42dc69a5...226b | Sequential Behavior
Try VMRay Analyzer
VTI SCORE: 93/100
Dynamic Analysis Report
Classification: Ransomware, Wiper, Trojan, Dropper

Monitored Processes

Process Overview
»
ID PID Monitor Reason Integrity Level Image Name Command Line Origin ID
#1 0xe64 Analysis Target High (Elevated) unnam3d - ransm.exe "C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe" -
#3 0xf00 Child Process High (Elevated) cmd.exe "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Desktop && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Desktop * #1
#4 0x46c Child Process High (Elevated) cmd.exe "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Documents && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Documents * #1
#6 0xa9c Child Process High (Elevated) cmd.exe "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Pictures && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Pictures * #1
#9 0xe3c Child Process High (Elevated) winrar.exe C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Desktop * #3
#10 0xf64 Child Process High (Elevated) winrar.exe C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Documents * #4
#11 0x754 Child Process High (Elevated) winrar.exe C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Pictures * #6

Behavior Information - Sequential View

Process #1: unnam3d - ransm.exe
421 0
»
Information Value
ID #1
File Name c:\users\fd1hvy\desktop\unnam3d - ransm.exe
Command Line "C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe"
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:25, Reason: Analysis Target
Unmonitor End Time: 00:04:33, Reason: Terminated by Timeout
Monitor Duration 00:04:07
OS Process Information
»
Information Value
PID 0xe64
Parent PID 0x860 (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x EB4
0x 4F0
0x 60
0x B6C
0x F50
0x BEC
0x 490
0x 260
0x 8F0
0x 1A4
0x 2D0
0x 3CC
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points YARA Actions
clrjit.dll 0x74330000 0x743AFFFF Marked Writable - 32-bit - False
buffer 0x049D0000 0x049D0FFF First Execution - 32-bit 0x049D0000 False
clrjit.dll 0x74330000 0x743AFFFF Content Changed - 32-bit 0x7439A2A6, 0x74369E12 False
clrjit.dll 0x74330000 0x743AFFFF Content Changed - 32-bit 0x74391000 False
buffer 0x06567000 0x06567FFF First Execution - 32-bit 0x06567000 False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe 2.17 MB MD5: 1e3a2a966f593ad33125f26916267008
SHA1: 38b1a547ddee671edeee7385cac138458a6a6858
SHA256: b18c9b9200e354f81882b29dc8143ec5d6f2b731cf4c7da3800e339ffb3c8827
SSDeep: 49152:m2IoCBtJnxlyU/mWhRcQYhie6/UIdjjQuctXnFDu3nAzNjteyUHBdH3y2:xrCBrtcy/lfkD0nANte9BpC2
False
c:\users\fd1hvy\appdata\local\temp\wallpaper.png 679.01 KB MD5: 4eaf9cbc1438214622460aa18fbf050d
SHA1: 543c921d0f75bb5a8a9cd1bf1096d2d0af69170e
SHA256: a935f1af2674e6577a02f7b2f53ad98612fd55dd2f3f51cb476767c01f4076e8
SSDeep: 12288:whHUpY2wdt2pD5969U59o6xM4T1GFg6qaUlZCZSjX4lZuuS+L+26TCNYBuGAR:va2K2pD596mzosrGFg6qao0SjXGuu/+S
False
Threads
Thread 0xeb4
421 0
»
Category Operation Information Success Count Logfile
User Lookup Privilege privilege = SeDebugPrivilege, luid = 20 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\ntdll.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSCOREE.DLL, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\KERNEL32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\KERNELBASE.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\apphelp.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ADVAPI32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\msvcrt.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\sechost.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\RPCRT4.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\SspiCli.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\CRYPTBASE.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\bcryptPrimitives.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\SHLWAPI.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\combase.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ucrtbase.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\GDI32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\gdi32full.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\msvcp_win.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\USER32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\win32u.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\IMM32.DLL, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\kernel.appcore.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\VERSION.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSVCR120_CLR0400.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\f12799647dc4f4abd2f0f17790337f04\mscorlib.ni.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ole32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\system32\uxtheme.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\OLEAUT32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\fcfb8bac8ea9a0e69d72c350b22f8e3f\System.ni.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\psapi.dll, size = 2048 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AppContext False 1
Fn
File Get Info filename = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, type = file_attributes True 1
Fn
Module Load module_name = mscorjit.dll, base_address = 0x0 False 1
Fn
Module Load module_name = clrjit.dll, base_address = 0x74330000 True 1
Fn
Module Get Address module_name = c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll, function = getJit, address_out = 0x74383d60 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\ntdll.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSCOREE.DLL, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\KERNEL32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\KERNELBASE.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\apphelp.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ADVAPI32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\msvcrt.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\sechost.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\RPCRT4.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\SspiCli.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\CRYPTBASE.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\bcryptPrimitives.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\SHLWAPI.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\combase.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ucrtbase.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\GDI32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\gdi32full.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\msvcp_win.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\USER32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\win32u.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\IMM32.DLL, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\kernel.appcore.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\VERSION.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSVCR120_CLR0400.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\f12799647dc4f4abd2f0f17790337f04\mscorlib.ni.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\ole32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\system32\uxtheme.dll, size = 2048 True 1
Fn
Module Get Filename module_name = c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll, process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\OLEAUT32.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\fcfb8bac8ea9a0e69d72c350b22f8e3f\System.ni.dll, size = 2048 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, file_name_orig = C:\WINDOWS\System32\psapi.dll, size = 2048 True 1
Fn
File Get Info filename = C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, type = file_attributes True 2
Fn
File Create filename = C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, type = file_type True 2
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\XML False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\.NETFramework\XML False 1
Fn
File Get Info filename = C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, type = size, size_out = 0 True 1
Fn
File Read filename = C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, size = 4096, size_out = 4096 True 8
Fn
Data
File Read filename = C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, size = 4096, size_out = 3215 True 1
Fn
Data
File Read filename = C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, size = 4096, size_out = 0 True 1
Fn
File Get Info filename = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe.config, type = file_attributes False 2
Fn
Module Get Handle module_name = comctl32.dll, base_address = 0x0 False 1
Fn
Module Load module_name = comctl32.dll, base_address = 0x742a0000 True 1
Fn
Module Get Handle module_name = comctl32.dll, base_address = 0x0 False 1
Fn
Module Load module_name = comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\user32.dll, base_address = 0x74b70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x74600140 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 2
Fn
Window Create class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Window Set Attribute class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 1952448832 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework, value_name = DbgJITDebugLaunchSetting, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework, value_name = DbgManagedDebugger, type = REG_NONE False 1
Fn
Window Set Attribute class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 78513854 True 1
Fn
File Get Info filename = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe, type = file_attributes True 1
Fn
File Create filename = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe, type = file_type True 2
Fn
File Get Info filename = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe, type = size, size_out = 0 True 1
Fn
File Read filename = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe, size = 2876416, size_out = 2876416 True 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.413_none_55bc94a37c2a2854\comctl32.dll, base_address = 0x742a0000 True 9
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 2
Fn
Window Create window_name = .NET-BroadcastEventWindow.4.0.0.0.141b42a.0, class_name = .NET-BroadcastEventWindow.4.0.0.0.141b42a.0, wndproc_parameter = 0 True 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.413_none_55bc94a37c2a2854\comctl32.dll, base_address = 0x742a0000 True 5
Fn
File Get Info filename = C:\Users\FD1HVy\Desktop\UNNAM3D - RANSM.exe.config, type = file_attributes False 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.413_none_55bc94a37c2a2854\comctl32.dll, base_address = 0x742a0000 True 21
Fn
System Get Cursor x_out = 44, y_out = 346 True 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.413_none_55bc94a37c2a2854\comctl32.dll, base_address = 0x742a0000 True 1
Fn
System Get Cursor x_out = 44, y_out = 346 True 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.413_none_55bc94a37c2a2854\comctl32.dll, base_address = 0x742a0000 True 22
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
System Get Cursor x_out = 44, y_out = 346 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 1
Fn
Window Create window_name = UNNAM3D - R@NSOMEWARE!, class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Window Set Attribute window_name = UNNAM3D - R@NSOMEWARE!, class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 1952448832 True 1
Fn
Window Set Attribute window_name = UNNAM3D - R@NSOMEWARE!, class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 78514702 True 1
Fn
Window Set Attribute window_name = UNNAM3D - R@NSOMEWARE!, class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -8, new_long = 0 False 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
System Get Cursor x_out = 44, y_out = 346 True 1
Fn
Window Set Attribute window_name = UNNAM3D - R@NSOMEWARE!, class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -16, new_long = 46858240 True 1
Fn
Window Set Attribute window_name = UNNAM3D - R@NSOMEWARE!, class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -20, new_long = 327681 True 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 1
Fn
Window Create class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Window Set Attribute class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 1952448832 True 1
Fn
Window Set Attribute class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 78514742 True 1
Fn
Window Set Attribute class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -12, new_long = 393334 False 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 2
Fn
Window Create window_name = Discord: UNNAM3D#6666, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Window Set Attribute window_name = Discord: UNNAM3D#6666, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Window Set Attribute window_name = Discord: UNNAM3D#6666, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78514822 True 1
Fn
Window Set Attribute window_name = Discord: UNNAM3D#6666, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 458798 False 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 1
Fn
Window Create window_name = You will need to send an message to the below discord with a $50 amazon giftcard code. Then you will shortley get an message back with a password to unlock your files., class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Window Set Attribute window_name = You will need to send an message to the below discord with a $50 amazon giftcard code. Then you will shortley get an message back with a password to unlock your files., class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Window Set Attribute window_name = You will need to send an message to the below discord with a $50 amazon giftcard code. Then you will shortley get an message back with a password to unlock your files., class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78514862 True 1
Fn
Window Set Attribute window_name = You will need to send an message to the below discord with a $50 amazon giftcard code. Then you will shortley get an message back with a password to unlock your files., class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 131612 False 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 1
Fn
Window Create window_name = All your personal files have been locked and you need to pay a ransom to get them back. You will have 24 hours to pay or the password will be deleted of our servers making it impossible to get your files back. , class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Window Set Attribute window_name = All your personal files have been locked and you need to pay a ransom to get them back. You will have 24 hours to pay or the password will be deleted of our servers making it impossible to get your files back. , class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Window Set Attribute window_name = All your personal files have been locked and you need to pay a ransom to get them back. You will have 24 hours to pay or the password will be deleted of our servers making it impossible to get your files back. , class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78514902 True 1
Fn
Window Set Attribute window_name = All your personal files have been locked and you need to pay a ransom to get them back. You will have 24 hours to pay or the password will be deleted of our servers making it impossible to get your files back. , class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 589846 False 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 1
Fn
Window Create window_name = How do i pay?, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Window Set Attribute window_name = How do i pay?, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Window Set Attribute window_name = How do i pay?, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78514942 True 1
Fn
Window Set Attribute window_name = How do i pay?, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 393750 False 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 1
Fn
Window Create window_name = What Happend?, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Window Set Attribute window_name = What Happend?, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Window Set Attribute window_name = What Happend?, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78514982 True 1
Fn
Window Set Attribute window_name = What Happend?, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 131616 False 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 1
Fn
Window Create window_name = -YOUR FILES HAVE BEEN LOCKED-, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Window Set Attribute window_name = -YOUR FILES HAVE BEEN LOCKED-, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 1875094464 True 1
Fn
Window Set Attribute window_name = -YOUR FILES HAVE BEEN LOCKED-, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -4, new_long = 78515022 True 1
Fn
Window Set Attribute window_name = -YOUR FILES HAVE BEEN LOCKED-, class_name = WindowsForms10.STATIC.app.0.141b42a_r9_ad1, index = -12, new_long = 328216 False 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll, base_address = 0x6fbc0000 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\desktop\unnam3d - ransm.exe, base_address = 0xd0000 True 1
Fn
Window Create class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, wndproc_parameter = 0 True 1
Fn
Window Set Attribute class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 1952448832 True 1
Fn
Window Set Attribute class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -4, new_long = 78515062 True 1
Fn
Window Set Attribute class_name = WindowsForms10.Window.8.app.0.141b42a_r9_ad1, index = -12, new_long = 197146 False 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, type = file_type True 2
Fn
File Write filename = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2276568 True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Create Desktop desktop_name = MeinTestDesktop True 1
Fn
System Switch Desktop desktop_name = MeinTestDesktop True 1
Fn
Process Create process_name = cmd.exe, show_window = SW_HIDE True 1
Fn
Process Create process_name = cmd.exe, show_window = SW_HIDE True 1
Fn
Process Create process_name = cmd.exe, show_window = SW_HIDE True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
System Sleep duration = 3000 milliseconds (3.000 seconds) True 1
Fn
Process #3: cmd.exe
57 0
»
Information Value
ID #3
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Desktop && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Desktop *
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:53, Reason: Child Process
Unmonitor End Time: 00:04:33, Reason: Terminated by Timeout
Monitor Duration 00:03:40
OS Process Information
»
Information Value
PID 0xf00
Parent PID 0xe64 (c:\users\fd1hvy\desktop\unnam3d - ransm.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 384
0x 36C
Threads
Thread 0x384
57 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\cmd.exe, base_address = 0x8e0000 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetThreadUILanguage, address_out = 0x75ea4f70 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 3
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 136, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 32743 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\FD1HVy\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\FD1HVy\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x75ea4330 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75ea5930 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x74fe09d0 True 1
Fn
File Get Info filename = C:\Users\FD1HVy\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\FD1HVy\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process Create process_name = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, os_pid = 0xe3c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Process #4: cmd.exe
66 0
»
Information Value
ID #4
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Documents && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Documents *
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:53, Reason: Child Process
Unmonitor End Time: 00:01:29, Reason: Self Terminated
Monitor Duration 00:00:36
OS Process Information
»
Information Value
PID 0x46c
Parent PID 0xe64 (c:\users\fd1hvy\desktop\unnam3d - ransm.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x F04
0x 86C
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points YARA Actions
cmd.exe 0x008E0000 0x00938FFF Process Termination - 32-bit - False
Threads
Thread 0xf04
66 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\cmd.exe, base_address = 0x8e0000 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetThreadUILanguage, address_out = 0x75ea4f70 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 3
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 197, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 32743 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\FD1HVy\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\FD1HVy\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x75ea4330 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75ea5930 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x74fe09d0 True 1
Fn
File Get Info filename = C:\Users\FD1HVy\Documents, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\FD1HVy\Documents True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process Create process_name = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, os_pid = 0xf64, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 3
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
Process #6: cmd.exe
66 0
»
Information Value
ID #6
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /C cd C:\Users\FD1HVy\Pictures && C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Pictures *
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:53, Reason: Child Process
Unmonitor End Time: 00:01:19, Reason: Self Terminated
Monitor Duration 00:00:25
OS Process Information
»
Information Value
PID 0xa9c
Parent PID 0xe64 (c:\users\fd1hvy\desktop\unnam3d - ransm.exe)
Bitness 32-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 784
0x F6C
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points YARA Actions
cmd.exe 0x008E0000 0x00938FFF Process Termination - 32-bit - False
Threads
Thread 0x784
66 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\cmd.exe, base_address = 0x8e0000 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetThreadUILanguage, address_out = 0x75ea4f70 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 3
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 32743 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\FD1HVy\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\FD1HVy\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x75ea4330 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75ea5930 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x74fe09d0 True 1
Fn
File Get Info filename = C:\Users\FD1HVy\Pictures, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\FD1HVy\Pictures True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process Create process_name = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, os_pid = 0x754, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 3
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
Process #9: winrar.exe
3340 0
»
Information Value
ID #9
File Name c:\users\fd1hvy\appdata\local\temp\winrar.exe
Command Line C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Desktop *
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:56, Reason: Child Process
Unmonitor End Time: 00:04:33, Reason: Terminated by Timeout
Monitor Duration 00:03:37
OS Process Information
»
Information Value
PID 0xe3c
Parent PID 0xf00 (c:\windows\syswow64\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 4A4
0x E7C
0x D08
0x FAC
0x F24
0x 3FC
0x 10C0
0x 10C4
0x 10C8
0x 10CC
0x 10D0
0x 10D4
0x 10D8
0x 10DC
0x 10E0
0x 10E4
0x 10E8
0x 10EC
0x 10F0
0x 10F4
0x 10F8
0x 10FC
0x 1100
0x 1104
0x 1108
0x 110C
0x 1110
0x 1114
0x 1118
0x 111C
0x 1120
0x 1124
0x 1128
0x 112C
0x 1130
0x 1134
0x 1138
0x 113C
0x 1140
0x 1144
0x 1148
0x 114C
0x 1150
0x 1154
0x 1158
0x 115C
0x 1160
0x 1164
0x 1168
0x 116C
0x 1170
0x 1174
0x 1178
0x 117C
0x 1180
0x 1184
0x 1188
0x 118C
0x 1190
0x 1194
0x 1198
0x 119C
0x 11A0
0x 11A4
0x 11A8
0x 11AC
0x 11B0
0x 11B4
0x 11B8
0x 11BC
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
Desktop.rar 4.93 MB MD5: efa4ac54e99fdd29a9c5edf45ddaaa54
SHA1: 7d248783bb8ff1b88458ebd21c9ec8fd56275281
SHA256: 41290334b1e39a052138f7397495cccebc4675f3fd5a49b0a28ea015d768e5cc
SSDeep: 98304:sqq9/v6ZTjRW6S8TP7PaTxncuJf6fVc2hnfzbOrTPg8X4p7Y8b:9q9cA6FTjnLKrD7Xw7pb
False
Modified Files
»
Filename File Size Hash Values YARA Match Actions
c:\users\fd1hvy\appdata\local\microsoft\windows\explorer\iconcache_idx.db 113.77 KB MD5: 73bfba05899b33a27858f4c19b1a671b
SHA1: c6f1c292ff85bb4fb84055975879c8345290b413
SHA256: c2c4cdff22f9ca0ef6e49c25c19f020fbe3bed1712451c61aa02f1342acf4d19
SSDeep: 384:40cn3yWhXKXxUAuLD/q3sOqXp16KPo7Eo9erZoieAco37MwaDeYfs:rOaWDLrq3JMUWxnZoit7Mnq
False
c:\users\fd1hvy\appdata\local\microsoft\windows\explorer\iconcache_16.db 1.00 MB MD5: 59dda5dae4ef7b50a99d041e7a9e97e6
SHA1: 644e29965aef4527bc670bb0cecda464a0eb60b4
SHA256: f25e9070985e75877834f377d7ca21eec0961f2c7a87e815bffca320334ba90f
SSDeep: 12288:99sS9vByHE1a4Cxl/pGvfRBG4+EFjnFEd0jJg8ey:9DNBRi6G4+uA8ey
False
Threads
Thread 0x4a4
3340 0
»
Category Operation Information Success Count Logfile
Module Load module_name = api-ms-win-core-synch-l1-2-0, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = InitializeCriticalSectionEx, address_out = 0x7ff92f1ad580 True 1
Fn
Module Load module_name = api-ms-win-core-fibers-l1-1-1, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsAlloc, address_out = 0x7ff92f1bd3e0 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsSetValue, address_out = 0x7ff92f198c10 True 1
Fn
Module Load module_name = api-ms-win-core-synch-l1-2-0, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = InitializeCriticalSectionEx, address_out = 0x7ff92f1ad580 True 1
Fn
Module Load module_name = api-ms-win-core-fibers-l1-1-1, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsAlloc, address_out = 0x7ff92f1bd3e0 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsGetValue, address_out = 0x7ff92f192340 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsSetValue, address_out = 0x7ff92f198c10 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
Module Load module_name = api-ms-win-core-localization-l1-2-1, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = LCMapStringEx, address_out = 0x7ff92f17c800 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 260 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff92fdd0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = InitializeConditionVariable, address_out = 0x7ff931fb35c0 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SleepConditionVariableCS, address_out = 0x7ff92f1be960 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = WakeAllConditionVariable, address_out = 0x7ff931fa6090 True 1
Fn
System Get Time type = Performance Ctr, time = 14841558905 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff92fdd0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetDllDirectoryW, address_out = 0x7ff92fdee3c0 True 1
Fn
File Add Search Path - True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetDefaultDllDirectories, address_out = 0x7ff92f228b70 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, base_address = 0x7ff6f74d0000, flags = GET_MODULE_HANDLE_EX_FLAG_UNCHANGED_REFCOUNT, GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes False 1
Fn
File Create Directory C:\Users\FD1HVy\AppData\Roaming\WinRAR True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General False 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, base_address = 0x0 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General False 1
Fn
Module Get Filename module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = \\?\C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
System Get Info type = System Directory, result_out = C:\WINDOWS\system32 True 1
Fn
