907f48f3...e07e | Grouped Behavior
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Ransomware, Wiper

Monitored Processes

Process Overview
»
ID PID Monitor Reason Integrity Level Image Name Command Line Origin ID
#1 0xe0c Analysis Target High (Elevated) hgaibc.exe "C:\Users\FD1HVy\Desktop\hgaibc.exe" -
#2 0xf8c Child Process High (Elevated) cmd.exe "C:\WINDOWS\system32\cmd.exe" #1
#4 0x83c Child Process High (Elevated) mode.com mode con cp select=1251 #2
#5 0xe24 Autostart Medium hgaibc.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe" -
#6 0xe34 Autostart Medium hgaibc.exe "C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe" -
#7 0xe40 Child Process Medium cmd.exe "C:\WINDOWS\system32\cmd.exe" #5
#10 0xed8 Child Process Medium mode.com mode con cp select=1251 #7
#11 0xf98 Child Process Medium vssadmin.exe vssadmin delete shadows /all /quiet #7
#12 0x2a8 Child Process High (Elevated) hgaibc.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe" -a #5
#13 0xc40 Child Process High (Elevated) cmd.exe "C:\WINDOWS\system32\cmd.exe" #12
#15 0xbb0 Child Process Medium cmd.exe "C:\WINDOWS\system32\cmd.exe" #5
#17 0x500 Child Process High (Elevated) mode.com mode con cp select=1251 #13
#18 0x4a0 Child Process High (Elevated) vssadmin.exe vssadmin delete shadows /all /quiet #13

Behavior Information - Grouped by Category

Process #1: hgaibc.exe
37310 0
»
Information Value
ID #1
File Name c:\users\fd1hvy\desktop\hgaibc.exe
Command Line "C:\Users\FD1HVy\Desktop\hgaibc.exe"
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:27, Reason: Analysis Target
Unmonitor End Time: 00:01:14, Reason: Self Terminated
Monitor Duration 00:00:46
OS Process Information
»
Information Value
PID 0xe0c
Parent PID 0x860 (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 408
0x DB8
0x F78
0x D78
0x F58
0x A8C
0x D14
0x EF8
0x EFC
0x D24
0x CF4
0x A98
0x D44
0x 58
0x 2E8
0x A34
0x D9C
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points AV YARA Actions
hgaibc.exe 0x00400000 0x00418FFF Relevant Image - 32-bit - False False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\FD1HVy\Desktop\hgaibc.exe 92.50 KB MD5: 5cb48ce239ba5b3ca53eeb45c155b9ee
SHA1: 3cd62251b8d580115dc0913ffd4e071b96000493
SHA256: 907f48f3480d0de1c0fc7a518e31e38f7d2da11fefaef88a5888e89194ace07e
SSDeep: 1536:mBwl+KXpsqN5vlwWYyhY9S4AQI2fKMQf7X5R7q1py3RMkkoA9hX9Jz1:Qw+asqN5aW/hLONffQfL5R7q7k7yh/1
False
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id-B4197730.[idecryptyourdata@cock.li].bat 416 bytes MD5: 7966c59f048a68e8ba4e6e88c6f3fd5f
SHA1: ec13dabd2c9028ed617319d022a9ef3f39488384
SHA256: b275b7f9f5f74b3ab50478743bbc17ec84a16f89de39f01433048c0a0c75fa7c
SSDeep: 12:8ynAHNEUXdpKpKUW/laqarNUKguXny3sl:lSNNdApKH/laq8LXny3E
False
C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat 378 bytes MD5: 72a89fbc3ae3555a54d59d3894f50c7e
SHA1: 7669935464029589fb40d2665ef7dfcef1e9b135
SHA256: 20eb1bc39b2fd720b9ec89225dba9a98964009e037ea973120b14de614cc18e4
SSDeep: 6:0RtE0ECLtem0V4OpCx4Ypzya89c6WC2EyySwACtXUPSgu1lw6QGyAER+:0RQAXg4OpCx4YpzXk8rAVJUKguXny3+
False
C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 14.09 KB MD5: 30eaca111ed5515a5c45fdd995bf111e
SHA1: c375e0ce6bc9b72b5e2dfbd3ef697630c496854c
SHA256: 25ca13c0a640cee0bbc7b60c0e53777e2cb3d5d60a2c7b08703db8929c14c192
SSDeep: 384:lMYrxMMj0AKYbbqIXFJjwVIdyLIcSY/fbn7Enw:hxjAlYlUVyyUqDn7Ew
False
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat 5.71 MB MD5: 68e1b85cb6f7365fbaaa6fdf7af3c6a5
SHA1: f35ab7ed5d6e2756cfdf0d79719835d964c47645
SHA256: da08eeeed28ec19df8cc23c3beaef1066d01b73d5b7237796b17ac98844fde21
SSDeep: 98304:uuEAUjb7BkOKxUKnat45mFe4H5+Ju4JKUYc93iKlOK1U2:e3PBkOK2Knq45mY4H5OMKkKN
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: a2bbf31bb88939e21c0d7f429a04f98a
SHA1: 8c1c63b614fd35dc026c92161abd63a7efc83187
SHA256: 4933f64eda641d23bff597464dd477bac1219514deff860ddf3dec4cf46089c3
SSDeep: 48:WlC3Qkd1Jw9wC5fv/Bwla2MWwsg5bHzwylIy3a:WlAbd1xCVy9MWzg5Xw70a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: bb7ac606121e1f8b896ba51b64302d16
SHA1: c003fdc30a9badecf02786bc370dda78e71a0c3c
SHA256: 364c7a1afb2db092d7bdecb194d70970325d8e583de660fbef57c9a7081a70cb
SSDeep: 48:OgyO3rtBJhDeXW/NAGw+oJ4E00Nj3IRBGBQB1lnm0y3a:n3hpCG/6zj4EvNT486a00a
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 4.53 KB MD5: 7babbe7f341ab2ae480064b259b4a653
SHA1: 03ff7b67ae26560b43f463a8be37c06192a062d4
SHA256: b0ddddf21dfeb6dede110625c2bace7a23c7c4b642fa2d9a6d67ca41c831983f
SSDeep: 96:pYJecTh98CeeLSa6Z3ZA0iyKNc90nwo012lftDLM0o:Szh98C2Z3O0idcSwo0ytDg0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.51 KB MD5: 3cd4a37e799fd4a15593e09339e68f05
SHA1: 7ebcc2fc0ae5d4d0bf3e0a079c7e8c753d93af09
SHA256: 33d9f8a3b0fcaaf5bd495ee9f9da39e1dc2b49fb3c3ffdd0e16340b2cf8e3df8
