 1124
0x 1128
0x 112C
0x 1130
0x 1134
0x 1138
0x 113C
0x 1140
0x 1144
0x 1148
0x 114C
0x 1150
0x 1154
0x 1158
0x 115C
0x 1160
0x 1164
0x 1168
0x 116C
0x 1170
0x 1174
0x 1178
0x 117C
0x 1180
0x 1184
0x 1188
0x 118C
0x 1190
0x 1194
0x 1198
0x 119C
0x 11A0
0x 11A4
0x 11A8
0x 11AC
0x 11B0
0x 11B4
0x 11B8
0x 11BC
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
Desktop.rar 4.93 MB MD5: efa4ac54e99fdd29a9c5edf45ddaaa54
SHA1: 7d248783bb8ff1b88458ebd21c9ec8fd56275281
SHA256: 41290334b1e39a052138f7397495cccebc4675f3fd5a49b0a28ea015d768e5cc
SSDeep: 98304:sqq9/v6ZTjRW6S8TP7PaTxncuJf6fVc2hnfzbOrTPg8X4p7Y8b:9q9cA6FTjnLKrD7Xw7pb
False
Modified Files
»
Filename File Size Hash Values YARA Match Actions
c:\users\fd1hvy\appdata\local\microsoft\windows\explorer\iconcache_idx.db 113.77 KB MD5: 73bfba05899b33a27858f4c19b1a671b
SHA1: c6f1c292ff85bb4fb84055975879c8345290b413
SHA256: c2c4cdff22f9ca0ef6e49c25c19f020fbe3bed1712451c61aa02f1342acf4d19
SSDeep: 384:40cn3yWhXKXxUAuLD/q3sOqXp16KPo7Eo9erZoieAco37MwaDeYfs:rOaWDLrq3JMUWxnZoit7Mnq
False
c:\users\fd1hvy\appdata\local\microsoft\windows\explorer\iconcache_16.db 1.00 MB MD5: 59dda5dae4ef7b50a99d041e7a9e97e6
SHA1: 644e29965aef4527bc670bb0cecda464a0eb60b4
SHA256: f25e9070985e75877834f377d7ca21eec0961f2c7a87e815bffca320334ba90f
SSDeep: 12288:99sS9vByHE1a4Cxl/pGvfRBG4+EFjnFEd0jJg8ey:9DNBRi6G4+uA8ey
False
Host Behavior
COM (17)
»
Operation Class Interface Additional Information Success Count Logfile
Create 56FDF344-FD6D-11D0-958A-006097C9A090 EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF cls_context = CLSCTX_INPROC_SERVER True 17
Fn
File (342)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create \\?\C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create Desktop.rar desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create \\?\C:\Users\FD1HVy\Desktop\Desktop.rar desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create Desktop.rar desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create \\?\C:\Users\FD1HVy\Desktop\Desktop.rar desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create Desktop.rar desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create -mQiD8fm.doc desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 0KL2Gz9JGd.wav desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 0RRIlXg9.xls desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 1GbClcrwPdCacbM-.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 3 58nW.pps desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 4WmeXcoy8E.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 6u_EXsIYn4N.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create AG0E6OHBnNCn.mkv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create cdf 0O.avi desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create chO6xvKC4SuwQxTe.rtf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create desktop.ini desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create dRR2.wav desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create EKbd9czGD.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create GAXF44R72SInzUMj.mp3 desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create gG_HZ-HV.swf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create H9Q00myyEZo.mp3 desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create HBzA3ifwtSZxE.avi desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create hh4lRnb.ods desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create hqk1KnpsNtd.mkv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Hx3Tlhe_5jId0OJhP6.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create IaWqKnXFr.m4a desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Jil3P9aQS_.avi desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create jkHmqBwZLlx L8N.m4a desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create k5qtEIg5teHIWg.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Kd7Nt21v7fSUs0ibbZr.pdf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create kVcraZcrAD.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create kZvsWRlw_Unl_4-z2.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create M6unjbqHC6Vi.avi desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create mwUpgAicntsdXOa.wav desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create oOWu_URf4xodTCzItb.m4a desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create P1f3eP0sOin1nUyy.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Q00ZHL.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create r 8Z60WGh0PY-Uxk.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create rnJlU.swf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create sKJ-dBYfyDB.swf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Sn MlQKdcUAQKuOMiL.mp4 desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create t1UTy\0jOnjZop-702GRg.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create t1UTy\P4m7gaW ZT.flv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create t1UTy\rjFeGvlijme.swf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create t1UTy\x ddEQMGCa7.ots desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create t1UTy\y04cYW4-8JsL5Y8T29Y.xls desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create ttLWBUDVomotx85.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create UNNAM3D - RANSM.exe desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create vmwN.flv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create yo39-hWsdk Kwqd0cHA.flv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create _wLo_T-_xHQoQCx.mp4 desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Directory C:\Users\FD1HVy\AppData\Roaming\WinRAR - True 1
Fn
Add Search Path - - True 1
Fn
Get Info C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR type = file_attributes False 3
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR type = file_attributes False 3
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR type = file_attributes True 5
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat type = file_type True 1
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR\Settings.reg type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\Settings.reg type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg type = file_attributes False 2
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg type = file_attributes False 2
Fn
Get Info Desktop type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\Desktop\Desktop type = file_attributes False 1
Fn
Get Info Desktop.rar type = file_attributes False 3
Fn
Get Info \\?\C:\Users\FD1HVy\Desktop\Desktop.rar type = file_attributes False 3
Fn
Get Info Desktop.zip type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\Desktop\Desktop.zip type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR\Themes type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\Themes type = file_attributes False 1
Fn
Open STD_INPUT_HANDLE - True 1
Fn
Open STD_OUTPUT_HANDLE - True 1
Fn
Open STD_ERROR_HANDLE - True 1
Fn
Read C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat size = 4096, size_out = 12 True 1
Fn
Data
Read -mQiD8fm.doc size = 1048576, size_out = 87151 True 1
Fn
Data
Read -mQiD8fm.doc size = 961425, size_out = 0 True 1
Fn
Read 0KL2Gz9JGd.wav size = 1048576, size_out = 32756 True 1
Fn
Data
Read 0KL2Gz9JGd.wav size = 1015820, size_out = 0 True 1
Fn
Read 0RRIlXg9.xls size = 1048576, size_out = 70986 True 1
Fn
Data
Read 0RRIlXg9.xls size = 977590, size_out = 0 True 1
Fn
Read 1GbClcrwPdCacbM-.png size = 1048576, size_out = 48854 True 1
Fn
Data
Read 1GbClcrwPdCacbM-.png size = 999722, size_out = 0 True 1
Fn
Read 3 58nW.pps size = 1048576, size_out = 42558 True 1
Fn
Data
Read 3 58nW.pps size = 1006018, size_out = 0 True 1
Fn
Read 4WmeXcoy8E.gif size = 1048576, size_out = 2157 True 1
Fn
Data
Read 4WmeXcoy8E.gif size = 1046419, size_out = 0 True 1
Fn
Read 6u_EXsIYn4N.jpg size = 1048576, size_out = 42205 True 1
Fn
Data
Read 6u_EXsIYn4N.jpg size = 1006371, size_out = 0 True 1
Fn
Read AG0E6OHBnNCn.mkv size = 1048576, size_out = 18068 True 1
Fn
Data
Read AG0E6OHBnNCn.mkv size = 1030508, size_out = 0 True 1
Fn
Read cdf 0O.avi size = 1048576, size_out = 76020 True 1
Fn
Data
Read cdf 0O.avi size = 972556, size_out = 0 True 1
Fn
Read chO6xvKC4SuwQxTe.rtf size = 1048576, size_out = 25149 True 1
Fn
Data
Read chO6xvKC4SuwQxTe.rtf size = 1023427, size_out = 0 True 1
Fn
Read desktop.ini size = 1048576, size_out = 282 True 1
Fn
Data
Read desktop.ini size = 1048294, size_out = 0 True 1
Fn
Read dRR2.wav size = 1048576, size_out = 52046 True 1
Fn
Data
Read dRR2.wav size = 996530, size_out = 0 True 1
Fn
Read EKbd9czGD.bmp size = 1048576, size_out = 93926 True 1
Fn
Data
Read EKbd9czGD.bmp size = 954650, size_out = 0 True 1
Fn
Read GAXF44R72SInzUMj.mp3 size = 1048576, size_out = 100343 True 1
Fn
Data
Read GAXF44R72SInzUMj.mp3 size = 948233, size_out = 0 True 1
Fn
Read gG_HZ-HV.swf size = 1048576, size_out = 17620 True 1
Fn
Data
Read gG_HZ-HV.swf size = 1030956, size_out = 0 True 1
Fn
Read H9Q00myyEZo.mp3 size = 1048576, size_out = 44115 True 1
Fn
Data
Read H9Q00myyEZo.mp3 size = 1004461, size_out = 0 True 1
Fn
Read HBzA3ifwtSZxE.avi size = 1048576, size_out = 75630 True 1
Fn
Data
Read HBzA3ifwtSZxE.avi size = 972946, size_out = 0 True 1
Fn
Read hh4lRnb.ods size = 1048576, size_out = 26379 True 1
Fn
Data
Read hh4lRnb.ods size = 1022197, size_out = 0 True 1
Fn
Read hqk1KnpsNtd.mkv size = 1048576, size_out = 6447 True 1
Fn
Data
Read hqk1KnpsNtd.mkv size = 1042129, size_out = 0 True 1
Fn
Read Hx3Tlhe_5jId0OJhP6.pptx size = 1048576, size_out = 10395 True 1
Fn
Data
Read Hx3Tlhe_5jId0OJhP6.pptx size = 1038181, size_out = 0 True 1
Fn
Read IaWqKnXFr.m4a size = 1048576, size_out = 61480 True 1
Fn
Data
Read IaWqKnXFr.m4a size = 987096, size_out = 0 True 1
Fn
Read Jil3P9aQS_.avi size = 1048576, size_out = 37816 True 1
Fn
Data
Read Jil3P9aQS_.avi size = 1010760, size_out = 0 True 1
Fn
Read jkHmqBwZLlx L8N.m4a size = 1048576, size_out = 102378 True 1
Fn
Data
Read jkHmqBwZLlx L8N.m4a size = 946198, size_out = 0 True 1
Fn
Read k5qtEIg5teHIWg.png size = 1048576, size_out = 76357 True 1
Fn
Data
Read k5qtEIg5teHIWg.png size = 972219, size_out = 0 True 1
Fn
Read Kd7Nt21v7fSUs0ibbZr.pdf size = 1048576, size_out = 66164 True 1
Fn
Data
Read Kd7Nt21v7fSUs0ibbZr.pdf size = 982412, size_out = 0 True 1
Fn
Read kVcraZcrAD.png size = 1048576, size_out = 52758 True 1
Fn
Data
Read kVcraZcrAD.png size = 995818, size_out = 0 True 1
Fn
Read kZvsWRlw_Unl_4-z2.png size = 1048576, size_out = 17280 True 1
Fn
Data
Read kZvsWRlw_Unl_4-z2.png size = 1031296, size_out = 0 True 1
Fn
Read M6unjbqHC6Vi.avi size = 1048576, size_out = 68338 True 1
Fn
Data
Read M6unjbqHC6Vi.avi size = 980238, size_out = 0 True 1
Fn
Read mwUpgAicntsdXOa.wav size = 1048576, size_out = 96083 True 1
Fn
Data
Read mwUpgAicntsdXOa.wav size = 952493, size_out = 0 True 1
Fn
Read oOWu_URf4xodTCzItb.m4a size = 1048576, size_out = 86992 True 1
Fn
Data
Read oOWu_URf4xodTCzItb.m4a size = 961584, size_out = 0 True 1
Fn
Read P1f3eP0sOin1nUyy.csv size = 1048576, size_out = 68351 True 1
Fn
Data
Read P1f3eP0sOin1nUyy.csv size = 980225, size_out = 0 True 1
Fn
Read Q00ZHL.bmp size = 1048576, size_out = 29896 True 1
Fn
Data
Read Q00ZHL.bmp size = 1018680, size_out = 0 True 1
Fn
Read r 8Z60WGh0PY-Uxk.gif size = 1048576, size_out = 99365 True 1
Fn
Data
Read r 8Z60WGh0PY-Uxk.gif size = 949211, size_out = 0 True 1
Fn
Read rnJlU.swf size = 1048576, size_out = 7896 True 1
Fn
Data
Read rnJlU.swf size = 1040680, size_out = 0 True 1
Fn
Read sKJ-dBYfyDB.swf size = 1048576, size_out = 80603 True 1
Fn
Data
Read sKJ-dBYfyDB.swf size = 967973, size_out = 0 True 1
Fn
Read Sn MlQKdcUAQKuOMiL.mp4 size = 1048576, size_out = 49851 True 1
Fn
Data
Read Sn MlQKdcUAQKuOMiL.mp4 size = 998725, size_out = 0 True 1
Fn
Read t1UTy\0jOnjZop-702GRg.png size = 1048576, size_out = 82820 True 1
Fn
Data
Read t1UTy\0jOnjZop-702GRg.png size = 965756, size_out = 0 True 1
Fn
Read t1UTy\P4m7gaW ZT.flv size = 1048576, size_out = 6356 True 1
Fn
Data
Read t1UTy\P4m7gaW ZT.flv size = 1042220, size_out = 0 True 1
Fn
Read t1UTy\rjFeGvlijme.swf size = 1048576, size_out = 81605 True 1
Fn
Data
Read t1UTy\rjFeGvlijme.swf size = 966971, size_out = 0 True 1
Fn
Read t1UTy\x ddEQMGCa7.ots size = 1048576, size_out = 2906 True 1
Fn
Data
Read t1UTy\x ddEQMGCa7.ots size = 1045670, size_out = 0 True 1
Fn
Read t1UTy\y04cYW4-8JsL5Y8T29Y.xls size = 1048576, size_out = 82326 True 1
Fn
Data
Read t1UTy\y04cYW4-8JsL5Y8T29Y.xls size = 966250, size_out = 0 True 1
Fn
Read ttLWBUDVomotx85.gif size = 1048576, size_out = 29056 True 1
Fn
Data
Read ttLWBUDVomotx85.gif size = 1019520, size_out = 0 True 1
Fn
Read UNNAM3D - RANSM.exe size = 1048576, size_out = 1048576 True 1
Fn
Data
Read UNNAM3D - RANSM.exe size = 3145728, size_out = 1827840 True 1
Fn
Read UNNAM3D - RANSM.exe size = 4194304, size_out = 0 True 1
Fn
Read vmwN.flv size = 1048576, size_out = 48558 True 1
Fn
Data
Read vmwN.flv size = 1000018, size_out = 0 True 1
Fn
Read yo39-hWsdk Kwqd0cHA.flv size = 1048576, size_out = 36491 True 1
Fn
Data
Read yo39-hWsdk Kwqd0cHA.flv size = 1012085, size_out = 0 True 1
Fn
Read _wLo_T-_xHQoQCx.mp4 size = 1048576, size_out = 92113 True 1
Fn
Data
Read _wLo_T-_xHQoQCx.mp4 size = 956463, size_out = 0 True 1
Fn
Write Desktop.rar size = 8 True 2
Fn
Data
Write Desktop.rar size = 17 True 2
Fn
Data
Write Desktop.rar size = 87360 True 1
Fn
Data
Write Desktop.rar size = 96 True 4
Fn
Data
Write Desktop.rar size = 32832 True 1
Fn
Data
Write Desktop.rar size = 98 True 3
Fn
Data
Write Desktop.rar size = 71168 True 1
Fn
Data
Write Desktop.rar size = 48944 True 1
Fn
Data
Write Desktop.rar size = 104 True 5
Fn
Data
Write Desktop.rar size = 42624 True 1
Fn
Data
Write Desktop.rar size = 94 True 3
Fn
Data
Write Desktop.rar size = 2208 True 1
Fn
Data
Write Desktop.rar size = 42320 True 1
Fn
Data
Write Desktop.rar size = 99 True 3
Fn
Data
Write Desktop.rar size = 18176 True 1
Fn
Data
Write Desktop.rar size = 100 True 2
Fn
Data
Write Desktop.rar size = 76176 True 1
Fn
Data
Write Desktop.rar size = 21312 True 1
Fn
Data
Write Desktop.rar size = 176 True 1
Fn
Data
Write Desktop.rar size = 93 True 2
Fn
Data
Write Desktop.rar size = 52224 True 1
Fn
Data
Write Desktop.rar size = 92 True 2
Fn
Data
Write Desktop.rar size = 94128 True 1
Fn
Data
Write Desktop.rar size = 97 True 3
Fn
Data
Write Desktop.rar size = 100576 True 1
Fn
Data
Write Desktop.rar size = 17728 True 1
Fn
Data
Write Desktop.rar size = 44224 True 1
Fn
Data
Write Desktop.rar size = 75792 True 1
Fn
Data
Write Desktop.rar size = 101 True 1
Fn
Data
Write Desktop.rar size = 26464 True 1
Fn
Data
Write Desktop.rar size = 95 True 1
Fn
Data
Write Desktop.rar size = 6496 True 1
Fn
Data
Write Desktop.rar size = 10432 True 1
Fn
Data
Write Desktop.rar size = 107 True 4
Fn
Data
Write Desktop.rar size = 61632 True 1
Fn
Data
Write Desktop.rar size = 37936 True 1
Fn
Data
Write Desktop.rar size = 102608 True 1
Fn
Data
Write Desktop.rar size = 103 True 5
Fn
Data
Write Desktop.rar size = 76528 True 1
Fn
Data
Write Desktop.rar size = 102 True 2
Fn
Data
Write Desktop.rar size = 66368 True 1
Fn
Data
Write Desktop.rar size = 52896 True 1
Fn
Data
Write Desktop.rar size = 17392 True 1
Fn
Data
Write Desktop.rar size = 105 True 2
Fn
Data
Write Desktop.rar size = 68544 True 1
Fn
Data
Write Desktop.rar size = 96288 True 1
Fn
Data
Write Desktop.rar size = 87216 True 1
Fn
Data
Write Desktop.rar size = 106 True 2
Fn
Data
Write Desktop.rar size = 68512 True 1
Fn
Data
Write Desktop.rar size = 29952 True 1
Fn
Data
Write Desktop.rar size = 99600 True 1
Fn
Data
Write Desktop.rar size = 7952 True 1
Fn
Data
Write Desktop.rar size = 80768 True 1
Fn
Data
Write Desktop.rar size = 50016 True 1
Fn
Data
Write Desktop.rar size = 83040 True 1
Fn
Data
Write Desktop.rar size = 109 True 1
Fn
Data
Write Desktop.rar size = 6432 True 1
Fn
Data
Write Desktop.rar size = 81776 True 1
Fn
Data
Write Desktop.rar size = 2976 True 1
Fn
Data
Write Desktop.rar size = 82512 True 1
Fn
Data
Write Desktop.rar size = 113 True 1
Fn
Data
Write Desktop.rar size = 29136 True 1
Fn
Data
Write Desktop.rar size = 262144 True 10
Fn
Data
Write Desktop.rar size = 202912 True 1
Fn
Data
Write Desktop.rar size = 48656 True 1
Fn
Data
Write Desktop.rar size = 36624 True 1
Fn
Data
Write Desktop.rar size = 92320 True 1
Fn
Data
Write Desktop.rar size = 36 True 1
Fn
Data
Write Desktop.rar size = 19 True 1
Fn
Data
Write Desktop.rar size = 4803 True 1
Fn
Data
Delete Directory t1UTy - True 1
Fn
Delete _wLo_T-_xHQoQCx.mp4 - True 1
Fn
Delete yo39-hWsdk Kwqd0cHA.flv - True 1
Fn
Delete vmwN.flv - True 1
Fn
Delete UNNAM3D - RANSM.exe - False 1
Fn
Delete \\?\C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe - False 1
Fn
Delete ttLWBUDVomotx85.gif - True 1
Fn
Delete t1UTy\y04cYW4-8JsL5Y8T29Y.xls - True 1
Fn
Delete t1UTy\x ddEQMGCa7.ots - True 1
Fn
Delete t1UTy\rjFeGvlijme.swf - True 1
Fn
Delete t1UTy\P4m7gaW ZT.flv - True 1
Fn
Delete t1UTy\0jOnjZop-702GRg.png - True 1
Fn
Delete Sn MlQKdcUAQKuOMiL.mp4 - True 1
Fn
Delete sKJ-dBYfyDB.swf - True 1
Fn
Delete rnJlU.swf - True 1
Fn
Delete r 8Z60WGh0PY-Uxk.gif - True 1
Fn
Delete Q00ZHL.bmp - True 1
Fn
Delete P1f3eP0sOin1nUyy.csv - True 1
Fn
Delete oOWu_URf4xodTCzItb.m4a - True 1
Fn
Delete mwUpgAicntsdXOa.wav - True 1
Fn
Delete M6unjbqHC6Vi.avi - True 1
Fn
Delete kZvsWRlw_Unl_4-z2.png - True 1
Fn
Delete kVcraZcrAD.png - True 1
Fn
Delete Kd7Nt21v7fSUs0ibbZr.pdf - True 1
Fn
Delete k5qtEIg5teHIWg.png - True 1
Fn
Delete jkHmqBwZLlx L8N.m4a - True 1
Fn
Delete Jil3P9aQS_.avi - True 1
Fn
Delete IaWqKnXFr.m4a - True 1
Fn
Delete Hx3Tlhe_5jId0OJhP6.pptx - True 1
Fn
Delete hqk1KnpsNtd.mkv - True 1
Fn
Delete hh4lRnb.ods - True 1
Fn
Delete HBzA3ifwtSZxE.avi - True 1
Fn
Delete H9Q00myyEZo.mp3 - True 1
Fn
Delete gG_HZ-HV.swf - True 1
Fn
Delete GAXF44R72SInzUMj.mp3 - True 1
Fn
Delete EKbd9czGD.bmp - True 1
Fn
Delete dRR2.wav - True 1
Fn
Delete desktop.ini - True 1
Fn
Delete chO6xvKC4SuwQxTe.rtf - True 1
Fn
Delete cdf 0O.avi - True 1
Fn
Delete AG0E6OHBnNCn.mkv - True 1
Fn
Delete 6u_EXsIYn4N.jpg - True 1
Fn
Delete 4WmeXcoy8E.gif - True 1
Fn
Delete 3 58nW.pps - True 1
Fn
Delete 1GbClcrwPdCacbM-.png - True 1
Fn
Delete 0RRIlXg9.xls - True 1
Fn
Delete 0KL2Gz9JGd.wav - True 1
Fn
Delete -mQiD8fm.doc - True 1
Fn
Registry (1032)
»
Operation Key Additional Information Success Count Logfile
Create Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 - True 72
Fn
Create Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 - True 8
Fn
Create Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 - True 64
Fn
Create Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 - True 72
Fn
Create Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 - True 72
Fn
Create Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 - True 70
Fn
Create Key HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - False 5
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Paths - False 7
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 - True 5
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 - True 3
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - True 4
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 - True 6
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 - True 6
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 - True 7
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 - True 5
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\Software\WinRAR\Policy - False 4
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Policy - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\Software\WinRAR - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Extraction - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 - True 81
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\5 - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Compression - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList - False 8
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths - False 9
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates - False 5
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates - False 5
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Interface - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Interface\ErrList - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = SMP, data = 1, type = REG_NONE False 3
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Name, data = Default Profile, type = REG_SZ True 3
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Name, data = Create e-mail attachment, type = REG_SZ True 3
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Name, data = Backup selected files, type = REG_SZ True 2
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Name, data = Create 10 MB volumes, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = VerInfo, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR value_name = rarkey, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = Priority, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR value_name = rarreg.key, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = SMP, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Default, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 2