Module Load module_name = C:\WINDOWS\system32\riched20.dll, base_address = 0x7ff912450000 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Name, data = Default Profile, size = 32, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Default, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcName False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileNames False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ImmExec, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ExclNames, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = StoreNames, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = UseRAR, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RAR5, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXModule, size = 2, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFX False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXIcon, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXLogo, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXElevate, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtFile, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtDataWide, size = 2, type = REG_BINARY True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolumeSize, data = 0, size = 4, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolSizeMod, data = 2, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolPause, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = OldVolNames, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecVolNumber, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Update, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Fresh, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SyncFiles, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Overwrite, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Move, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcRecBin, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcWipe, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = WipeIfPassword, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Solid, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Test, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecEnabled, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecSize, data = 4294967293, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EraseDest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = AddArcOnly, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ClearArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Lock, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Method, data = 3, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = DictSizeLZ, data = 4194304, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = DictSize, data = 33554432, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Background, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = WaitForOther, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Shutdown, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PasswordData, size = 1, type = REG_BINARY True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EncryptHeaders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ZipLegacyEncrypt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = OpenShared, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ProcessOwners, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveStreams, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveSymLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveHardLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = GenerateArcName, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VersionControl, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = BLAKE2, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileCopies, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = QuickOpen, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = GenerateMask, data = yyyymmddhhmmss, size = 30, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileTimeMode, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileDays, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileHours, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileMinutes, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileTimeLimit, data = 0, size = 8, type = REG_QWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcTimeOriginal, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcTimeLatest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = mtime, data = 4, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ctime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = atime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PathsAbs, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PathsNone, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PathsAbsDrive, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SeparateArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SeparateArcDoubleExt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SeparateArcSubfolders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EmailArcTo, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PackDetails, size = 192, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Name, data = Create e-mail attachment, size = 50, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Default, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ArcName False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = FileNames False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ImmExec, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ExclNames, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = StoreNames, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = UseRAR, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = RAR5, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SFXModule, size = 2, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SFX False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SFXIcon, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SFXLogo, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SFXElevate, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = CmtFile, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = CmtDataWide, size = 2, type = REG_BINARY True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = VolumeSize, data = 0, size = 4, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = VolSizeMod, data = 2, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = VolPause, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = OldVolNames, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = RecVolNumber, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Update, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Fresh, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SyncFiles, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Overwrite, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Move, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ArcRecBin, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ArcWipe, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = WipeIfPassword, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Solid, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Test, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = RecEnabled, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = RecSize, data = 4294967293, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = EraseDest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = AddArcOnly, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ClearArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Lock, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Method, data = 5, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = DictSizeLZ, data = 33554432, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = DictSize, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Background, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = WaitForOther, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Shutdown, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = PasswordData, size = 1, type = REG_BINARY True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = EncryptHeaders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ZipLegacyEncrypt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = OpenShared, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ProcessOwners, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SaveStreams, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SaveSymLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SaveHardLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = GenerateArcName, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = VersionControl, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = BLAKE2, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = FileCopies, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = QuickOpen, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = GenerateMask, data = yyyymmddhhmmss, size = 30, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = FileTimeMode, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = FileDays, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = FileHours, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = FileMinutes, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = FileTimeLimit, data = 0, size = 8, type = REG_QWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ArcTimeOriginal, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ArcTimeLatest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = mtime, data = 4, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = ctime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = atime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = PathsAbs, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = PathsNone, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = PathsAbsDrive, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SeparateArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SeparateArcDoubleExt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = SeparateArcSubfolders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = EmailArcTo, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = PackDetails, size = 192, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = SMP, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Name, data = Create e-mail attachment, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Name, data = Backup selected files, size = 44, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Default, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ArcName False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = FileNames False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ImmExec, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ExclNames, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = StoreNames, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = UseRAR, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = RAR5, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SFXModule, size = 2, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SFX False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SFXIcon, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SFXLogo, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SFXElevate, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = CmtFile, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = CmtDataWide, size = 2, type = REG_BINARY True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = VolumeSize, data = 0, size = 4, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = VolSizeMod, data = 2, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = VolPause, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = OldVolNames, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = RecVolNumber, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Update, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Fresh, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SyncFiles, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Overwrite, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Move, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ArcRecBin, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ArcWipe, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = WipeIfPassword, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Solid, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Test, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = RecEnabled, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = RecSize, data = 4294967293, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = EraseDest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = AddArcOnly, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ClearArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Lock, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Method, data = 3, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = DictSizeLZ, data = 33554432, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = DictSize, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Background, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = WaitForOther, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Shutdown, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = PasswordData, size = 1, type = REG_BINARY True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = EncryptHeaders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ZipLegacyEncrypt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = OpenShared, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ProcessOwners, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SaveStreams, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SaveSymLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SaveHardLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = GenerateArcName, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = VersionControl, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = BLAKE2, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = FileCopies, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = QuickOpen, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = GenerateMask, data = yyyymmddhhmmss, size = 30, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = FileTimeMode, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = FileDays, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = FileHours, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = FileMinutes, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = FileTimeLimit, data = 0, size = 8, type = REG_QWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ArcTimeOriginal, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ArcTimeLatest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = mtime, data = 4, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = ctime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = atime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = PathsAbs, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = PathsNone, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = PathsAbsDrive, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SeparateArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SeparateArcDoubleExt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = SeparateArcSubfolders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = EmailArcTo, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = PackDetails, size = 192, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = SMP, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Name, data = Create e-mail attachment, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Name, data = Backup selected files, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Name, data = Create 10 MB volumes, size = 42, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Default, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ArcName False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = FileNames False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ImmExec, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ExclNames, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = StoreNames, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = UseRAR, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = RAR5, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SFXModule, size = 2, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SFX False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SFXIcon, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SFXLogo, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SFXElevate, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = CmtFile, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = CmtDataWide, size = 2, type = REG_BINARY True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = VolumeSize, data = 10485760, size = 18, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = VolSizeMod, data = 2, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = VolPause, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = OldVolNames, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = RecVolNumber, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Update, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Fresh, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SyncFiles, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Overwrite, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Move, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ArcRecBin, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ArcWipe, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = WipeIfPassword, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Solid, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Test, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = RecEnabled, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = RecSize, data = 4294967293, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = EraseDest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = AddArcOnly, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ClearArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Lock, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Method, data = 3, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = DictSizeLZ, data = 33554432, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = DictSize, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Background, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = WaitForOther, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Shutdown, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = PasswordData, size = 1, type = REG_BINARY True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = EncryptHeaders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ZipLegacyEncrypt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = OpenShared, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ProcessOwners, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SaveStreams, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SaveSymLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SaveHardLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = GenerateArcName, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = VersionControl, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = BLAKE2, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = FileCopies, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = QuickOpen, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = GenerateMask, data = yyyymmddhhmmss, size = 30, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = FileTimeMode, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = FileDays, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = FileHours, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = FileMinutes, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = FileTimeLimit, data = 0, size = 8, type = REG_QWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ArcTimeOriginal, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ArcTimeLatest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = mtime, data = 4, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = ctime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = atime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = PathsAbs, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = PathsNone, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = PathsAbsDrive, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SeparateArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SeparateArcDoubleExt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = SeparateArcSubfolders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = EmailArcTo, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = PackDetails, size = 192, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = SMP, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1, value_name = Name, data = Create e-mail attachment, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2, value_name = Name, data = Backup selected files, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3, value_name = Name, data = Create 10 MB volumes, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Name, data = ZIP archive (low compression), size = 60, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Default, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ArcName False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = FileNames False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ImmExec, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ExclNames, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = StoreNames, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = UseRAR, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = RAR5, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SFXModule, size = 2, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Delete Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SFX False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SFXIcon, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SFXLogo, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SFXElevate, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = CmtFile, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = CmtDataWide, size = 2, type = REG_BINARY True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = VolumeSize, data = 0, size = 4, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = VolSizeMod, data = 2, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = VolPause, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = OldVolNames, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = RecVolNumber, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Update, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Fresh, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SyncFiles, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Overwrite, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Move, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ArcRecBin, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ArcWipe, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = WipeIfPassword, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Solid, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Test, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = RecEnabled, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = RecSize, data = 4294967293, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = EraseDest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = AddArcOnly, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ClearArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Lock, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Method, data = 3, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Background, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = WaitForOther, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = Shutdown, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = PasswordData, size = 1, type = REG_BINARY True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = EncryptHeaders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ZipLegacyEncrypt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = OpenShared, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ProcessOwners, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SaveStreams, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SaveSymLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SaveHardLinks, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = GenerateArcName, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = VersionControl, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = BLAKE2, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = FileCopies, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = QuickOpen, data = 1, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = GenerateMask, data = yyyymmddhhmmss, size = 30, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = FileTimeMode, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = FileDays, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = FileHours, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = FileMinutes, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = FileTimeLimit, data = 0, size = 8, type = REG_QWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ArcTimeOriginal, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ArcTimeLatest, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = mtime, data = 4, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = ctime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = atime, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = PathsAbs, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = PathsNone, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = PathsAbsDrive, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SeparateArc, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SeparateArcDoubleExt, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = SeparateArcSubfolders, data = 0, size = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = EmailArcTo, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4, value_name = PackDetails, size = 192, type = REG_BINARY True 1
Fn
Data
System Get Time type = System Time, time = 2019-03-31 21:13:35 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = VerInfo, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat, type = file_type True 1
Fn
File Read filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat, size = 4096, size_out = 12 True 1
Fn
Data
Mutex Create mutex_name = WinRAR_Busy True 1
Fn
Window Find class_name = WinRarWindow True 1
Fn
Window Create window_name = WinRAR, class_name = WinRarWindow, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
System Get Time type = Local Time, time = 2019-03-31 23:13:38 (Local Time) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
Module Get Filename module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR, value_name = rarkey, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = Priority, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR, value_name = rarreg.key, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\Settings.reg, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\Settings.reg, type = file_attributes False 1
Fn
Module Get Filename module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg, type = file_attributes False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Extraction False 1
Fn
Keyboard Get Info type = KB_CODEPAGE, result_out = 437 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = SMP, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\5 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Default, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcName, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileNames False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ExclNames True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ExclNames, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = StoreNames True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = StoreNames, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Default, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = UseRAR, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RAR5, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXModule, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFX, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXIcon, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXLogo, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXElevate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtDataWide, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtTextWide, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtTextData, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolumeSize, data = 0, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolSizeMod, data = 2, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolPause, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = OldVolNames, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecVolNumber, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Update, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Fresh, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SyncFiles, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Overwrite, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Move, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcRecBin, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcWipe, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = WipeIfPassword, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Solid, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Test, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecEnabled, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecSize, data = 4294967293, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Recovery, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EraseDest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = AddArcOnly, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ClearArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Lock, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Method, data = 3, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = DictSizeLZ, data = 4194304, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = DictSize, data = 33554432, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PasswordData, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EncryptHeaders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ZipLegacyEncrypt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = OpenShared, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ProcessOwners, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveStreams, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveSymLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveHardLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Background, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = WaitForOther, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
For performance reasons, the remaining 1102 entries are omitted.