SSDeep: 96:Hfkea/JGjOE8E+Z31jvdJ8Bf90bg9tzrpKHj5C0o:uRGjh+rjUr9tzrWjc0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.43 KB MD5: 1f2a094545f38548d661727ef70992e1
SHA1: f0dd8affa742fa7fba78b6eb1a4f37bd419e5ce1
SHA256: 58050007d320338cae967028d50dbe66263dfbb63eec29077dc665f860d6d731
SSDeep: 96:iZg0rWHyrv2+gOaGcIxr4mXyaslXFt7oLnTxub6ht11SZRLsW0o:4ginu+CGc6xfsFn7untjh4x0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 9.82 KB MD5: 1b3a39f0d9f7a9c10e329c28a5d1de5e
SHA1: c2b1051ebf14047eb4e29448e974b56fbb9317ba
SHA256: dd367672e5fe8d17795133a91dc884409a411eb8313f693a43d3f57848192ecc
SSDeep: 192:+0iBiZzxAvqZRpL5jCmB14SlgY5cWi/7nzuT6weseJv9JQ0o:+0zqI5+mB6WiTvwesCvr3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 10.15 KB MD5: 4dbb00daeabb094c73440f2cc82627e9
SHA1: 799e971e56bae75d75392c1b4feecc0ae7f81d04
SHA256: f3567760631ce992d33c2a47dcd5d07ee691bce932ec28f4ecc7b2568b7f4557
SSDeep: 192:Oqk/ZFQF1aNZpKXSpewzFBy5JXPxVuH8iX2gCRru7FNtqLWkyq2FoDqtyO5oNBww:ONo3a9KCpeyaJXPmGVRaPtqL/yq2iDA2
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.67 KB MD5: fe2b70c8913b3cf92094d995ef66a601
SHA1: 512e2f7132772c934433c65d86a2eb72d533650b
SHA256: 99bbbfeebf99bf906ba3277c5c1e08d3c771a74b6c1f563292cc3d00ef04142f
SSDeep: 48:gie2cNM7//EbOVM09Ng2o6SddWDtdz6WhADy3o:eRw/yOL9Ov6SkdBhAD0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00525_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 9.61 KB MD5: 5e53faa479d9897a32b44e5d79ba3e62
SHA1: c763ae03a0a8a732ea634fe61a277a3f6e20d080
SHA256: ae2bf4502dc1bd931e41479560e609b0e77b9b0d49355d9907ce7dcc8900ed34
SSDeep: 192:au9ItfNJhRe6TGMqeYV2xdKdw/e6LoAxReMCXSG1WNzHO0Zixyy2Q0o:j9Itf9Tl/YV2xdKdtEehXb1WzPZixyyx
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.68 KB MD5: b4a1b9e2a374b1882e80a1c7687c0b5a
SHA1: 3bc5ea59767d081daf7e9d42fa6bd9a7f2ceff7f
SHA256: c55409deaf5ea12f7a490cd2135b4b586fbbdde5d94a2eab26712e7ab3e601a4
SSDeep: 96:q43rWDgoE+dX996KZI0zX0uPfk6FZUl59wtKjho6dLqQE1LY2j7mpOkUI3D7UG/x:q4bgfT9T20zdk6FZUl5t1RVE1fmpOkj/
False
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: f936d2e011cebf2b2c30c2c86f9a4c63
SHA1: c8f3783725f54c3efd8445f57d536921aa7d8363
SHA256: c976a7a2c136307235b5072b7960d59ef6cfacd4478e562106918e247d0c9a95
SSDeep: 1536:+GFuHjTsryxfDWGvFNPOm029/tkk7iKPlV4wChXfkBcF6CIwxys5:+GUHjTsrGJdRR029ukDPslhXUA6Bw0q
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.51 KB MD5: dcb2be5a7d569ff1302d982839cc20a5
SHA1: 44ed44e155ba59b03c322391a2357b9546752829
SHA256: 6d144adccfbd729363e9118774b0ed8a8f9e0df2af8649361f1b1511b1d93889
SSDeep: 48:fIAAIWhXueUulbr+P0oMB7Xthp0Mud3RsaBySuTg+KeJ8DuLAsn+Tvy3o:fIAQITLcp9hUdmNS+UGQuLZn+Tv0o
False
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.30 KB MD5: 08e06f44ab1532b08898d5ef3c714c25
SHA1: 8c83f4facae3014a8887fb13786a698aeb2e7233
SHA256: 41b54a1dd185c43bd241a3bf833ebfd87553b386d7785881f6ab2c1d307db7fa
SSDeep: 1536:vnuY4y7mkMd1CnJkp/BKTSb+2xeRKm1++089T+n:vuYFmJ1qJ8BKTe3erY+0Q+n
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 22.23 KB MD5: 658089ea6ddf2c23a5aef5dc89476d62
SHA1: 4e7f45c2f155e85f8e05674f5bc89721ba2d7066
SHA256: e34cb9e41458d3313b85ab4031c52ab721c569edcea855441e85bc02252bad34
SSDeep: 384:B6Sak8HSIC3iiKjHIAG/JBS+Whx43QAjXQKyCJOl99PRDoP3mBE6OafF98YgOo:B6SIfiKj5G/4x4AAjAMOza3wVO6FiYgh
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00372_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.01 KB MD5: 0752dfe5f73c92b7866e1e9284550dc7
SHA1: a606d617164219b1ced8ee5dc45aa886828eef40
SHA256: df700caa020934e1594702f11a809f21d8a77bdde4dcff21540b6ec5273169e8
SSDeep: 24:uYAcyn3VfdkzoDFSA08dZiFWwZ2awt989GFfYHXny3o:u3cynlfSzoDn086JZ6989GBcy3o
False
C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat 566 bytes MD5: 81e59b1bd54d7e11bfadc45593a71cbe
SHA1: deebcfe71c324ac1d23b1c8dbba5687cb6866f01
SHA256: 764a556198f0ca2832f055e58a5342ad16ce93e4df977363f3231b6a5169ab89
SSDeep: 12:hoiePL6I0DxK+oXooUnwAtKHgS7tniFH8lxxarrRgoQkNKyXFd6if1GDrpo/:hoix9DxJfoWbTS7tiFH8l38DvNFXrjE6
False
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat 852 bytes MD5: 627229317709a4231acb289e518c9762
SHA1: ddf28a623867c5f8d1219bba628edf36d426ee2a
SHA256: 65133525809563f0487a7599abd1ba80ee7c7b166e7963d55fc799aa49a3162b
SSDeep: 24:RCqX3jvZfCT8yXnWW9JsblMP2HuBfP0xeH8l38FR0NFXrjEDc:DpS7XB9J1L8lMFS1rIo
False
C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat 378 bytes MD5: 1e3695380fc868852817edcdba07a81f
SHA1: feb9d88cf95c5ecce0e09ad6e98868a807404e92
SHA256: 14892b618d9892d0a7d8528e16e11236e7821cca46a354f82ec188ee5f7e0cfb
SSDeep: 6:Gngyxf9bnt1cjd5KjPi2IlK6WC2EyySiEYQHsD/kXUPSgu1lw6QGyAER+:45tuH8r3NMYUKguXny3+
False
C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 17.09 KB MD5: cdc87eee806bb139179a9f3cb2bc09b3
SHA1: 8ccaf9e0af643295869120aa03573ec34eea874c
SHA256: ee753269e4e43b591376ec142ace726279df0e9c7ce9a00cfe373be28bfcbac2
SSDeep: 384:Xx9Htb0Opv6IeglbuqXkQo5VgiqwdCCpAEc0l3ohq:hnQO96IegljXkpVgiqwIwAEN2A