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcName, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileNames False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ExclNames True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ExclNames, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = StoreNames True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = StoreNames, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = UseRAR, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RAR5, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXModule, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFX, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXIcon, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXLogo, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXElevate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtFile, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtDataWide, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtTextWide, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtTextData, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolumeSize, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolSizeMod, data = 2, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolPause, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = OldVolNames, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecVolNumber, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Update, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Fresh, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SyncFiles, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Overwrite, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Move, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcRecBin, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcWipe, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = WipeIfPassword, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Solid, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Test, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecEnabled, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecSize, data = 4294967293, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Recovery, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EraseDest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = AddArcOnly, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ClearArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Lock, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Method, data = 3, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = DictSizeLZ, data = 4194304, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = DictSize, data = 33554432, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PasswordData, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EncryptHeaders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ZipLegacyEncrypt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = OpenShared, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ProcessOwners, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveStreams, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveSymLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveHardLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Background, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = WaitForOther, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Shutdown, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = GenerateArcName, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VersionControl, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = BLAKE2, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileCopies, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = QuickOpen, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = GenerateMask, data = yyyymmddhhmmss, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileTimeMode, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileDays, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileHours, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileMinutes, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcTimeOriginal, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcTimeLatest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = mtime, data = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ctime, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = atime, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsAbs, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsNone, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsAbsDrive, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ImmExec, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArcDoubleExt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArcSubfolders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EmailArcTo, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PackDetails, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR\Interface value_name = SystemProgressBar, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Interface value_name = TaskbarProgressBar, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = Log, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = Sound, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = Log, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = Sound, data = 1, type = REG_NONE False 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Name, data = Default Profile, size = 32, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Default, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ImmExec, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ExclNames, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = StoreNames, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = UseRAR, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RAR5, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXModule, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXIcon, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXLogo, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXElevate, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtFile, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtDataWide, size = 2, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolumeSize, data = 0, size = 4, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolSizeMod, data = 2, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolPause, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = OldVolNames, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecVolNumber, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Update, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Fresh, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SyncFiles, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Overwrite, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Move, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcRecBin, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcWipe, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = WipeIfPassword, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Solid, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Test, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecEnabled, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecSize, data = 4294967293, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EraseDest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = AddArcOnly, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ClearArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Lock, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Method, data = 3, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = DictSizeLZ, data = 4194304, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = DictSize, data = 33554432, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Background, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = WaitForOther, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Shutdown, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PasswordData, size = 1, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EncryptHeaders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ZipLegacyEncrypt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = OpenShared, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ProcessOwners, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveStreams, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveSymLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveHardLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = GenerateArcName, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VersionControl, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = BLAKE2, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileCopies, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = QuickOpen, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = GenerateMask, data = yyyymmddhhmmss, size = 30, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileTimeMode, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileDays, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileHours, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileMinutes, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileTimeLimit, data = 0, size = 8, type = REG_QWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcTimeOriginal, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcTimeLatest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = mtime, data = 4, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ctime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = atime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsAbs, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsNone, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsAbsDrive, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArcDoubleExt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArcSubfolders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EmailArcTo, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PackDetails, size = 192, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Name, data = Create e-mail attachment, size = 50, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Default, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ImmExec, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ExclNames, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = StoreNames, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = UseRAR, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = RAR5, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SFXModule, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SFXIcon, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SFXLogo, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SFXElevate, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = CmtFile, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = CmtDataWide, size = 2, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = VolumeSize, data = 0, size = 4, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = VolSizeMod, data = 2, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = VolPause, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = OldVolNames, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = RecVolNumber, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Update, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Fresh, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SyncFiles, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Overwrite, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Move, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ArcRecBin, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ArcWipe, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = WipeIfPassword, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Solid, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Test, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = RecEnabled, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = RecSize, data = 4294967293, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = EraseDest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = AddArcOnly, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ClearArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Lock, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Method, data = 5, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = DictSizeLZ, data = 33554432, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = DictSize, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Background, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = WaitForOther, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = Shutdown, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = PasswordData, size = 1, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = EncryptHeaders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ZipLegacyEncrypt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = OpenShared, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ProcessOwners, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SaveStreams, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SaveSymLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SaveHardLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = GenerateArcName, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = VersionControl, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = BLAKE2, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = FileCopies, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = QuickOpen, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = GenerateMask, data = yyyymmddhhmmss, size = 30, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = FileTimeMode, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = FileDays, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = FileHours, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = FileMinutes, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = FileTimeLimit, data = 0, size = 8, type = REG_QWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ArcTimeOriginal, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ArcTimeLatest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = mtime, data = 4, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ctime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = atime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = PathsAbs, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = PathsNone, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = PathsAbsDrive, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SeparateArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SeparateArcDoubleExt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SeparateArcSubfolders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = EmailArcTo, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = PackDetails, size = 192, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Name, data = Backup selected files, size = 44, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Default, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ImmExec, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ExclNames, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = StoreNames, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = UseRAR, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = RAR5, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SFXModule, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SFXIcon, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SFXLogo, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SFXElevate, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = CmtFile, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = CmtDataWide, size = 2, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = VolumeSize, data = 0, size = 4, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = VolSizeMod, data = 2, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = VolPause, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = OldVolNames, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = RecVolNumber, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Update, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Fresh, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SyncFiles, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Overwrite, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Move, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ArcRecBin, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ArcWipe, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = WipeIfPassword, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Solid, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Test, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = RecEnabled, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = RecSize, data = 4294967293, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = EraseDest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = AddArcOnly, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ClearArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Lock, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Method, data = 3, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = DictSizeLZ, data = 33554432, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = DictSize, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Background, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = WaitForOther, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = Shutdown, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = PasswordData, size = 1, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = EncryptHeaders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ZipLegacyEncrypt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = OpenShared, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ProcessOwners, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SaveStreams, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SaveSymLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SaveHardLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = GenerateArcName, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = VersionControl, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = BLAKE2, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = FileCopies, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = QuickOpen, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = GenerateMask, data = yyyymmddhhmmss, size = 30, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = FileTimeMode, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = FileDays, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = FileHours, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = FileMinutes, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = FileTimeLimit, data = 0, size = 8, type = REG_QWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ArcTimeOriginal, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ArcTimeLatest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = mtime, data = 4, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ctime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = atime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = PathsAbs, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = PathsNone, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = PathsAbsDrive, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SeparateArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SeparateArcDoubleExt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SeparateArcSubfolders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = EmailArcTo, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = PackDetails, size = 192, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Name, data = Create 10 MB volumes, size = 42, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Default, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ImmExec, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ExclNames, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = StoreNames, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = UseRAR, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = RAR5, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SFXModule, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SFXIcon, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SFXLogo, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SFXElevate, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = CmtFile, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = CmtDataWide, size = 2, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = VolumeSize, data = 10485760, size = 18, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = VolSizeMod, data = 2, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = VolPause, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = OldVolNames, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = RecVolNumber, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Update, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Fresh, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SyncFiles, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Overwrite, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Move, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ArcRecBin, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ArcWipe, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = WipeIfPassword, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Solid, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Test, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = RecEnabled, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = RecSize, data = 4294967293, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = EraseDest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = AddArcOnly, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ClearArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Lock, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Method, data = 3, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = DictSizeLZ, data = 33554432, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = DictSize, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Background, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = WaitForOther, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = Shutdown, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = PasswordData, size = 1, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = EncryptHeaders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ZipLegacyEncrypt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = OpenShared, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ProcessOwners, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SaveStreams, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SaveSymLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SaveHardLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = GenerateArcName, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = VersionControl, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = BLAKE2, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = FileCopies, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = QuickOpen, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = GenerateMask, data = yyyymmddhhmmss, size = 30, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = FileTimeMode, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = FileDays, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = FileHours, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = FileMinutes, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = FileTimeLimit, data = 0, size = 8, type = REG_QWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ArcTimeOriginal, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ArcTimeLatest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = mtime, data = 4, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ctime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = atime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = PathsAbs, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = PathsNone, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = PathsAbsDrive, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SeparateArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SeparateArcDoubleExt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SeparateArcSubfolders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = EmailArcTo, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = PackDetails, size = 192, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Name, data = ZIP archive (low compression), size = 60, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Default, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ImmExec, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ExclNames, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = StoreNames, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = UseRAR, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = RAR5, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SFXModule, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SFXIcon, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SFXLogo, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SFXElevate, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = CmtFile, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = CmtDataWide, size = 2, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = VolumeSize, data = 0, size = 4, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = VolSizeMod, data = 2, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = VolPause, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = OldVolNames, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = RecVolNumber, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Update, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Fresh, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SyncFiles, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Overwrite, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Move, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ArcRecBin, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ArcWipe, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = WipeIfPassword, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Solid, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Test, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = RecEnabled, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = RecSize, data = 4294967293, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = EraseDest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = AddArcOnly, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ClearArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Lock, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Method, data = 3, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Background, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = WaitForOther, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = Shutdown, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = PasswordData, size = 1, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = EncryptHeaders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ZipLegacyEncrypt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = OpenShared, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ProcessOwners, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SaveStreams, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SaveSymLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SaveHardLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = GenerateArcName, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = VersionControl, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = BLAKE2, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = FileCopies, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = QuickOpen, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = GenerateMask, data = yyyymmddhhmmss, size = 30, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = FileTimeMode, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = FileDays, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = FileHours, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = FileMinutes, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = FileTimeLimit, data = 0, size = 8, type = REG_QWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ArcTimeOriginal, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ArcTimeLatest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = mtime, data = 4, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ctime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = atime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = PathsAbs, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = PathsNone, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = PathsAbsDrive, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SeparateArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SeparateArcDoubleExt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SeparateArcSubfolders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = EmailArcTo, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = PackDetails, size = 192, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes value_name = ShellExtBMP, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes value_name = ShellExtIcon, size = 2, type = REG_SZ True 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcName False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileNames False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFX False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = ArcName False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = FileNames False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 value_name = SFX False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = ArcName False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = FileNames False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 value_name = SFX False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = ArcName False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = FileNames False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 value_name = SFX False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = ArcName False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = FileNames False 1
Fn
Delete Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 value_name = SFX False 1
Fn
Module (39)
»
Operation Module Additional Information Success Count Logfile
Load api-ms-win-core-synch-l1-2-0 base_address = 0x7ff92f150000 True 2
Fn
Load api-ms-win-core-fibers-l1-1-1 base_address = 0x7ff92f150000 True 2
Fn
Load api-ms-win-core-localization-l1-2-1 base_address = 0x7ff92f150000 True 1
Fn
Load C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll base_address = 0x0 False 1
Fn
Load C:\WINDOWS\system32\riched20.dll base_address = 0x7ff912450000 True 1
Fn
Load C:\WINDOWS\system32\Crypt32.dll base_address = 0x7ff92e880000 True 1
Fn
Get Handle c:\windows\system32\kernel32.dll base_address = 0x7ff92fdd0000 True 3
Fn
Get Handle c:\users\fd1hvy\appdata\local\temp\winrar.exe base_address = 0x7ff6f74d0000, flags = GET_MODULE_HANDLE_EX_FLAG_UNCHANGED_REFCOUNT, GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS True 1
Fn
Get Handle c:\windows\system32\shell32.dll base_address = 0x7ff9300e0000 True 2
Fn
Get Filename - process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 260 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 2
Fn
Get Filename C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 4
Fn
Get Address c:\windows\system32\kernelbase.dll function = InitializeCriticalSectionEx, address_out = 0x7ff92f1ad580 True 2
Fn
Get Address c:\windows\system32\kernelbase.dll function = FlsAlloc, address_out = 0x7ff92f1bd3e0 True 2
Fn
Get Address c:\windows\system32\kernelbase.dll function = FlsSetValue, address_out = 0x7ff92f198c10 True 2
Fn
Get Address c:\windows\system32\kernelbase.dll function = FlsGetValue, address_out = 0x7ff92f192340 True 1
Fn
Get Address c:\windows\system32\kernelbase.dll function = LCMapStringEx, address_out = 0x7ff92f17c800 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = InitializeConditionVariable, address_out = 0x7ff931fb35c0 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SleepConditionVariableCS, address_out = 0x7ff92f1be960 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = WakeAllConditionVariable, address_out = 0x7ff931fa6090 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetDllDirectoryW, address_out = 0x7ff92fdee3c0 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetDefaultDllDirectories, address_out = 0x7ff92f228b70 True 1
Fn
Get Address c:\windows\system32\crypt32.dll function = CryptProtectMemory, address_out = 0x7ff92d8c1770 True 1
Fn
Get Address c:\windows\system32\crypt32.dll function = CryptUnprotectMemory, address_out = 0x7ff92d8c17a0 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = CompareStringOrdinal, address_out = 0x7ff92fde8fb0 True 1
Fn
Get Address c:\windows\system32\shell32.dll function = SHGetStockIconInfo, address_out = 0x7ff9301bf2c0 True 2
Fn
Window (5)
»
Operation Window Name Additional Information Success Count Logfile
Create WinRAR class_name = WinRarWindow, wndproc_parameter = 0 True 1
Fn
Create - class_name = SysListView32, wndproc_parameter = 0 True 1
Fn
Create - class_name = tooltips_class32, wndproc_parameter = 0 True 1
Fn
Create - class_name = tooltips_class32, wndproc_parameter = 0 True 1
Fn
Find - class_name = WinRarWindow True 1
Fn
Keyboard (11)
»
Operation Additional Information Success Count Logfile
Get Info type = KB_CODEPAGE, result_out = 437 True 1
Fn
Read virtual_key_code = VK_SHIFT, result_out = 0 True 10
Fn
System (908)
»
Operation Additional Information Success Count Logfile
Get Time type = Performance Ctr, time = 14841558905 True 1
Fn
Get Time type = System Time, time = 2019-03-31 21:13:35 (UTC) True 1
Fn
Get Time type = Local Time, time = 2019-03-31 23:13:38 (Local Time) True 1
Fn
Get Time type = Performance Ctr, time = 15211619882 True 1
Fn
Get Time type = Ticks, time = 153281 True 1
Fn
Get Time type = Performance Ctr, time = 15331568388 True 1
Fn
Get Time type = Performance Ctr, time = 15331917197 True 1
Fn
Get Time type = Ticks, time = 153453 True 3
Fn
Get Time type = System Time, time = 2019-03-31 21:13:39 (UTC) True 2
Fn
Get Time type = Performance Ctr, time = 15380147605 True 1
Fn
Get Time type = Performance Ctr, time = 15380497701 True 1
Fn
Get Time type = Ticks, time = 153781 True 1
Fn
Get Time type = Ticks, time = 157562 True 2
Fn
Get Time type = Performance Ctr, time = 15759605264 True 1
Fn
Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
Get Time type = Performance Ctr, time = 15760237502 True 1
Fn
Get Time type = Ticks, time = 157578 True 4
Fn
Get Time type = Performance Ctr, time = 15761530531 True 1
Fn
Get Time type = Ticks, time = 157750 True 4
Fn
Get Time type = Performance Ctr, time = 15777963577 True 1
Fn
Get Time type = Ticks, time = 157906 True 8
Fn
Get Time type = System Time, time = 2019-03-31 21:13:44 (UTC) True 22
Fn
Get Time type = Performance Ctr, time = 15793990891 True 1
Fn
Get Time type = Performance Ctr, time = 15794276923 True 1
Fn
Get Time type = Performance Ctr, time = 15794833612 True 1
Fn
Get Time type = Ticks, time = 157921 True 12
Fn
Get Time type = Performance Ctr, time = 15795337748 True 1
Fn
Get Time type = Performance Ctr, time = 15795506864 True 1
Fn
Get Time type = Performance Ctr, time = 15796110275 True 1
Fn
Get Time type = Ticks, time = 157937 True 11
Fn
Get Time type = Performance Ctr, time = 15796722484 True 1
Fn
Get Time type = Performance Ctr, time = 15796993348 True 1
Fn
Get Time type = Performance Ctr, time = 15797418767 True 1
Fn
Get Time type = Ticks, time = 157953 True 15
Fn
Get Time type = Performance Ctr, time = 15798110827 True 1
Fn
Get Time type = Performance Ctr, time = 15798323723 True 1
Fn
Get Time type = Performance Ctr, time = 15798695360 True 1
Fn
Get Time type = Performance Ctr, time = 15799265394 True 1
Fn
Get Time type = Performance Ctr, time = 15799450459 True 1
Fn
Get Time type = Ticks, time = 158296 True 10
Fn
Get Time type = Performance Ctr, time = 15832514521 True 1
Fn
Get Time type = Performance Ctr, time = 15833768269 True 1
Fn
Get Time type = Performance Ctr, time = 15833863095 True 1
Fn
Get Time type = Ticks, time = 158312 True 10
Fn
Get Time type = Performance Ctr, time = 15834475441 True 1
Fn
Get Time type = Performance Ctr, time = 15835071353 True 1
Fn
Get Time type = Performance Ctr, time = 15835283060 True 1
Fn
Get Time type = Ticks, time = 158328 True 10
Fn
Get Time type = Performance Ctr, time = 15835864120 True 1
Fn
Get Time type = Performance Ctr, time = 15836357168 True 1
Fn
Get Time type = Performance Ctr, time = 15836485291 True 1
Fn
Get Time type = Ticks, time = 158343 True 14
Fn
Get Time type = Performance Ctr, time = 15837307936 True 1
Fn
Get Time type = Performance Ctr, time = 15838004771 True 1
Fn
Get Time type = Performance Ctr, time = 15838243970 True 1
Fn
Get Time type = Performance Ctr, time = 15838561470 True 1
Fn
Get Time type = Ticks, time = 158359 True 6
Fn
Get Time type = Performance Ctr, time = 15839245567 True 1
Fn
Get Time type = Performance Ctr, time = 15839362914 True 1
Fn
Get Time type = Ticks, time = 158453 True 14
Fn
Get Time type = Performance Ctr, time = 15848158189 True 1
Fn
Get Time type = Performance Ctr, time = 15848605316 True 1
Fn
Get Time type = Performance Ctr, time = 15848743207 True 1
Fn
Get Time type = Performance Ctr, time = 15849201922 True 1
Fn
Get Time type = Ticks, time = 158468 True 10
Fn
Get Time type = Performance Ctr, time = 15849906195 True 1
Fn
Get Time type = Performance Ctr, time = 15850120518 True 1
Fn
Get Time type = Performance Ctr, time = 15850994393 True 1
Fn
Get Time type = Ticks, time = 158484 True 6
Fn
Get Time type = Performance Ctr, time = 15851774169 True 1
Fn
Get Time type = Performance Ctr, time = 15852145920 True 1
Fn
Get Time type = Ticks, time = 158500 True 5
Fn
Get Time type = Performance Ctr, time = 15853241994 True 1
Fn
Get Time type = Ticks, time = 158515 True 15
Fn
Get Time type = Performance Ctr, time = 15854326252 True 1
Fn
Get Time type = Performance Ctr, time = 15854720218 True 1
Fn
Get Time type = Performance Ctr, time = 15854954684 True 1
Fn
Get Time type = Performance Ctr, time = 15855397573 True 1
Fn
Get Time type = Performance Ctr, time = 15855509479 True 1
Fn
Get Time type = Ticks, time = 158593 True 10
Fn
Get Time type = Performance Ctr, time = 15862475073 True 1
Fn
Get Time type = Performance Ctr, time = 15863315363 True 1
Fn
Get Time type = Performance Ctr, time = 15863516626 True 1
Fn
Get Time type = Ticks, time = 158609 True 4
Fn
Get Time type = Performance Ctr, time = 15864328062 True 1
Fn
Get Time type = Ticks, time = 158625 True 16
Fn
Get Time type = Performance Ctr, time = 15865462728 True 1
Fn
Get Time type = Performance Ctr, time = 15865713147 True 1
Fn
Get Time type = Performance Ctr, time = 15865995405 True 1
Fn
Get Time type = Performance Ctr, time = 15866460081 True 1
Fn
Get Time type = Performance Ctr, time = 15866580216 True 1
Fn
Get Time type = Ticks, time = 158640 True 10
Fn
Get Time type = Performance Ctr, time = 15866782793 True 1
Fn
Get Time type = Performance Ctr, time = 15867349379 True 1
Fn
Get Time type = Performance Ctr, time = 15867425778 True 1
Fn
Get Time type = Ticks, time = 158703 True 10
Fn
Get Time type = Performance Ctr, time = 15873254395 True 1
Fn
Get Time type = Performance Ctr, time = 15874057527 True 1
Fn
Get Time type = Performance Ctr, time = 15874221690 True 1
Fn
Get Time type = Ticks, time = 158718 True 11
Fn
Get Time type = Performance Ctr, time = 15874819496 True 1
Fn
Get Time type = Performance Ctr, time = 15875442238 True 1
Fn
Get Time type = Performance Ctr, time = 15875667510 True 1
Fn
Get Time type = Performance Ctr, time = 15876120908 True 1
Fn
Get Time type = Ticks, time = 158734 True 9
Fn
Get Time type = Performance Ctr, time = 15877008700 True 1
Fn
Get Time type = Performance Ctr, time = 15877247669 True 1
Fn
Get Time type = Ticks, time = 158750 True 5
Fn
Get Time type = Performance Ctr, time = 15878224459 True 1
Fn
Get Time type = Ticks, time = 158828 True 5
Fn
Get Time type = System Time, time = 2019-03-31 21:13:45 (UTC) True 17
Fn
Get Time type = Performance Ctr, time = 15886110562 True 1
Fn
Get Time type = Performance Ctr, time = 15886663733 True 1
Fn
Get Time type = Ticks, time = 158843 True 10
Fn
Get Time type = Performance Ctr, time = 15887458750 True 1
Fn
Get Time type = Performance Ctr, time = 15888054280 True 1
Fn
Get Time type = Performance Ctr, time = 15888421290 True 1
Fn
Get Time type = Ticks, time = 158859 True 10
Fn
Get Time type = Performance Ctr, time = 15889248223 True 1
Fn
Get Time type = Performance Ctr, time = 15889832908 True 1
Fn
Get Time type = Performance Ctr, time = 15890082089 True 1
Fn
Get Time type = Ticks, time = 158875 True 6
Fn
Get Time type = Performance Ctr, time = 15890719818 True 1
Fn
Get Time type = Performance Ctr, time = 15891575811 True 1
Fn
Get Time type = Ticks, time = 158968 True 10
Fn
Get Time type = Performance Ctr, time = 15899775398 True 1
Fn
Get Time type = Performance Ctr, time = 15900340180 True 1
Fn
Get Time type = Performance Ctr, time = 15900940015 True 1
Fn
Get Time type = Ticks, time = 159296 True 4
Fn
Get Time type = Performance Ctr, time = 15932776920 True 1
Fn
Get Time type = Ticks, time = 159312 True 7
Fn
Get Time type = Performance Ctr, time = 15934548032 True 1
Fn
Get Time type = Performance Ctr, time = 15935195647 True 1
Fn
Get Time type = Performance Ctr, time = 15935461196 True 1
Fn
Get Time type = Ticks, time = 159328 True 7
Fn
Get Time type = Performance Ctr, time = 15936524317 True 1
Fn
Get Time type = Ticks, time = 159343 True 6
Fn
Get Time type = Performance Ctr, time = 15937395133 True 1
Fn
Get Time type = Performance Ctr, time = 15937732234 True 1
Fn
Get Time type = Ticks, time = 159453 True 6
Fn
Get Time type = Performance Ctr, time = 15948667962 True 1
Fn
Get Time type = Performance Ctr, time = 15949445311 True 1
Fn
Get Time type = Ticks, time = 159468 True 8
Fn
Get Time type = Performance Ctr, time = 15950036201 True 1
Fn
Get Time type = Performance Ctr, time = 15951000577 True 1
Fn
Get Time type = Ticks, time = 159484 True 6
Fn
Get Time type = Performance Ctr, time = 15951954453 True 1
Fn
Get Time type = Performance Ctr, time = 15952232966 True 1
Fn
Get Time type = Ticks, time = 159500 True 10
Fn
Get Time type = Performance Ctr, time = 15952819474 True 1
Fn
Get Time type = Performance Ctr, time = 15953834572 True 1
Fn
Get Time type = Performance Ctr, time = 15954084260 True 1
Fn
Get Time type = Ticks, time = 159515 True 5
Fn
Get Time type = Performance Ctr, time = 15955034972 True 1
Fn
Get Time type = Ticks, time = 159609 True 5
Fn
Get Time type = Performance Ctr, time = 15964271030 True 1
Fn
Get Time type = Performance Ctr, time = 15964711272 True 1
Fn
Get Time type = Ticks, time = 159625 True 10
Fn
Get Time type = Performance Ctr, time = 15965708369 True 1
Fn
Get Time type = Performance Ctr, time = 15966226750 True 1
Fn
Get Time type = Performance Ctr, time = 15966389078 True 1
Fn
Get Time type = Ticks, time = 159640 True 10
Fn
Get Time type = Performance Ctr, time = 15967229968 True 1
Fn
Get Time type = Performance Ctr, time = 15967866206 True 1
Fn
Get Time type = Performance Ctr, time = 15968210801 True 1
Fn
Get Time type = Ticks, time = 159656 True 4
Fn
Get Time type = Performance Ctr, time = 15968708638 True 1
Fn
Get Time type = Ticks, time = 159718 True 6
Fn
Get Time type = Performance Ctr, time = 15975408717 True 1
Fn
Get Time type = Performance Ctr, time = 15975707022 True 1
Fn
Get Time type = Ticks, time = 159734 True 6
Fn
Get Time type = Performance Ctr, time = 15976789374 True 1
Fn
Get Time type = Performance Ctr, time = 15977404185 True 1
Fn
Get Time type = Ticks, time = 159750 True 14
Fn
Get Time type = Performance Ctr, time = 15977877733 True 1
Fn
Get Time type = Performance Ctr, time = 15978102276 True 1
Fn
Get Time type = Performance Ctr, time = 15978452279 True 1
Fn
Get Time type = Performance Ctr, time = 15978616470 True 1
Fn
Get Time type = Ticks, time = 159765 True 10
Fn
Get Time type = Performance Ctr, time = 15979328059 True 1
Fn
Get Time type = Performance Ctr, time = 15979924793 True 1
Fn
Get Time type = Performance Ctr, time = 15980231238 True 1
Fn