The remaining entries can be found in glog.xml.
Process #10: winrar.exe
2745 0
»
Information Value
ID #10
File Name c:\users\fd1hvy\appdata\local\temp\winrar.exe
Command Line C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Documents *
Initial Working Directory C:\Users\FD1HVy\Documents\
Monitor Start Time: 00:00:57, Reason: Child Process
Unmonitor End Time: 00:01:29, Reason: Self Terminated
Monitor Duration 00:00:32
OS Process Information
»
Information Value
PID 0xf64
Parent PID 0x46c (c:\windows\syswow64\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 48C
0x D2C
0x E44
0x 174
0x 9E8
0x 9FC
0x 1204
0x 1208
0x 120C
0x 1210
0x 1214
0x 1218
0x 121C
0x 1220
0x 1224
0x 1228
0x 122C
0x 1230
0x 1234
0x 1238
0x 123C
0x 1240
0x 1244
0x 1248
0x 124C
0x 1250
0x 1254
0x 1258
0x 125C
0x 1260
0x 1264
0x 1268
0x 126C
0x 1270
0x 1274
0x 1278
0x 127C
0x 1280
0x 1284
0x 1288
0x 128C
0x 1290
0x 1294
0x 1298
0x 129C
0x 12A0
0x 12A4
0x 12A8
0x 12AC
0x 12B0
0x 12B4
0x 12B8
0x 12BC
0x 12C0
0x 12C4
0x 12C8
0x 12CC
0x 12D0
0x 12D4
0x 12D8
0x 12DC
0x 12E0
0x 12E4
0x 12E8
0x 12EC
0x 12F0
0x 12F4
0x 12F8
0x 12FC
0x 1300
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points YARA Actions
winrar.exe 0x7FF6F74D0000 0x7FF6F779FFFF Process Termination - 64-bit - False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat 0.01 KB MD5: 86d13c755ee816538758ea7aa2942899
SHA1: 2bc649ed0171190ae9d4a76a399a2c82310c4c2d
SHA256: 1dcf06035130cacff7d4ff78c0337532eacb190647b9e1633d247fc69e34d62a
SSDeep: 3:bZi:4
False
Documents.rar 2.54 MB MD5: 370e8acf7a8d836e91d6f1a593bfad56
SHA1: 624bebba8d39ce5f887f41d51e66160f4c3596cc
SHA256: 012fb962c6ff6e5153eb240c019c139c5bfb95c1bf664d5750b102b6058057ab
SSDeep: 49152:eZJE7juqkEOpR7YAjDh1+n65Q/6qChell8dlKffN48iRFTxrT5g:eZojKpLb+iy8hof21xe
False
Threads
Thread 0x48c
2745 0
»
Category Operation Information Success Count Logfile
Module Load module_name = api-ms-win-core-synch-l1-2-0, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = InitializeCriticalSectionEx, address_out = 0x7ff92f1ad580 True 1
Fn
Module Load module_name = api-ms-win-core-fibers-l1-1-1, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsAlloc, address_out = 0x7ff92f1bd3e0 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsSetValue, address_out = 0x7ff92f198c10 True 1
Fn
Module Load module_name = api-ms-win-core-synch-l1-2-0, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = InitializeCriticalSectionEx, address_out = 0x7ff92f1ad580 True 1
Fn
Module Load module_name = api-ms-win-core-fibers-l1-1-1, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsAlloc, address_out = 0x7ff92f1bd3e0 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsGetValue, address_out = 0x7ff92f192340 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsSetValue, address_out = 0x7ff92f198c10 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
Module Load module_name = api-ms-win-core-localization-l1-2-1, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = LCMapStringEx, address_out = 0x7ff92f17c800 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 260 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff92fdd0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = InitializeConditionVariable, address_out = 0x7ff931fb35c0 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SleepConditionVariableCS, address_out = 0x7ff92f1be960 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = WakeAllConditionVariable, address_out = 0x7ff931fa6090 True 1
Fn
System Get Time type = Performance Ctr, time = 14893080587 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff92fdd0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetDllDirectoryW, address_out = 0x7ff92fdee3c0 True 1
Fn
File Add Search Path - True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetDefaultDllDirectories, address_out = 0x7ff92f228b70 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, base_address = 0x7ff6f74d0000, flags = GET_MODULE_HANDLE_EX_FLAG_UNCHANGED_REFCOUNT, GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\WinRAR.ini, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\WinRAR.ini, type = file_attributes False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General False 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, base_address = 0x0 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General False 1
Fn
Module Get Filename module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = \\?\C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
System Get Info type = System Directory, result_out = C:\WINDOWS\system32 True 1
Fn
Module Load module_name = C:\WINDOWS\system32\riched20.dll, base_address = 0x7ff912450000 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:35 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = VerInfo, size = 12, type = REG_BINARY True 1
Fn
Data
File Create filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat, type = file_type True 1
Fn
File Write filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat, size = 12 True 1
Fn
Data
Mutex Create mutex_name = WinRAR_Busy True 1
Fn
Window Find class_name = WinRarWindow False 1
Fn
Window Create window_name = WinRAR, class_name = WinRarWindow, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
System Get Time type = Local Time, time = 2019-03-31 23:13:38 (Local Time) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
Module Get Filename module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR, value_name = rarkey, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = Priority, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR, value_name = rarreg.key, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\Settings.reg, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\Settings.reg, type = file_attributes False 1
Fn
Module Get Filename module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Local\Temp\Settings.reg, type = file_attributes False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Extraction False 1
Fn
Keyboard Get Info type = KB_CODEPAGE, result_out = 437 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = SMP, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\5 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Default, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcName, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileNames False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ExclNames True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ExclNames, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = StoreNames True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = StoreNames, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Default, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = UseRAR, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RAR5, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXModule, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFX, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXIcon, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXLogo, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXElevate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtDataWide, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtTextWide, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtTextData, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolumeSize, data = 0, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolSizeMod, data = 2, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolPause, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = OldVolNames, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecVolNumber, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Update, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Fresh, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SyncFiles, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Overwrite, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Move, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcRecBin, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcWipe, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = WipeIfPassword, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Solid, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Test, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecEnabled, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecSize, data = 4294967293, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Recovery, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EraseDest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = AddArcOnly, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ClearArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Lock, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Method, data = 3, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = DictSizeLZ, data = 4194304, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = DictSize, data = 33554432, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PasswordData, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EncryptHeaders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ZipLegacyEncrypt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = OpenShared, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ProcessOwners, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveStreams, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveSymLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveHardLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Background, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = WaitForOther, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Shutdown, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = GenerateArcName, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VersionControl, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = BLAKE2, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileCopies, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = QuickOpen, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = GenerateMask, data = yyyymmddhhmmss, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileTimeMode, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileDays, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileHours, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileMinutes, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcTimeOriginal, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcTimeLatest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = mtime, data = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ctime, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = atime, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PathsAbs, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PathsNone, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PathsAbsDrive, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ImmExec, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SeparateArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SeparateArcDoubleExt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SeparateArcSubfolders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EmailArcTo, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PackDetails, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
System Get Info type = System Directory, result_out = C:\WINDOWS\system32 True 1
Fn
Module Load module_name = C:\WINDOWS\system32\Crypt32.dll, base_address = 0x7ff92e880000 True 1
Fn
Module Get Address module_name = c:\windows\system32\crypt32.dll, function = CryptProtectMemory, address_out = 0x7ff92d8c1770 True 1
Fn
Module Get Address module_name = c:\windows\system32\crypt32.dll, function = CryptUnprotectMemory, address_out = 0x7ff92d8c17a0 True 1
Fn
File Get Info filename = Documents, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\Documents\Documents, type = file_attributes False 1
Fn
File Get Info filename = Documents.rar, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\Documents\Documents.rar, type = file_attributes False 1
Fn
File Get Info filename = Documents.zip, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\Documents\Documents.zip, type = file_attributes False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Compression False 1
Fn
File Create filename = Documents.rar, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
File Create filename = \\?\C:\Users\FD1HVy\Documents\Documents.rar, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
File Get Info filename = Documents.rar, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\Documents\Documents.rar, type = file_attributes False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes, value_name = ActivePath, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\Themes, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\Themes, type = file_attributes False 1
Fn
Module Get Filename module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes, value_name = ShellExtBMP, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes, value_name = ShellExtIcon, size = 2, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList False 1
Fn
Window Create class_name = SysListView32, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList False 6
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths False 9
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = Documents.rar, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\Documents\Documents.rar, type = file_attributes False 1
Fn
System Get Time type = Performance Ctr, time = 15237274695 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface, value_name = SystemProgressBar, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface, value_name = TaskbarProgressBar, data = 1, type = REG_NONE False 1
Fn
Window Create class_name = tooltips_class32, wndproc_parameter = 0 True 1
Fn
Window Create class_name = tooltips_class32, wndproc_parameter = 0 True 1
Fn
System Get Time type = Ticks, time = 152781 True 1
Fn
System Get Time type = Performance Ctr, time = 15281397310 True 1
Fn
System Get Time type = Performance Ctr, time = 15338057145 True 1
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 153718 True 1
Fn
Keyboard Read virtual_key_code = VK_SHIFT, result_out = 0 True 1
Fn
System Get Time type = Ticks, time = 153734 True 1
Fn
System Get Time type = Ticks, time = 153734 True 1
Fn
File Get Info filename = My Music, type = file_attributes True 1
Fn
File Get Info filename = My Pictures, type = file_attributes True 1
Fn
File Get Info filename = My Videos, type = file_attributes True 1
Fn
System Get Time type = Ticks, time = 153750 True 1
Fn
Keyboard Read virtual_key_code = VK_SHIFT, result_out = 0 True 1
Fn
System Get Time type = Ticks, time = 153750 True 1
Fn
Keyboard Read virtual_key_code = VK_SHIFT, result_out = 0 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff92fdd0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CompareStringOrdinal, address_out = 0x7ff92fde8fb0 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:40 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15389937088 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:40 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15390308705 True 1
Fn
File Create filename = Documents.rar, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
File Create filename = \\?\C:\Users\FD1HVy\Documents\Documents.rar, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
File Create filename = Documents.rar, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
System Get Time type = Ticks, time = 153875 True 1
Fn
File Write filename = Documents.rar, size = 8 True 1
Fn
Data
File Write filename = Documents.rar, size = 17 True 1
Fn
Data
File Create filename = -3PSVPdo1rq8.docx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 172296 True 1
Fn
System Get Time type = Performance Ctr, time = 17233011526 True 1
Fn
System Get Time type = Ticks, time = 172296 True 1
Fn
Keyboard Read virtual_key_code = VK_SHIFT, result_out = 0 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:58 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17233895528 True 1
Fn
File Read filename = -3PSVPdo1rq8.docx, size = 1048576, size_out = 22681 True 1
Fn
Data
File Read filename = -3PSVPdo1rq8.docx, size = 1025895, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 172312 True 1
Fn
System Get Time type = Performance Ctr, time = 17234931677 True 1
Fn
System Get Time type = Ticks, time = 172312 True 1
Fn
System Get Time type = Ticks, time = 172312 True 1
Fn
System Get Time type = Ticks, time = 172312 True 1
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 172390 True 1
Fn
System Get Time type = Performance Ctr, time = 17243097170 True 1
Fn
System Get Time type = Ticks, time = 172390 True 3
Fn
File Write filename = Documents.rar, size = 22768 True 1
Fn
Data
File Write filename = Documents.rar, size = 101 True 1
Fn
Data
File Create filename = 5okJ0wdSjHps.docx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173093 True 1
Fn
System Get Time type = Ticks, time = 173093 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17312499738 True 1
Fn
File Read filename = 5okJ0wdSjHps.docx, size = 1048576, size_out = 22922 True 1
Fn
Data
File Read filename = 5okJ0wdSjHps.docx, size = 1025654, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173093 True 1
Fn
System Get Time type = Performance Ctr, time = 17312694042 True 1
Fn
System Get Time type = Ticks, time = 173093 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 173093 True 1
Fn
System Get Time type = Performance Ctr, time = 17313268252 True 1
Fn
System Get Time type = Ticks, time = 173093 True 3
Fn
File Write filename = Documents.rar, size = 23024 True 1
Fn
Data
File Write filename = Documents.rar, size = 101 True 1
Fn
Data
File Create filename = 5YJHRW-JZoT5E S09D.pptx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173109 True 1
Fn
System Get Time type = Ticks, time = 173109 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17313828493 True 1
Fn
File Read filename = 5YJHRW-JZoT5E S09D.pptx, size = 1048576, size_out = 1917 True 1
Fn
Data
File Read filename = 5YJHRW-JZoT5E S09D.pptx, size = 1046659, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173109 True 1
Fn
System Get Time type = Performance Ctr, time = 17314001516 True 1
Fn
System Get Time type = Ticks, time = 173109 True 4
Fn
System Get Time type = Performance Ctr, time = 17314079364 True 1
Fn
System Get Time type = Ticks, time = 173109 True 3
Fn
File Write filename = Documents.rar, size = 1984 True 1
Fn
Data
File Write filename = Documents.rar, size = 105 True 1
Fn
Data
File Create filename = 7I1yC6W53.doc, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173109 True 1
Fn