False
C:\588bce7c90097ed212\1028\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 14.09 KB MD5: d86a3934b97610fd1dbac10156dea797
SHA1: 5646e2652f56a3273fdbee23f39b099b74d68e60
SHA256: 92a6c798dec994a50fc7a5acb66a7e81160d1a9e309b0e5c04095229fa3c2edf
SSDeep: 384:VJHz6LpU/1Nl/SgHjSCvX/Iyfa4V0xZI5q+3e/a:/yo1Xfvv76x0q+3z
False
C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: 2abef858b47bf900e2b41989d69cf36b
SHA1: 4eb4c077cc065b24d4004683ea7f6d4a7e96f6a9
SHA256: d8ab5bbea5b9202e6437698d9d7f8fc39338666570ee45e198af9e9dcd81d612
SSDeep: 384:EPWBDqrXKsbawpw+ionju0X+DoXo/KWX7OlrV62Lyi89EfrdxNFtu4s:WWBD0KsbJJiyi0WLOlZLyi8KrNFtu5
False
C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[idecryptyourdata@cock.li].bat 314 bytes MD5: ee30ec4e00e595ba9c769b092a8ec363
SHA1: 25905bba7673d41912e422938f239be992e0f393
SHA256: afa30c0f3be410444f23b67dff40ed9245495ccfedc3fa2a620bb34df9d53711
SSDeep: 6:OqWi17Q/8PHDQlSaXxaEyySO47EqOzINWrZMxNFV36if1GDrp5C3:OqZU/8vraXxarhkkNKyXFd6if1GDrps
False
C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.59 KB MD5: 0b2583bb3625b330d8e48fb0bec9ab28
SHA1: d00faf2e12d4a01841edd8ed4a7ddf9d81b7072a
SHA256: 2854bab655d5363874ca8c653a1e8a303944776da3769eee4f60be0584469de1
SSDeep: 384:dndYv+bZt9k4/KCRahl+GkcCcoflNtBnnqKmqXDIKS742HMJHK:dGv+zSoPAQVNn6qTPSzHSq
False
C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 19.09 KB MD5: b76aab9244df2148bdc05601a284b9da
SHA1: 6109b3206e86bc61b03a388bbb362b4bc3ccb6c7
SHA256: 6a3472aea2159d49806795d6918d3b2c0e9eb38c5a9555a590639b36801f6048
SSDeep: 192:3wMauiLPe3NEdDVbYkDo6q3xoZ34n0Q/F+xvDwNIOJ1VparivaPEtNX9YK8OZ/JV:g9zsqdqkDOOE0C4xOJFrtDJUxkS9bnK5
False
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id-B4197730.[idecryptyourdata@cock.li].bat 140.95 KB MD5: 887bcde435102c501e9311d6633c8f2b
SHA1: d51d1af357f861d6a03c1f6e1a2eea2b733b4319
SHA256: 0eece7b90e566d2ddc14ea9a3424fc648c22bf3cdd4657026c69ae52c9e222a9
SSDeep: 3072:eUQdUi9zYD5lDSzTnKzUCMGM4VlvnebYGRhBZsT5vLIT4i4VilXOj:eUQdUi9zs5lDIPCMv4VlvnebYGRaVvLb
False
C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 7.61 KB MD5: 02bbf5c4af24cfaa729130a13df641df
SHA1: 503489bfaa5ccfc6c9dd4ef2369132e4181d8d40
SHA256: 2b50203b193306d2c53935fb980adbbdd6607b787cf4aa2fef361d7e0bfd5804
SSDeep: 192:DlPZrx+JV4PNQhxR5RY03Qo+lRYNZuMsyX5UxlogiWET0Q:9ZNQV4PWffRY03QINdX5UUgiTQQ
False
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id-B4197730.[idecryptyourdata@cock.li].bat 320 bytes MD5: 14ebff8b9c9f0ebd29503daa61cb536d
SHA1: f42b2e1890f10553e4bbe1fca0257d681e6f987f
SHA256: 47fb8c57b586cda49964e995f35667e6f72fb9217e0a1bcec5cbdf0b5d179387
SSDeep: 6:09Tod41FlUel1DmRH8lD7gTcEyySYyjoWXUPSgu1lw6QGyAER0:0RoG9/1UH8lITcroyj7UKguXny30
False
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id-B4197730.[idecryptyourdata@cock.li].bat 41.97 KB MD5: 02200f8502e18db40d31c56d2bc141ad
SHA1: e38b060d2ceda0154cc76c605f77f7920f27ef59
SHA256: 9a258b6be923d71eb5368f2814620b3caa556d7f46d1d834b6ac01f6728a1a11
SSDeep: 768:80ZLXYuRKXlYzSD1pgEOwtnPpT3rHpEuCAjfODnKidFLi/umw1evPr1OW8NO6FHa:7LoUeYziohGnPpT3rdjfAnKidFe/0Qgm
False
C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 6.39 KB MD5: 956e6ed5565645d957262188e9617078
SHA1: e64beb8b1c33033e9b85031dc58d24504af69872
SHA256: e7e01988a7960e71ed477260c4669490e4ccca0d6452d0a78312676748b7c332
SSDeep: 192:qgDQm2vI6pHggZfHtj02/4QFIrmoLrYJRc0Q:qQQaOrbP/HISJRTQ
False
C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 59.65 KB MD5: 24b41cf398eecbc9ebfa9580987fd00f
SHA1: 8a7083ef43e90c09a30583819ee1049b3e774153
SHA256: fa76b1be78e1af1eb699d05ef467d2e7e034d71b94f4cbef5245e19fc1cda2c8
SSDeep: 1536:U5L8hCn0K+zUmr1JImKW37Dg6vA9Qnwpe2EMsmth:U5L8hCh/01737DtJA
False
C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 72.72 KB MD5: 11ddb0d2ce7ef60b632a3eca704dac53
SHA1: ef1c68e56aa264aee7dbd6f5a4d710d6e8737105
SHA256: 71358b152eeecac2a53cb284c9bdcd50f603ffb6aed2cbd41fb77f939f242766
SSDeep: 1536:utbtuw89AhI3ystsKZaga5p8FQamS7xzBArK22c/frIApAVL/fQQBOTo:G9QAiisXZagGp8FJFF6KBgfrICAVDfQi
False
C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 79.32 KB MD5: f4a8a3a384505359927cfa3a1cefff54
SHA1: eb87fbf3bda51f8fc2d24088bb6108430f7079b5
SHA256: 8c42462c961f368bbb4c44224e1b5c577c4fb83e2fcef2d11ed534b3bdc8d616
SSDeep: 1536:WCfXbc4Y0U2z7rGlnl1IHFJTX0KVLmoAu73qmKvRawa+lW7k7cXzl2eq:vLVYZ7IHFJTXZLmovLl2xlbwXEeq
False
C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.47 KB MD5: fd74695ec1fabfe2d4f11099f7897228
SHA1: 75b35a55707a984fa0edca200778fc734462e28d
SHA256: 35cc276f60ab86a6d4caa32ec11a3feab13df36fe4765dd87f615573181e9c30
SSDeep: 96:rlY82a+10hLmWXVp/F2slRflUtNFm0x5cJpY0Q:rd2a20NVkoRj0xF0Q
False
C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 76.18 KB MD5: a5432df8906deb930b5ded09da4c6a24
SHA1: 6ee6c5c26405afc7aa4d21fd0f93edcddaac87b6