Get Time type = Ticks, time = 160296 True 4
Fn
Get Time type = Performance Ctr, time = 16032672563 True 1
Fn
Get Time type = Ticks, time = 160312 True 10
Fn
Get Time type = System Time, time = 2019-03-31 21:13:46 (UTC) True 3
Fn
Get Time type = Performance Ctr, time = 16034515512 True 1
Fn
Get Time type = Performance Ctr, time = 16034671556 True 1
Fn
Get Time type = Performance Ctr, time = 16035397130 True 1
Fn
Get Time type = Ticks, time = 160328 True 2
Fn
Get Time type = Performance Ctr, time = 16036863414 True 1
Fn
Get Time type = Ticks, time = 160343 True 10
Fn
Get Time type = Performance Ctr, time = 16037396790 True 1
Fn
Get Time type = Performance Ctr, time = 16037977084 True 1
Fn
Get Time type = Performance Ctr, time = 16038548352 True 1
Fn
Get Time type = Ticks, time = 160437 True 1
Fn
Get Time type = Performance Ctr, time = 16047997435 True 1
Fn
Get Time type = Ticks, time = 160453 True 3
Fn
Get Time type = Ticks, time = 161953 True 4
Fn
Get Time type = Performance Ctr, time = 16198765580 True 1
Fn
Get Time type = Ticks, time = 161968 True 10
Fn
Get Time type = System Time, time = 2019-03-31 21:13:48 (UTC) True 3
Fn
Get Time type = Performance Ctr, time = 16200283227 True 1
Fn
Get Time type = Performance Ctr, time = 16200436054 True 1
Fn
Get Time type = Performance Ctr, time = 16201020734 True 1
Fn
Get Time type = Ticks, time = 162281 True 6
Fn
Get Time type = Performance Ctr, time = 16231686070 True 1
Fn
Get Time type = Performance Ctr, time = 16231902344 True 1
Fn
Get Time type = Ticks, time = 162296 True 10
Fn
Get Time type = Performance Ctr, time = 16232828994 True 1
Fn
Get Time type = Performance Ctr, time = 16233378185 True 1
Fn
Get Time type = Performance Ctr, time = 16233626426 True 1
Fn
Get Time type = Ticks, time = 162312 True 6
Fn
Get Time type = Performance Ctr, time = 16234506113 True 1
Fn
Get Time type = Ticks, time = 163375 True 1
Fn
Get Time type = Performance Ctr, time = 16347419002 True 1
Fn
Get Time type = Ticks, time = 163437 True 3
Fn
Get Time type = Ticks, time = 163796 True 8
Fn
Get Time type = Performance Ctr, time = 16383172666 True 1
Fn
Get Time type = Performance Ctr, time = 16383554128 True 1
Fn
Get Time type = Ticks, time = 163843 True 7
Fn
Get Time type = Performance Ctr, time = 16388085710 True 1
Fn
Get Time type = Performance Ctr, time = 16388276565 True 1
Fn
Get Time type = Performance Ctr, time = 16392075967 True 1
Fn
Get Time type = Ticks, time = 165375 True 4
Fn
Get Time type = Performance Ctr, time = 16540922303 True 1
Fn
Get Time type = Ticks, time = 165859 True 4
Fn
Get Time type = Performance Ctr, time = 16589766036 True 1
Fn
Get Time type = Ticks, time = 166109 True 4
Fn
Get Time type = Performance Ctr, time = 16614145907 True 1
Fn
Get Time type = Ticks, time = 166171 True 4
Fn
Get Time type = Performance Ctr, time = 16620292392 True 1
Fn
Get Time type = Ticks, time = 166234 True 4
Fn
Get Time type = Performance Ctr, time = 16626421425 True 1
Fn
Get Time type = Ticks, time = 166343 True 4
Fn
Get Time type = Performance Ctr, time = 16637417212 True 1
Fn
Get Time type = Ticks, time = 166781 True 2
Fn
Get Time type = Performance Ctr, time = 16682451730 True 1
Fn
Get Time type = Ticks, time = 166796 True 14
Fn
Get Time type = Performance Ctr, time = 16682936555 True 1
Fn
Get Time type = Performance Ctr, time = 16683263954 True 1
Fn
Get Time type = Performance Ctr, time = 16683628637 True 1
Fn
Get Time type = Ticks, time = 166828 True 4
Fn
Get Time type = Performance Ctr, time = 16685651018 True 1
Fn
Get Time type = Ticks, time = 166875 True 4
Fn
Get Time type = Performance Ctr, time = 16690575171 True 1
Fn
Get Time type = Ticks, time = 166968 True 12
Fn
Get Time type = Performance Ctr, time = 16699966197 True 1
Fn
Get Time type = Performance Ctr, time = 16700407887 True 1
Fn
Get Time type = Performance Ctr, time = 16700780096 True 1
Fn
Get Time type = Ticks, time = 166984 True 4
Fn
Get Time type = Performance Ctr, time = 16701235015 True 1
Fn
Get Time type = Ticks, time = 167078 True 12
Fn
Get Time type = Performance Ctr, time = 16711007710 True 1
Fn
Get Time type = Performance Ctr, time = 16711408101 True 1
Fn
Get Time type = Performance Ctr, time = 16711727857 True 1
Fn
Get Time type = Ticks, time = 167250 True 2
Fn
Get Time type = Performance Ctr, time = 16729271833 True 1
Fn
Get Time type = Ticks, time = 167265 True 15
Fn
Get Time type = Performance Ctr, time = 16729683078 True 1
Fn
Get Time type = Performance Ctr, time = 16730088895 True 1
Fn
Get Time type = Performance Ctr, time = 16730408128 True 1
Fn
Get Time type = Ticks, time = 167281 True 15
Fn
Get Time type = Performance Ctr, time = 16730822089 True 1
Fn
Get Time type = Performance Ctr, time = 16731093647 True 1
Fn
Get Time type = Performance Ctr, time = 16731366430 True 1
Fn
Get Time type = Performance Ctr, time = 16731674832 True 1
Fn
Get Time type = Ticks, time = 167359 True 4
Fn
Get Time type = Performance Ctr, time = 16739973758 True 1
Fn
Get Time type = Ticks, time = 167765 True 8
Fn
Get Time type = Performance Ctr, time = 16780125972 True 1
Fn
Get Time type = Performance Ctr, time = 16780563441 True 1
Fn
Get Time type = Ticks, time = 167828 True 12
Fn
Get Time type = Performance Ctr, time = 16786015040 True 1
Fn
Get Time type = Performance Ctr, time = 16786553621 True 1
Fn
Get Time type = Performance Ctr, time = 16786873768 True 1
Fn
Get Time type = Ticks, time = 167843 True 8
Fn
Get Time type = Performance Ctr, time = 16787339900 True 1
Fn
Get Time type = Performance Ctr, time = 16787726584 True 1
Fn
Get Time type = Ticks, time = 167906 True 12
Fn
Get Time type = Performance Ctr, time = 16793839897 True 1
Fn
Get Time type = Performance Ctr, time = 16794274615 True 1
Fn
Get Time type = Performance Ctr, time = 16794576139 True 1
Fn
Get Time type = Ticks, time = 167921 True 4
Fn
Get Time type = Performance Ctr, time = 16795210479 True 1
Fn
Get Time type = Ticks, time = 168031 True 4
Fn
Get Time type = Performance Ctr, time = 16807043351 True 1
Fn
Get Time type = Ticks, time = 168078 True 8
Fn
Get Time type = Performance Ctr, time = 16811446690 True 1
Fn
Get Time type = Performance Ctr, time = 16811929965 True 1
Fn
Get Time type = Ticks, time = 168140 True 4
Fn
Get Time type = Performance Ctr, time = 16817591936 True 1
Fn
Get Time type = Performance Ctr, time = 16821245297 True 1
Fn
Get Time type = Performance Ctr, time = 16821272282 True 1
Fn
Get Info type = Operating System True 2
Fn
Get Info type = System Directory, result_out = C:\WINDOWS\system32 True 2
Fn
Mutex (2)
»
Operation Additional Information Success Count Logfile
Create mutex_name = WinRAR_Busy True 1
Fn
Release mutex_name = WinRAR_Busy True 1
Fn
Environment (1)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 1
Fn
Data
Process #10: winrar.exe
2745 0
»
Information Value
ID #10
File Name c:\users\fd1hvy\appdata\local\temp\winrar.exe
Command Line C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Documents *
Initial Working Directory C:\Users\FD1HVy\Documents\
Monitor Start Time: 00:00:57, Reason: Child Process
Unmonitor End Time: 00:01:29, Reason: Self Terminated
Monitor Duration 00:00:32
OS Process Information
»
Information Value
PID 0xf64
Parent PID 0x46c (c:\windows\syswow64\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 48C
0x D2C
0x E44
0x 174
0x 9E8
0x 9FC
0x 1204
0x 1208
0x 120C
0x 1210
0x 1214
0x 1218
0x 121C
0x 1220
0x 1224
0x 1228
0x 122C
0x 1230
0x 1234
0x 1238
0x 123C
0x 1240
0x 1244
0x 1248
0x 124C
0x 1250
0x 1254
0x 1258
0x 125C
0x 1260
0x 1264
0x 1268
0x 126C
0x 1270
0x 1274
0x 1278
0x 127C
0x 1280
0x 1284
0x 1288
0x 128C
0x 1290
0x 1294
0x 1298
0x 129C
0x 12A0
0x 12A4
0x 12A8
0x 12AC
0x 12B0
0x 12B4
0x 12B8
0x 12BC
0x 12C0
0x 12C4
0x 12C8
0x 12CC
0x 12D0
0x 12D4
0x 12D8
0x 12DC
0x 12E0
0x 12E4
0x 12E8
0x 12EC
0x 12F0
0x 12F4
0x 12F8
0x 12FC
0x 1300
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points YARA Actions
winrar.exe 0x7FF6F74D0000 0x7FF6F779FFFF Process Termination - 64-bit - False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat 0.01 KB MD5: 86d13c755ee816538758ea7aa2942899
SHA1: 2bc649ed0171190ae9d4a76a399a2c82310c4c2d
SHA256: 1dcf06035130cacff7d4ff78c0337532eacb190647b9e1633d247fc69e34d62a
SSDeep: 3:bZi:4
False
Documents.rar 2.54 MB MD5: 370e8acf7a8d836e91d6f1a593bfad56
SHA1: 624bebba8d39ce5f887f41d51e66160f4c3596cc
SHA256: 012fb962c6ff6e5153eb240c019c139c5bfb95c1bf664d5750b102b6058057ab
SSDeep: 49152:eZJE7juqkEOpR7YAjDh1+n65Q/6qChell8dlKffN48iRFTxrT5g:eZojKpLb+iy8hof21xe
False
Host Behavior
COM (15)
»
Operation Class Interface Additional Information Success Count Logfile
Create 56FDF344-FD6D-11D0-958A-006097C9A090 EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF cls_context = CLSCTX_INPROC_SERVER True 15
Fn
File (436)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create \\?\C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create Documents.rar desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create \\?\C:\Users\FD1HVy\Documents\Documents.rar desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create Documents.rar desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create \\?\C:\Users\FD1HVy\Documents\Documents.rar desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create Documents.rar desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create -3PSVPdo1rq8.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 5okJ0wdSjHps.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 5YJHRW-JZoT5E S09D.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 7I1yC6W53.doc desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 8CFpoZ DqeCI.doc desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\-4NjCVEIvkCBj.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\l7Td5TRgfXzOW kF6H0.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\-mjM.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\35mJ-.pdf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\3jMLs-qdS.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\BTQU2WOZsFUjw.pdf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\cA7tY- cuM.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\1q4uHOxj.odt desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\Kin6ms4WyJhH.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\KzP2.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\mbQ0b7o.ots desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\ww2bCvn.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\_fBJ yDh9e.ods desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\rDvRexnp0.xls desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XGIfB05FTyHqB.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XiqWm6izl6v FQ5Q.doc desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XXRZ1Ntz_m owLhUomX.rtf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\xZQ7e8.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\DLaLU5Np1FYR8L.ods desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\iOBweAZSY.ods desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\5S3P3.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\9NEdDu7cj0FPBRK.odt desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\Qx eo7HW.odt desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jfYQRF.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jLF_V3JmdmbQkD.ots desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\3k35ZmjoIQgYRoHKpmkK.pdf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\99y9.odt desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\l 4nHi8sklRbErgBL.pps desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\L_jtuZX b2fVSoNPf.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\XCn-HpOwlmV9G3Gdf9O.ods desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\QrQLcl.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\qfqeMqDF\R2r4mFlAna2enKE.odp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9EMbKuPh551l7_WJZv\WKv89hDvOzA.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create d8N7eT8cGeAbq0mZ CKY.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Database1.accdb desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create desktop.ini desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create eBvOtmtGs9oVXiPynY.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create FoGmW sbJbVrE-.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create g9y9 K 4j.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create jYH_Ha3VQR8eB_bONWr9.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create My Shapes\desktop.ini desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create My Shapes\Favorites.vssx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create My Shapes\_private\folder.ico desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create MZgybshM.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create NdfE2nFSq.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create nt5k6gcCx.pdf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Outlook Files\kkcie@kdj.kd.pst desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create qBs_.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create rhEg_RUaix7K66ZWCFGd.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create uGw1_n9EtC7y-G8.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Vtgh45Nfdq0.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create vZ5hUHAIiw4NGepftsf.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create XvD0nTrkTg7W8h.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create _jIR7aHVEY1Y7.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Add Search Path - - True 1
Fn
Get Info C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR type = file_attributes True 7
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR\WinRAR.ini type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\WinRAR.ini type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat type = file_type True 1
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR\Settings.reg type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\Settings.reg type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg type = file_attributes False 2
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg type = file_attributes False 2
Fn
Get Info Documents type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\Documents\Documents type = file_attributes False 1
Fn
Get Info Documents.rar type = file_attributes False 3
Fn
Get Info \\?\C:\Users\FD1HVy\Documents\Documents.rar type = file_attributes False 3
Fn
Get Info Documents.zip type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\Documents\Documents.zip type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR\Themes type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\Themes type = file_attributes False 1
Fn
Get Info My Music type = file_attributes True 1
Fn
Get Info My Pictures type = file_attributes True 1
Fn
Get Info My Videos type = file_attributes True 1
Fn
Open STD_INPUT_HANDLE - True 1
Fn
Open STD_OUTPUT_HANDLE - True 1
Fn
Open STD_ERROR_HANDLE - True 1
Fn
Read -3PSVPdo1rq8.docx size = 1048576, size_out = 22681 True 1
Fn
Data
Read -3PSVPdo1rq8.docx size = 1025895, size_out = 0 True 1
Fn
Read 5okJ0wdSjHps.docx size = 1048576, size_out = 22922 True 1
Fn
Data
Read 5okJ0wdSjHps.docx size = 1025654, size_out = 0 True 1
Fn
Read 5YJHRW-JZoT5E S09D.pptx size = 1048576, size_out = 1917 True 1
Fn
Data
Read 5YJHRW-JZoT5E S09D.pptx size = 1046659, size_out = 0 True 1
Fn
Read 7I1yC6W53.doc size = 1048576, size_out = 2265 True 1
Fn
Data
Read 7I1yC6W53.doc size = 1046311, size_out = 0 True 1
Fn
Read 8CFpoZ DqeCI.doc size = 1048576, size_out = 99449 True 1
Fn
Data
Read 8CFpoZ DqeCI.doc size = 949127, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\-4NjCVEIvkCBj.docx size = 1048576, size_out = 72805 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\-4NjCVEIvkCBj.docx size = 975771, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\l7Td5TRgfXzOW kF6H0.docx size = 1048576, size_out = 75828 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\l7Td5TRgfXzOW kF6H0.docx size = 972748, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\-mjM.xlsx size = 1048576, size_out = 21820 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\-mjM.xlsx size = 1026756, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\35mJ-.pdf size = 1048576, size_out = 50615 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\35mJ-.pdf size = 997961, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\3jMLs-qdS.docx size = 1048576, size_out = 79280 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\3jMLs-qdS.docx size = 969296, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\BTQU2WOZsFUjw.pdf size = 1048576, size_out = 59842 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\BTQU2WOZsFUjw.pdf size = 988734, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\cA7tY- cuM.pptx size = 1048576, size_out = 65013 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\cA7tY- cuM.pptx size = 983563, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\1q4uHOxj.odt size = 1048576, size_out = 17856 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\1q4uHOxj.odt size = 1030720, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\Kin6ms4WyJhH.xlsx size = 1048576, size_out = 41060 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\Kin6ms4WyJhH.xlsx size = 1007516, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\KzP2.csv size = 1048576, size_out = 3270 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\KzP2.csv size = 1045306, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\mbQ0b7o.ots size = 1048576, size_out = 75533 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\mbQ0b7o.ots size = 973043, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\ww2bCvn.csv size = 1048576, size_out = 4370 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\ww2bCvn.csv size = 1044206, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\_fBJ yDh9e.ods size = 1048576, size_out = 12823 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\_fBJ yDh9e.ods size = 1035753, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\rDvRexnp0.xls size = 1048576, size_out = 101096 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\rDvRexnp0.xls size = 947480, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XGIfB05FTyHqB.xlsx size = 1048576, size_out = 51715 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XGIfB05FTyHqB.xlsx size = 996861, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XiqWm6izl6v FQ5Q.doc size = 1048576, size_out = 11225 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XiqWm6izl6v FQ5Q.doc size = 1037351, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XXRZ1Ntz_m owLhUomX.rtf size = 1048576, size_out = 76789 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XXRZ1Ntz_m owLhUomX.rtf size = 971787, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\xZQ7e8.pptx size = 1048576, size_out = 101996 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\xZQ7e8.pptx size = 946580, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\DLaLU5Np1FYR8L.ods size = 1048576, size_out = 76279 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\DLaLU5Np1FYR8L.ods size = 972297, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\iOBweAZSY.ods size = 1048576, size_out = 28325 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\iOBweAZSY.ods size = 1020251, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\5S3P3.csv size = 1048576, size_out = 74809 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\5S3P3.csv size = 973767, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\9NEdDu7cj0FPBRK.odt size = 1048576, size_out = 79125 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\9NEdDu7cj0FPBRK.odt size = 969451, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\Qx eo7HW.odt size = 1048576, size_out = 67193 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\Qx eo7HW.odt size = 981383, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jfYQRF.csv size = 1048576, size_out = 1058 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jfYQRF.csv size = 1047518, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jLF_V3JmdmbQkD.ots size = 1048576, size_out = 102227 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jLF_V3JmdmbQkD.ots size = 946349, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\3k35ZmjoIQgYRoHKpmkK.pdf size = 1048576, size_out = 34385 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\3k35ZmjoIQgYRoHKpmkK.pdf size = 1014191, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\99y9.odt size = 1048576, size_out = 62018 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\99y9.odt size = 986558, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\l 4nHi8sklRbErgBL.pps size = 1048576, size_out = 53507 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\l 4nHi8sklRbErgBL.pps size = 995069, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\L_jtuZX b2fVSoNPf.docx size = 1048576, size_out = 100419 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\L_jtuZX b2fVSoNPf.docx size = 948157, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\XCn-HpOwlmV9G3Gdf9O.ods size = 1048576, size_out = 33711 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\XCn-HpOwlmV9G3Gdf9O.ods size = 1014865, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\QrQLcl.csv size = 1048576, size_out = 55794 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\QrQLcl.csv size = 992782, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\R2r4mFlAna2enKE.odp size = 1048576, size_out = 30026 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\qfqeMqDF\R2r4mFlAna2enKE.odp size = 1018550, size_out = 0 True 1
Fn
Read 9EMbKuPh551l7_WJZv\WKv89hDvOzA.pptx size = 1048576, size_out = 44333 True 1
Fn
Data
Read 9EMbKuPh551l7_WJZv\WKv89hDvOzA.pptx size = 1004243, size_out = 0 True 1
Fn
Read d8N7eT8cGeAbq0mZ CKY.xlsx size = 1048576, size_out = 52391 True 1