System Get Time type = Ticks, time = 173109 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17314408867 True 1
Fn
File Read filename = 7I1yC6W53.doc, size = 1048576, size_out = 2265 True 1
Fn
Data
File Read filename = 7I1yC6W53.doc, size = 1046311, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173109 True 1
Fn
System Get Time type = Performance Ctr, time = 17314525949 True 1
Fn
System Get Time type = Ticks, time = 173109 True 4
Fn
System Get Time type = Performance Ctr, time = 17314683803 True 1
Fn
System Get Time type = Ticks, time = 173109 True 3
Fn
File Write filename = Documents.rar, size = 2320 True 1
Fn
Data
File Write filename = Documents.rar, size = 95 True 1
Fn
Data
File Create filename = 8CFpoZ DqeCI.doc, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173109 True 1
Fn
System Get Time type = Ticks, time = 173109 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17315004614 True 1
Fn
File Read filename = 8CFpoZ DqeCI.doc, size = 1048576, size_out = 99449 True 1
Fn
Data
File Read filename = 8CFpoZ DqeCI.doc, size = 949127, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173125 True 1
Fn
System Get Time type = Performance Ctr, time = 17315292954 True 1
Fn
System Get Time type = Ticks, time = 173125 True 3
Fn
System Get Time type = Ticks, time = 173234 True 1
Fn
System Get Time type = Performance Ctr, time = 17327489494 True 1
Fn
System Get Time type = Ticks, time = 173234 True 3
Fn
File Write filename = Documents.rar, size = 99680 True 1
Fn
Data
File Write filename = Documents.rar, size = 100 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\-4NjCVEIvkCBj.docx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173250 True 1
Fn
System Get Time type = Ticks, time = 173250 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17329009933 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\-4NjCVEIvkCBj.docx, size = 1048576, size_out = 72805 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\-4NjCVEIvkCBj.docx, size = 975771, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173265 True 1
Fn
System Get Time type = Performance Ctr, time = 17329562430 True 1
Fn
System Get Time type = Ticks, time = 173265 True 4
Fn
System Get Time type = Performance Ctr, time = 17330182227 True 1
Fn
System Get Time type = Ticks, time = 173265 True 3
Fn
File Write filename = Documents.rar, size = 72960 True 1
Fn
Data
File Write filename = Documents.rar, size = 121 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\l7Td5TRgfXzOW kF6H0.docx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173265 True 1
Fn
System Get Time type = Ticks, time = 173281 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17330982924 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\l7Td5TRgfXzOW kF6H0.docx, size = 1048576, size_out = 75828 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\l7Td5TRgfXzOW kF6H0.docx, size = 972748, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173281 True 1
Fn
System Get Time type = Performance Ctr, time = 17331326499 True 1
Fn
System Get Time type = Ticks, time = 173281 True 4
Fn
System Get Time type = Performance Ctr, time = 17331985157 True 1
Fn
System Get Time type = Ticks, time = 173281 True 3
Fn
File Write filename = Documents.rar, size = 76000 True 1
Fn
Data
File Write filename = Documents.rar, size = 127 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\-mjM.xlsx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173296 True 1
Fn
System Get Time type = Ticks, time = 173296 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17333035000 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\-mjM.xlsx, size = 1048576, size_out = 21820 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\-mjM.xlsx, size = 1026756, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173296 True 1
Fn
System Get Time type = Performance Ctr, time = 17333349121 True 1
Fn
System Get Time type = Ticks, time = 173296 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 173296 True 1
Fn
System Get Time type = Performance Ctr, time = 17333826325 True 1
Fn
System Get Time type = Ticks, time = 173296 True 3
Fn
File Write filename = Documents.rar, size = 21904 True 1
Fn
Data
File Write filename = Documents.rar, size = 121 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\35mJ-.pdf, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173312 True 1
Fn
System Get Time type = Ticks, time = 173312 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17334326921 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\35mJ-.pdf, size = 1048576, size_out = 50615 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\35mJ-.pdf, size = 997961, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173312 True 1
Fn
System Get Time type = Performance Ctr, time = 17334518280 True 1
Fn
System Get Time type = Ticks, time = 173312 True 1
Fn
System Get Time type = Ticks, time = 173312 True 1
Fn
System Get Time type = Ticks, time = 173312 True 2
Fn
System Get Time type = Performance Ctr, time = 17335113686 True 1
Fn
System Get Time type = Ticks, time = 173312 True 3
Fn
File Write filename = Documents.rar, size = 50784 True 1
Fn
Data
File Write filename = Documents.rar, size = 121 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\3jMLs-qdS.docx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173328 True 1
Fn
System Get Time type = Ticks, time = 173328 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17335908914 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\3jMLs-qdS.docx, size = 1048576, size_out = 79280 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\3jMLs-qdS.docx, size = 969296, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173328 True 1
Fn
System Get Time type = Performance Ctr, time = 17336184496 True 1
Fn
System Get Time type = Ticks, time = 173328 True 3
Fn
System Get Time type = Ticks, time = 173343 True 1
Fn
System Get Time type = Performance Ctr, time = 17337519676 True 1
Fn
System Get Time type = Ticks, time = 173343 True 3
Fn
File Write filename = Documents.rar, size = 79424 True 1
Fn
Data
File Write filename = Documents.rar, size = 126 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\BTQU2WOZsFUjw.pdf, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173343 True 1
Fn
System Get Time type = Ticks, time = 173343 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17338151059 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\BTQU2WOZsFUjw.pdf, size = 1048576, size_out = 59842 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\BTQU2WOZsFUjw.pdf, size = 988734, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173343 True 1
Fn
System Get Time type = Performance Ctr, time = 17338495493 True 1
Fn
System Get Time type = Ticks, time = 173343 True 3
Fn
System Get Time type = Ticks, time = 173359 True 1
Fn
System Get Time type = Performance Ctr, time = 17339096636 True 1
Fn
System Get Time type = Ticks, time = 173359 True 3
Fn
File Write filename = Documents.rar, size = 59968 True 1
Fn
Data
File Write filename = Documents.rar, size = 137 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\cA7tY- cuM.pptx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173359 True 1
Fn
System Get Time type = Ticks, time = 173359 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17339690163 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\cA7tY- cuM.pptx, size = 1048576, size_out = 65013 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\cA7tY- cuM.pptx, size = 983563, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173359 True 1
Fn
System Get Time type = Performance Ctr, time = 17340026632 True 1
Fn
System Get Time type = Ticks, time = 173359 True 3
Fn
System Get Time type = Ticks, time = 173375 True 1
Fn
System Get Time type = Performance Ctr, time = 17340790813 True 1
Fn
System Get Time type = Ticks, time = 173375 True 3
Fn
File Write filename = Documents.rar, size = 65152 True 1
Fn
Data
File Write filename = Documents.rar, size = 135 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\1q4uHOxj.odt, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173375 True 1
Fn
System Get Time type = Ticks, time = 173375 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17341572289 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\1q4uHOxj.odt, size = 1048576, size_out = 17856 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\1q4uHOxj.odt, size = 1030720, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173390 True 1
Fn
System Get Time type = Performance Ctr, time = 17341891199 True 1
Fn
System Get Time type = Ticks, time = 173390 True 4
Fn
System Get Time type = Performance Ctr, time = 17342133985 True 1
Fn
System Get Time type = Ticks, time = 173390 True 3
Fn
File Write filename = Documents.rar, size = 17968 True 1
Fn
Data
File Write filename = Documents.rar, size = 141 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\Kin6ms4WyJhH.xlsx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173390 True 1
Fn
System Get Time type = Ticks, time = 173390 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:59 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17342682309 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\Kin6ms4WyJhH.xlsx, size = 1048576, size_out = 41060 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\Kin6ms4WyJhH.xlsx, size = 1007516, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173390 True 1
Fn
System Get Time type = Performance Ctr, time = 17342858027 True 1
Fn
System Get Time type = Ticks, time = 173390 True 3
Fn
System Get Time type = Ticks, time = 173906 True 1
Fn
System Get Time type = Performance Ctr, time = 17393863167 True 1
Fn
System Get Time type = Ticks, time = 173906 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
File Write filename = Documents.rar, size = 41168 True 1
Fn
Data
File Write filename = Documents.rar, size = 146 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\KzP2.csv, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173921 True 1
Fn
System Get Time type = Ticks, time = 173921 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17395400110 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\KzP2.csv, size = 1048576, size_out = 3270 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\KzP2.csv, size = 1045306, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173921 True 1
Fn
System Get Time type = Performance Ctr, time = 17395637798 True 1
Fn
System Get Time type = Ticks, time = 173921 True 4
Fn
System Get Time type = Performance Ctr, time = 17395791743 True 1
Fn
System Get Time type = Ticks, time = 173921 True 3
Fn
File Write filename = Documents.rar, size = 3328 True 1
Fn
Data
File Write filename = Documents.rar, size = 135 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\mbQ0b7o.ots, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173921 True 1
Fn
System Get Time type = Ticks, time = 173921 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17396157927 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\mbQ0b7o.ots, size = 1048576, size_out = 75533 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\mbQ0b7o.ots, size = 973043, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173921 True 1
Fn
System Get Time type = Performance Ctr, time = 17396316566 True 1
Fn
System Get Time type = Ticks, time = 173921 True 3
Fn
System Get Time type = Ticks, time = 173937 True 1
Fn
System Get Time type = Performance Ctr, time = 17397211839 True 1
Fn
System Get Time type = Ticks, time = 173937 True 3
Fn
File Write filename = Documents.rar, size = 75712 True 1
Fn
Data
File Write filename = Documents.rar, size = 140 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\ww2bCvn.csv, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173937 True 1
Fn
System Get Time type = Ticks, time = 173937 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17397794181 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\ww2bCvn.csv, size = 1048576, size_out = 4370 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\ww2bCvn.csv, size = 1044206, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173953 True 1
Fn
System Get Time type = Performance Ctr, time = 17398270680 True 1
Fn
System Get Time type = Ticks, time = 173953 True 4
Fn
System Get Time type = Performance Ctr, time = 17398459574 True 1
Fn
System Get Time type = Ticks, time = 173953 True 3
Fn
File Write filename = Documents.rar, size = 4432 True 1
Fn
Data
File Write filename = Documents.rar, size = 138 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\_fBJ yDh9e.ods, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173953 True 1
Fn
System Get Time type = Ticks, time = 173953 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17398813251 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\_fBJ yDh9e.ods, size = 1048576, size_out = 12823 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\Q9 7uahS\_fBJ yDh9e.ods, size = 1035753, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173953 True 1
Fn
System Get Time type = Performance Ctr, time = 17398946892 True 1
Fn
System Get Time type = Ticks, time = 173953 True 3
Fn
System Get Time type = Ticks, time = 173968 True 1
Fn
System Get Time type = Performance Ctr, time = 17399944876 True 1
Fn
System Get Time type = Ticks, time = 173968 True 3
Fn
File Write filename = Documents.rar, size = 12880 True 1
Fn
Data
File Write filename = Documents.rar, size = 143 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\rDvRexnp0.xls, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173968 True 1
Fn
System Get Time type = Ticks, time = 173968 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17400304892 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\rDvRexnp0.xls, size = 1048576, size_out = 101096 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\rDvRexnp0.xls, size = 947480, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 173968 True 1
Fn
System Get Time type = Performance Ctr, time = 17400496353 True 1
Fn
System Get Time type = Ticks, time = 173968 True 3
Fn
System Get Time type = Ticks, time = 173984 True 1
Fn
System Get Time type = Performance Ctr, time = 17401471925 True 1
Fn
System Get Time type = Ticks, time = 173984 True 3
Fn
File Write filename = Documents.rar, size = 101344 True 1
Fn
Data
File Write filename = Documents.rar, size = 132 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XGIfB05FTyHqB.xlsx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 173984 True 1
Fn
System Get Time type = Ticks, time = 173984 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17402440986 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XGIfB05FTyHqB.xlsx, size = 1048576, size_out = 51715 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XGIfB05FTyHqB.xlsx, size = 996861, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174000 True 1
Fn
System Get Time type = Performance Ctr, time = 17402883607 True 1
Fn
System Get Time type = Ticks, time = 174000 True 4
Fn
System Get Time type = Performance Ctr, time = 17403545391 True 1
Fn
System Get Time type = Ticks, time = 174000 True 3
Fn
File Write filename = Documents.rar, size = 51856 True 1
Fn
Data
File Write filename = Documents.rar, size = 138 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XiqWm6izl6v FQ5Q.doc, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174000 True 1
Fn
System Get Time type = Ticks, time = 174000 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17404148748 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XiqWm6izl6v FQ5Q.doc, size = 1048576, size_out = 11225 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XiqWm6izl6v FQ5Q.doc, size = 1037351, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174015 True 1
Fn
System Get Time type = Performance Ctr, time = 17404593969 True 1
Fn
System Get Time type = Ticks, time = 174015 True 4
Fn
System Get Time type = Performance Ctr, time = 17404814499 True 1
Fn
System Get Time type = Ticks, time = 174015 True 3
Fn
File Write filename = Documents.rar, size = 11248 True 1
Fn
Data
File Write filename = Documents.rar, size = 140 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XXRZ1Ntz_m owLhUomX.rtf, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174015 True 1
Fn
System Get Time type = Ticks, time = 174015 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17405223615 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XXRZ1Ntz_m owLhUomX.rtf, size = 1048576, size_out = 76789 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\XXRZ1Ntz_m owLhUomX.rtf, size = 971787, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174015 True 1
Fn
System Get Time type = Performance Ctr, time = 17405442557 True 1
Fn
System Get Time type = Ticks, time = 174015 True 3
Fn
System Get Time type = Ticks, time = 174031 True 1
Fn
System Get Time type = Performance Ctr, time = 17406977159 True 1
Fn
System Get Time type = Ticks, time = 174031 True 3
Fn
File Write filename = Documents.rar, size = 65008 True 1
Fn
Data
File Write filename = Documents.rar, size = 143 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\xZQ7e8.pptx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174046 True 1
Fn
System Get Time type = Ticks, time = 174046 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17407912127 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\xZQ7e8.pptx, size = 1048576, size_out = 101996 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\5HLd-s\xZQ7e8.pptx, size = 946580, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174046 True 1
Fn
System Get Time type = Performance Ctr, time = 17408362001 True 1
Fn
System Get Time type = Ticks, time = 174046 True 3
Fn
System Get Time type = Ticks, time = 174062 True 1
Fn
System Get Time type = Performance Ctr, time = 17409572212 True 1
Fn
System Get Time type = Ticks, time = 174062 True 3
Fn
File Write filename = Documents.rar, size = 102224 True 1
Fn
Data
File Write filename = Documents.rar, size = 130 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\DLaLU5Np1FYR8L.ods, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174078 True 1
Fn
System Get Time type = Ticks, time = 174078 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17411165982 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\DLaLU5Np1FYR8L.ods, size = 1048576, size_out = 76279 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\DLaLU5Np1FYR8L.ods, size = 972297, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174078 True 1
Fn
System Get Time type = Performance Ctr, time = 17411705448 True 1
Fn
System Get Time type = Ticks, time = 174078 True 3
Fn
System Get Time type = Ticks, time = 174109 True 1
Fn
System Get Time type = Performance Ctr, time = 17414018315 True 1
Fn
System Get Time type = Ticks, time = 174109 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