SHA256: 700ab610649e7e27689c584474c1c5cef89901e5e53d20cd13691500fd796c8a
SSDeep: 1536:TFUm1rnCz5tS2azG/nHchgihcLQmGQumczUTxd83W8955fK/U:TmAoxaq/HcKiNNWY3W8vfn
False
C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.86 KB MD5: 0488fc9eb46148b493ea591a36c83204
SHA1: 598f9bdd65ad1497c84fe8a3ec3cd06503d4790c
SHA256: d30b605d0449fce04cc1343c2721edfc850513738f619aa1a7cfd091b574d6c9
SSDeep: 96:Oui3JjbP6ppWDjyc1NanFG4XuAm6Jm0H7KaMsOUu1M/GX0Q:OuucSusquAFmCKa8N0Q
False
C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 80.66 KB MD5: 68b1e47b1f708f865c980b64ee86647b
SHA1: b8084a73be8172845d4aa77e0866bf95b14061e3
SHA256: f2c7e7f25e7208d6f23efb738c9c374d71acf5167ffbd9b9b9486b952653a292
SSDeep: 1536:EIKq3dPSbaLJIGcOTnmapjJ/CnQwYYHPU0CsVUtN4va/0PkJSEB:ETqob9GcO7Fw7Ss6tj+sB
False
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id-B4197730.[idecryptyourdata@cock.li].bat 6.14 KB MD5: 03ff9a3c84c71c134d89e1ee682909e8
SHA1: 4ea6ac5a5be2d13fb46dadb78af6be7102a084d3
SHA256: f367b2a96fa1cfee411fe08ff23568170f3dcfb386f71ffc08dcdf2545102404
SSDeep: 96:f7WAcKnPYJaZBC8zAlSc670pDG4NnJAYIZr4As7TPnMW4/dD4YN8WedWPVDuZZ8u:TnuUSiA/67MNrIZ8V3ulHtDud0g
False
C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.59 KB MD5: 1f465f9994178a358bfd7e8d139cd915
SHA1: 4ffe645c03a552b08ad4242a5110cefe6574a841
SHA256: 64b919f8206aaed1bad37e94853f92c371a730a8aea057568219305c47a28084
SSDeep: 384:vUFToXQbRePfY4yUgwiV/SP+aagLntA8YAbkaDyJcZS6eoowOzv:vsoXaePfY4OwSSp7tZd4uyus3opOb
False
C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 16.59 KB MD5: 14b410989e8a7aaf20550267bd2a48c8
SHA1: db5e9a77df80ab78809f9dd8252184d5055b03f3
SHA256: 232976da126a3cee50666660a3274e7cc7c6ad39166a80e8533d3a99893b251b
SSDeep: 384:ylylcAwL3dqjs//axc9CLkMrp28xHsoI2/pbGrTMiZqQOYd:ylyc7pcs/6clC4azI+AYiZqPo
False
C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.59 KB MD5: dfdf12aceba3588810afba8f50631a41
SHA1: bce38528143c8053df329f3da2dbaaeed6f8916f
SHA256: 6661b3e70eb05704907f19abebd6bc0e94f53bba86b51e310f0ea1d70aed62a2
SSDeep: 384:J7exjjc6IxC+3F0Q67bqPVM4Zk6uCEHyn0PtQT9sHySjf5zmP//6ZdWsXMjspka5:teFo6ICKP67bt4ZkDYn0qT9EyAOeFXMa
False
C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: 216ef4bdc6b77456f6e01e9993c8d3fd
SHA1: 40006f8bdd8b0133efbca76e7d4c42a7d5eaf69b
SHA256: 2bca198d1212c111f7580378ee348edd66cb694dfde412d7fafa684621e4844b
SSDeep: 384:1Y60Ixt/UrZk6UgJp/Sh+08OVAo6E1DegzFglXVLt:1DlUrFUGn08OCo6ERF0VZ
False
C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 15.59 KB MD5: f7c440243acfadc56f56c5cbe76cbd5d
SHA1: d6c887cf3c8039481101ffa609ffa0ba44621b15
SHA256: c847b094aeadb27bd21893503b85ec859c046902a4da92741ca17940ab32fbbf
SSDeep: 192:80xQoPfFbmhsQB34m5n4A2CUFufBRaVczYShq/SyRhMvsGIQdysiDFjBEFsrxIs1:E0yVppUFOBQCh+SwXDgk1EurxsvTg
False
C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 8.89 KB MD5: 381e95b4377193ba81346fc0964b76ca
SHA1: 89185241c95fce905192e14babd0acc796d06ab7
SHA256: 24d0212d7dd856e8ef074ecdd1934dd73d1b1b2bff634c6a268d6425a2cbf7af
SSDeep: 192:tjvLuaCnGFymQcmPDLLjYXStgNyMCw206S0Fd25RwYsUtaZ8xk0Q:tjvLP8NPffYogNyMCVLZd25RIZCLQ
False
C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 15.09 KB MD5: a39dc270015f9db44b250d8729a2ffa7
SHA1: 80a8bf696c0f80c1d11cf76f7e6836385c1810e2
SHA256: 00edd3f4be782d46fe3f4e0b80c6e97a6314d46417a40e37535cda2a948b560b
SSDeep: 384:hLT0etnCA75z/wp6IANwiK2tlRxkY7sDl7TB4BDiDQ+46JtVAOlh:hLTnZdwp6pu+xyBA+EziVAOv
False
C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 84.51 KB MD5: 9559316b94fe12382acb3449426a029c
SHA1: f217906638e6250afee8a25ad077241c2953708b
SHA256: 443a757d5cb295158e2115fa08e645c4faf326bc984955bc0677b08d76392f8e
SSDeep: 1536:/rgpfggYwwZZ4iQDOa61wrvnC6b0tOFOP8/zOpRI5dRFlmcj0e+zBm:/MpfggXAZ4gwbb0t4OP0z95X4Bm
False
C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.35 KB MD5: 0846a91b271f08f8de67447ce5d00968
SHA1: ec0aca83632b197c8005a1aa8d9540fe7e9628e4
SHA256: 0f3b580d37a5880bf332532874c005a3265eeefa357f45b0ce8edecc963b4473
SSDeep: 96:dG79b1V+2EPU668bwbKg+OoIKqfVhaDi0Q:dk9buhU7tbaO59ha+0Q
False
C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 75.68 KB MD5: c7583bd7457abbb75f1817d1852e6f31
SHA1: aed0ccb86a1e65a0d6af4d1c2d709d670ff43baa
SHA256: a8c2442c2a9fa1f82a9d324e8b60d7f4d05d050454fb186712f23d5733e96dcc
SSDeep: 1536:sWc+Ancnpumoz2kP37GYHqz1/e+GrBBn58Wvl5fVAg7BjZty/RS8+NBI:sWc9SqzcPArV//7dVXywDN+
False
C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.85 KB MD5: 02fab8934ee5f3beb4ad0838b9ee9e2c
SHA1: 99eca6a9d61d86bd49e393861986e5e7633f0e72
SHA256: fc702139b1bb906a8cf697db03b0b44587e9cbba340d4707647c52ad2d864fdf
SSDeep: 96:LzVMaUO9h/i9FYyRUeiPg4XLxztW5o9eA1gVz6/l9uQPZ0Q:Lmoa9F0tPdztWpRz6fn0Q
False
C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 17.09 KB MD5: 8d65803915f5418bb2c725b5dd8f3a12
SHA1: 0858756145c9a0829e71f5428cbb700241c79eda
SHA256: e20f02c36207591db9b1108730484b1147f795ef0f6002f56b0d4bf5fa2e21c0