Fn
Data
Read d8N7eT8cGeAbq0mZ CKY.xlsx size = 996185, size_out = 0 True 1
Fn
Read Database1.accdb size = 1048576, size_out = 348160 True 1
Fn
Data
Read Database1.accdb size = 700416, size_out = 0 True 1
Fn
Read desktop.ini size = 1048576, size_out = 402 True 1
Fn
Data
Read desktop.ini size = 1048174, size_out = 0 True 1
Fn
Read eBvOtmtGs9oVXiPynY.xlsx size = 1048576, size_out = 26111 True 1
Fn
Data
Read eBvOtmtGs9oVXiPynY.xlsx size = 1022465, size_out = 0 True 1
Fn
Read FoGmW sbJbVrE-.pptx size = 1048576, size_out = 7234 True 1
Fn
Data
Read FoGmW sbJbVrE-.pptx size = 1041342, size_out = 0 True 1
Fn
Read g9y9 K 4j.pptx size = 1048576, size_out = 85473 True 1
Fn
Data
Read g9y9 K 4j.pptx size = 963103, size_out = 0 True 1
Fn
Read jYH_Ha3VQR8eB_bONWr9.pptx size = 1048576, size_out = 51177 True 1
Fn
Data
Read jYH_Ha3VQR8eB_bONWr9.pptx size = 997399, size_out = 0 True 1
Fn
Read My Shapes\desktop.ini size = 1048576, size_out = 216 True 1
Fn
Data
Read My Shapes\desktop.ini size = 1048360, size_out = 0 True 1
Fn
Read My Shapes\Favorites.vssx size = 1048576, size_out = 0 True 1
Fn
Read My Shapes\_private\folder.ico size = 1048576, size_out = 29926 True 1
Fn
Data
Read My Shapes\_private\folder.ico size = 1018650, size_out = 0 True 1
Fn
Read MZgybshM.pptx size = 1048576, size_out = 54061 True 1
Fn
Data
Read MZgybshM.pptx size = 994515, size_out = 0 True 1
Fn
Read NdfE2nFSq.xlsx size = 1048576, size_out = 59045 True 1
Fn
Data
Read NdfE2nFSq.xlsx size = 989531, size_out = 0 True 1
Fn
Read nt5k6gcCx.pdf size = 1048576, size_out = 33243 True 1
Fn
Data
Read nt5k6gcCx.pdf size = 1015333, size_out = 0 True 1
Fn
Read Outlook Files\kkcie@kdj.kd.pst size = 1048576, size_out = 271360 True 1
Fn
Data
Read Outlook Files\kkcie@kdj.kd.pst size = 777216, size_out = 0 True 1
Fn
Read qBs_.docx size = 1048576, size_out = 60299 True 1
Fn
Data
Read qBs_.docx size = 988277, size_out = 0 True 1
Fn
Read rhEg_RUaix7K66ZWCFGd.xlsx size = 1048576, size_out = 80968 True 1
Fn
Data
Read rhEg_RUaix7K66ZWCFGd.xlsx size = 967608, size_out = 0 True 1
Fn
Read uGw1_n9EtC7y-G8.xlsx size = 1048576, size_out = 18127 True 1
Fn
Data
Read uGw1_n9EtC7y-G8.xlsx size = 1030449, size_out = 0 True 1
Fn
Read Vtgh45Nfdq0.pptx size = 1048576, size_out = 96832 True 1
Fn
Data
Read Vtgh45Nfdq0.pptx size = 951744, size_out = 0 True 1
Fn
Read vZ5hUHAIiw4NGepftsf.docx size = 1048576, size_out = 12413 True 1
Fn
Data
Read vZ5hUHAIiw4NGepftsf.docx size = 1036163, size_out = 0 True 1
Fn
Read XvD0nTrkTg7W8h.xlsx size = 1048576, size_out = 51056 True 1
Fn
Data
Read XvD0nTrkTg7W8h.xlsx size = 997520, size_out = 0 True 1
Fn
Read _jIR7aHVEY1Y7.docx size = 1048576, size_out = 12279 True 1
Fn
Data
Read _jIR7aHVEY1Y7.docx size = 1036297, size_out = 0 True 1
Fn
Write C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat size = 12 True 1
Fn
Data
Write Documents.rar size = 8 True 2
Fn
Data
Write Documents.rar size = 17 True 2
Fn
Data
Write Documents.rar size = 22768 True 1
Fn
Data
Write Documents.rar size = 101 True 3
Fn
Data
Write Documents.rar size = 23024 True 1
Fn
Data
Write Documents.rar size = 1984 True 1
Fn
Data
Write Documents.rar size = 105 True 1
Fn
Data
Write Documents.rar size = 2320 True 1
Fn
Data
Write Documents.rar size = 95 True 1
Fn
Data
Write Documents.rar size = 99680 True 1
Fn
Data
Write Documents.rar size = 100 True 2
Fn
Data
Write Documents.rar size = 72960 True 1
Fn
Data
Write Documents.rar size = 121 True 3
Fn
Data
Write Documents.rar size = 76000 True 1
Fn
Data
Write Documents.rar size = 127 True 1
Fn
Data
Write Documents.rar size = 21904 True 1
Fn
Data
Write Documents.rar size = 50784 True 1
Fn
Data
Write Documents.rar size = 79424 True 1
Fn
Data
Write Documents.rar size = 126 True 1
Fn
Data
Write Documents.rar size = 59968 True 1
Fn
Data
Write Documents.rar size = 137 True 1
Fn
Data
Write Documents.rar size = 65152 True 1
Fn
Data
Write Documents.rar size = 135 True 2
Fn
Data
Write Documents.rar size = 17968 True 1
Fn
Data
Write Documents.rar size = 141 True 2
Fn
Data
Write Documents.rar size = 41168 True 1
Fn
Data
Write Documents.rar size = 146 True 1
Fn
Data
Write Documents.rar size = 3328 True 1
Fn
Data
Write Documents.rar size = 75712 True 1
Fn
Data
Write Documents.rar size = 140 True 2
Fn
Data
Write Documents.rar size = 4432 True 1
Fn
Data
Write Documents.rar size = 138 True 2
Fn
Data
Write Documents.rar size = 12880 True 1
Fn
Data
Write Documents.rar size = 143 True 2
Fn
Data
Write Documents.rar size = 101344 True 1
Fn
Data
Write Documents.rar size = 132 True 1
Fn
Data
Write Documents.rar size = 51856 True 1
Fn
Data
Write Documents.rar size = 11248 True 1
Fn
Data
Write Documents.rar size = 65008 True 1
Fn
Data
Write Documents.rar size = 102224 True 1
Fn
Data
Write Documents.rar size = 130 True 1
Fn
Data
Write Documents.rar size = 76464 True 1
Fn
Data
Write Documents.rar size = 157 True 2
Fn
Data
Write Documents.rar size = 28400 True 1
Fn
Data
Write Documents.rar size = 152 True 1
Fn
Data
Write Documents.rar size = 74976 True 1
Fn
Data
Write Documents.rar size = 79296 True 1
Fn
Data
Write Documents.rar size = 167 True 1
Fn
Data
Write Documents.rar size = 67376 True 1
Fn
Data
Write Documents.rar size = 151 True 2
Fn
Data
Write Documents.rar size = 1120 True 1
Fn
Data
Write Documents.rar size = 102464 True 1
Fn
Data
Write Documents.rar size = 34512 True 1
Fn
Data
Write Documents.rar size = 171 True 1
Fn
Data
Write Documents.rar size = 62160 True 1
Fn
Data
Write Documents.rar size = 155 True 1
Fn
Data
Write Documents.rar size = 53648 True 1
Fn
Data
Write Documents.rar size = 178 True 1
Fn
Data
Write Documents.rar size = 100656 True 1
Fn
Data
Write Documents.rar size = 179 True 1
Fn
Data
Write Documents.rar size = 33856 True 1
Fn
Data
Write Documents.rar size = 180 True 1
Fn
Data
Write Documents.rar size = 55936 True 1
Fn
Data
Write Documents.rar size = 122 True 1
Fn
Data
Write Documents.rar size = 30112 True 1
Fn
Data
Write Documents.rar size = 131 True 1
Fn
Data
Write Documents.rar size = 44432 True 1
Fn
Data
Write Documents.rar size = 119 True 1
Fn
Data
Write Documents.rar size = 52544 True 1
Fn
Data
Write Documents.rar size = 109 True 3
Fn
Data
Write Documents.rar size = 11312 True 1
Fn
Data
Write Documents.rar size = 99 True 1
Fn
Data
Write Documents.rar size = 192 True 1
Fn
Data
Write Documents.rar size = 93 True 3
Fn
Data
Write Documents.rar size = 26176 True 1
Fn
Data
Write Documents.rar size = 107 True 1
Fn
Data
Write Documents.rar size = 7280 True 1
Fn
Data
Write Documents.rar size = 85680 True 1
Fn
Data
Write Documents.rar size = 98 True 2
Fn
Data
Write Documents.rar size = 51344 True 1
Fn
Data
Write Documents.rar size = 160 True 1
Fn
Data
Write Documents.rar size = 103 True 2
Fn
Data
Write Documents.rar size = 16 True 1
Fn
Data
Write Documents.rar size = 106 True 1
Fn
Data
Write Documents.rar size = 11904 True 1
Fn
Data
Write Documents.rar size = 113 True 1
Fn
Data
Write Documents.rar size = 54208 True 1
Fn
Data
Write Documents.rar size = 97 True 2
Fn
Data
Write Documents.rar size = 59168 True 1
Fn
Data
Write Documents.rar size = 33376 True 1
Fn
Data
Write Documents.rar size = 14400 True 1
Fn
Data
Write Documents.rar size = 115 True 1
Fn
Data
Write Documents.rar size = 60432 True 1
Fn
Data
Write Documents.rar size = 81120 True 1
Fn
Data
Write Documents.rar size = 18224 True 1
Fn
Data
Write Documents.rar size = 104 True 1
Fn
Data
Write Documents.rar size = 97024 True 1
Fn
Data
Write Documents.rar size = 12464 True 1
Fn
Data
Write Documents.rar size = 108 True 1
Fn
Data
Write Documents.rar size = 51200 True 1
Fn
Data
Write Documents.rar size = 12320 True 1
Fn
Data
Write Documents.rar size = 102 True 2
Fn
Data
Write Documents.rar size = 74 True 1
Fn
Data
Write Documents.rar size = 84 True 1
Fn
Data
Write Documents.rar size = 92 True 1
Fn
Data
Write Documents.rar size = 65 True 1
Fn
Data
Write Documents.rar size = 78 True 1
Fn
Data
Write Documents.rar size = 58 True 1
Fn
Data
Write Documents.rar size = 49 True 2
Fn
Data
Write Documents.rar size = 40 True 2
Fn
Data
Write Documents.rar size = 43 True 1
Fn
Data
Write Documents.rar size = 41 True 1
Fn
Data
Write Documents.rar size = 44 True 1
Fn
Data
Write Documents.rar size = 19 True 1
Fn
Data
Write Documents.rar size = 7192 True 1
Fn
Data
Delete Directory Outlook Files - True 1
Fn
Delete Directory My Videos - True 1
Fn
Delete Directory My Shapes\_private - True 1
Fn
Delete Directory My Shapes - True 1
Fn
Delete Directory My Pictures - True 1
Fn
Delete Directory My Music - True 1
Fn
Delete Directory 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav - True 1
Fn
Delete Directory 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z - True 1
Fn
Delete Directory 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy - True 1
Fn
Delete Directory 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5 - True 1
Fn
Delete Directory 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY - True 1
Fn
Delete Directory 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS - True 1
Fn
Delete Directory 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s - True 1
Fn
Delete Directory 9EMbKuPh551l7_WJZv\qfqeMqDF - True 1
Fn
Delete Directory 9EMbKuPh551l7_WJZv - True 1
Fn
Delete _jIR7aHVEY1Y7.docx - True 1
Fn
Delete XvD0nTrkTg7W8h.xlsx - True 1
Fn
Delete vZ5hUHAIiw4NGepftsf.docx - True 1
Fn
Delete Vtgh45Nfdq0.pptx - True 1
Fn
Delete uGw1_n9EtC7y-G8.xlsx - True 1
Fn
Delete rhEg_RUaix7K66ZWCFGd.xlsx - True 1
Fn
Delete qBs_.docx - True 1
Fn
Delete Outlook Files\kkcie@kdj.kd.pst - True 1
Fn
Delete nt5k6gcCx.pdf - True 1
Fn
Delete NdfE2nFSq.xlsx - True 1
Fn
Delete MZgybshM.pptx - True 1
Fn
Delete My Shapes\_private\folder.ico - True 1
Fn
Delete My Shapes\Favorites.vssx - True 1
Fn
Delete My Shapes\desktop.ini - True 1
Fn
Delete jYH_Ha3VQR8eB_bONWr9.pptx - True 1
Fn
Delete g9y9 K 4j.pptx - True 1
Fn
Delete FoGmW sbJbVrE-.pptx - True 1
Fn
Delete eBvOtmtGs9oVXiPynY.xlsx - True 1
Fn
Delete desktop.ini - True 1
Fn
Delete Database1.accdb - True 1
Fn
Delete d8N7eT8cGeAbq0mZ CKY.xlsx - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\WKv89hDvOzA.pptx - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\R2r4mFlAna2enKE.odp - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\QrQLcl.csv - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\XCn-HpOwlmV9G3Gdf9O.ods - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\L_jtuZX b2fVSoNPf.docx - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\l 4nHi8sklRbErgBL.pps - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\99y9.odt - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\3k35ZmjoIQgYRoHKpmkK.pdf - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jLF_V3JmdmbQkD.ots - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jfYQRF.csv - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\Qx eo7HW.odt - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\9NEdDu7cj0FPBRK.odt - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\5S3P3.csv - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\iOBweAZSY.ods - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\DLaLU5Np1FYR8L.ods - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\xZQ7e8.pptx - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XXRZ1Ntz_m owLhUomX.rtf - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XiqWm6izl6v FQ5Q.doc - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XGIfB05FTyHqB.xlsx - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\rDvRexnp0.xls - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\_fBJ yDh9e.ods - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\ww2bCvn.csv - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\mbQ0b7o.ots - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\KzP2.csv - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\Kin6ms4WyJhH.xlsx - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\1q4uHOxj.odt - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\cA7tY- cuM.pptx - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\BTQU2WOZsFUjw.pdf - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\3jMLs-qdS.docx - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\35mJ-.pdf - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\qfqeMqDF\-mjM.xlsx - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\l7Td5TRgfXzOW kF6H0.docx - True 1
Fn
Delete 9EMbKuPh551l7_WJZv\-4NjCVEIvkCBj.docx - True 1
Fn
Delete 8CFpoZ DqeCI.doc - True 1
Fn
Delete 7I1yC6W53.doc - True 1
Fn
Delete 5YJHRW-JZoT5E S09D.pptx - True 1
Fn
Delete 5okJ0wdSjHps.docx - True 1
Fn
Delete -3PSVPdo1rq8.docx - True 1
Fn
Registry (244)
»
Operation Key Additional Information Success Count Logfile
Create Key HKEY_CURRENT_USER\Software\WinRAR\General - True 1
Fn
Create Key HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes - True 2
Fn
Create Key HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths - True 4
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - False 4
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Paths - False 7
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\WinRAR\Policy - False 4
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Policy - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\Software\WinRAR - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Extraction - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 - True 81
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\5 - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Compression - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList - False 8
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths - False 9
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates - False 5
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates - False 5
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Interface - True 2
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR value_name = rarkey, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = Priority, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR value_name = rarreg.key, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = SMP, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Default, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 2
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcName, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileNames False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ExclNames True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ExclNames, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = StoreNames True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = StoreNames, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = UseRAR, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RAR5, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXModule, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFX, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXIcon, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXLogo, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXElevate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtFile, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtDataWide, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtTextWide, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtTextData, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolumeSize, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolSizeMod, data = 2, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolPause, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = OldVolNames, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecVolNumber, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Update, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Fresh, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SyncFiles, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Overwrite, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Move, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcRecBin, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcWipe, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = WipeIfPassword, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Solid, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Test, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecEnabled, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecSize, data = 4294967293, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Recovery, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EraseDest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = AddArcOnly, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ClearArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Lock, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Method, data = 3, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = DictSizeLZ, data = 4194304, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = DictSize, data = 33554432, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PasswordData, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EncryptHeaders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ZipLegacyEncrypt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = OpenShared, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ProcessOwners, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveStreams, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveSymLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveHardLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Background, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = WaitForOther, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Shutdown, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = GenerateArcName, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VersionControl, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = BLAKE2, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileCopies, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = QuickOpen, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = GenerateMask, data = yyyymmddhhmmss, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileTimeMode, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileDays, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileHours, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileMinutes, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcTimeOriginal, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcTimeLatest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = mtime, data = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ctime, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = atime, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsAbs, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsNone, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsAbsDrive, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ImmExec, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArcDoubleExt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArcSubfolders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EmailArcTo, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PackDetails, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes value_name = ActivePath, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Interface value_name = SystemProgressBar, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Interface value_name = TaskbarProgressBar, data = 1, type = REG_NONE False 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = VerInfo, size = 12, type = REG_BINARY True 1
Fn
Data
Write Value HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes value_name = ShellExtBMP, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes value_name = ShellExtIcon, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths value_name = name, data = 120, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths value_name = size, data = 80, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths value_name = type, data = 120, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths value_name = mtime, data = 100, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Module (40)
»
Operation Module Additional Information Success Count Logfile
Load api-ms-win-core-synch-l1-2-0 base_address = 0x7ff92f150000 True 2
Fn
Load api-ms-win-core-fibers-l1-1-1 base_address = 0x7ff92f150000 True 2
Fn
Load api-ms-win-core-localization-l1-2-1 base_address = 0x7ff92f150000 True 1
Fn
Load C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll base_address = 0x0 False 1
Fn
Load C:\WINDOWS\system32\riched20.dll base_address = 0x7ff912450000 True 1
Fn
Load C:\WINDOWS\system32\Crypt32.dll base_address = 0x7ff92e880000 True 1
Fn
Load api-ms-win-appmodel-runtime-l1-1-1 base_address = 0x7ff92e3f0000 True 1
Fn
Get Handle c:\windows\system32\kernel32.dll base_address = 0x7ff92fdd0000 True 3
Fn
Get Handle c:\users\fd1hvy\appdata\local\temp\winrar.exe base_address = 0x7ff6f74d0000, flags = GET_MODULE_HANDLE_EX_FLAG_UNCHANGED_REFCOUNT, GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS True 1
Fn
Get Handle c:\users\fd1hvy\appdata\local\temp\winrar.exe base_address = 0x7ff6f74d0000 True 2
Fn
Get Handle mscoree.dll - False 1
Fn
Get Filename - process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 260 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 2
Fn
Get Filename C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 4
Fn
Get Address c:\windows\system32\kernelbase.dll function = InitializeCriticalSectionEx, address_out = 0x7ff92f1ad580 True 2
Fn
Get Address c:\windows\system32\kernelbase.dll function = FlsAlloc, address_out = 0x7ff92f1bd3e0 True 2
Fn
Get Address c:\windows\system32\kernelbase.dll function = FlsSetValue, address_out = 0x7ff92f198c10 True 2
Fn
Get Address c:\windows\system32\kernelbase.dll function = FlsGetValue, address_out = 0x7ff92f192340 True 1
Fn