File Write filename = Documents.rar, size = 76464 True 1
Fn
Data
File Write filename = Documents.rar, size = 157 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\iOBweAZSY.ods, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174125 True 1
Fn
System Get Time type = Ticks, time = 174125 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17415595849 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\iOBweAZSY.ods, size = 1048576, size_out = 28325 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\iOBweAZSY.ods, size = 1020251, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174125 True 1
Fn
System Get Time type = Performance Ctr, time = 17416072396 True 1
Fn
System Get Time type = Ticks, time = 174125 True 4
Fn
System Get Time type = Performance Ctr, time = 17416546950 True 1
Fn
System Get Time type = Ticks, time = 174125 True 3
Fn
File Write filename = Documents.rar, size = 28400 True 1
Fn
Data
File Write filename = Documents.rar, size = 152 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\5S3P3.csv, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174140 True 1
Fn
System Get Time type = Ticks, time = 174140 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17417539088 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\5S3P3.csv, size = 1048576, size_out = 74809 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\5S3P3.csv, size = 973767, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174140 True 1
Fn
System Get Time type = Performance Ctr, time = 17417817700 True 1
Fn
System Get Time type = Ticks, time = 174140 True 3
Fn
System Get Time type = Ticks, time = 174156 True 1
Fn
System Get Time type = Performance Ctr, time = 17418905920 True 1
Fn
System Get Time type = Ticks, time = 174156 True 3
Fn
File Write filename = Documents.rar, size = 74976 True 1
Fn
Data
File Write filename = Documents.rar, size = 157 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\9NEdDu7cj0FPBRK.odt, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174156 True 1
Fn
System Get Time type = Ticks, time = 174156 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17419571659 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\9NEdDu7cj0FPBRK.odt, size = 1048576, size_out = 79125 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\lIHAtSXy\9NEdDu7cj0FPBRK.odt, size = 969451, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174171 True 1
Fn
System Get Time type = Performance Ctr, time = 17420835313 True 1
Fn
System Get Time type = Ticks, time = 174171 True 3
Fn
System Get Time type = Ticks, time = 174187 True 1
Fn
System Get Time type = Performance Ctr, time = 17421662984 True 1
Fn
System Get Time type = Ticks, time = 174187 True 3
Fn
File Write filename = Documents.rar, size = 79296 True 1
Fn
Data
File Write filename = Documents.rar, size = 167 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\Qx eo7HW.odt, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174187 True 1
Fn
System Get Time type = Ticks, time = 174187 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17422489183 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\Qx eo7HW.odt, size = 1048576, size_out = 67193 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\2NOJ5\Qx eo7HW.odt, size = 981383, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174187 True 1
Fn
System Get Time type = Performance Ctr, time = 17422854279 True 1
Fn
System Get Time type = Ticks, time = 174187 True 3
Fn
System Get Time type = Ticks, time = 174203 True 1
Fn
System Get Time type = Performance Ctr, time = 17423656811 True 1
Fn
System Get Time type = Ticks, time = 174203 True 3
Fn
File Write filename = Documents.rar, size = 67376 True 1
Fn
Data
File Write filename = Documents.rar, size = 151 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jfYQRF.csv, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174203 True 1
Fn
System Get Time type = Ticks, time = 174203 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17424228922 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jfYQRF.csv, size = 1048576, size_out = 1058 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jfYQRF.csv, size = 1047518, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174218 True 1
Fn
System Get Time type = Performance Ctr, time = 17424875515 True 1
Fn
System Get Time type = Ticks, time = 174218 True 4
Fn
System Get Time type = Performance Ctr, time = 17425298146 True 1
Fn
System Get Time type = Ticks, time = 174218 True 3
Fn
File Write filename = Documents.rar, size = 1120 True 1
Fn
Data
File Write filename = Documents.rar, size = 141 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jLF_V3JmdmbQkD.ots, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174218 True 1
Fn
System Get Time type = Ticks, time = 174218 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17425642081 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jLF_V3JmdmbQkD.ots, size = 1048576, size_out = 102227 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\jLF_V3JmdmbQkD.ots, size = 946349, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174218 True 1
Fn
System Get Time type = Performance Ctr, time = 17425820029 True 1
Fn
System Get Time type = Ticks, time = 174218 True 3
Fn
System Get Time type = Ticks, time = 174234 True 1
Fn
System Get Time type = Performance Ctr, time = 17426953934 True 1
Fn
System Get Time type = Ticks, time = 174234 True 3
Fn
File Write filename = Documents.rar, size = 102464 True 1
Fn
Data
File Write filename = Documents.rar, size = 151 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\3k35ZmjoIQgYRoHKpmkK.pdf, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174250 True 1
Fn
System Get Time type = Ticks, time = 174250 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17427826814 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\3k35ZmjoIQgYRoHKpmkK.pdf, size = 1048576, size_out = 34385 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\3k35ZmjoIQgYRoHKpmkK.pdf, size = 1014191, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174250 True 1
Fn
System Get Time type = Performance Ctr, time = 17428244571 True 1
Fn
System Get Time type = Ticks, time = 174250 True 4
Fn
System Get Time type = Performance Ctr, time = 17429156392 True 1
Fn
System Get Time type = Ticks, time = 174250 True 3
Fn
File Write filename = Documents.rar, size = 34512 True 1
Fn
Data
File Write filename = Documents.rar, size = 171 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\99y9.odt, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174265 True 1
Fn
System Get Time type = Ticks, time = 174265 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17429850768 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\99y9.odt, size = 1048576, size_out = 62018 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\99y9.odt, size = 986558, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174265 True 1
Fn
System Get Time type = Performance Ctr, time = 17430101247 True 1
Fn
System Get Time type = Ticks, time = 174265 True 4
Fn
System Get Time type = Performance Ctr, time = 17430610303 True 1
Fn
System Get Time type = Ticks, time = 174265 True 3
Fn
File Write filename = Documents.rar, size = 62160 True 1
Fn
Data
File Write filename = Documents.rar, size = 155 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\l 4nHi8sklRbErgBL.pps, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174281 True 1
Fn
System Get Time type = Ticks, time = 174281 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17431475713 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\l 4nHi8sklRbErgBL.pps, size = 1048576, size_out = 53507 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\l 4nHi8sklRbErgBL.pps, size = 995069, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174281 True 1
Fn
System Get Time type = Performance Ctr, time = 17431788652 True 1
Fn
System Get Time type = Ticks, time = 174281 True 4
Fn
System Get Time type = Performance Ctr, time = 17432297566 True 1
Fn
System Get Time type = Ticks, time = 174281 True 3
Fn
File Write filename = Documents.rar, size = 53648 True 1
Fn
Data
File Write filename = Documents.rar, size = 178 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\L_jtuZX b2fVSoNPf.docx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174296 True 1
Fn
System Get Time type = Ticks, time = 174296 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17433202104 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\L_jtuZX b2fVSoNPf.docx, size = 1048576, size_out = 100419 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\L_jtuZX b2fVSoNPf.docx, size = 948157, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174296 True 1
Fn
System Get Time type = Performance Ctr, time = 17433503087 True 1
Fn
System Get Time type = Ticks, time = 174296 True 3
Fn
System Get Time type = Ticks, time = 174312 True 1
Fn
System Get Time type = Performance Ctr, time = 17434478550 True 1
Fn
System Get Time type = Ticks, time = 174312 True 1
Fn
System Get Time type = Ticks, time = 174312 True 1
Fn
System Get Time type = Ticks, time = 174312 True 1
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
File Write filename = Documents.rar, size = 100656 True 1
Fn
Data
File Write filename = Documents.rar, size = 179 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\XCn-HpOwlmV9G3Gdf9O.ods, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174328 True 1
Fn
System Get Time type = Ticks, time = 174328 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17436970994 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\XCn-HpOwlmV9G3Gdf9O.ods, size = 1048576, size_out = 33711 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\eSCikz2YIWaDp58m1bY\NHc9hBVFvdQ5Z\K qThybav\XCn-HpOwlmV9G3Gdf9O.ods, size = 1014865, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174343 True 1
Fn
System Get Time type = Performance Ctr, time = 17437569162 True 1
Fn
System Get Time type = Ticks, time = 174343 True 3
Fn
System Get Time type = Ticks, time = 174359 True 1
Fn
System Get Time type = Performance Ctr, time = 17439596112 True 1
Fn
System Get Time type = Ticks, time = 174359 True 3
Fn
File Write filename = Documents.rar, size = 33856 True 1
Fn
Data
File Write filename = Documents.rar, size = 180 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\QrQLcl.csv, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174359 True 1
Fn
System Get Time type = Ticks, time = 174359 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17440109337 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\QrQLcl.csv, size = 1048576, size_out = 55794 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\QrQLcl.csv, size = 992782, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174375 True 1
Fn
System Get Time type = Performance Ctr, time = 17440476526 True 1
Fn
System Get Time type = Ticks, time = 174375 True 4
Fn
System Get Time type = Performance Ctr, time = 17441103127 True 1
Fn
System Get Time type = Ticks, time = 174375 True 3
Fn
File Write filename = Documents.rar, size = 55936 True 1
Fn
Data
File Write filename = Documents.rar, size = 122 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\R2r4mFlAna2enKE.odp, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174375 True 1
Fn
System Get Time type = Ticks, time = 174390 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17441969475 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\R2r4mFlAna2enKE.odp, size = 1048576, size_out = 30026 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\qfqeMqDF\R2r4mFlAna2enKE.odp, size = 1018550, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174390 True 1
Fn
System Get Time type = Performance Ctr, time = 17442368944 True 1
Fn
System Get Time type = Ticks, time = 174390 True 4
Fn
System Get Time type = Performance Ctr, time = 17442733852 True 1
Fn
System Get Time type = Ticks, time = 174390 True 3
Fn
File Write filename = Documents.rar, size = 30112 True 1
Fn
Data
File Write filename = Documents.rar, size = 131 True 1
Fn
Data
File Create filename = 9EMbKuPh551l7_WJZv\WKv89hDvOzA.pptx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174390 True 1
Fn
System Get Time type = Ticks, time = 174390 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:00 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17443201816 True 1
Fn
File Read filename = 9EMbKuPh551l7_WJZv\WKv89hDvOzA.pptx, size = 1048576, size_out = 44333 True 1
Fn
Data
File Read filename = 9EMbKuPh551l7_WJZv\WKv89hDvOzA.pptx, size = 1004243, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174406 True 1
Fn
System Get Time type = Performance Ctr, time = 17443591628 True 1
Fn
System Get Time type = Ticks, time = 174406 True 4
Fn
System Get Time type = Performance Ctr, time = 17444793067 True 1
Fn
System Get Time type = Ticks, time = 174406 True 3
Fn
File Write filename = Documents.rar, size = 44432 True 1
Fn
Data
File Write filename = Documents.rar, size = 119 True 1
Fn
Data
File Create filename = d8N7eT8cGeAbq0mZ CKY.xlsx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174828 True 1
Fn
System Get Time type = Ticks, time = 174828 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:01 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17486883434 True 1
Fn
File Read filename = d8N7eT8cGeAbq0mZ CKY.xlsx, size = 1048576, size_out = 52391 True 1
Fn
Data
File Read filename = d8N7eT8cGeAbq0mZ CKY.xlsx, size = 996185, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174843 True 1
Fn
System Get Time type = Performance Ctr, time = 17487317354 True 1
Fn
System Get Time type = Ticks, time = 174843 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 174843 True 1
Fn
System Get Time type = Performance Ctr, time = 17488156602 True 1
Fn
System Get Time type = Ticks, time = 174843 True 3
Fn
File Write filename = Documents.rar, size = 52544 True 1
Fn
Data
File Write filename = Documents.rar, size = 109 True 1
Fn
Data
File Create filename = Database1.accdb, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174859 True 1
Fn
System Get Time type = Ticks, time = 174859 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:01 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17488984057 True 1
Fn
File Read filename = Database1.accdb, size = 1048576, size_out = 348160 True 1
Fn
Data
File Read filename = Database1.accdb, size = 700416, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174921 True 1
Fn
System Get Time type = Performance Ctr, time = 17496229028 True 1
Fn
System Get Time type = Ticks, time = 174921 True 3
Fn
System Get Time type = Ticks, time = 174968 True 1
Fn
System Get Time type = Performance Ctr, time = 17499825070 True 1
Fn
System Get Time type = Ticks, time = 174968 True 3
Fn
File Write filename = Documents.rar, size = 11312 True 1
Fn
Data
File Write filename = Documents.rar, size = 99 True 1
Fn
Data
File Create filename = desktop.ini, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174968 True 1
Fn
System Get Time type = Ticks, time = 174968 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:01 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17500708533 True 1
Fn
File Read filename = desktop.ini, size = 1048576, size_out = 402 True 1
Fn
Data
File Read filename = desktop.ini, size = 1048174, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174968 True 1
Fn
System Get Time type = Performance Ctr, time = 17500908483 True 1
Fn
System Get Time type = Ticks, time = 174968 True 4
Fn
System Get Time type = Performance Ctr, time = 17501032263 True 1
Fn
System Get Time type = Ticks, time = 174968 True 3
Fn
File Write filename = Documents.rar, size = 192 True 1
Fn
Data
File Write filename = Documents.rar, size = 93 True 1
Fn
Data
File Create filename = eBvOtmtGs9oVXiPynY.xlsx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 174984 True 1
Fn
System Get Time type = Ticks, time = 174984 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:01 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17501845711 True 1
Fn
File Read filename = eBvOtmtGs9oVXiPynY.xlsx, size = 1048576, size_out = 26111 True 1
Fn
Data
File Read filename = eBvOtmtGs9oVXiPynY.xlsx, size = 1022465, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 174984 True 1
Fn
System Get Time type = Performance Ctr, time = 17502047160 True 1
Fn
System Get Time type = Ticks, time = 174984 True 3
Fn
System Get Time type = Ticks, time = 175000 True 1
Fn
System Get Time type = Performance Ctr, time = 17502846151 True 1
Fn
System Get Time type = Ticks, time = 175000 True 3
Fn
File Write filename = Documents.rar, size = 26176 True 1
Fn
Data
File Write filename = Documents.rar, size = 107 True 1
Fn
Data
File Create filename = FoGmW sbJbVrE-.pptx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 175000 True 1
Fn
System Get Time type = Ticks, time = 175000 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:01 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17503586839 True 1
Fn
File Read filename = FoGmW sbJbVrE-.pptx, size = 1048576, size_out = 7234 True 1
Fn
Data
File Read filename = FoGmW sbJbVrE-.pptx, size = 1041342, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 175000 True 1
Fn
System Get Time type = Performance Ctr, time = 17503848586 True 1
Fn
System Get Time type = Ticks, time = 175000 True 3
Fn
System Get Time type = Ticks, time = 175015 True 1
Fn
System Get Time type = Performance Ctr, time = 17504714568 True 1
Fn
System Get Time type = Ticks, time = 175015 True 3
Fn
File Write filename = Documents.rar, size = 7280 True 1
Fn
Data
File Write filename = Documents.rar, size = 101 True 1
Fn
Data
File Create filename = g9y9 K 4j.pptx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 175015 True 1
Fn
System Get Time type = Ticks, time = 175015 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:14:01 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 17505072750 True 1
Fn
File Read filename = g9y9 K 4j.pptx, size = 1048576, size_out = 85473 True 1
Fn
Data
File Read filename = g9y9 K 4j.pptx, size = 963103, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 175015 True 1
Fn
System Get Time type = Performance Ctr, time = 17505249582 True 1
Fn
System Get Time type = Ticks, time = 175015 True 3
Fn
System Get Time type = Ticks, time = 175031 True 1
Fn
System Get Time type = Performance Ctr, time = 17506145268 True 1
Fn
System Get Time type = Ticks, time = 175031 True 3
Fn
File Write filename = Documents.rar, size = 85680 True 1
Fn
Data
File Write filename = Documents.rar, size = 98 True 1
Fn
Data
File Create filename = jYH_Ha3VQR8eB_bONWr9.pptx, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 175031 True 1
Fn
For performance reasons, the remaining 608 entries are omitted.
The remaining entries can be found in glog.xml.