SSDeep: 384:0IpR2dUI4c5lrR0dgo8oQlb9Swt5CnjvBhtGiUER4XtSg3o:0KsgyJRAgoJu9SgsnLBvRYog4
False
C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 17.59 KB MD5: 73f022fd834d39f6c0ede5143867453c
SHA1: c2623fef2e1c5d099f534ee29785a038129c729c
SHA256: 7ce4f65692a02bb795427a30b084bb3d4664e4a187acf6767ef03c92eabaf233
SSDeep: 384:7dxyGpWVnqbZjdirnaDw0GVjXqck9hZ425J82U0dfO14iIS8S:BxyGQVn2ZqSGV84yJ82LdfKDf
False
C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: aa29c394ebeec30c35d9034bde1d3016
SHA1: bfc7f2fc2a5f647f869a6120ae34827dbf2af8fb
SHA256: 0e036da7606229e63ab04b6d2f0a0feddc273cf16aefc53362f87c172e8052a0
SSDeep: 384:Idqc3wpuE6Htqf0iS5grRn/zzWPF3fzQ0NajHqqVFCr+rXoSpb3xl:Ioc1E6HtoS8RLzWfzQ0YTCrCXoGn
False
C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.68 KB MD5: 354f996331246c4ae2ab012ec89338b5
SHA1: 6923057910d2acee209989987986aa971c6528fa
SHA256: 015349aea24d711656b003d65b0cf714abfe2e51e724a1b86b0f634e288fd87e
SSDeep: 96:o5+JNN9X3WTKtDFPDZ/XY2mA7meBWrgfcAv0Q:o5EN/Y8PDZ/o9emKWMEs0Q
False
C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: d868bd1697c42e1a252242289367e4db
SHA1: 18d4207064e19ac2dd35278e4ab84210baa08bbe
SHA256: c6b3f6425b729e74dc5f761e16025caf48b33336cb3e9b9e0193853cdb5454c7
SSDeep: 384:ZJ2R9MkT5xQylYbzsshulIq1EE2earRcsKaHzcgGgc+x/6llc:iRXPQlU3oL1dKaHAEF
False
C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 75.46 KB MD5: 3dc5653b99f6fddf2b590f32798058de
SHA1: 910ed6e1e8e91e5946a0d85835f263097cade3ed
SHA256: 603b6865bfe60f6181c52fb808bd77120c674d9b82533d60a9de8e018618517a
SSDeep: 1536:hMuzc4ojNr9zZLY7l/YAdFNbBPhpIhyhyDmZ2ZxQ3mUUmMoMF7ZxP/5:GmaNrPy/XvBDtEDmIZ6PMoa7p
False
C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 6.93 KB MD5: 71d77aca14520ca21a4d5d4292d5d8f0
SHA1: 438673812275b0a1cebb0fac69863b4d4716e284
SHA256: ebd786cb62f8c8f5c0e94d7556acef3273417854de8b955f4f4e3bc35eadc3bb
SSDeep: 192:nYCOKQMhd51LL/6jzXKKCEfNM9DERjbUl0Q:n13QMh9LL/qzsUWERjbUiQ
False
C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 81.27 KB MD5: 96934984af63b196ab2263d7e5727fa9
SHA1: e15285466020271db2b8edcfe774c8f9f5098494
SHA256: 8c64d7b59853529d714e893dcccf70441753270ac8f556d80b0d77eb31056b26
SSDeep: 1536:SNbJ4QcknQC2uasmaUW8svVQS3+/Uboi3c7rxcO4Wg5qRidvlvn+YOznL:A4Q/QluasmaUW8KppoisnVQqwnfOzL
False
C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: 4fc9e3d699d7ae3a5ae4c30c070e2604
SHA1: 81fd857b8e22f410bb5a9c171f0e700fc1533c0d
SHA256: 7349035bb72b51a36156c7505122a878b40683dece9c4a8be82f12536005a8ee
SSDeep: 384:jPWk0G8YySMwKnjCJmLrOMl71rv6NB4sGSzVyPlDYQEU/t+Yw:zWk0rJpvPOeUHzAP1YQEJ
False
C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 17.59 KB MD5: 1bc70d14df9fdf8fa2d77f83de2a7b21
SHA1: dd53a96c94017f65871db4aebda27b03170e80db
SHA256: dcc81cd5b6a21d5aebd48930d20d780bc0064c364d5ea1ee516bdabbd89e07ca
SSDeep: 384:6MBbDJkp5CnDkWD4uLJRuIBBHxD1m/qaAwGsV+/Aupvg6er70ZyYpn/l:F5kp8Y8zuIL6HzGt/D/vh
False
C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 70.63 KB MD5: cf757704dc735c1d335e30fbf76c0cc3
SHA1: 1e12fc6b27593bd08d531404670ec44ed4f11a02
SHA256: 887d4e5e572378fb5edef09f463ba0241fc25757ba4f0967370134801fe4989a
SSDeep: 1536:27BKz/vaiZ0zI04WfSXoE9LXagohn/a9Uq3uevNvmiE3AeS12ZcKsVnbPn:2FeZTSwX9+Xh/AVvNvm3wz12ZcKmbv
False
C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 4.38 KB MD5: 744288cccbd96f209111490816b7df76
SHA1: 80a377edd78582cf85f8a0443041c6a3ce66a5a9
SHA256: bacbd74e34097b3a6000e025e5c6df26ff5ec0562524f422e6cba85f8946f865
SSDeep: 96:QpgLdyjNywE8iL4lrUFgRwa0nF/0et8ycH+Bn2g7JySa0Q:QpZ+CUFgRwa0nFKycH+BnHG0Q
False
C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 84.66 KB MD5: 2656f1133f03e9d238ce5ef5ccad97be
SHA1: bb4ede7ea31a7ee4075bfb934292853c46443730
SHA256: 64319675b0892a04541198461d82c133425f5883516e30ea5f01c70844c2311c
SSDeep: 1536:C/30RZVN/VOXSBOKMHjAjw19DRn50KZFzPCe+swzqIWgHXzgkwGJ/Wkqg:CvOVN/VOXSBOKMHEj45Rn6yFzPvMzz3L
False
C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 78.43 KB MD5: 5ef01ad236952c393cb475ee68b94d1e
SHA1: 4d66e1b9cde8a06a1a957d6763c2db4909b47a3e
SHA256: af140a8b7a319f87bd32b85f3d8c193c76272f0ad9a93a710e0b7b363a0303f1
SSDeep: 1536:bjEU5zouvdWzjZ0E+nZJPN1k+R8NLgYoL5sq2n+n7YU3Kb5UF8oLSgFJBg/:nEUpqfncXPDk+R8BoLGqdCVsnLRJe/
False
C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: 95fefc796dcd8c936fa59c3056f5e55d
SHA1: 5be65811214d7aaf615c8013cddd5d6a0a2318d6
SHA256: 7c30b49e320b0710a7e6a4c3e1d8904e3935e63bad719f881147cd90f6b5957c
SSDeep: 384:8l8Y292V2iJHkMwB43IuQEXtdgQGeu2jifnTLFhfex1IRIqyR:8+YY2ZWLB43/8BnFEx1vqy
False
C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 14.09 KB MD5: dead14bc2c4e31d9dc27aeabeade310d
SHA1: 94c693beb8aa1b7fa49d84172b32e521ca849e2e
SHA256: a290dc0887399e52b443033854819908430794c5cbbd7f03ecac66a0b0efa85f
SSDeep: 384:4m4YNX3DKBpA+daIeCTQlNdAOlK3B2WfRBNw/JyJ2Yh5on0+9:J7M/+yTfRBS/rYbE0G