Get Address c:\windows\system32\kernelbase.dll function = LCMapStringEx, address_out = 0x7ff92f17c800 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = InitializeConditionVariable, address_out = 0x7ff931fb35c0 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SleepConditionVariableCS, address_out = 0x7ff92f1be960 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = WakeAllConditionVariable, address_out = 0x7ff931fa6090 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetDllDirectoryW, address_out = 0x7ff92fdee3c0 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetDefaultDllDirectories, address_out = 0x7ff92f228b70 True 1
Fn
Get Address c:\windows\system32\crypt32.dll function = CryptProtectMemory, address_out = 0x7ff92d8c1770 True 1
Fn
Get Address c:\windows\system32\crypt32.dll function = CryptUnprotectMemory, address_out = 0x7ff92d8c17a0 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = CompareStringOrdinal, address_out = 0x7ff92fde8fb0 True 1
Fn
Get Address c:\windows\system32\kernel.appcore.dll function = GetCurrentPackageId, address_out = 0x7ff92e3f2b30 True 1
Fn
Window (6)
»
Operation Window Name Additional Information Success Count Logfile
Create WinRAR class_name = WinRarWindow, wndproc_parameter = 0 True 1
Fn
Create - class_name = SysListView32, wndproc_parameter = 0 True 1
Fn
Create - class_name = tooltips_class32, wndproc_parameter = 0 True 1
Fn
Create - class_name = tooltips_class32, wndproc_parameter = 0 True 1
Fn
Find - class_name = WinRarWindow False 1
Fn
Find - class_name = WinRarWindow True 1
Fn
Keyboard (7)
»
Operation Additional Information Success Count Logfile
Get Info type = KB_CODEPAGE, result_out = 437 True 1
Fn
Read virtual_key_code = VK_SHIFT, result_out = 0 True 6
Fn
System (1185)
»
Operation Additional Information Success Count Logfile
Get Time type = Performance Ctr, time = 14893080587 True 1
Fn
Get Time type = System Time, time = 2019-03-31 21:13:35 (UTC) True 1
Fn
Get Time type = Local Time, time = 2019-03-31 23:13:38 (Local Time) True 1
Fn
Get Time type = Performance Ctr, time = 15237274695 True 1
Fn
Get Time type = Ticks, time = 152781 True 1
Fn
Get Time type = Performance Ctr, time = 15281397310 True 1
Fn
Get Time type = Performance Ctr, time = 15338057145 True 1
Fn
Get Time type = Ticks, time = 153718 True 1
Fn
Get Time type = Ticks, time = 153734 True 2
Fn
Get Time type = Ticks, time = 153750 True 2
Fn
Get Time type = System Time, time = 2019-03-31 21:13:40 (UTC) True 2
Fn
Get Time type = Performance Ctr, time = 15389937088 True 1
Fn
Get Time type = Performance Ctr, time = 15390308705 True 1
Fn
Get Time type = Ticks, time = 153875 True 1
Fn
Get Time type = Ticks, time = 172296 True 2
Fn
Get Time type = Performance Ctr, time = 17233011526 True 1
Fn
Get Time type = System Time, time = 2019-03-31 21:13:58 (UTC) True 1
Fn
Get Time type = Performance Ctr, time = 17233895528 True 1
Fn
Get Time type = Ticks, time = 172312 True 4
Fn
Get Time type = Performance Ctr, time = 17234931677 True 1
Fn
Get Time type = Ticks, time = 172390 True 4
Fn
Get Time type = Performance Ctr, time = 17243097170 True 1
Fn
Get Time type = Ticks, time = 173093 True 10
Fn
Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 13
Fn
Get Time type = Performance Ctr, time = 17312499738 True 1
Fn
Get Time type = Performance Ctr, time = 17312694042 True 1
Fn
Get Time type = Performance Ctr, time = 17313268252 True 1
Fn
Get Time type = Ticks, time = 173109 True 22
Fn
Get Time type = Performance Ctr, time = 17313828493 True 1
Fn
Get Time type = Performance Ctr, time = 17314001516 True 1
Fn
Get Time type = Performance Ctr, time = 17314079364 True 1
Fn
Get Time type = Performance Ctr, time = 17314408867 True 1
Fn
Get Time type = Performance Ctr, time = 17314525949 True 1
Fn
Get Time type = Performance Ctr, time = 17314683803 True 1
Fn
Get Time type = Performance Ctr, time = 17315004614 True 1
Fn
Get Time type = Ticks, time = 173125 True 4
Fn
Get Time type = Performance Ctr, time = 17315292954 True 1
Fn
Get Time type = Ticks, time = 173234 True 4
Fn
Get Time type = Performance Ctr, time = 17327489494 True 1
Fn
Get Time type = Ticks, time = 173250 True 2
Fn
Get Time type = Performance Ctr, time = 17329009933 True 1
Fn
Get Time type = Ticks, time = 173265 True 9
Fn
Get Time type = Performance Ctr, time = 17329562430 True 1
Fn
Get Time type = Performance Ctr, time = 17330182227 True 1
Fn
Get Time type = Ticks, time = 173281 True 9
Fn
Get Time type = Performance Ctr, time = 17330982924 True 1
Fn
Get Time type = Performance Ctr, time = 17331326499 True 1
Fn
Get Time type = Performance Ctr, time = 17331985157 True 1
Fn
Get Time type = Ticks, time = 173296 True 10
Fn
Get Time type = Performance Ctr, time = 17333035000 True 1
Fn
Get Time type = Performance Ctr, time = 17333349121 True 1
Fn
Get Time type = Performance Ctr, time = 17333826325 True 1
Fn
Get Time type = Ticks, time = 173312 True 10
Fn
Get Time type = Performance Ctr, time = 17334326921 True 1
Fn
Get Time type = Performance Ctr, time = 17334518280 True 1
Fn
Get Time type = Performance Ctr, time = 17335113686 True 1
Fn
Get Time type = Ticks, time = 173328 True 6
Fn
Get Time type = Performance Ctr, time = 17335908914 True 1
Fn
Get Time type = Performance Ctr, time = 17336184496 True 1
Fn
Get Time type = Ticks, time = 173343 True 10
Fn
Get Time type = Performance Ctr, time = 17337519676 True 1
Fn
Get Time type = Performance Ctr, time = 17338151059 True 1
Fn
Get Time type = Performance Ctr, time = 17338495493 True 1
Fn
Get Time type = Ticks, time = 173359 True 10
Fn
Get Time type = Performance Ctr, time = 17339096636 True 1
Fn
Get Time type = Performance Ctr, time = 17339690163 True 1
Fn
Get Time type = Performance Ctr, time = 17340026632 True 1
Fn
Get Time type = Ticks, time = 173375 True 6
Fn
Get Time type = Performance Ctr, time = 17340790813 True 1
Fn
Get Time type = Performance Ctr, time = 17341572289 True 1
Fn
Get Time type = Ticks, time = 173390 True 14
Fn
Get Time type = Performance Ctr, time = 17341891199 True 1
Fn
Get Time type = Performance Ctr, time = 17342133985 True 1
Fn
Get Time type = Performance Ctr, time = 17342682309 True 1
Fn
Get Time type = Performance Ctr, time = 17342858027 True 1
Fn
Get Time type = Ticks, time = 173906 True 4
Fn
Get Time type = Performance Ctr, time = 17393863167 True 1
Fn
Get Time type = Ticks, time = 173921 True 16
Fn
Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 24
Fn
Get Time type = Performance Ctr, time = 17395400110 True 1
Fn
Get Time type = Performance Ctr, time = 17395637798 True 1
Fn
Get Time type = Performance Ctr, time = 17395791743 True 1
Fn
Get Time type = Performance Ctr, time = 17396157927 True 1
Fn
Get Time type = Performance Ctr, time = 17396316566 True 1
Fn
Get Time type = Ticks, time = 173937 True 6
Fn
Get Time type = Performance Ctr, time = 17397211839 True 1
Fn
Get Time type = Performance Ctr, time = 17397794181 True 1
Fn
Get Time type = Ticks, time = 173953 True 14
Fn
Get Time type = Performance Ctr, time = 17398270680 True 1
Fn
Get Time type = Performance Ctr, time = 17398459574 True 1
Fn
Get Time type = Performance Ctr, time = 17398813251 True 1
Fn
Get Time type = Performance Ctr, time = 17398946892 True 1
Fn
Get Time type = Ticks, time = 173968 True 10
Fn
Get Time type = Performance Ctr, time = 17399944876 True 1
Fn
Get Time type = Performance Ctr, time = 17400304892 True 1
Fn
Get Time type = Performance Ctr, time = 17400496353 True 1
Fn
Get Time type = Ticks, time = 173984 True 6
Fn
Get Time type = Performance Ctr, time = 17401471925 True 1
Fn
Get Time type = Performance Ctr, time = 17402440986 True 1
Fn
Get Time type = Ticks, time = 174000 True 10
Fn
Get Time type = Performance Ctr, time = 17402883607 True 1
Fn
Get Time type = Performance Ctr, time = 17403545391 True 1
Fn
Get Time type = Performance Ctr, time = 17404148748 True 1
Fn
Get Time type = Ticks, time = 174015 True 14
Fn
Get Time type = Performance Ctr, time = 17404593969 True 1
Fn
Get Time type = Performance Ctr, time = 17404814499 True 1
Fn
Get Time type = Performance Ctr, time = 17405223615 True 1
Fn
Get Time type = Performance Ctr, time = 17405442557 True 1
Fn
Get Time type = Ticks, time = 174031 True 4
Fn
Get Time type = Performance Ctr, time = 17406977159 True 1
Fn
Get Time type = Ticks, time = 174046 True 6
Fn
Get Time type = Performance Ctr, time = 17407912127 True 1
Fn
Get Time type = Performance Ctr, time = 17408362001 True 1
Fn
Get Time type = Ticks, time = 174062 True 4
Fn
Get Time type = Performance Ctr, time = 17409572212 True 1
Fn
Get Time type = Ticks, time = 174078 True 6
Fn
Get Time type = Performance Ctr, time = 17411165982 True 1
Fn
Get Time type = Performance Ctr, time = 17411705448 True 1
Fn
Get Time type = Ticks, time = 174109 True 4
Fn
Get Time type = Performance Ctr, time = 17414018315 True 1
Fn
Get Time type = Ticks, time = 174125 True 10
Fn
Get Time type = Performance Ctr, time = 17415595849 True 1
Fn
Get Time type = Performance Ctr, time = 17416072396 True 1
Fn
Get Time type = Performance Ctr, time = 17416546950 True 1
Fn
Get Time type = Ticks, time = 174140 True 6
Fn
Get Time type = Performance Ctr, time = 17417539088 True 1
Fn
Get Time type = Performance Ctr, time = 17417817700 True 1
Fn
Get Time type = Ticks, time = 174156 True 6
Fn
Get Time type = Performance Ctr, time = 17418905920 True 1
Fn
Get Time type = Performance Ctr, time = 17419571659 True 1
Fn
Get Time type = Ticks, time = 174171 True 4
Fn
Get Time type = Performance Ctr, time = 17420835313 True 1
Fn
Get Time type = Ticks, time = 174187 True 10
Fn
Get Time type = Performance Ctr, time = 17421662984 True 1
Fn
Get Time type = Performance Ctr, time = 17422489183 True 1
Fn
Get Time type = Performance Ctr, time = 17422854279 True 1
Fn
Get Time type = Ticks, time = 174203 True 6
Fn
Get Time type = Performance Ctr, time = 17423656811 True 1
Fn
Get Time type = Performance Ctr, time = 17424228922 True 1
Fn
Get Time type = Ticks, time = 174218 True 14
Fn
Get Time type = Performance Ctr, time = 17424875515 True 1
Fn
Get Time type = Performance Ctr, time = 17425298146 True 1
Fn
Get Time type = Performance Ctr, time = 17425642081 True 1
Fn
Get Time type = Performance Ctr, time = 17425820029 True 1
Fn
Get Time type = Ticks, time = 174234 True 4
Fn
Get Time type = Performance Ctr, time = 17426953934 True 1
Fn
Get Time type = Ticks, time = 174250 True 10
Fn
Get Time type = Performance Ctr, time = 17427826814 True 1
Fn
Get Time type = Performance Ctr, time = 17428244571 True 1
Fn
Get Time type = Performance Ctr, time = 17429156392 True 1
Fn
Get Time type = Ticks, time = 174265 True 10
Fn
Get Time type = Performance Ctr, time = 17429850768 True 1
Fn
Get Time type = Performance Ctr, time = 17430101247 True 1
Fn
Get Time type = Performance Ctr, time = 17430610303 True 1
Fn
Get Time type = Ticks, time = 174281 True 10
Fn
Get Time type = Performance Ctr, time = 17431475713 True 1
Fn
Get Time type = Performance Ctr, time = 17431788652 True 1
Fn
Get Time type = Performance Ctr, time = 17432297566 True 1
Fn
Get Time type = Ticks, time = 174296 True 6
Fn
Get Time type = Performance Ctr, time = 17433202104 True 1
Fn
Get Time type = Performance Ctr, time = 17433503087 True 1
Fn
Get Time type = Ticks, time = 174312 True 4
Fn
Get Time type = Performance Ctr, time = 17434478550 True 1
Fn
Get Time type = Ticks, time = 174328 True 2
Fn
Get Time type = Performance Ctr, time = 17436970994 True 1
Fn
Get Time type = Ticks, time = 174343 True 4
Fn
Get Time type = Performance Ctr, time = 17437569162 True 1
Fn
Get Time type = Ticks, time = 174359 True 6
Fn
Get Time type = Performance Ctr, time = 17439596112 True 1
Fn
Get Time type = Performance Ctr, time = 17440109337 True 1
Fn
Get Time type = Ticks, time = 174375 True 9
Fn
Get Time type = Performance Ctr, time = 17440476526 True 1
Fn
Get Time type = Performance Ctr, time = 17441103127 True 1
Fn
Get Time type = Ticks, time = 174390 True 11
Fn
Get Time type = Performance Ctr, time = 17441969475 True 1
Fn
Get Time type = Performance Ctr, time = 17442368944 True 1
Fn
Get Time type = Performance Ctr, time = 17442733852 True 1
Fn
Get Time type = Performance Ctr, time = 17443201816 True 1
Fn
Get Time type = Ticks, time = 174406 True 8
Fn
Get Time type = Performance Ctr, time = 17443591628 True 1
Fn
Get Time type = Performance Ctr, time = 17444793067 True 1
Fn
Get Time type = Ticks, time = 174828 True 2
Fn
Get Time type = System Time, time = 2019-03-31 21:14:01 (UTC) True 21
Fn
Get Time type = Performance Ctr, time = 17486883434 True 1
Fn
Get Time type = Ticks, time = 174843 True 8
Fn
Get Time type = Performance Ctr, time = 17487317354 True 1
Fn
Get Time type = Performance Ctr, time = 17488156602 True 1
Fn
Get Time type = Ticks, time = 174859 True 2
Fn
Get Time type = Performance Ctr, time = 17488984057 True 1
Fn
Get Time type = Ticks, time = 174921 True 4
Fn
Get Time type = Performance Ctr, time = 17496229028 True 1
Fn
Get Time type = Ticks, time = 174968 True 14
Fn
Get Time type = Performance Ctr, time = 17499825070 True 1
Fn
Get Time type = Performance Ctr, time = 17500708533 True 1
Fn
Get Time type = Performance Ctr, time = 17500908483 True 1
Fn
Get Time type = Performance Ctr, time = 17501032263 True 1
Fn
Get Time type = Ticks, time = 174984 True 6
Fn
Get Time type = Performance Ctr, time = 17501845711 True 1
Fn
Get Time type = Performance Ctr, time = 17502047160 True 1
Fn
Get Time type = Ticks, time = 175000 True 10
Fn
Get Time type = Performance Ctr, time = 17502846151 True 1
Fn
Get Time type = Performance Ctr, time = 17503586839 True 1
Fn
Get Time type = Performance Ctr, time = 17503848586 True 1
Fn
Get Time type = Ticks, time = 175015 True 10
Fn
Get Time type = Performance Ctr, time = 17504714568 True 1
Fn
Get Time type = Performance Ctr, time = 17505072750 True 1
Fn
Get Time type = Performance Ctr, time = 17505249582 True 1
Fn
Get Time type = Ticks, time = 175031 True 5
Fn
Get Time type = Performance Ctr, time = 17506145268 True 1
Fn
Get Time type = Ticks, time = 175046 True 9
Fn
Get Time type = Performance Ctr, time = 17507484539 True 1
Fn
Get Time type = Performance Ctr, time = 17508028699 True 1
Fn
Get Time type = Performance Ctr, time = 17508791658 True 1
Fn
Get Time type = Ticks, time = 175062 True 16
Fn
Get Time type = Performance Ctr, time = 17509544708 True 1
Fn
Get Time type = Performance Ctr, time = 17509830108 True 1
Fn
Get Time type = Performance Ctr, time = 17509856124 True 1
Fn
Get Time type = Performance Ctr, time = 17510222792 True 1
Fn
Get Time type = Performance Ctr, time = 17510276768 True 1
Fn
Get Time type = Ticks, time = 175093 True 10
Fn
Get Time type = Performance Ctr, time = 17512711009 True 1
Fn
Get Time type = Performance Ctr, time = 17512919464 True 1
Fn
Get Time type = Performance Ctr, time = 17513344999 True 1
Fn
Get Time type = Ticks, time = 175109 True 10
Fn
Get Time type = Performance Ctr, time = 17514186020 True 1
Fn
Get Time type = Performance Ctr, time = 17514392927 True 1
Fn
Get Time type = Performance Ctr, time = 17514896637 True 1
Fn
Get Time type = Ticks, time = 175125 True 10
Fn
Get Time type = Performance Ctr, time = 17515615397 True 1
Fn
Get Time type = Performance Ctr, time = 17515918095 True 1
Fn
Get Time type = Performance Ctr, time = 17516471876 True 1
Fn
Get Time type = Ticks, time = 175140 True 6
Fn
Get Time type = Performance Ctr, time = 17517382322 True 1
Fn
Get Time type = Performance Ctr, time = 17517680647 True 1
Fn
Get Time type = Ticks, time = 175156 True 4
Fn
Get Time type = Performance Ctr, time = 17519388254 True 1
Fn
Get Time type = Ticks, time = 175171 True 2
Fn
Get Time type = Performance Ctr, time = 17520503562 True 1
Fn
Get Time type = Ticks, time = 175265 True 4
Fn
Get Time type = Performance Ctr, time = 17530420120 True 1
Fn
Get Time type = Ticks, time = 175281 True 6
Fn
Get Time type = Performance Ctr, time = 17531753452 True 1
Fn
Get Time type = Performance Ctr, time = 17532276274 True 1
Fn
Get Time type = Ticks, time = 175296 True 10
Fn
Get Time type = Performance Ctr, time = 17532728270 True 1
Fn
Get Time type = Performance Ctr, time = 17533251013 True 1
Fn
Get Time type = Performance Ctr, time = 17533975658 True 1
Fn
Get Time type = Ticks, time = 175312 True 4
Fn
Get Time type = Performance Ctr, time = 17534319474 True 1
Fn
Get Time type = Ticks, time = 175328 True 6
Fn
Get Time type = Performance Ctr, time = 17536269939 True 1
Fn
Get Time type = Performance Ctr, time = 17537125405 True 1
Fn
Get Time type = Ticks, time = 175343 True 14
Fn
Get Time type = Performance Ctr, time = 17537516461 True 1
Fn
Get Time type = Performance Ctr, time = 17537770793 True 1
Fn
Get Time type = Performance Ctr, time = 17538232087 True 1
Fn
Get Time type = Performance Ctr, time = 17538430126 True 1
Fn
Get Time type = Ticks, time = 175359 True 5
Fn
Get Time type = Performance Ctr, time = 17539332054 True 1
Fn
Get Time type = Ticks, time = 175375 True 9
Fn
Get Time type = Performance Ctr, time = 17540747802 True 1
Fn
Get Time type = Performance Ctr, time = 17541140759 True 1
Fn
Get Time type = Performance Ctr, time = 17541466602 True 1
Fn
Get Time type = Ticks, time = 175390 True 6
Fn
Get Time type = Performance Ctr, time = 17542231547 True 1
Fn
Get Time type = Performance Ctr, time = 17542532123 True 1
Fn
Get Time type = Ticks, time = 175734 True 4
Fn
Get Time type = Performance Ctr, time = 17577015267 True 1
Fn
Get Time type = Ticks, time = 175750 True 12
Fn
Get Time type = Performance Ctr, time = 17578273100 True 1
Fn
Get Time type = Performance Ctr, time = 17578545243 True 1
Fn
Get Time type = Performance Ctr, time = 17578758359 True 1
Fn
Get Time type = Ticks, time = 175765 True 10
Fn
Get Time type = Ticks, time = 175781 True 9
Fn
Get Time type = Ticks, time = 175796 True 9
Fn
Get Time type = Ticks, time = 178859 True 2
Fn
Get Time type = Performance Ctr, time = 17889674789 True 1
Fn
Get Time type = Ticks, time = 178875 True 2
Fn
Get Time type = Ticks, time = 178953 True 4
Fn
Get Time type = Performance Ctr, time = 17898830696 True 1
Fn
Get Time type = Ticks, time = 178968 True 8
Fn
Get Time type = Performance Ctr, time = 17900048800 True 1
Fn
Get Time type = Performance Ctr, time = 17900365671 True 1
Fn
Get Time type = Ticks, time = 179015 True 4
Fn
Get Time type = Performance Ctr, time = 17904867157 True 1
Fn
Get Time type = Ticks, time = 179031 True 12
Fn
Get Time type = Performance Ctr, time = 17905861202 True 1
Fn
Get Time type = Performance Ctr, time = 17906562083 True 1
Fn
Get Time type = Performance Ctr, time = 17906874778 True 1
Fn
Get Time type = Ticks, time = 179046 True 12
Fn
Get Time type = Performance Ctr, time = 17907403320 True 1
Fn
Get Time type = Performance Ctr, time = 17907740271 True 1
Fn
Get Time type = Performance Ctr, time = 17908353731 True 1
Fn
Get Time type = Ticks, time = 179062 True 10
Fn
Get Time type = Performance Ctr, time = 17909464018 True 1
Fn
Get Time type = Performance Ctr, time = 17909764005 True 1
Fn
Get Time type = Performance Ctr, time = 17915905047 True 1
Fn
Get Time type = Ticks, time = 179125 True 4
Fn
Get Time type = Performance Ctr, time = 17916437164 True 1
Fn
Get Time type = Ticks, time = 179140 True 22
Fn
Get Time type = Performance Ctr, time = 17916782902 True 1
Fn
Get Time type = Performance Ctr, time = 17917007099 True 1
Fn
Get Time type = Performance Ctr, time = 17917294523 True 1
Fn
Get Time type = Performance Ctr, time = 17917518306 True 1
Fn
Get Time type = Performance Ctr, time = 17917762068 True 1
Fn
Get Time type = Ticks, time = 179156 True 16
Fn
Get Time type = Performance Ctr, time = 17918459191 True 1
Fn
Get Time type = Performance Ctr, time = 17918767603 True 1
Fn
Get Time type = Performance Ctr, time = 17919073266 True 1
Fn
Get Time type = Performance Ctr, time = 17919345699 True 1
Fn
Get Time type = Ticks, time = 179171 True 8
Fn
Get Time type = Performance Ctr, time = 17919659472 True 1
Fn
Get Time type = Performance Ctr, time = 17919972662 True 1
Fn
Get Time type = Ticks, time = 179187 True 10
Fn
Get Time type = Performance Ctr, time = 17921738478 True 1
Fn
Get Time type = Performance Ctr, time = 17922235545 True 1
Fn
Get Time type = Performance Ctr, time = 17923111805 True 1
Fn
Get Time type = Ticks, time = 179203 True 14
Fn
Get Time type = Performance Ctr, time = 17923415324 True 1
Fn
Get Time type = Performance Ctr, time = 17923709041 True 1
Fn
Get Time type = Performance Ctr, time = 17924005872 True 1
Fn
Get Time type = Ticks, time = 179218 True 1
Fn
Get Time type = Ticks, time = 179234 True 7
Fn
Get Time type = Performance Ctr, time = 17925804232 True 1
Fn
Get Time type = Performance Ctr, time = 17927208697 True 1
Fn
Get Time type = Ticks, time = 179250 True 8
Fn
Get Time type = Performance Ctr, time = 17928197459 True 1
Fn
Get Time type = Performance Ctr, time = 17928586139 True 1
Fn
Get Time type = Ticks, time = 179265 True 8
Fn
Get Time type = Performance Ctr, time = 17929429624 True 1
Fn
Get Time type = Performance Ctr, time = 17929970266 True 1
Fn
Get Time type = Ticks, time = 179281 True 8
Fn
Get Time type = Performance Ctr, time = 17931374379 True 1
Fn
Get Time type = Performance Ctr, time = 17931674388 True 1
Fn
Get Time type = Ticks, time = 179296 True 17
Fn
Get Time type = Performance Ctr, time = 17932218098 True 1
Fn
Get Time type = Performance Ctr, time = 17932540059 True 1
Fn
Get Time type = Performance Ctr, time = 17932853992 True 1
Fn
Get Time type = Performance Ctr, time = 17933188998 True 1
Fn
Get Time type = Ticks, time = 179312 True 15
Fn
Get Time type = Performance Ctr, time = 17933777472 True 1
Fn
Get Time type = Performance Ctr, time = 17934321877 True 1
Fn
Get Time type = Performance Ctr, time = 17934652315 True 1
Fn
Get Time type = Performance Ctr, time = 17934932669 True 1
Fn
Get Time type = Ticks, time = 179328 True 8
Fn
Get Time type = Performance Ctr, time = 17935601482 True 1
Fn
Get Time type = Performance Ctr, time = 17936339247 True 1
Fn
Get Time type = Ticks, time = 179343 True 20
Fn
Get Time type = Performance Ctr, time = 17936746879 True 1
Fn
Get Time type = Performance Ctr, time = 17937208053 True 1
Fn
Get Time type = Performance Ctr, time = 17937530601 True 1
Fn
Get Time type = Performance Ctr, time = 17937862308 True 1
Fn