Process #11: winrar.exe
2030 0
»
Information Value
ID #11
File Name c:\users\fd1hvy\appdata\local\temp\winrar.exe
Command Line C:\Users\FD1HVy\AppData\Local\Temp\\WinRAR.exe m -r -pMyPassword Pictures *
Initial Working Directory C:\Users\FD1HVy\Pictures\
Monitor Start Time: 00:00:57, Reason: Child Process
Unmonitor End Time: 00:01:17, Reason: Self Terminated
Monitor Duration 00:00:20
OS Process Information
»
Information Value
PID 0x754
Parent PID 0xa9c (c:\windows\syswow64\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x CD8
0x 388
0x 824
0x 4AC
0x EF8
0x F70
0x 9E0
0x B84
0x D6C
0x EB0
0x E40
0x FBC
0x E90
0x BEC
0x FB8
0x F84
0x D5C
0x CA0
0x D1C
0x FB4
0x D7C
0x ECC
0x E98
0x EE0
0x 324
0x FB0
0x 1004
0x 1008
0x 100C
0x 1010
0x 1014
0x 1018
0x 101C
0x 1020
0x 1024
0x 1028
0x 102C
0x 1030
0x 1034
0x 1038
0x 103C
0x 1040
0x 1044
0x 1048
0x 104C
0x 1050
0x 1054
0x 1058
0x 105C
0x 1060
0x 1064
0x 1068
0x 106C
0x 1070
0x 1074
0x 1078
0x 107C
0x 1080
0x 1084
0x 1088
0x 108C
0x 1090
0x 1094
0x 1098
0x 109C
0x 10A0
0x 10A4
0x 10A8
0x 10AC
0x 10B0
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points YARA Actions
winrar.exe 0x7FF6F74D0000 0x7FF6F779FFFF Process Termination - 64-bit - False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
Pictures.rar 2.09 MB MD5: 1529f351c2fa6e418339daccb62c82e7
SHA1: 8553fc21b935c408f801bc2080da58f1bff66f69
SHA256: 799c8d082fe7ee8bd2094495e17edd836ff1680e185d8297eb5da5a5a1ce8c3e
SSDeep: 49152:QJODSx4QT/yfmAl/gencu3YT/woKEo5HKOqA0A5JOGKwOyVCN:QJ9ufmLhwb5KAa5
False
Threads
Thread 0xcd8
2030 0
»
Category Operation Information Success Count Logfile
Module Load module_name = api-ms-win-core-synch-l1-2-0, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = InitializeCriticalSectionEx, address_out = 0x7ff92f1ad580 True 1
Fn
Module Load module_name = api-ms-win-core-fibers-l1-1-1, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsAlloc, address_out = 0x7ff92f1bd3e0 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsSetValue, address_out = 0x7ff92f198c10 True 1
Fn
Module Load module_name = api-ms-win-core-synch-l1-2-0, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = InitializeCriticalSectionEx, address_out = 0x7ff92f1ad580 True 1
Fn
Module Load module_name = api-ms-win-core-fibers-l1-1-1, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsAlloc, address_out = 0x7ff92f1bd3e0 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsGetValue, address_out = 0x7ff92f192340 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = FlsSetValue, address_out = 0x7ff92f198c10 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
Module Load module_name = api-ms-win-core-localization-l1-2-1, base_address = 0x7ff92f150000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernelbase.dll, function = LCMapStringEx, address_out = 0x7ff92f17c800 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 260 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff92fdd0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = InitializeConditionVariable, address_out = 0x7ff931fb35c0 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SleepConditionVariableCS, address_out = 0x7ff92f1be960 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = WakeAllConditionVariable, address_out = 0x7ff931fa6090 True 1
Fn
System Get Time type = Performance Ctr, time = 14920805244 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff92fdd0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetDllDirectoryW, address_out = 0x7ff92fdee3c0 True 1
Fn
File Add Search Path - True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetDefaultDllDirectories, address_out = 0x7ff92f228b70 True 1
Fn
Module Get Handle module_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, base_address = 0x7ff6f74d0000, flags = GET_MODULE_HANDLE_EX_FLAG_UNCHANGED_REFCOUNT, GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.ini, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\WinRAR.ini, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\WinRAR.ini, type = file_attributes False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = LanguageFolder, data = 0, type = REG_NONE False 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, base_address = 0x0 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = LanguageFolder, data = 33, type = REG_NONE False 1
Fn
Module Get Filename module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = \\?\C:\Users\FD1HVy\AppData\Local\Temp\winrar.lng, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
System Get Info type = System Directory, result_out = C:\WINDOWS\system32 True 1
Fn
Module Load module_name = C:\WINDOWS\system32\riched20.dll, base_address = 0x7ff912450000 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:35 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = VerInfo, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat, type = file_type True 1
Fn
File Read filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\version.dat, size = 4096, size_out = 12 True 1
Fn
Data
Mutex Create mutex_name = WinRAR_Busy True 1
Fn
Window Find class_name = WinRarWindow True 1
Fn
Window Create window_name = WinRAR, class_name = WinRarWindow, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
System Get Time type = Local Time, time = 2019-03-31 23:13:38 (Local Time) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
Module Get Filename module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR, value_name = rarkey, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = Priority, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR, value_name = rarreg.key, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Extraction False 1
Fn
Keyboard Get Info type = KB_CODEPAGE, result_out = 437 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\General True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\General, value_name = SMP, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\1 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\3 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\4 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\5 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Default, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcName, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileNames False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ExclNames True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ExclNames, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = StoreNames True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = StoreNames, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Default, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = UseRAR, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RAR5, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXModule, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFX, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXIcon, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXLogo, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SFXElevate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtDataWide, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtTextWide, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = CmtTextData, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolumeSize, data = 0, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolSizeMod, data = 2, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VolPause, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = OldVolNames, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecVolNumber, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Update, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Fresh, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SyncFiles, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Overwrite, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Move, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcRecBin, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcWipe, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = WipeIfPassword, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Solid, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Test, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecEnabled, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = RecSize, data = 4294967293, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Recovery, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EraseDest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = AddArcOnly, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ClearArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Lock, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Method, data = 3, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = DictSizeLZ, data = 4194304, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = DictSize, data = 33554432, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Name, data = Default Profile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PasswordData, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EncryptHeaders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ZipLegacyEncrypt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = OpenShared, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ProcessOwners, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveStreams, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveSymLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SaveHardLinks, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Background, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = WaitForOther, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = Shutdown, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = GenerateArcName, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = VersionControl, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = BLAKE2, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileCopies, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = QuickOpen, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = GenerateMask, data = yyyymmddhhmmss, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileTimeMode, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileDays, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileHours, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = FileMinutes, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcTimeOriginal, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ArcTimeLatest, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = mtime, data = 4, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ctime, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = atime, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PathsAbs, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PathsNone, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PathsAbsDrive, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = ImmExec, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SeparateArc, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SeparateArcDoubleExt, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = SeparateArcSubfolders, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = EmailArcTo, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0 True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Profiles\0, value_name = PackDetails, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WinRAR\Policy False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Policy False 1
Fn
System Get Info type = System Directory, result_out = C:\WINDOWS\system32 True 1
Fn
Module Load module_name = C:\WINDOWS\system32\Crypt32.dll, base_address = 0x7ff92e880000 True 1
Fn
Module Get Address module_name = c:\windows\system32\crypt32.dll, function = CryptProtectMemory, address_out = 0x7ff92d8c1770 True 1
Fn
Module Get Address module_name = c:\windows\system32\crypt32.dll, function = CryptUnprotectMemory, address_out = 0x7ff92d8c17a0 True 1
Fn
File Get Info filename = Pictures, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\Pictures\Pictures, type = file_attributes False 1
Fn
File Get Info filename = Pictures.rar, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\Pictures\Pictures.rar, type = file_attributes False 1
Fn
File Get Info filename = Pictures.zip, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\Pictures\Pictures.zip, type = file_attributes False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Compression False 1
Fn
File Create filename = Pictures.rar, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
File Create filename = \\?\C:\Users\FD1HVy\Pictures\Pictures.rar, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
File Get Info filename = Pictures.rar, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\Pictures\Pictures.rar, type = file_attributes False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes, value_name = ActivePath, data = 0, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\FD1HVy\AppData\Roaming\WinRAR\Themes, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\AppData\Roaming\WinRAR\Themes, type = file_attributes False 1
Fn
Module Get Filename module_name = C:\Users\FD1HVy\AppData\Local\Temp\rarlng.dll, process_name = c:\users\fd1hvy\appdata\local\temp\winrar.exe, file_name_orig = C:\Users\FD1HVy\AppData\Local\Temp\WinRAR.exe, size = 2048 True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes, value_name = ShellExtBMP, size = 2, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes, value_name = ShellExtIcon, size = 2, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList False 1
Fn
Window Create class_name = SysListView32, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList False 6
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths False 9
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnStates False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Paths False 1
Fn
File Get Info filename = Pictures.rar, type = file_attributes False 1
Fn
File Get Info filename = \\?\C:\Users\FD1HVy\Pictures\Pictures.rar, type = file_attributes False 1
Fn
System Get Time type = Performance Ctr, time = 15224004289 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface, value_name = SystemProgressBar, data = 1, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR\Interface, value_name = TaskbarProgressBar, data = 1, type = REG_NONE False 1
Fn
Window Create class_name = tooltips_class32, wndproc_parameter = 0 True 1
Fn
Window Create class_name = tooltips_class32, wndproc_parameter = 0 True 1
Fn
System Get Time type = Ticks, time = 152781 True 1
Fn
System Get Time type = Performance Ctr, time = 15281653057 True 1
Fn
System Get Time type = Performance Ctr, time = 15282303572 True 1
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 153546 True 1
Fn
Keyboard Read virtual_key_code = VK_SHIFT, result_out = 0 True 1
Fn
System Get Time type = Ticks, time = 153546 True 1
Fn
System Get Time type = Ticks, time = 153546 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff92fdd0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CompareStringOrdinal, address_out = 0x7ff92fde8fb0 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:40 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15384843085 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:40 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15385165545 True 1
Fn
File Create filename = Pictures.rar, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
File Create filename = \\?\C:\Users\FD1HVy\Pictures\Pictures.rar, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ False 1
Fn
File Create filename = Pictures.rar, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
System Get Time type = Ticks, time = 153828 True 1
Fn
File Write filename = Pictures.rar, size = 8 True 1
Fn
Data
File Write filename = Pictures.rar, size = 17 True 1
Fn
Data
File Create filename = 17Kei.bmp, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 154250 True 1
Fn
System Get Time type = Performance Ctr, time = 15428579620 True 1
Fn
System Get Time type = Ticks, time = 154250 True 1
Fn
Keyboard Read virtual_key_code = VK_SHIFT, result_out = 0 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:40 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15429182027 True 1
Fn
File Read filename = 17Kei.bmp, size = 1048576, size_out = 48846 True 1
Fn
Data
File Read filename = 17Kei.bmp, size = 999730, size_out = 0 True 1
Fn
Keyboard Read virtual_key_code = VK_SHIFT, result_out = 0 True 1
Fn
System Get Time type = Ticks, time = 154265 True 1
Fn
System Get Time type = Performance Ctr, time = 15430284429 True 1
Fn
System Get Time type = Ticks, time = 154265 True 1
Fn
System Get Time type = Ticks, time = 154265 True 1
Fn
System Get Time type = Ticks, time = 154265 True 1
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 154406 True 1
Fn
System Get Time type = Performance Ctr, time = 15444704119 True 1
Fn
System Get Time type = Ticks, time = 154406 True 3
Fn
Keyboard Read virtual_key_code = VK_SHIFT, result_out = 0 True 1
Fn
File Write filename = Pictures.rar, size = 48928 True 1
Fn
Data
File Write filename = Pictures.rar, size = 93 True 1
Fn
Data
File Create filename = 1Uee5Fu 2XCwi8fG.gif, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 154718 True 1
Fn
System Get Time type = Ticks, time = 154718 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:40 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15475913466 True 1
Fn
File Read filename = 1Uee5Fu 2XCwi8fG.gif, size = 1048576, size_out = 75056 True 1
Fn
Data
File Read filename = 1Uee5Fu 2XCwi8fG.gif, size = 973520, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 154718 True 1
Fn
System Get Time type = Performance Ctr, time = 15476004927 True 1
Fn
System Get Time type = Ticks, time = 154718 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 154734 True 1
Fn
System Get Time type = Performance Ctr, time = 15477639772 True 1
Fn
System Get Time type = Ticks, time = 154734 True 3
Fn
File Write filename = Pictures.rar, size = 75232 True 1
Fn
Data
File Write filename = Pictures.rar, size = 104 True 1
Fn
Data
File Create filename = 5qnTEjfG9KjtBUIojvlC.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 154750 True 1
Fn
System Get Time type = Ticks, time = 154750 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:40 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15478554322 True 1
Fn
File Read filename = 5qnTEjfG9KjtBUIojvlC.png, size = 1048576, size_out = 73639 True 1
Fn
Data