False
C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.59 KB MD5: 5dcea09f85cd4591800d42fc8c055ea4
SHA1: cfcc358c9e68b77f45d93ecaf04613fdf80f6cda
SHA256: 989d08db25cd13c8ed31ee882a740d87fd4e1e674717944ad0311cd22dc94459
SSDeep: 384:XmuXtOYxP+vuBf6bZuEgPdmTHDjP6DJc5zuQmMcNQqgRsMMhByOwPAd7bubN3lM8:XbtZlBSvjmDJOKTMcaq/MuJwPAdPupVD
False
C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.79 KB MD5: f45891c15524035b273c9d5868387d71
SHA1: 20ddb496fb457e799bb10502ae72d5bf54beea2d
SHA256: c10721e28322986cabc2b25e60184211a25422abdb2ca8bb78fa3a6b940fde9a
SSDeep: 96:GYFdGQKMnIW2VjsReY7KgyIzSf+AyRpKbTZ3eN0Q:h+Q1IWjReYW7IzSfFUKJo0Q
False
C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 66.88 KB MD5: 69226ec46ccdf20e527567b22056eadd
SHA1: fb44c58acba637bf2d0c4613440d89ebf008bbe7
SHA256: 0595d0e912a86298314996ff8549d6d39e660c85979f20a1b1df83a3e65af1d0
SSDeep: 1536:dg/SmNGk7TKJpgjJpKRvlKw36cYh/L+7OGjmuFaAk4dW:EGmCgjJpoh3nYBLRGSMfdW
False
C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 10.11 KB MD5: 94af235c30b9a72175468268c81de75f
SHA1: 426b70e8c691077d77d5e955041e773a8203c26d
SHA256: d18f772867ef250d668f87fb14c4ba7b0356d2f6dc0d4828773d10e8d124a591
SSDeep: 192:IfffIEQKikr4fDszQFaZ58dH5mLXj3W80DTRmHJoPkO3n3BYSnaJ6RJpEgpE0Q:OikcDszco5+5mL77MTRmHOZ3uSn7hBrQ
False
C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 63.96 KB MD5: 254e644fd60cafcf4eb050ae3d791656
SHA1: 60e0fc442fcf935c56e227af0042b5ff55eaca25
SHA256: 384548ba9d54e10cdeef23388c730673ca588e8c675a1b94790805bb58d56b40
SSDeep: 1536:lIffDTq63MLZU8ZVZAOF/Hd8E8f+/tiLwJn9/S5XxV:lIvN8LKAAmGE8W/YLUiXxV
False
C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.57 KB MD5: 84d94060ceb3c885682e7acdb152252e
SHA1: 088c5312aff762fddc6f8962e898b027ef3f96f8
SHA256: d7eeb2624b90ab0059aa9b65c969cff791db9c656e90df72effda7767c84e56a
SSDeep: 96:KP5qtPP6SQZ2wfI+GxfXUTooZFiarXJSc0Q:KhqJdQjfIxfUU0ii70Q
False
C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.69 KB MD5: f9405ee087f0688daea3c71d21ccb5ed
SHA1: 69b67aeff8a383bf5865962a5cec59bc29c01c8c
SHA256: 21ca7a0c546e2beb27e93dd18c7180dcfd7eeb6411f8293dc89f765b3549b33b
SSDeep: 96:TCihyEsOIFT8vGUqD3tPauVw/602TICmvPYknIU92Cu0Q:OifGT8dqtnE6fxmvxn9s0Q
False
C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 19.09 KB MD5: 7b99bba8e8370d0a315ce150410c63ac
SHA1: 55fbb10155700a85ca7cafd21146e7a8efe46be4
SHA256: 40bdd967373063da43f6afed7c20e38e679de199b22bf9895b8bb537f34a6651
SSDeep: 384:kTSWB1hYkJta38ekqVQ9Sth2Uh5MQTAp3rJATuw7V6lWH8gmnSma3:knBYKtR7ihNYQMtYuw7AIcgmxo
False
C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 12.61 KB MD5: 6a7d7c245f803fa79d58a5fc1f97ad3f
SHA1: 93586760b35c6d6043c11aca2220a910b0428e24
SHA256: fa5ec943b758ef824da7589b4e6586099997e1f77743ed5fe056d09790dff20b
SSDeep: 384:CNxMF6wRnJqsP4uBJ/cKUNYPmZ9gGJRwTqehQ:gMBCyJ/FUNKSZzovy
False
C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.59 KB MD5: bdc4f6a7642d71e9685ebc45cd311f15
SHA1: 999c5df49e7ac3f26926c326abce439257fa0b3a
SHA256: 97a98e8966d429afb0bc345ef0607a39729e78705c16fbd4f8361dcd15fce271
SSDeep: 384:2x7D10BaAKGg6+vQtOuvoHMnUmqbI4b7r0SLnjVl0BI5z/ejeI4s5nY:2Jhuc64QtOugCUmqbI80SLjVl4Qj2e
False
C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[idecryptyourdata@cock.li].bat 86.71 KB MD5: 485a6654528b8da2c2344cdbe5eeaade
SHA1: f25fd807ca529afb917201bfb997876c50b7cae6
SHA256: dc05ba2636c979ea067984666206ffc892f473e190afbdc5bfe51c3e11848ba8
SSDeep: 1536:nApM8azMmoxsUA3OIvJIbsNEPZRUQhTMCVR0YrsxWx8vkvHCU8bW4D5tztnymMea:nv6nLA3OIR4DUQdMCPIWwkvkRVjymLs
False
C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.21 KB MD5: 2a40075d067e0b329952ff459038d0eb
SHA1: a18f52fd80065c5f06c29df93f4004315675d487
SHA256: 532e4705a14da2a9b09379436db3a29f585142f99c69033c462106903031761e
SSDeep: 48:M/eEdRm6hSI5hSTID2c4EvUoPEbBOaM5p6ETg4J69N5VYW2bRNg0t7by3Q:REKI5hSTa7R7PY32p6Ubs759K1b0Q
False
C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 77.69 KB MD5: a7abec74e01e510b6449e8b2ca39b716
SHA1: 211ccc07e92e115aee065a1727799637386083d8
SHA256: 3c3baa8607ff801dff709434f7f0910a3edc299c4e6a86d717d733a6e3f7230a
SSDeep: 1536:6uU5RTYBqZ2Ez7U34pO1B4Ppumkej2yrAycF3d5saOkRn:67TYM26JdDV2rAaOkp
False
C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 80.69 KB MD5: 8472fb87594a875a9f90ffd9909c5566
SHA1: 8e50b0de8953b4ee37a0fb9c5a80d53bd35b5f1b
SHA256: 1f599644df9eee65d4337a34fb86b61ab5000afae597e53f785aa1610e97b5e0
SSDeep: 1536:qqXqLTPeqio1/IMpimnHYdAdpsvTDhcnBJg8njyj+yfHCa:qqaLT281/IMMmnqhcXgIyjpHv
False
C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 4.18 KB MD5: f70b78b271bce9bf7dd998edad0651ca
SHA1: 6a08fa5e284725fd11191186b872e36f49e03fcf
SHA256: d190a6af5b5b07abeaa746e9610cf0eaa542a63d3eb4626bc100a6915a9b2383
SSDeep: 96:uyU2n0h1FBq7v7reSJyJvrvH4ynKwpYu0BuKUcoV8MGwuI6L8iwZquS0Q:uH20hf2DreO4TvPKwpn0BupcQlARpz0Q
False