Get Time type = Performance Ctr, time = 17938145710 True 1
Fn
Get Time type = Ticks, time = 179359 True 12
Fn
Get Time type = Performance Ctr, time = 17938704546 True 1
Fn
Get Time type = Performance Ctr, time = 17939001190 True 1
Fn
Get Time type = Performance Ctr, time = 17939301425 True 1
Fn
Get Time type = Ticks, time = 179375 True 8
Fn
Get Time type = Performance Ctr, time = 17940437139 True 1
Fn
Get Time type = Performance Ctr, time = 17941239470 True 1
Fn
Get Time type = Ticks, time = 179390 True 9
Fn
Get Time type = Performance Ctr, time = 17941726917 True 1
Fn
Get Time type = Performance Ctr, time = 17942030174 True 1
Fn
Get Time type = Performance Ctr, time = 17956122216 True 1
Fn
Get Info type = Operating System True 2
Fn
Get Info type = System Directory, result_out = C:\WINDOWS\system32 True 2
Fn
Mutex (2)
»
Operation Additional Information Success Count Logfile
Create mutex_name = WinRAR_Busy True 1
Fn
Release mutex_name = WinRAR_Busy False 1
Fn
Environment (1)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 1
Fn
Data
Process #11: winrar.exe
2030 0
»
Information Value
ID #11
File Name c:\users\fd1hvy\appdata\local\temp\winrar.exe
Command Line C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Pictures *
Initial Working Directory C:\Users\FD1HVy\Pictures\
Monitor Start Time: 00:00:57, Reason: Child Process
Unmonitor End Time: 00:01:17, Reason: Self Terminated
Monitor Duration 00:00:20
OS Process Information
»
Information Value
PID 0x754
Parent PID 0xa9c (c:\windows\syswow64\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x CD8
0x 388
0x 824
0x 4AC
0x EF8
0x F70
0x 9E0
0x B84
0x D6C
0x EB0
0x E40
0x FBC
0x E90
0x BEC
0x FB8
0x F84
0x D5C
0x CA0
0x D1C
0x FB4
0x D7C
0x ECC
0x E98
0x EE0
0x 324
0x FB0
0x 1004
0x 1008
0x 100C
0x 1010
0x 1014
0x 1018
0x 101C
0x 1020
0x 1024
0x 1028
0x 102C
0x 1030
0x 1034
0x 1038
0x 103C
0x 1040
0x 1044
0x 1048
0x 104C
0x 1050
0x 1054
0x 1058
0x 105C
0x 1060
0x 1064
0x 1068
0x 106C
0x 1070
0x 1074
0x 1078
0x 107C
0x 1080
0x 1084
0x 1088
0x 108C
0x 1090
0x 1094
0x 1098
0x 109C
0x 10A0
0x 10A4
0x 10A8
0x 10AC
0x 10B0
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points YARA Actions
winrar.exe 0x7FF6F74D0000 0x7FF6F779FFFF Process Termination - 64-bit - False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
Pictures.rar 2.09 MB MD5: 1529f351c2fa6e418339daccb62c82e7
SHA1: 8553fc21b935c408f801bc2080da58f1bff66f69
SHA256: 799c8d082fe7ee8bd2094495e17edd836ff1680e185d8297eb5da5a5a1ce8c3e
SSDeep: 49152:QJODSx4QT/yfmAl/gencu3YT/woKEo5HKOqA0A5JOGKwOyVCN:QJ9ufmLhwb5KAa5
False
Host Behavior
COM (16)
»
Operation Class Interface Additional Information Success Count Logfile
Create 56FDF344-FD6D-11D0-958A-006097C9A090 EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF cls_context = CLSCTX_INPROC_SERVER True 16
Fn
File (291)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create \\?\C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create Pictures.rar desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create \\?\C:\Users\FD1HVy\Pictures\Pictures.rar desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create Pictures.rar desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create \\?\C:\Users\FD1HVy\Pictures\Pictures.rar desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
Create Pictures.rar desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create 17Kei.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 1Uee5Fu 2XCwi8fG.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 5qnTEjfG9KjtBUIojvlC.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 6xi8hATC8ep.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 7ZwWGMcIaUjWjMVJAe.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 8eYKFrOBbq-TuX.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create 9BtQRHA1y.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create A4ii4MOpBgpQwQBT.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create aHz4Hx-PBeuX.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create awTUht89JcK2K D7j9i.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create c9ZaReaCiTG.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Camera Roll\desktop.ini desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Cg4L5J0Hp5g.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create desktop.ini desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create dw0z-rObH0-zF2.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create FiPd_4qvOx8j.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create g6r96fa7GyN6.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create gTXyE1NkEEb.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create H6PwCN3oyZKOwFQ.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create H7Jzn2.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create hh1Bz.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create HPs4cKd.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create job -V_cE7uVrHssoWW.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create KmDsFaqbjMnNn4BN.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create m3ksaTaVuXM_ADoCvA.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create m3Vfo.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Pe_4G6TNHBiw7.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create q0 y.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create QX41YSfi6.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Saved Pictures\desktop.ini desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create sj6 1xhDAi0ypw.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create svWwwq0D.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create W-jIjn6.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Ww lmr4coeaZVkLVzHS.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create YBodpCQ1OYUO B.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create yova8.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create yWEcS.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create y_QmYlvwtNWjwI0tZ.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create Z8PEjH5b.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create zdKqdR.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create zoYWy0tnNuqg-Zdh4.gif desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Add Search Path - - True 1
Fn
Get Info C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR type = file_attributes True 5
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR\WinRAR.ini type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\WinRAR.ini type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat type = file_type True 1
Fn
Get Info Pictures type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\Pictures\Pictures type = file_attributes False 1
Fn
Get Info Pictures.rar type = file_attributes False 3
Fn
Get Info \\?\C:\Users\FD1HVy\Pictures\Pictures.rar type = file_attributes False 3
Fn
Get Info Pictures.zip type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\Pictures\Pictures.zip type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\AppData\Roaming\WinRAR\Themes type = file_attributes False 1
Fn
Get Info \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\Themes type = file_attributes False 1
Fn
Open STD_INPUT_HANDLE - True 1
Fn
Open STD_OUTPUT_HANDLE - True 1
Fn
Open STD_ERROR_HANDLE - True 1
Fn
Read C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat size = 4096, size_out = 12 True 1
Fn
Data
Read 17Kei.bmp size = 1048576, size_out = 48846 True 1
Fn
Data
Read 17Kei.bmp size = 999730, size_out = 0 True 1
Fn
Read 1Uee5Fu 2XCwi8fG.gif size = 1048576, size_out = 75056 True 1
Fn
Data
Read 1Uee5Fu 2XCwi8fG.gif size = 973520, size_out = 0 True 1
Fn
Read 5qnTEjfG9KjtBUIojvlC.png size = 1048576, size_out = 73639 True 1
Fn
Data
Read 5qnTEjfG9KjtBUIojvlC.png size = 974937, size_out = 0 True 1
Fn
Read 6xi8hATC8ep.gif size = 1048576, size_out = 15219 True 1
Fn
Data
Read 6xi8hATC8ep.gif size = 1033357, size_out = 0 True 1
Fn
Read 7ZwWGMcIaUjWjMVJAe.jpg size = 1048576, size_out = 43455 True 1
Fn
Data
Read 7ZwWGMcIaUjWjMVJAe.jpg size = 1005121, size_out = 0 True 1
Fn
Read 8eYKFrOBbq-TuX.bmp size = 1048576, size_out = 20756 True 1
Fn
Data
Read 8eYKFrOBbq-TuX.bmp size = 1027820, size_out = 0 True 1
Fn
Read 9BtQRHA1y.gif size = 1048576, size_out = 42415 True 1
Fn
Data
Read 9BtQRHA1y.gif size = 1006161, size_out = 0 True 1
Fn
Read A4ii4MOpBgpQwQBT.jpg size = 1048576, size_out = 87534 True 1
Fn
Data
Read A4ii4MOpBgpQwQBT.jpg size = 961042, size_out = 0 True 1
Fn
Read aHz4Hx-PBeuX.png size = 1048576, size_out = 81997 True 1
Fn
Data
Read aHz4Hx-PBeuX.png size = 966579, size_out = 0 True 1
Fn
Read awTUht89JcK2K D7j9i.png size = 1048576, size_out = 34167 True 1
Fn
Data
Read awTUht89JcK2K D7j9i.png size = 1014409, size_out = 0 True 1
Fn
Read c9ZaReaCiTG.png size = 1048576, size_out = 82983 True 1
Fn
Data
Read c9ZaReaCiTG.png size = 965593, size_out = 0 True 1
Fn
Read Camera Roll\desktop.ini size = 1048576, size_out = 190 True 1
Fn
Data
Read Camera Roll\desktop.ini size = 1048386, size_out = 0 True 1
Fn
Read Cg4L5J0Hp5g.bmp size = 1048576, size_out = 3689 True 1
Fn
Data
Read Cg4L5J0Hp5g.bmp size = 1044887, size_out = 0 True 1
Fn
Read desktop.ini size = 1048576, size_out = 504 True 1
Fn
Data
Read desktop.ini size = 1048072, size_out = 0 True 1
Fn
Read dw0z-rObH0-zF2.png size = 1048576, size_out = 6965 True 1
Fn
Data
Read dw0z-rObH0-zF2.png size = 1041611, size_out = 0 True 1
Fn
Read FiPd_4qvOx8j.jpg size = 1048576, size_out = 46505 True 1
Fn
Data
Read FiPd_4qvOx8j.jpg size = 1002071, size_out = 0 True 1
Fn
Read g6r96fa7GyN6.gif size = 1048576, size_out = 57322 True 1
Fn
Data
Read g6r96fa7GyN6.gif size = 991254, size_out = 0 True 1
Fn
Read gTXyE1NkEEb.jpg size = 1048576, size_out = 96501 True 1
Fn
Data
Read gTXyE1NkEEb.jpg size = 952075, size_out = 0 True 1
Fn
Read H6PwCN3oyZKOwFQ.png size = 1048576, size_out = 101635 True 1
Fn
Data
Read H6PwCN3oyZKOwFQ.png size = 946941, size_out = 0 True 1
Fn
Read H7Jzn2.png size = 1048576, size_out = 81996 True 1
Fn
Data
Read H7Jzn2.png size = 966580, size_out = 0 True 1
Fn
Read hh1Bz.png size = 1048576, size_out = 97065 True 1
Fn
Data
Read hh1Bz.png size = 951511, size_out = 0 True 1
Fn
Read HPs4cKd.bmp size = 1048576, size_out = 59374 True 1
Fn
Data
Read HPs4cKd.bmp size = 989202, size_out = 0 True 1
Fn
Read job -V_cE7uVrHssoWW.jpg size = 1048576, size_out = 48923 True 1
Fn
Data
Read job -V_cE7uVrHssoWW.jpg size = 999653, size_out = 0 True 1
Fn
Read KmDsFaqbjMnNn4BN.jpg size = 1048576, size_out = 33999 True 1
Fn
Data
Read KmDsFaqbjMnNn4BN.jpg size = 1014577, size_out = 0 True 1
Fn
Read m3ksaTaVuXM_ADoCvA.jpg size = 1048576, size_out = 92134 True 1
Fn
Data
Read m3ksaTaVuXM_ADoCvA.jpg size = 956442, size_out = 0 True 1
Fn
Read m3Vfo.png size = 1048576, size_out = 93174 True 1
Fn
Data
Read m3Vfo.png size = 955402, size_out = 0 True 1
Fn
Read Pe_4G6TNHBiw7.gif size = 1048576, size_out = 70389 True 1
Fn
Data
Read Pe_4G6TNHBiw7.gif size = 978187, size_out = 0 True 1
Fn
Read q0 y.bmp size = 1048576, size_out = 14550 True 1
Fn
Data
Read q0 y.bmp size = 1034026, size_out = 0 True 1
Fn
Read QX41YSfi6.bmp size = 1048576, size_out = 86135 True 1
Fn
Data
Read QX41YSfi6.bmp size = 962441, size_out = 0 True 1
Fn
Read Saved Pictures\desktop.ini size = 1048576, size_out = 190 True 1
Fn
Data
Read Saved Pictures\desktop.ini size = 1048386, size_out = 0 True 1
Fn
Read sj6 1xhDAi0ypw.jpg size = 1048576, size_out = 22861 True 1
Fn
Data
Read sj6 1xhDAi0ypw.jpg size = 1025715, size_out = 0 True 1
Fn
Read svWwwq0D.png size = 1048576, size_out = 92299 True 1
Fn
Data
Read svWwwq0D.png size = 956277, size_out = 0 True 1
Fn
Read W-jIjn6.gif size = 1048576, size_out = 63593 True 1
Fn
Data
Read W-jIjn6.gif size = 984983, size_out = 0 True 1
Fn
Read Ww lmr4coeaZVkLVzHS.jpg size = 1048576, size_out = 6330 True 1
Fn
Data
Read Ww lmr4coeaZVkLVzHS.jpg size = 1042246, size_out = 0 True 1
Fn
Read YBodpCQ1OYUO B.gif size = 1048576, size_out = 93957 True 1
Fn
Data
Read YBodpCQ1OYUO B.gif size = 954619, size_out = 0 True 1
Fn
Read yova8.bmp size = 1048576, size_out = 23571 True 1
Fn
Data
Read yova8.bmp size = 1025005, size_out = 0 True 1
Fn
Read yWEcS.bmp size = 1048576, size_out = 11930 True 1
Fn
Data
Read yWEcS.bmp size = 1036646, size_out = 0 True 1
Fn
Read y_QmYlvwtNWjwI0tZ.bmp size = 1048576, size_out = 48977 True 1
Fn
Data
Read y_QmYlvwtNWjwI0tZ.bmp size = 999599, size_out = 0 True 1
Fn
Read Z8PEjH5b.jpg size = 1048576, size_out = 83459 True 1
Fn
Data
Read Z8PEjH5b.jpg size = 965117, size_out = 0 True 1
Fn
Read zdKqdR.png size = 1048576, size_out = 43236 True 1
Fn
Data
Read zdKqdR.png size = 1005340, size_out = 0 True 1
Fn
Read zoYWy0tnNuqg-Zdh4.gif size = 1048576, size_out = 91998 True 1
Fn
Data
Read zoYWy0tnNuqg-Zdh4.gif size = 956578, size_out = 0 True 1
Fn
Write Pictures.rar size = 8 True 2
Fn
Data
Write Pictures.rar size = 17 True 2
Fn
Data
Write Pictures.rar size = 48928 True 1
Fn
Data
Write Pictures.rar size = 93 True 6
Fn
Data
Write Pictures.rar size = 75232 True 1
Fn
Data
Write Pictures.rar size = 104 True 3
Fn
Data
Write Pictures.rar size = 73808 True 1
Fn
Data
Write Pictures.rar size = 108 True 2
Fn
Data
Write Pictures.rar size = 15248 True 1
Fn
Data
Write Pictures.rar size = 99 True 3
Fn
Data
Write Pictures.rar size = 43552 True 1
Fn
Data
Write Pictures.rar size = 106 True 2
Fn
Data
Write Pictures.rar size = 20832 True 1
Fn
Data
Write Pictures.rar size = 102 True 3
Fn
Data
Write Pictures.rar size = 42528 True 1
Fn
Data
Write Pictures.rar size = 97 True 3
Fn
Data
Write Pictures.rar size = 87728 True 1
Fn
Data
Write Pictures.rar size = 82160 True 1
Fn
Data
Write Pictures.rar size = 100 True 4
Fn
Data
Write Pictures.rar size = 34288 True 1
Fn
Data
Write Pictures.rar size = 107 True 2
Fn
Data
Write Pictures.rar size = 83216 True 1
Fn
Data
Write Pictures.rar size = 160 True 2
Fn
Data
Write Pictures.rar size = 105 True 4
Fn
Data
Write Pictures.rar size = 3744 True 1
Fn
Data
Write Pictures.rar size = 208 True 1
Fn
Data
Write Pictures.rar size = 7008 True 1
Fn
Data
Write Pictures.rar size = 46608 True 1
Fn
Data
Write Pictures.rar size = 57456 True 1
Fn
Data
Write Pictures.rar size = 96688 True 1
Fn
Data
Write Pictures.rar size = 101872 True 1
Fn
Data
Write Pictures.rar size = 103 True 1
Fn
Data
Write Pictures.rar size = 82176 True 1
Fn
Data
Write Pictures.rar size = 94 True 2
Fn
Data
Write Pictures.rar size = 97248 True 1
Fn
Data
Write Pictures.rar size = 59504 True 1
Fn
Data
Write Pictures.rar size = 95 True 2
Fn
Data
Write Pictures.rar size = 49024 True 1
Fn
Data
Write Pictures.rar size = 34160 True 1
Fn
Data
Write Pictures.rar size = 92320 True 1
Fn
Data
Write Pictures.rar size = 93376 True 1
Fn
Data
Write Pictures.rar size = 70560 True 1
Fn
Data
Write Pictures.rar size = 101 True 1
Fn
Data
Write Pictures.rar size = 14576 True 1
Fn
Data
Write Pictures.rar size = 92 True 1
Fn
Data
Write Pictures.rar size = 86336 True 1
Fn
Data
Write Pictures.rar size = 22944 True 1
Fn
Data
Write Pictures.rar size = 92496 True 1
Fn
Data
Write Pictures.rar size = 96 True 2
Fn
Data
Write Pictures.rar size = 63728 True 1
Fn
Data
Write Pictures.rar size = 6400 True 1
Fn
Data
Write Pictures.rar size = 94144 True 1
Fn
Data
Write Pictures.rar size = 23648 True 1
Fn
Data
Write Pictures.rar size = 11952 True 1
Fn
Data
Write Pictures.rar size = 49056 True 1
Fn
Data
Write Pictures.rar size = 83680 True 1
Fn
Data
Write Pictures.rar size = 43344 True 1
Fn
Data
Write Pictures.rar size = 92192 True 1
Fn
Data
Write Pictures.rar size = 42 True 1
Fn
Data
Write Pictures.rar size = 45 True 1
Fn
Data
Write Pictures.rar size = 19 True 1
Fn
Data
Write Pictures.rar size = 4061 True 1
Fn
Data
Delete Directory Saved Pictures - True 1
Fn
Delete Directory Camera Roll - True 1
Fn
Delete zoYWy0tnNuqg-Zdh4.gif - True 1
Fn
Delete zdKqdR.png - True 1
Fn
Delete Z8PEjH5b.jpg - True 1
Fn
Delete y_QmYlvwtNWjwI0tZ.bmp - True 1
Fn
Delete yWEcS.bmp - True 1
Fn
Delete yova8.bmp - True 1
Fn
Delete YBodpCQ1OYUO B.gif - True 1
Fn
Delete Ww lmr4coeaZVkLVzHS.jpg - True 1
Fn
Delete W-jIjn6.gif - True 1
Fn
Delete svWwwq0D.png - True 1
Fn
Delete sj6 1xhDAi0ypw.jpg - True 1
Fn
Delete Saved Pictures\desktop.ini - True 1
Fn
Delete QX41YSfi6.bmp - True 1
Fn
Delete q0 y.bmp - True 1
Fn
Delete Pe_4G6TNHBiw7.gif - True 1
Fn
Delete m3Vfo.png - True 1
Fn
Delete m3ksaTaVuXM_ADoCvA.jpg - True 1
Fn
Delete KmDsFaqbjMnNn4BN.jpg - True 1
Fn
Delete job -V_cE7uVrHssoWW.jpg - True 1
Fn
Delete HPs4cKd.bmp - True 1
Fn
Delete hh1Bz.png - True 1
Fn
Delete H7Jzn2.png - True 1
Fn
Delete H6PwCN3oyZKOwFQ.png - True 1
Fn
Delete gTXyE1NkEEb.jpg - True 1
Fn
Delete g6r96fa7GyN6.gif - True 1
Fn
Delete FiPd_4qvOx8j.jpg - True 1
Fn
Delete dw0z-rObH0-zF2.png - True 1
Fn
Delete desktop.ini - True 1
Fn
Delete Cg4L5J0Hp5g.bmp - True 1
Fn
Delete Camera Roll\desktop.ini - True 1
Fn
Delete c9ZaReaCiTG.png - True 1
Fn
Delete awTUht89JcK2K D7j9i.png - True 1
Fn
Delete aHz4Hx-PBeuX.png - True 1
Fn
Delete A4ii4MOpBgpQwQBT.jpg - True 1
Fn
Delete 9BtQRHA1y.gif - True 1
Fn
Delete 8eYKFrOBbq-TuX.bmp - True 1
Fn
Delete 7ZwWGMcIaUjWjMVJAe.jpg - True 1
Fn
Delete 6xi8hATC8ep.gif - True 1
Fn
Delete 5qnTEjfG9KjtBUIojvlC.png - True 1
Fn
Delete 1Uee5Fu 2XCwi8fG.gif - True 1
Fn
Delete 17Kei.bmp - True 1
Fn
Registry (243)
»
Operation Key Additional Information Success Count Logfile
Create Key HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes - True 2
Fn
Create Key HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths - True 4
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - True 3
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Paths - False 5
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\WinRAR\Policy - False 4
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Policy - False 4
Fn
Open Key HKEY_LOCAL_MACHINE\Software\WinRAR - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\General - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Extraction - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 - True 81
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Profiles\5 - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Compression - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList - False 8
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths - False 9
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates - False 5
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates - False 5
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR\Interface - True 2
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = LanguageFolder, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = LanguageFolder, data = 33, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = VerInfo, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR value_name = rarkey, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = Priority, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR value_name = rarreg.key, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\General value_name = SMP, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Default, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 2
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcName, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileNames False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ExclNames True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ExclNames, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = StoreNames True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = StoreNames, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = UseRAR, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RAR5, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXModule, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFX, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXIcon, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXLogo, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SFXElevate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtFile, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtDataWide, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtTextWide, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = CmtTextData, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolumeSize, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolSizeMod, data = 2, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VolPause, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = OldVolNames, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecVolNumber, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Update, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Fresh, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SyncFiles, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Overwrite, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Move, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcRecBin, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcWipe, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = WipeIfPassword, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Solid, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Test, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecEnabled, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = RecSize, data = 4294967293, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Recovery, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EraseDest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = AddArcOnly, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ClearArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Lock, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Method, data = 3, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = DictSizeLZ, data = 4194304, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = DictSize, data = 33554432, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PasswordData, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EncryptHeaders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ZipLegacyEncrypt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = OpenShared, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ProcessOwners, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveStreams, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveSymLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SaveHardLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Background, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = WaitForOther, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = Shutdown, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = GenerateArcName, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = VersionControl, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = BLAKE2, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileCopies, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = QuickOpen, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = GenerateMask, data = yyyymmddhhmmss, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileTimeMode, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileDays, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileHours, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = FileMinutes, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcTimeOriginal, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ArcTimeLatest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = mtime, data = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ctime, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = atime, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsAbs, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsNone, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PathsAbsDrive, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = ImmExec, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArcDoubleExt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = SeparateArcSubfolders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = EmailArcTo, type = REG_SZ True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 value_name = PackDetails, type = REG_BINARY True 1