File Read filename = 5qnTEjfG9KjtBUIojvlC.png, size = 974937, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 154750 True 1
Fn
System Get Time type = Performance Ctr, time = 15478645452 True 1
Fn
System Get Time type = Ticks, time = 154750 True 4
Fn
System Get Time type = Performance Ctr, time = 15479195811 True 1
Fn
System Get Time type = Ticks, time = 154750 True 3
Fn
File Write filename = Pictures.rar, size = 73808 True 1
Fn
Data
File Write filename = Pictures.rar, size = 108 True 1
Fn
Data
File Create filename = 6xi8hATC8ep.gif, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 154765 True 1
Fn
System Get Time type = Ticks, time = 155296 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:41 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15552745954 True 1
Fn
File Read filename = 6xi8hATC8ep.gif, size = 1048576, size_out = 15219 True 1
Fn
Data
File Read filename = 6xi8hATC8ep.gif, size = 1033357, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155500 True 1
Fn
System Get Time type = Performance Ctr, time = 15552894602 True 1
Fn
System Get Time type = Ticks, time = 155500 True 1
Fn
System Get Time type = Ticks, time = 155500 True 1
Fn
System Get Time type = Ticks, time = 155500 True 1
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 155500 True 1
Fn
System Get Time type = Performance Ctr, time = 15553461517 True 1
Fn
System Get Time type = Ticks, time = 155500 True 3
Fn
File Write filename = Pictures.rar, size = 15248 True 1
Fn
Data
File Write filename = Pictures.rar, size = 99 True 1
Fn
Data
File Create filename = 7ZwWGMcIaUjWjMVJAe.jpg, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155500 True 1
Fn
System Get Time type = Ticks, time = 155500 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:41 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15553869096 True 1
Fn
File Read filename = 7ZwWGMcIaUjWjMVJAe.jpg, size = 1048576, size_out = 43455 True 1
Fn
Data
File Read filename = 7ZwWGMcIaUjWjMVJAe.jpg, size = 1005121, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155500 True 1
Fn
System Get Time type = Performance Ctr, time = 15553969903 True 1
Fn
System Get Time type = Ticks, time = 155500 True 3
Fn
System Get Time type = Ticks, time = 155515 True 1
Fn
System Get Time type = Performance Ctr, time = 15554382242 True 1
Fn
System Get Time type = Ticks, time = 155515 True 3
Fn
File Write filename = Pictures.rar, size = 43552 True 1
Fn
Data
File Write filename = Pictures.rar, size = 106 True 1
Fn
Data
File Create filename = 8eYKFrOBbq-TuX.bmp, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155515 True 1
Fn
System Get Time type = Ticks, time = 155515 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:41 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15554972683 True 1
Fn
File Read filename = 8eYKFrOBbq-TuX.bmp, size = 1048576, size_out = 20756 True 1
Fn
Data
File Read filename = 8eYKFrOBbq-TuX.bmp, size = 1027820, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155515 True 1
Fn
System Get Time type = Performance Ctr, time = 15555041538 True 1
Fn
System Get Time type = Ticks, time = 155515 True 4
Fn
System Get Time type = Performance Ctr, time = 15555267540 True 1
Fn
System Get Time type = Ticks, time = 155515 True 3
Fn
File Write filename = Pictures.rar, size = 20832 True 1
Fn
Data
File Write filename = Pictures.rar, size = 102 True 1
Fn
Data
File Create filename = 9BtQRHA1y.gif, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155515 True 1
Fn
System Get Time type = Ticks, time = 155531 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:41 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15555881697 True 1
Fn
File Read filename = 9BtQRHA1y.gif, size = 1048576, size_out = 42415 True 1
Fn
Data
File Read filename = 9BtQRHA1y.gif, size = 1006161, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155531 True 1
Fn
System Get Time type = Performance Ctr, time = 15555982959 True 1
Fn
System Get Time type = Ticks, time = 155531 True 4
Fn
System Get Time type = Performance Ctr, time = 15556310925 True 1
Fn
System Get Time type = Ticks, time = 155531 True 3
Fn
File Write filename = Pictures.rar, size = 42528 True 1
Fn
Data
File Write filename = Pictures.rar, size = 97 True 1
Fn
Data
File Create filename = A4ii4MOpBgpQwQBT.jpg, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155531 True 1
Fn
System Get Time type = Ticks, time = 155531 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:41 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15556911962 True 1
Fn
File Read filename = A4ii4MOpBgpQwQBT.jpg, size = 1048576, size_out = 87534 True 1
Fn
Data
File Read filename = A4ii4MOpBgpQwQBT.jpg, size = 961042, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155531 True 1
Fn
System Get Time type = Performance Ctr, time = 15557007078 True 1
Fn
System Get Time type = Ticks, time = 155531 True 3
Fn
System Get Time type = Ticks, time = 155546 True 1
Fn
System Get Time type = Performance Ctr, time = 15558169755 True 1
Fn
System Get Time type = Ticks, time = 155546 True 3
Fn
File Write filename = Pictures.rar, size = 87728 True 1
Fn
Data
File Write filename = Pictures.rar, size = 104 True 1
Fn
Data
File Create filename = aHz4Hx-PBeuX.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155703 True 1
Fn
System Get Time type = Ticks, time = 155703 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:41 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15573580648 True 1
Fn
File Read filename = aHz4Hx-PBeuX.png, size = 1048576, size_out = 81997 True 1
Fn
Data
File Read filename = aHz4Hx-PBeuX.png, size = 966579, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155703 True 1
Fn
System Get Time type = Performance Ctr, time = 15573680198 True 1
Fn
System Get Time type = Ticks, time = 155703 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 155718 True 1
Fn
System Get Time type = Performance Ctr, time = 15574676739 True 1
Fn
System Get Time type = Ticks, time = 155718 True 3
Fn
File Write filename = Pictures.rar, size = 82160 True 1
Fn
Data
File Write filename = Pictures.rar, size = 100 True 1
Fn
Data
File Create filename = awTUht89JcK2K D7j9i.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155718 True 1
Fn
System Get Time type = Ticks, time = 155718 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:41 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15575338188 True 1
Fn
File Read filename = awTUht89JcK2K D7j9i.png, size = 1048576, size_out = 34167 True 1
Fn
Data
File Read filename = awTUht89JcK2K D7j9i.png, size = 1014409, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155718 True 1
Fn
System Get Time type = Performance Ctr, time = 15575424647 True 1
Fn
System Get Time type = Ticks, time = 155718 True 4
Fn
System Get Time type = Performance Ctr, time = 15575707603 True 1
Fn
System Get Time type = Ticks, time = 155718 True 3
Fn
File Write filename = Pictures.rar, size = 34288 True 1
Fn
Data
File Write filename = Pictures.rar, size = 107 True 1
Fn
Data
File Create filename = c9ZaReaCiTG.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155734 True 1
Fn
System Get Time type = Ticks, time = 155734 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:41 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15576465158 True 1
Fn
File Read filename = c9ZaReaCiTG.png, size = 1048576, size_out = 82983 True 1
Fn
Data
File Read filename = c9ZaReaCiTG.png, size = 965593, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155734 True 1
Fn
System Get Time type = Performance Ctr, time = 15576555848 True 1
Fn
System Get Time type = Ticks, time = 155734 True 4
Fn
System Get Time type = Performance Ctr, time = 15577159390 True 1
Fn
System Get Time type = Ticks, time = 155734 True 3
Fn
File Write filename = Pictures.rar, size = 83216 True 1
Fn
Data
File Write filename = Pictures.rar, size = 99 True 1
Fn
Data
File Create filename = Camera Roll\desktop.ini, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155734 True 1
Fn
System Get Time type = Ticks, time = 155750 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:41 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15577874247 True 1
Fn
File Read filename = Camera Roll\desktop.ini, size = 1048576, size_out = 190 True 1
Fn
Data
File Read filename = Camera Roll\desktop.ini, size = 1048386, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155890 True 1
Fn
System Get Time type = Performance Ctr, time = 15592099498 True 1
Fn
System Get Time type = Ticks, time = 155890 True 4
Fn
System Get Time type = Performance Ctr, time = 15592560719 True 1
Fn
System Get Time type = Ticks, time = 155890 True 3
Fn
File Write filename = Pictures.rar, size = 160 True 1
Fn
Data
File Write filename = Pictures.rar, size = 105 True 1
Fn
Data
File Create filename = Cg4L5J0Hp5g.bmp, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155890 True 1
Fn
System Get Time type = Ticks, time = 155890 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15593021908 True 1
Fn
File Read filename = Cg4L5J0Hp5g.bmp, size = 1048576, size_out = 3689 True 1
Fn
Data
File Read filename = Cg4L5J0Hp5g.bmp, size = 1044887, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155890 True 1
Fn
System Get Time type = Performance Ctr, time = 15593079817 True 1
Fn
System Get Time type = Ticks, time = 155890 True 4
Fn
System Get Time type = Performance Ctr, time = 15593228704 True 1
Fn
System Get Time type = Ticks, time = 155890 True 3
Fn
File Write filename = Pictures.rar, size = 3744 True 1
Fn
Data
File Write filename = Pictures.rar, size = 97 True 1
Fn
Data
File Create filename = desktop.ini, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155906 True 1
Fn
System Get Time type = Ticks, time = 155906 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15593595182 True 1
Fn
File Read filename = desktop.ini, size = 1048576, size_out = 504 True 1
Fn
Data
File Read filename = desktop.ini, size = 1048072, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155906 True 1
Fn
System Get Time type = Performance Ctr, time = 15593666729 True 1
Fn
System Get Time type = Ticks, time = 155906 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 155906 True 1
Fn
System Get Time type = Performance Ctr, time = 15594095924 True 1
Fn
System Get Time type = Ticks, time = 155906 True 3
Fn
File Write filename = Pictures.rar, size = 208 True 1
Fn
Data
File Write filename = Pictures.rar, size = 93 True 1
Fn
Data
File Create filename = dw0z-rObH0-zF2.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155906 True 1
Fn
System Get Time type = Ticks, time = 155906 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15594466548 True 1
Fn
File Read filename = dw0z-rObH0-zF2.png, size = 1048576, size_out = 6965 True 1
Fn
Data
File Read filename = dw0z-rObH0-zF2.png, size = 1041611, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155906 True 1
Fn
System Get Time type = Performance Ctr, time = 15594536010 True 1
Fn
System Get Time type = Ticks, time = 155906 True 4
Fn
System Get Time type = Performance Ctr, time = 15594726747 True 1
Fn
System Get Time type = Ticks, time = 155906 True 3
Fn
File Write filename = Pictures.rar, size = 7008 True 1
Fn
Data
File Write filename = Pictures.rar, size = 100 True 1
Fn
Data
File Create filename = FiPd_4qvOx8j.jpg, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155921 True 1
Fn
System Get Time type = Ticks, time = 155921 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15595321350 True 1
Fn
File Read filename = FiPd_4qvOx8j.jpg, size = 1048576, size_out = 46505 True 1
Fn
Data
File Read filename = FiPd_4qvOx8j.jpg, size = 1002071, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 155921 True 1
Fn
System Get Time type = Performance Ctr, time = 15595420948 True 1
Fn
System Get Time type = Ticks, time = 155921 True 4
Fn
System Get Time type = Performance Ctr, time = 15595802347 True 1
Fn
System Get Time type = Ticks, time = 155921 True 3
Fn
File Write filename = Pictures.rar, size = 46608 True 1
Fn
Data
File Write filename = Pictures.rar, size = 100 True 1
Fn
Data
File Create filename = g6r96fa7GyN6.gif, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 155921 True 1
Fn
System Get Time type = Ticks, time = 156250 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15628770326 True 1
Fn
File Read filename = g6r96fa7GyN6.gif, size = 1048576, size_out = 57322 True 1
Fn
Data
File Read filename = g6r96fa7GyN6.gif, size = 991254, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156250 True 1
Fn
System Get Time type = Performance Ctr, time = 15629057832 True 1
Fn
System Get Time type = Ticks, time = 156250 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 156265 True 1
Fn
System Get Time type = Performance Ctr, time = 15629936552 True 1
Fn
System Get Time type = Ticks, time = 156265 True 3
Fn
File Write filename = Pictures.rar, size = 57456 True 1
Fn
Data
File Write filename = Pictures.rar, size = 100 True 1
Fn
Data
File Create filename = gTXyE1NkEEb.jpg, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156265 True 1
Fn
System Get Time type = Ticks, time = 156265 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15630625888 True 1
Fn
File Read filename = gTXyE1NkEEb.jpg, size = 1048576, size_out = 96501 True 1
Fn
Data
File Read filename = gTXyE1NkEEb.jpg, size = 952075, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156265 True 1
Fn
System Get Time type = Performance Ctr, time = 15630724071 True 1
Fn
System Get Time type = Ticks, time = 156265 True 3
Fn
System Get Time type = Ticks, time = 156281 True 1
Fn
System Get Time type = Performance Ctr, time = 15631980409 True 1
Fn
System Get Time type = Ticks, time = 156281 True 3
Fn
File Write filename = Pictures.rar, size = 96688 True 1
Fn
Data
File Write filename = Pictures.rar, size = 99 True 1
Fn
Data
File Create filename = H6PwCN3oyZKOwFQ.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156296 True 1
Fn
System Get Time type = Ticks, time = 156296 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15632952118 True 1
Fn
File Read filename = H6PwCN3oyZKOwFQ.png, size = 1048576, size_out = 101635 True 1
Fn
Data
File Read filename = H6PwCN3oyZKOwFQ.png, size = 946941, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156296 True 1
Fn
System Get Time type = Performance Ctr, time = 15633055075 True 1
Fn
System Get Time type = Ticks, time = 156296 True 3
Fn
System Get Time type = Ticks, time = 156312 True 1
Fn
System Get Time type = Performance Ctr, time = 15634290097 True 1
Fn
System Get Time type = Ticks, time = 156312 True 3
Fn
File Write filename = Pictures.rar, size = 101872 True 1
Fn
Data
File Write filename = Pictures.rar, size = 103 True 1
Fn
Data
File Create filename = H7Jzn2.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156312 True 1
Fn
System Get Time type = Ticks, time = 156312 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15635046995 True 1
Fn
File Read filename = H7Jzn2.png, size = 1048576, size_out = 81996 True 1
Fn
Data
File Read filename = H7Jzn2.png, size = 966580, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156312 True 1
Fn
System Get Time type = Performance Ctr, time = 15635150620 True 1
Fn
System Get Time type = Ticks, time = 156312 True 3
Fn
System Get Time type = Ticks, time = 156484 True 1
Fn
System Get Time type = Performance Ctr, time = 15652073934 True 1
Fn
System Get Time type = Ticks, time = 156484 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
File Write filename = Pictures.rar, size = 82176 True 1
Fn
Data
File Write filename = Pictures.rar, size = 94 True 1
Fn
Data
File Create filename = hh1Bz.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156500 True 1
Fn
System Get Time type = Ticks, time = 156500 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15653992504 True 1
Fn
File Read filename = hh1Bz.png, size = 1048576, size_out = 97065 True 1
Fn
Data
File Read filename = hh1Bz.png, size = 951511, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156500 True 1
Fn
System Get Time type = Performance Ctr, time = 15654119859 True 1
Fn
System Get Time type = Ticks, time = 156500 True 1
Fn
System Get Time type = Ticks, time = 156500 True 1
Fn
System Get Time type = Ticks, time = 156515 True 1
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 156515 True 1
Fn
System Get Time type = Performance Ctr, time = 15655737210 True 1
Fn
System Get Time type = Ticks, time = 156515 True 3
Fn
File Write filename = Pictures.rar, size = 97248 True 1
Fn
Data
File Write filename = Pictures.rar, size = 93 True 1
Fn
Data
File Create filename = HPs4cKd.bmp, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156531 True 1
Fn
System Get Time type = Ticks, time = 156531 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15657293993 True 1
Fn
File Read filename = HPs4cKd.bmp, size = 1048576, size_out = 59374 True 1
Fn
Data
File Read filename = HPs4cKd.bmp, size = 989202, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156718 True 1
Fn
System Get Time type = Performance Ctr, time = 15675522978 True 1
Fn
System Get Time type = Ticks, time = 156718 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
Keyboard Read virtual_key_code = VK_SHIFT, result_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156734 True 1
Fn
System Get Time type = Performance Ctr, time = 15676323380 True 1
Fn
System Get Time type = Ticks, time = 156734 True 3
Fn
File Write filename = Pictures.rar, size = 59504 True 1
Fn
Data
File Write filename = Pictures.rar, size = 95 True 1
Fn
Data
File Create filename = job -V_cE7uVrHssoWW.jpg, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156734 True 1
Fn
System Get Time type = Ticks, time = 156734 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15677025788 True 1
Fn
File Read filename = job -V_cE7uVrHssoWW.jpg, size = 1048576, size_out = 48923 True 1
Fn
Data
File Read filename = job -V_cE7uVrHssoWW.jpg, size = 999653, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156734 True 1
Fn
System Get Time type = Performance Ctr, time = 15677116797 True 1
Fn
System Get Time type = Ticks, time = 156734 True 4
Fn
System Get Time type = Performance Ctr, time = 15677469922 True 1
Fn
System Get Time type = Ticks, time = 156734 True 3
Fn
File Write filename = Pictures.rar, size = 49024 True 1
Fn
Data
File Write filename = Pictures.rar, size = 107 True 1
Fn
Data
File Create filename = KmDsFaqbjMnNn4BN.jpg, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156750 True 1
Fn
System Get Time type = Ticks, time = 156750 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15678083973 True 1
Fn
File Read filename = KmDsFaqbjMnNn4BN.jpg, size = 1048576, size_out = 33999 True 1
Fn
Data