C:\588bce7c90097ed212\1046\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: 653551f4f249ceb86b6441fce3665069
SHA1: 15069c679a0b93a0c1c01663abb06311fb872fd1
SHA256: c083cbd28e813b063cc1b3647727faff2144b76440f2514055a8ab83510f0fd8
SSDeep: 384:4epoF7I86xuL+AL312yWSgpfrm+DfPZRQx9v8kXAvy:4e67IzuLT2yWS3+Df8x9vVXAK
False
C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: e7434507f1f19704bddac570fec2a75b
SHA1: 10294a008a1f24f2bd7e2da0dcbc0f8a5e68c42f
SHA256: ca33e2eab7770641ce3a2e16fff1f87aec9a683e9ec2ea9be4dc7f4a5f3b29fc
SSDeep: 24:OOZMLmx+w/OQjgDFEXw03lX5eAcELaiWVKH92RByx/lT4WPBAA3RxeNFXrjEDq:OOZ+w/O2gEXNV5WSai+Kd2RcsA3Rc1r5
False
C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: 0b85ef32c09b96ab7c1a68cdaadc3dac
SHA1: cd9157231df75f4f2be07da40e36ab84287f896b
SHA256: f6591fe63a89750e57ac124a6333afdbc842a976460fd39351f3010fbbcf3e7e
SSDeep: 24:BPQwzIDm+lenUqQJ1jSg5yxj0+GvPByPwC5edU6GznQ77epJvNFXrjEDq:BPFIDNlBz/5yTGvpyoC8U6wQv0j1rIG
False
C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: bf976e7f9eaf1ebe1a290233f357ff50
SHA1: 5c63e442c9a2aeef0aaf46773796ff5587adb644
SHA256: c882fd4e45ec11bcdac80a90812b5eef56853cd6c39df7af959d1cc53d0165ab
SSDeep: 24:Re6y3C7nSaRLgf7iRBiRaLT8MLdloHzWxC8cGNFXrjEDq:R37SaRkTimRaLT8RCxC8L1rIG
False
C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.35 KB MD5: dec61601a944c3b6274820aec7314f0a
SHA1: 777f0d56fdb4bec7a915bb76ad7966187e4bb9a4
SHA256: e3d34783bab94ee8ff491d2e08896fa3050e6a9b15b2afe86534b6acff8fff7f
SSDeep: 24:K/Z8b3QrHCeaRpNSGA7znvcgo75ZE2jN7SjBrtpEpfMcZczk6ftM10O9PlPU7WI3:w43QrHQN7invcg+bEAOHqpfBcnfC179G
False
C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 79.10 KB MD5: 104686fa0a10257277722a3b889c5e0f
SHA1: c9ffe6d77d70e80920a6e34169d7938eaafa5180
SHA256: bb6c34a7dd9ca905a09b3d8de0c19082421c6e1bfdb3a2a4197125ea2a83a581
SSDeep: 1536:vfcgGYyVdsqyF8gJUxLcjJZjd5JqY/L+MRK9bUGPrGGn4ToQsrEQp:vkgGLQp8g+xUZzJqYjBGPrGOD
False
C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 53.41 KB MD5: 7d5cf5eab0f5e0d6fe4c49982cc3f4f8
SHA1: 5cda4a373bdf97c5fefcc4faa7c271127b45b906
SHA256: 9a9a42df5123881e8ec0ec9f1fc2c07aebdd04d8833555cbe731e0ee39d819be
SSDeep: 1536:OttMpv5MuIrhqnLOhXevf8J/hNogOqJK2Q:CMpv5MZ6ShXaf8J/8tqJbQ
False
C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: ef571b3db28c86a00af0b468b0f78ca0
SHA1: 8081447a67a322e7aaa3a782a9a3e4e63a9a250b
SHA256: eca07c19a11f5d2d940943943844448b88a10e06628d43318b069028b299920e
SSDeep: 24:Rxc71CTrsvAKbo8yZ9TrPrQQ/AsNgbLx3RLQqF6cNFXrjEDq:fVsvAd8yZNzQQ/AsWbvQqF601rIG
False
C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: 727c9623178c1c57a41e7bbfee6686d3
SHA1: e452a81fed05224f2c409ab9b2a59edc738289e9
SHA256: db932c503d2b76deb585eeb81de8d8bd3cfc8d68b32dc3ffb15e101536a38d92
SSDeep: 24:vWn7lkibMTCkkEmU06Kv1SLPjUmtwxHNOI8yqkR1P9ayyNFXrjEDq:vKkiIzkCK9wPjUmt+NnP9a11rIG
False
C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 4.00 KB MD5: 4a2dd7e316ac3fee3d5136fa6155c682
SHA1: 04fad01edf6f752e4e6d28136dae9d7374827b14
SHA256: e8b37e6dd69dddaa19ea301daadd180e932759869e460b278c7b5539143e5986
SSDeep: 96:sSiTUV/5tqFer+tGdJkYwSjqY2ROV2a/OBQnZ/dHxlAInStLF0Q:sSECjRFqYlNOmZFex0Q
False
C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 79.82 KB MD5: 266c4082ef3be217aca38470f27dfbc3
SHA1: 66d5e7205405beb2b0fcb64a39ab506fd0412ede
SHA256: a093a335bf755263aecc541aba9e346c448955c0c4c3f6454356f59d8cfbdfc2
SSDeep: 1536:rhXZh1FkO+dKna+fd75jPX1ykJZAXgbxBva9UNr2OFEuIS8:rHtzta+fd7dAkJmQbxhjZ2gKv
False
C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: 77fa56cfc8fed4d064894f4a33b81bba
SHA1: 99e92588c6faba5146131a9f4cb6ea8619ae8807
SHA256: da72bf79598e5f16ab2756e4cc353c01475093c1d95bd3fc5410ff8852f2ed9c
SSDeep: 24:ncQgBrI+ZYV4St5TvYfSMMICox1RgLNFXrjEDq:WBUUEVt5DeSNBZ1rIG
False
C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 76.12 KB MD5: 5e514098f2999cd51531d75e3e0e7f6d
SHA1: 9c6306a1f5c532e3b8105213f3155a0016d1dccb
SHA256: 371d26ed70573e784bc637a42e72eeae874a7f09775ac0d44694c2a26a32690a
SSDeep: 1536:jwfWN+HqTemO9mqMd46iLWzAHkZQFBYTHPJYqSxbbFxksc:jwg+HqFO9G4TYZwYThY7x/c
False
C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.83 KB MD5: 3f8605b1f76fba0726e7bb1689bd77fa
SHA1: 075e691a39d0edd4222638106050a216fd8586fd
SHA256: 7ec16f11b85a380b1aaae87d0b91c5bbe5fd32a6acb02dbaf6134f04aff5221f
SSDeep: 96:GNespSees3nykUXhSe17qd/Dd52VxAndFXY1A0Q:GNespSm3g9GD2odF0Q
False
C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 17.59 KB MD5: 618a864bd936a71fae2751a00e8bb7d4
SHA1: 4032ca44afa5c8fd519e802230ae22aeffa7c637
SHA256: 3ec199b144b60c02a59fc4a3ec83204d8ff6116e13a46eaedf87706ad45231f5
SSDeep: 384:LVQBTf68MeKgztC4xYvUFWhfCyLfjcTxToDks5LbAv0uYKjZ5A4ubMJ:LVCTf68K4cZcF6fzjGTU5KRYAZ5A4ubg
False
C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: abfb813e106feb03dcdaffdd76722a73
SHA1: f089b3e2035075335bf6bebb81a7951cfb392aa1
SHA256: af0a109d17973aa6c4392b6908c3cbcd2f53341873d06e80727980ec543268e1