Fn
Data
Read Value HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes value_name = ActivePath, data = 0, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Interface value_name = SystemProgressBar, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR\Interface value_name = TaskbarProgressBar, data = 1, type = REG_NONE False 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes value_name = ShellExtBMP, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes value_name = ShellExtIcon, size = 2, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths value_name = name, data = 120, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths value_name = size, data = 80, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths value_name = type, data = 120, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths value_name = mtime, data = 100, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Module (39)
»
Operation Module Additional Information Success Count Logfile
Load api-ms-win-core-synch-l1-2-0 base_address = 0x7ff92f150000 True 2
Fn
Load api-ms-win-core-fibers-l1-1-1 base_address = 0x7ff92f150000 True 2
Fn
Load api-ms-win-core-localization-l1-2-1 base_address = 0x7ff92f150000 True 1
Fn
Load C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll base_address = 0x0 False 1
Fn
Load C:\WINDOWS\system32\riched20.dll base_address = 0x7ff912450000 True 1
Fn
Load C:\WINDOWS\system32\Crypt32.dll base_address = 0x7ff92e880000 True 1
Fn
Load api-ms-win-appmodel-runtime-l1-1-1 base_address = 0x7ff92e3f0000 True 1
Fn
Get Handle c:\windows\system32\kernel32.dll base_address = 0x7ff92fdd0000 True 3
Fn
Get Handle c:\users\fd1hvy\appdata\local\temp\winrar.exe base_address = 0x7ff6f74d0000, flags = GET_MODULE_HANDLE_EX_FLAG_UNCHANGED_REFCOUNT, GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS True 1
Fn
Get Handle c:\users\fd1hvy\appdata\local\temp\winrar.exe base_address = 0x7ff6f74d0000 True 2
Fn
Get Handle mscoree.dll - False 1
Fn
Get Filename - process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 260 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 2
Fn
Get Filename C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 3
Fn
Get Address c:\windows\system32\kernelbase.dll function = InitializeCriticalSectionEx, address_out = 0x7ff92f1ad580 True 2
Fn
Get Address c:\windows\system32\kernelbase.dll function = FlsAlloc, address_out = 0x7ff92f1bd3e0 True 2
Fn
Get Address c:\windows\system32\kernelbase.dll function = FlsSetValue, address_out = 0x7ff92f198c10 True 2
Fn
Get Address c:\windows\system32\kernelbase.dll function = FlsGetValue, address_out = 0x7ff92f192340 True 1
Fn
Get Address c:\windows\system32\kernelbase.dll function = LCMapStringEx, address_out = 0x7ff92f17c800 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = InitializeConditionVariable, address_out = 0x7ff931fb35c0 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SleepConditionVariableCS, address_out = 0x7ff92f1be960 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = WakeAllConditionVariable, address_out = 0x7ff931fa6090 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetDllDirectoryW, address_out = 0x7ff92fdee3c0 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetDefaultDllDirectories, address_out = 0x7ff92f228b70 True 1
Fn
Get Address c:\windows\system32\crypt32.dll function = CryptProtectMemory, address_out = 0x7ff92d8c1770 True 1
Fn
Get Address c:\windows\system32\crypt32.dll function = CryptUnprotectMemory, address_out = 0x7ff92d8c17a0 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = CompareStringOrdinal, address_out = 0x7ff92fde8fb0 True 1
Fn
Get Address c:\windows\system32\kernel.appcore.dll function = GetCurrentPackageId, address_out = 0x7ff92e3f2b30 True 1
Fn
Window (6)
»
Operation Window Name Additional Information Success Count Logfile
Create WinRAR class_name = WinRarWindow, wndproc_parameter = 0 True 1
Fn
Create - class_name = SysListView32, wndproc_parameter = 0 True 1
Fn
Create - class_name = tooltips_class32, wndproc_parameter = 0 True 1
Fn
Create - class_name = tooltips_class32, wndproc_parameter = 0 True 1
Fn
Find - class_name = WinRarWindow True 1
Fn
Find - class_name = WinRarWindow True 1
Fn
Keyboard (8)
»
Operation Additional Information Success Count Logfile
Get Info type = KB_CODEPAGE, result_out = 437 True 1
Fn
Read virtual_key_code = VK_SHIFT, result_out = 0 True 7
Fn
System (819)
»
Operation Additional Information Success Count Logfile
Get Time type = Performance Ctr, time = 14920805244 True 1
Fn
Get Time type = System Time, time = 2019-03-31 21:13:35 (UTC) True 1
Fn
Get Time type = Local Time, time = 2019-03-31 23:13:38 (Local Time) True 1
Fn
Get Time type = Performance Ctr, time = 15224004289 True 1
Fn
Get Time type = Ticks, time = 152781 True 1
Fn
Get Time type = Performance Ctr, time = 15281653057 True 1
Fn
Get Time type = Performance Ctr, time = 15282303572 True 1
Fn
Get Time type = Ticks, time = 153546 True 3
Fn
Get Time type = System Time, time = 2019-03-31 21:13:40 (UTC) True 5
Fn
Get Time type = Performance Ctr, time = 15384843085 True 1
Fn
Get Time type = Performance Ctr, time = 15385165545 True 1
Fn
Get Time type = Ticks, time = 153828 True 1
Fn
Get Time type = Ticks, time = 154250 True 2
Fn
Get Time type = Performance Ctr, time = 15428579620 True 1
Fn
Get Time type = Performance Ctr, time = 15429182027 True 1
Fn
Get Time type = Ticks, time = 154265 True 4
Fn
Get Time type = Performance Ctr, time = 15430284429 True 1
Fn
Get Time type = Ticks, time = 154406 True 4
Fn
Get Time type = Performance Ctr, time = 15444704119 True 1
Fn
Get Time type = Ticks, time = 154718 True 6
Fn
Get Time type = Performance Ctr, time = 15475913466 True 1
Fn
Get Time type = Performance Ctr, time = 15476004927 True 1
Fn
Get Time type = Ticks, time = 154734 True 4
Fn
Get Time type = Performance Ctr, time = 15477639772 True 1
Fn
Get Time type = Ticks, time = 154750 True 10
Fn
Get Time type = Performance Ctr, time = 15478554322 True 1
Fn
Get Time type = Performance Ctr, time = 15478645452 True 1
Fn
Get Time type = Performance Ctr, time = 15479195811 True 1
Fn
Get Time type = Ticks, time = 154765 True 1
Fn
Get Time type = Ticks, time = 155296 True 1
Fn
Get Time type = System Time, time = 2019-03-31 21:13:41 (UTC) True 9
Fn
Get Time type = Performance Ctr, time = 15552745954 True 1
Fn
Get Time type = Ticks, time = 155500 True 14
Fn
Get Time type = Performance Ctr, time = 15552894602 True 1
Fn
Get Time type = Performance Ctr, time = 15553461517 True 1
Fn
Get Time type = Performance Ctr, time = 15553869096 True 1
Fn
Get Time type = Performance Ctr, time = 15553969903 True 1
Fn
Get Time type = Ticks, time = 155515 True 15
Fn
Get Time type = Performance Ctr, time = 15554382242 True 1
Fn
Get Time type = Performance Ctr, time = 15554972683 True 1
Fn
Get Time type = Performance Ctr, time = 15555041538 True 1
Fn
Get Time type = Performance Ctr, time = 15555267540 True 1
Fn
Get Time type = Ticks, time = 155531 True 15
Fn
Get Time type = Performance Ctr, time = 15555881697 True 1
Fn
Get Time type = Performance Ctr, time = 15555982959 True 1
Fn
Get Time type = Performance Ctr, time = 15556310925 True 1
Fn
Get Time type = Performance Ctr, time = 15556911962 True 1
Fn
Get Time type = Performance Ctr, time = 15557007078 True 1
Fn
Get Time type = Ticks, time = 155546 True 4
Fn
Get Time type = Performance Ctr, time = 15558169755 True 1
Fn
Get Time type = Ticks, time = 155703 True 6
Fn
Get Time type = Performance Ctr, time = 15573580648 True 1
Fn
Get Time type = Performance Ctr, time = 15573680198 True 1
Fn
Get Time type = Ticks, time = 155718 True 14
Fn
Get Time type = Performance Ctr, time = 15574676739 True 1
Fn
Get Time type = Performance Ctr, time = 15575338188 True 1
Fn
Get Time type = Performance Ctr, time = 15575424647 True 1
Fn
Get Time type = Performance Ctr, time = 15575707603 True 1
Fn
Get Time type = Ticks, time = 155734 True 11
Fn
Get Time type = Performance Ctr, time = 15576465158 True 1
Fn
Get Time type = Performance Ctr, time = 15576555848 True 1
Fn
Get Time type = Performance Ctr, time = 15577159390 True 1
Fn
Get Time type = Ticks, time = 155750 True 1
Fn
Get Time type = Performance Ctr, time = 15577874247 True 1
Fn
Get Time type = Ticks, time = 155890 True 18
Fn
Get Time type = Performance Ctr, time = 15592099498 True 1
Fn
Get Time type = Performance Ctr, time = 15592560719 True 1
Fn
Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 14
Fn
Get Time type = Performance Ctr, time = 15593021908 True 1
Fn
Get Time type = Performance Ctr, time = 15593079817 True 1
Fn
Get Time type = Performance Ctr, time = 15593228704 True 1
Fn
Get Time type = Ticks, time = 155906 True 20
Fn
Get Time type = Performance Ctr, time = 15593595182 True 1
Fn
Get Time type = Performance Ctr, time = 15593666729 True 1
Fn
Get Time type = Performance Ctr, time = 15594095924 True 1
Fn
Get Time type = Performance Ctr, time = 15594466548 True 1
Fn
Get Time type = Performance Ctr, time = 15594536010 True 1
Fn
Get Time type = Performance Ctr, time = 15594726747 True 1
Fn
Get Time type = Ticks, time = 155921 True 11
Fn
Get Time type = Performance Ctr, time = 15595321350 True 1
Fn
Get Time type = Performance Ctr, time = 15595420948 True 1
Fn
Get Time type = Performance Ctr, time = 15595802347 True 1
Fn
Get Time type = Ticks, time = 156250 True 5
Fn
Get Time type = Performance Ctr, time = 15628770326 True 1
Fn
Get Time type = Performance Ctr, time = 15629057832 True 1
Fn
Get Time type = Ticks, time = 156265 True 10
Fn
Get Time type = Performance Ctr, time = 15629936552 True 1
Fn
Get Time type = Performance Ctr, time = 15630625888 True 1
Fn
Get Time type = Performance Ctr, time = 15630724071 True 1
Fn
Get Time type = Ticks, time = 156281 True 4
Fn
Get Time type = Performance Ctr, time = 15631980409 True 1
Fn
Get Time type = Ticks, time = 156296 True 6
Fn
Get Time type = Performance Ctr, time = 15632952118 True 1
Fn
Get Time type = Performance Ctr, time = 15633055075 True 1
Fn
Get Time type = Ticks, time = 156312 True 10
Fn
Get Time type = Performance Ctr, time = 15634290097 True 1
Fn
Get Time type = Performance Ctr, time = 15635046995 True 1
Fn
Get Time type = Performance Ctr, time = 15635150620 True 1
Fn
Get Time type = Ticks, time = 156484 True 4
Fn
Get Time type = Performance Ctr, time = 15652073934 True 1
Fn
Get Time type = Ticks, time = 156500 True 5
Fn
Get Time type = Performance Ctr, time = 15653992504 True 1
Fn
Get Time type = Performance Ctr, time = 15654119859 True 1
Fn
Get Time type = Ticks, time = 156515 True 5
Fn
Get Time type = Performance Ctr, time = 15655737210 True 1
Fn
Get Time type = Ticks, time = 156531 True 2
Fn
Get Time type = Performance Ctr, time = 15657293993 True 1
Fn
Get Time type = Ticks, time = 156718 True 4
Fn
Get Time type = Performance Ctr, time = 15675522978 True 1
Fn
Get Time type = Ticks, time = 156734 True 14
Fn
Get Time type = Performance Ctr, time = 15676323380 True 1
Fn
Get Time type = Performance Ctr, time = 15677025788 True 1
Fn
Get Time type = Performance Ctr, time = 15677116797 True 1
Fn
Get Time type = Performance Ctr, time = 15677469922 True 1
Fn
Get Time type = Ticks, time = 156750 True 16
Fn
Get Time type = Performance Ctr, time = 15678083973 True 1
Fn
Get Time type = Performance Ctr, time = 15678173538 True 1
Fn
Get Time type = Performance Ctr, time = 15678451820 True 1
Fn
Get Time type = Performance Ctr, time = 15678973106 True 1
Fn
Get Time type = Performance Ctr, time = 15679074681 True 1
Fn
Get Time type = Ticks, time = 156765 True 10
Fn
Get Time type = Performance Ctr, time = 15679713687 True 1
Fn
Get Time type = Performance Ctr, time = 15680500289 True 1
Fn
Get Time type = Performance Ctr, time = 15680602506 True 1
Fn
Get Time type = Ticks, time = 156875 True 4
Fn
Get Time type = Performance Ctr, time = 15691212358 True 1
Fn
Get Time type = Ticks, time = 156890 True 10
Fn
Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 15
Fn
Get Time type = Performance Ctr, time = 15692344301 True 1
Fn
Get Time type = Performance Ctr, time = 15692440011 True 1
Fn
Get Time type = Performance Ctr, time = 15692934793 True 1
Fn
Get Time type = Ticks, time = 156906 True 16
Fn
Get Time type = Performance Ctr, time = 15693555347 True 1
Fn
Get Time type = Performance Ctr, time = 15693628297 True 1
Fn
Get Time type = Performance Ctr, time = 15693818389 True 1
Fn
Get Time type = Performance Ctr, time = 15694202600 True 1
Fn
Get Time type = Performance Ctr, time = 15694378043 True 1
Fn
Get Time type = Ticks, time = 156921 True 6
Fn
Get Time type = Performance Ctr, time = 15695152515 True 1
Fn
Get Time type = Performance Ctr, time = 15696388153 True 1
Fn
Get Time type = Ticks, time = 156937 True 14
Fn
Get Time type = Performance Ctr, time = 15696649617 True 1
Fn
Get Time type = Performance Ctr, time = 15696675958 True 1
Fn
Get Time type = Performance Ctr, time = 15697000690 True 1
Fn
Get Time type = Performance Ctr, time = 15697063711 True 1
Fn
Get Time type = Ticks, time = 157250 True 1
Fn
Get Time type = Performance Ctr, time = 15729309834 True 1
Fn
Get Time type = Ticks, time = 157265 True 4
Fn
Get Time type = Ticks, time = 157281 True 11
Fn
Get Time type = Performance Ctr, time = 15730959815 True 1
Fn
Get Time type = Performance Ctr, time = 15731095609 True 1
Fn
Get Time type = Performance Ctr, time = 15731757621 True 1
Fn
Get Time type = Performance Ctr, time = 15732533587 True 1
Fn
Get Time type = Ticks, time = 157296 True 14
Fn
Get Time type = Performance Ctr, time = 15732646548 True 1
Fn
Get Time type = Performance Ctr, time = 15733201467 True 1
Fn
Get Time type = Performance Ctr, time = 15733794966 True 1
Fn
Get Time type = Performance Ctr, time = 15733860632 True 1
Fn
Get Time type = Ticks, time = 157312 True 10
Fn
Get Time type = Performance Ctr, time = 15734304294 True 1
Fn
Get Time type = Performance Ctr, time = 15734664622 True 1
Fn
Get Time type = Performance Ctr, time = 15734774033 True 1
Fn
Get Time type = Ticks, time = 157453 True 4
Fn
Get Time type = Performance Ctr, time = 15749337425 True 1
Fn
Get Time type = Ticks, time = 157468 True 10
Fn
Get Time type = Performance Ctr, time = 15750206567 True 1
Fn
Get Time type = Performance Ctr, time = 15750279437 True 1
Fn
Get Time type = Performance Ctr, time = 15750828265 True 1
Fn
Get Time type = Ticks, time = 157484 True 16
Fn
Get Time type = Performance Ctr, time = 15751461766 True 1
Fn
Get Time type = Performance Ctr, time = 15751575632 True 1
Fn
Get Time type = Performance Ctr, time = 15751784888 True 1
Fn
Get Time type = Performance Ctr, time = 15752162644 True 1
Fn
Get Time type = Performance Ctr, time = 15752277835 True 1
Fn
Get Time type = Ticks, time = 157500 True 10
Fn
Get Time type = Performance Ctr, time = 15752824991 True 1
Fn
Get Time type = Performance Ctr, time = 15753569568 True 1
Fn
Get Time type = Performance Ctr, time = 15753678170 True 1
Fn
Get Time type = Ticks, time = 157609 True 4
Fn
Get Time type = Performance Ctr, time = 15764695762 True 1
Fn
Get Time type = Ticks, time = 157625 True 10
Fn
Get Time type = Performance Ctr, time = 15766041990 True 1
Fn
Get Time type = Performance Ctr, time = 15766128159 True 1
Fn
Get Time type = Performance Ctr, time = 15766465471 True 1
Fn
Get Time type = Ticks, time = 157640 True 10
Fn
Get Time type = Performance Ctr, time = 15767264336 True 1
Fn
Get Time type = Performance Ctr, time = 15767369020 True 1
Fn
Get Time type = Performance Ctr, time = 15767976645 True 1
Fn
Get Time type = Ticks, time = 157656 True 4
Fn
Get Time type = Ticks, time = 158218 True 4
Fn
Get Time type = Performance Ctr, time = 15825376402 True 1
Fn
Get Time type = Ticks, time = 158640 True 2
Fn
Get Time type = Performance Ctr, time = 15868468578 True 1
Fn
Get Time type = Ticks, time = 158656 True 2
Fn
Get Time type = Ticks, time = 158765 True 8
Fn
Get Time type = Performance Ctr, time = 15880163914 True 1
Fn
Get Time type = Performance Ctr, time = 15880516898 True 1
Fn
Get Time type = Ticks, time = 158781 True 4
Fn
Get Time type = Performance Ctr, time = 15881064514 True 1
Fn
Get Time type = Ticks, time = 158890 True 8
Fn
Get Time type = Performance Ctr, time = 15892858477 True 1
Fn
Get Time type = Performance Ctr, time = 15893163132 True 1
Fn
Get Time type = Ticks, time = 158906 True 16
Fn
Get Time type = Performance Ctr, time = 15893568187 True 1
Fn
Get Time type = Performance Ctr, time = 15893953439 True 1
Fn
Get Time type = Performance Ctr, time = 15894318606 True 1
Fn
Get Time type = Performance Ctr, time = 15894711984 True 1
Fn
Get Time type = Ticks, time = 159343 True 2
Fn
Get Time type = Performance Ctr, time = 15938780782 True 1
Fn
Get Time type = Ticks, time = 159359 True 18
Fn
Get Time type = Performance Ctr, time = 15939139735 True 1
Fn
Get Time type = Performance Ctr, time = 15939483521 True 1
Fn
Get Time type = Performance Ctr, time = 15939842493 True 1
Fn
Get Time type = Performance Ctr, time = 15940124430 True 1
Fn
Get Time type = Ticks, time = 159375 True 16
Fn
Get Time type = Performance Ctr, time = 15940597327 True 1
Fn
Get Time type = Performance Ctr, time = 15940930194 True 1
Fn
Get Time type = Performance Ctr, time = 15941240161 True 1
Fn
Get Time type = Performance Ctr, time = 15941519501 True 1
Fn
Get Time type = Ticks, time = 159390 True 16
Fn
Get Time type = Performance Ctr, time = 15942003925 True 1
Fn
Get Time type = Performance Ctr, time = 15942327232 True 1
Fn
Get Time type = Performance Ctr, time = 15942659247 True 1
Fn
Get Time type = Performance Ctr, time = 15943047430 True 1
Fn
Get Time type = Ticks, time = 159531 True 12
Fn
Get Time type = Performance Ctr, time = 15956412971 True 1
Fn
Get Time type = Performance Ctr, time = 15956774790 True 1
Fn
Get Time type = Performance Ctr, time = 15957093506 True 1
Fn
Get Time type = Ticks, time = 159546 True 16
Fn
Get Time type = Performance Ctr, time = 15957764770 True 1
Fn
Get Time type = Performance Ctr, time = 15958129288 True 1
Fn
Get Time type = Performance Ctr, time = 15958492398 True 1
Fn
Get Time type = Performance Ctr, time = 15958842777 True 1
Fn
Get Time type = Ticks, time = 159562 True 4
Fn
Get Time type = Performance Ctr, time = 15959187191 True 1
Fn
Get Time type = Ticks, time = 159656 True 2
Fn
Get Time type = Performance Ctr, time = 15980513390 True 1
Fn
Get Time type = Ticks, time = 159765 True 2
Fn
Get Time type = Ticks, time = 159781 True 12
Fn
Get Time type = Performance Ctr, time = 15981256637 True 1
Fn
Get Time type = Performance Ctr, time = 15981816437 True 1
Fn
Get Time type = Performance Ctr, time = 15982140310 True 1
Fn
Get Time type = Ticks, time = 159796 True 8
Fn
Get Time type = Performance Ctr, time = 15982667732 True 1
Fn
Get Time type = Performance Ctr, time = 15983103393 True 1
Fn
Get Time type = Ticks, time = 160359 True 4
Fn
Get Time type = Performance Ctr, time = 16039321724 True 1
Fn
Get Time type = Ticks, time = 160453 True 2
Fn
Get Time type = Performance Ctr, time = 16051321130 True 1
Fn
Get Time type = Ticks, time = 160484 True 2
Fn
Get Time type = Ticks, time = 160656 True 8
Fn
Get Time type = Performance Ctr, time = 16069339866 True 1
Fn
Get Time type = Performance Ctr, time = 16069733648 True 1
Fn
Get Time type = Ticks, time = 160671 True 4
Fn
Get Time type = Performance Ctr, time = 16070299898 True 1
Fn
Get Time type = Ticks, time = 160765 True 4
Fn
Get Time type = Performance Ctr, time = 16080150242 True 1
Fn
Get Time type = Performance Ctr, time = 16094005803 True 1
Fn
Get Info type = Operating System True 2
Fn
Get Info type = System Directory, result_out = C:\WINDOWS\system32 True 2
Fn
Mutex (2)
»
Operation Additional Information Success Count Logfile
Create mutex_name = WinRAR_Busy True 1
Fn
Release mutex_name = WinRAR_Busy False 1
Fn
Environment (1)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 1
Fn
Data
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image