File Read filename = KmDsFaqbjMnNn4BN.jpg, size = 1014577, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156750 True 1
Fn
System Get Time type = Performance Ctr, time = 15678173538 True 1
Fn
System Get Time type = Ticks, time = 156750 True 4
Fn
System Get Time type = Performance Ctr, time = 15678451820 True 1
Fn
System Get Time type = Ticks, time = 156750 True 3
Fn
File Write filename = Pictures.rar, size = 34160 True 1
Fn
Data
File Write filename = Pictures.rar, size = 104 True 1
Fn
Data
File Create filename = m3ksaTaVuXM_ADoCvA.jpg, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156750 True 1
Fn
System Get Time type = Ticks, time = 156750 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15678973106 True 1
Fn
File Read filename = m3ksaTaVuXM_ADoCvA.jpg, size = 1048576, size_out = 92134 True 1
Fn
Data
File Read filename = m3ksaTaVuXM_ADoCvA.jpg, size = 956442, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156750 True 1
Fn
System Get Time type = Performance Ctr, time = 15679074681 True 1
Fn
System Get Time type = Ticks, time = 156750 True 3
Fn
System Get Time type = Ticks, time = 156765 True 1
Fn
System Get Time type = Performance Ctr, time = 15679713687 True 1
Fn
System Get Time type = Ticks, time = 156765 True 3
Fn
File Write filename = Pictures.rar, size = 92320 True 1
Fn
Data
File Write filename = Pictures.rar, size = 106 True 1
Fn
Data
File Create filename = m3Vfo.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156765 True 1
Fn
System Get Time type = Ticks, time = 156765 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:42 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15680500289 True 1
Fn
File Read filename = m3Vfo.png, size = 1048576, size_out = 93174 True 1
Fn
Data
File Read filename = m3Vfo.png, size = 955402, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156765 True 1
Fn
System Get Time type = Performance Ctr, time = 15680602506 True 1
Fn
System Get Time type = Ticks, time = 156765 True 3
Fn
System Get Time type = Ticks, time = 156875 True 1
Fn
System Get Time type = Performance Ctr, time = 15691212358 True 1
Fn
System Get Time type = Ticks, time = 156875 True 3
Fn
File Write filename = Pictures.rar, size = 93376 True 1
Fn
Data
File Write filename = Pictures.rar, size = 93 True 1
Fn
Data
File Create filename = Pe_4G6TNHBiw7.gif, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156890 True 1
Fn
System Get Time type = Ticks, time = 156890 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15692344301 True 1
Fn
File Read filename = Pe_4G6TNHBiw7.gif, size = 1048576, size_out = 70389 True 1
Fn
Data
File Read filename = Pe_4G6TNHBiw7.gif, size = 978187, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156890 True 1
Fn
System Get Time type = Performance Ctr, time = 15692440011 True 1
Fn
System Get Time type = Ticks, time = 156890 True 4
Fn
System Get Time type = Performance Ctr, time = 15692934793 True 1
Fn
System Get Time type = Ticks, time = 156890 True 3
Fn
File Write filename = Pictures.rar, size = 70560 True 1
Fn
Data
File Write filename = Pictures.rar, size = 101 True 1
Fn
Data
File Create filename = q0 y.bmp, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156906 True 1
Fn
System Get Time type = Ticks, time = 156906 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15693555347 True 1
Fn
File Read filename = q0 y.bmp, size = 1048576, size_out = 14550 True 1
Fn
Data
File Read filename = q0 y.bmp, size = 1034026, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156906 True 1
Fn
System Get Time type = Performance Ctr, time = 15693628297 True 1
Fn
System Get Time type = Ticks, time = 156906 True 4
Fn
System Get Time type = Performance Ctr, time = 15693818389 True 1
Fn
System Get Time type = Ticks, time = 156906 True 3
Fn
File Write filename = Pictures.rar, size = 14576 True 1
Fn
Data
File Write filename = Pictures.rar, size = 92 True 1
Fn
Data
File Create filename = QX41YSfi6.bmp, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156906 True 1
Fn
System Get Time type = Ticks, time = 156906 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15694202600 True 1
Fn
File Read filename = QX41YSfi6.bmp, size = 1048576, size_out = 86135 True 1
Fn
Data
File Read filename = QX41YSfi6.bmp, size = 962441, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156906 True 1
Fn
System Get Time type = Performance Ctr, time = 15694378043 True 1
Fn
System Get Time type = Ticks, time = 156906 True 3
Fn
System Get Time type = Ticks, time = 156921 True 1
Fn
System Get Time type = Performance Ctr, time = 15695152515 True 1
Fn
System Get Time type = Ticks, time = 156921 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
File Write filename = Pictures.rar, size = 86336 True 1
Fn
Data
File Write filename = Pictures.rar, size = 97 True 1
Fn
Data
File Create filename = Saved Pictures\desktop.ini, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156921 True 1
Fn
System Get Time type = Ticks, time = 156921 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15696388153 True 1
Fn
File Read filename = Saved Pictures\desktop.ini, size = 1048576, size_out = 190 True 1
Fn
Data
File Read filename = Saved Pictures\desktop.ini, size = 1048386, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156937 True 1
Fn
System Get Time type = Performance Ctr, time = 15696649617 True 1
Fn
System Get Time type = Ticks, time = 156937 True 4
Fn
System Get Time type = Performance Ctr, time = 15696675958 True 1
Fn
System Get Time type = Ticks, time = 156937 True 3
Fn
File Write filename = Pictures.rar, size = 160 True 1
Fn
Data
File Write filename = Pictures.rar, size = 108 True 1
Fn
Data
File Create filename = sj6 1xhDAi0ypw.jpg, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 156937 True 1
Fn
System Get Time type = Ticks, time = 156937 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15697000690 True 1
Fn
File Read filename = sj6 1xhDAi0ypw.jpg, size = 1048576, size_out = 22861 True 1
Fn
Data
File Read filename = sj6 1xhDAi0ypw.jpg, size = 1025715, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 156937 True 1
Fn
System Get Time type = Performance Ctr, time = 15697063711 True 1
Fn
System Get Time type = Ticks, time = 156937 True 3
Fn
System Get Time type = Ticks, time = 157250 True 1
Fn
System Get Time type = Performance Ctr, time = 15729309834 True 1
Fn
System Get Time type = Ticks, time = 157265 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
File Write filename = Pictures.rar, size = 22944 True 1
Fn
Data
File Write filename = Pictures.rar, size = 102 True 1
Fn
Data
File Create filename = svWwwq0D.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 157265 True 1
Fn
System Get Time type = Ticks, time = 157281 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15730959815 True 1
Fn
File Read filename = svWwwq0D.png, size = 1048576, size_out = 92299 True 1
Fn
Data
File Read filename = svWwwq0D.png, size = 956277, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 157281 True 1
Fn
System Get Time type = Performance Ctr, time = 15731095609 True 1
Fn
System Get Time type = Ticks, time = 157281 True 4
Fn
System Get Time type = Performance Ctr, time = 15731757621 True 1
Fn
System Get Time type = Ticks, time = 157281 True 3
Fn
File Write filename = Pictures.rar, size = 92496 True 1
Fn
Data
File Write filename = Pictures.rar, size = 96 True 1
Fn
Data
File Create filename = W-jIjn6.gif, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 157281 True 1
Fn
System Get Time type = Ticks, time = 157281 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15732533587 True 1
Fn
File Read filename = W-jIjn6.gif, size = 1048576, size_out = 63593 True 1
Fn
Data
File Read filename = W-jIjn6.gif, size = 984983, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 157296 True 1
Fn
System Get Time type = Performance Ctr, time = 15732646548 True 1
Fn
System Get Time type = Ticks, time = 157296 True 4
Fn
System Get Time type = Performance Ctr, time = 15733201467 True 1
Fn
System Get Time type = Ticks, time = 157296 True 3
Fn
File Write filename = Pictures.rar, size = 63728 True 1
Fn
Data
File Write filename = Pictures.rar, size = 95 True 1
Fn
Data
File Create filename = Ww lmr4coeaZVkLVzHS.jpg, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 157296 True 1
Fn
System Get Time type = Ticks, time = 157296 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15733794966 True 1
Fn
File Read filename = Ww lmr4coeaZVkLVzHS.jpg, size = 1048576, size_out = 6330 True 1
Fn
Data
File Read filename = Ww lmr4coeaZVkLVzHS.jpg, size = 1042246, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 157296 True 1
Fn
System Get Time type = Performance Ctr, time = 15733860632 True 1
Fn
System Get Time type = Ticks, time = 157296 True 3
Fn
System Get Time type = Ticks, time = 157312 True 1
Fn
System Get Time type = Performance Ctr, time = 15734304294 True 1
Fn
System Get Time type = Ticks, time = 157312 True 3
Fn
File Write filename = Pictures.rar, size = 6400 True 1
Fn
Data
File Write filename = Pictures.rar, size = 105 True 1
Fn
Data
File Create filename = YBodpCQ1OYUO B.gif, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 157312 True 1
Fn
System Get Time type = Ticks, time = 157312 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15734664622 True 1
Fn
File Read filename = YBodpCQ1OYUO B.gif, size = 1048576, size_out = 93957 True 1
Fn
Data
File Read filename = YBodpCQ1OYUO B.gif, size = 954619, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 157312 True 1
Fn
System Get Time type = Performance Ctr, time = 15734774033 True 1
Fn
System Get Time type = Ticks, time = 157312 True 3
Fn
System Get Time type = Ticks, time = 157453 True 1
Fn
System Get Time type = Performance Ctr, time = 15749337425 True 1
Fn
System Get Time type = Ticks, time = 157453 True 3
Fn
File Write filename = Pictures.rar, size = 94144 True 1
Fn
Data
File Write filename = Pictures.rar, size = 102 True 1
Fn
Data
File Create filename = yova8.bmp, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 157468 True 1
Fn
System Get Time type = Ticks, time = 157468 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15750206567 True 1
Fn
File Read filename = yova8.bmp, size = 1048576, size_out = 23571 True 1
Fn
Data
File Read filename = yova8.bmp, size = 1025005, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 157468 True 1
Fn
System Get Time type = Performance Ctr, time = 15750279437 True 1
Fn
System Get Time type = Ticks, time = 157468 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 157468 True 1
Fn
System Get Time type = Performance Ctr, time = 15750828265 True 1
Fn
System Get Time type = Ticks, time = 157468 True 3
Fn
File Write filename = Pictures.rar, size = 23648 True 1
Fn
Data
File Write filename = Pictures.rar, size = 93 True 1
Fn
Data
File Create filename = yWEcS.bmp, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 157484 True 1
Fn
System Get Time type = Ticks, time = 157484 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15751461766 True 1
Fn
File Read filename = yWEcS.bmp, size = 1048576, size_out = 11930 True 1
Fn
Data
File Read filename = yWEcS.bmp, size = 1036646, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 157484 True 1
Fn
System Get Time type = Performance Ctr, time = 15751575632 True 1
Fn
System Get Time type = Ticks, time = 157484 True 4
Fn
System Get Time type = Performance Ctr, time = 15751784888 True 1
Fn
System Get Time type = Ticks, time = 157484 True 3
Fn
File Write filename = Pictures.rar, size = 11952 True 1
Fn
Data
File Write filename = Pictures.rar, size = 93 True 1
Fn
Data
File Create filename = y_QmYlvwtNWjwI0tZ.bmp, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 157484 True 1
Fn
System Get Time type = Ticks, time = 157484 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15752162644 True 1
Fn
File Read filename = y_QmYlvwtNWjwI0tZ.bmp, size = 1048576, size_out = 48977 True 1
Fn
Data
File Read filename = y_QmYlvwtNWjwI0tZ.bmp, size = 999599, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 157484 True 1
Fn
System Get Time type = Performance Ctr, time = 15752277835 True 1
Fn
System Get Time type = Ticks, time = 157484 True 3
Fn
System Get Time type = Ticks, time = 157500 True 1
Fn
System Get Time type = Performance Ctr, time = 15752824991 True 1
Fn
System Get Time type = Ticks, time = 157500 True 1
Fn
System Get Time type = Ticks, time = 157500 True 1
Fn
System Get Time type = Ticks, time = 157500 True 1
Fn
File Write filename = Pictures.rar, size = 49056 True 1
Fn
Data
File Write filename = Pictures.rar, size = 105 True 1
Fn
Data
File Create filename = Z8PEjH5b.jpg, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 157500 True 1
Fn
System Get Time type = Ticks, time = 157500 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15753569568 True 1
Fn
File Read filename = Z8PEjH5b.jpg, size = 1048576, size_out = 83459 True 1
Fn
Data
File Read filename = Z8PEjH5b.jpg, size = 965117, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 157500 True 1
Fn
System Get Time type = Performance Ctr, time = 15753678170 True 1
Fn
System Get Time type = Ticks, time = 157500 True 3
Fn
System Get Time type = Ticks, time = 157609 True 1
Fn
System Get Time type = Performance Ctr, time = 15764695762 True 1
Fn
System Get Time type = Ticks, time = 157609 True 3
Fn
File Write filename = Pictures.rar, size = 83680 True 1
Fn
Data
File Write filename = Pictures.rar, size = 96 True 1
Fn
Data
File Create filename = zdKqdR.png, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 157625 True 1
Fn
System Get Time type = Ticks, time = 157625 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15766041990 True 1
Fn
File Read filename = zdKqdR.png, size = 1048576, size_out = 43236 True 1
Fn
Data
File Read filename = zdKqdR.png, size = 1005340, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 157625 True 1
Fn
System Get Time type = Performance Ctr, time = 15766128159 True 1
Fn
System Get Time type = Ticks, time = 157625 True 4
Fn
System Get Time type = Performance Ctr, time = 15766465471 True 1
Fn
System Get Time type = Ticks, time = 157625 True 3
Fn
File Write filename = Pictures.rar, size = 43344 True 1
Fn
Data
File Write filename = Pictures.rar, size = 94 True 1
Fn
Data
File Create filename = zoYWy0tnNuqg-Zdh4.gif, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
System Get Time type = Ticks, time = 157640 True 1
Fn
System Get Time type = Ticks, time = 157640 True 1
Fn
System Get Time type = System Time, time = 2019-03-31 21:13:43 (UTC) True 1
Fn
System Get Time type = Performance Ctr, time = 15767264336 True 1
Fn
File Read filename = zoYWy0tnNuqg-Zdh4.gif, size = 1048576, size_out = 91998 True 1
Fn
Data
File Read filename = zoYWy0tnNuqg-Zdh4.gif, size = 956578, size_out = 0 True 1
Fn
System Get Time type = Ticks, time = 157640 True 1
Fn
System Get Time type = Performance Ctr, time = 15767369020 True 1
Fn
System Get Time type = Ticks, time = 157640 True 4
Fn
System Get Time type = Performance Ctr, time = 15767976645 True 1
Fn
System Get Time type = Ticks, time = 157640 True 3
Fn
File Write filename = Pictures.rar, size = 92192 True 1
Fn
Data
File Write filename = Pictures.rar, size = 105 True 1
Fn
Data
System Get Time type = Ticks, time = 157656 True 1
Fn
System Get Time type = Ticks, time = 157656 True 1
Fn
File Write filename = Pictures.rar, size = 42 True 1
Fn
Data
System Get Time type = Ticks, time = 157656 True 1
Fn
System Get Time type = Ticks, time = 157656 True 1
Fn
File Write filename = Pictures.rar, size = 45 True 1
Fn
Data
System Get Time type = Ticks, time = 158218 True 1
Fn
System Get Time type = Performance Ctr, time = 15825376402 True 1
Fn
System Get Time type = Ticks, time = 158218 True 3
Fn
COM Create interface = EA1AFB91-9E28-4B86-90E9-9E9F8A5EEFAF, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
Keyboard Read virtual_key_code = VK_SHIFT, result_out = 0 True 1
Fn
File Write filename = Pictures.rar, size = 17 True 1
Fn
Data
File Write filename = Pictures.rar, size = 19 True 1
Fn
Data
File Write filename = Pictures.rar, size = 4061 True 1
Fn
Data
File Write filename = Pictures.rar, size = 8 True 1
Fn
Data
File Delete filename = zoYWy0tnNuqg-Zdh4.gif True 1
Fn
System Get Time type = Ticks, time = 158640 True 1
Fn
System Get Time type = Ticks, time = 158640 True 1
Fn
System Get Time type = Performance Ctr, time = 15868468578 True 1
Fn
System Get Time type = Ticks, time = 158656 True 1
Fn
System Get Time type = Ticks, time = 158656 True 1
Fn
File Delete filename = zdKqdR.png True 1
Fn
System Get Time type = Ticks, time = 158765 True 1
Fn
System Get Time type = Ticks, time = 158765 True 1
Fn
System Get Time type = Performance Ctr, time = 15880163914 True 1
Fn
System Get Time type = Ticks, time = 158765 True 2
Fn
File Delete filename = Z8PEjH5b.jpg True 1
Fn
System Get Time type = Ticks, time = 158765 True 1
Fn
System Get Time type = Ticks, time = 158765 True 1
Fn
System Get Time type = Performance Ctr, time = 15880516898 True 1
Fn
System Get Time type = Ticks, time = 158765 True 2
Fn
File Delete filename = y_QmYlvwtNWjwI0tZ.bmp True 1
Fn
System Get Time type = Ticks, time = 158781 True 1
Fn
System Get Time type = Ticks, time = 158781 True 1
Fn
System Get Time type = Performance Ctr, time = 15881064514 True 1
Fn
System Get Time type = Ticks, time = 158781 True 2
Fn
File Delete filename = yWEcS.bmp True 1
Fn
System Get Time type = Ticks, time = 158890 True 1
Fn
System Get Time type = Ticks, time = 158890 True 1
Fn
System Get Time type = Performance Ctr, time = 15892858477 True 1
Fn
System Get Time type = Ticks, time = 158890 True 2
Fn
File Delete filename = yova8.bmp True 1
Fn
System Get Time type = Ticks, time = 158890 True 1
Fn
System Get Time type = Ticks, time = 158890 True 1
Fn
System Get Time type = Performance Ctr, time = 15893163132 True 1
Fn
System Get Time type = Ticks, time = 158890 True 2
Fn
File Delete filename = YBodpCQ1OYUO B.gif True 1
Fn
System Get Time type = Ticks, time = 158906 True 1
Fn
System Get Time type = Ticks, time = 158906 True 1
Fn
System Get Time type = Performance Ctr, time = 15893568187 True 1
Fn
System Get Time type = Ticks, time = 158906 True 2
Fn
File Delete filename = Ww lmr4coeaZVkLVzHS.jpg True 1
Fn
System Get Time type = Ticks, time = 158906 True 1
Fn
System Get Time type = Ticks, time = 158906 True 1
Fn
System Get Time type = Performance Ctr, time = 15893953439 True 1
Fn
System Get Time type = Ticks, time = 158906 True 2
Fn
For performance reasons, the remaining 194 entries are omitted.
The remaining entries can be found in glog.xml.
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image