SSDeep: 24:G8RkCUui/kRmdKsniupDpWCsI1aR/vXcNFXrjEDq:GXZkRmdXniYDN6X01rIG
False
C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 5.93 KB MD5: 5ceda9210ce00d7be85668f0300ca89d
SHA1: 8809e0806c3683661e5efd981d3ac5bdce0fe0d8
SHA256: 38738d5f3293b6243cf76bbddb18e0815dc1665ac4c9fd199ca277a3bc907451
SSDeep: 96:MyySn1pd+wxxXb9yqtUN7yhBNGVSciWGC84guI780Q:MGn1psAfVUEhBcPiWdGuV0Q
False
C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 75.27 KB MD5: 8dbde3f8955498c595a7eb038481d0b5
SHA1: fe649f4063c6aa7c1648d2bc9e7eeea636a41132
SHA256: 76b03f7bd25671dddb9496fe7969c2b8b4cc2ff7c2d2a36412078540ba88d66a
SSDeep: 1536:gFP80ANtU0QFpE83QJ7ATzmjrnMYSPdsETM1ZRaC0anbmHF99rFe:CiNtU0QFuSuM7dI13vmHFFe
False
C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 4.00 KB MD5: 4064e735a44b16d659230f41e7d9f3fc
SHA1: b561e98b6c73b0b45e2cb5dbd33d8f337b584b3b
SHA256: 201bb8d4b92f8c89fd593a48459c7965afcea588668e848328c596359c521ebd
SSDeep: 96:6EZUd3l/PLFDp35a1Jq6YR/hZBGk8K4cIURwT0Q:6E01/PLFFc11YZhZ2Ss0Q
False
C:\588bce7c90097ed212\Graphics\Rotate8.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: a7f4a378bc5f3c66395b29f48260582f
SHA1: 5c4b523ecd3ce313c9f1ce5ccef2ae24136d73af
SHA256: 1e9197a72a79760b9bdfc2c259587d272741afe6b403607dcb143fd7ea55d98d
SSDeep: 24:8U6h/V1/jdfFXvC9jkCyMnDPsGjwomMENFXrjEDq:8th/V1/j5RqlJDOoDM1rIG
False
C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.35 KB MD5: 83249a645924193e15a3634190cee7f8
SHA1: e68907c7708518443524c03ba0a507e3cab96b6d
SHA256: b97d61fea41a1a3367f7e7fc3169868cc5dc5185e51e906bb3f4784dc9163118
SSDeep: 24:ZfIasipuqr4s3IWHn5/ZIzK0vE4cPipSv+dOvTtjTQVUIqi60McrhNFXrjED8:1IjWqs3hPSKAEt+dOWJqC31rII
False
C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 59.51 KB MD5: bb2202b7316e3ab60f236083ae3e9131
SHA1: 261465ec36b317097e85a890022a4c3ad9940b77
SHA256: ad87c1d47126709a7aff0bd0a16019c237221ddcb6ef6baa62379242e73238fd
SSDeep: 1536:fbxp/toWoJRnFo8+RJGn0kuRE9X3LgWMlSwpYsMQ:fbtoWofFj/9X3LVa/YsMQ
False
C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 78.62 KB MD5: bfbe041adb04b7871985bef57b7fdca8
SHA1: d306ac735964e5d68b4d001718b89df0ef659969
SHA256: 0b3a5855e0f137b08f010b2aa3a55502d7873e24d54c2404367bd521e6d5ec20
SSDeep: 1536:noDFUBIZgD3+jHyIvzXfFLV+bmkSJZivdJn9M5YQWfjwArm/Bsw:nyUBIKT+XDfFLQZmZivPn9BRfjwMm//
False
C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 6.39 KB MD5: ff9463f7ba223a103c23a69b60071cca
SHA1: 887449d56d5f1680125ed25df7804644aac8d67d
SHA256: e13c3bb75522f7a1f665c95e50c3a9f0dc81b09f2707f9784c53848805e59a64
SSDeep: 96:/AvteO0vHUHrCL+jgrSYIGhyBonqK3ZD/zlwMXyKTWsUzN5H8v9/QCFlKortgMjS:/A1eqLClXyBml3XozN5CyqVry0Q
False
C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 4.14 KB MD5: 8a56644ca4cc85bccac7184267ceae5a
SHA1: fe70356543387dcfdc8f7bf2d67d2c75fa2bc458
SHA256: 0767de23113cc2fafc69d2c867fb706949b4cd92eeef35d4b1aca9ec2e1994ba
SSDeep: 96:2Ggo+e5pNegF7RRw8ezaTwCSr8Nd1aYZV3xo0Q:2NgFRw8zTwLr8NdgY+0Q
False
C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 78.02 KB MD5: b31255052ac159b2c87fb25e49ffda77
SHA1: 431fa98728e9bbef5fcfc82923a503f5125c5a74
SHA256: 3fffc827250232e471a6c974fb91d698ef61389f387d48ef48ad07d6fc79a134
SSDeep: 1536:zMq3WHj14XpvzMVNErK1w9EUzGCnYAmswV39DpVFFkZ0m+6p/HekVBn:B3WHj+BYErTGOYV3DOk6ZHekVV
False
C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 59.65 KB MD5: b9a9f9978ff68357e8a4d1b1e2e6b575
SHA1: 84e93fdc7ad90a7f228147bc02b472d2767f6c7f
SHA256: d844e0eac32d65678c9b24e90ca247bc5da65d52f3baa9a2774ceab142372ea1
SSDeep: 1536:S/s/dTwS6RMK4XZeQhVDjH0WcAOgqeuhO9cI5N3EhlmI:Cs/ejCK4EWDb0oOgqXhO9cs3k
False
C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.22 KB MD5: 1af075c2c5ef49cad84366244e0c1e46
SHA1: 7605857247a1deb83a4d2c90a8fc906c8b107c2e
SHA256: b456c4017e4b6ec576672684745e0e2f220b34a3da81af5c8a1ce4f1bb9bab36
SSDeep: 96:V852yMHYTnSDKfDpImL34kRtyVdXXMWb4zJs0Q:Vw2yVnSD8DpMAy/npbR0Q
False
C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 78.37 KB MD5: 8b20d921dae895215c3f68ab65bef7b5
SHA1: d234ac0121b69b3bcc4926651582bcd059ccf206
SHA256: a58c42d8e1389724e9a60569c8d18bd4a1413ce4c3d58c5190e9264566e51b5d
SSDeep: 1536:sWCAEekvM3MzFzWxqrzEeznrfebO/Opk6u3O9lBv1s0v6cMqpBgEmINpT:sWAHvM8zFzWxBQfzyk/O9f9s0yVmBXZN
False
C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 197.32 KB MD5: ab59085240935ed52048bf7d90ee6bb6
SHA1: f47dda9725d1958f65d50a6063f3779354eafd91
SHA256: 0031e2973ab32a1989543ed0a9f60bb3d390ddcdced693bae858c14c46b65213
SSDeep: 3072:i79oelXMyy8hK0caz16oetPpne+nV3qO0xXCG5rzFXtBAi+G5rCE:i7GaXJphK0cc6oell133qXBz1tBx+amE
False
C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[idecryptyourdata@cock.li].bat 10.13 KB MD5: 43e264d21cbbc2b9b33612b683c11862
SHA1: 3199a541431d6e0c61dbac487c53a690de823bdf
SHA256: 3ebf3d7513366f9b799dede1c43d70a600948f85f488b31acc656aa6b34f08b9
SSDeep: 192:40xoD+uxXtxaysLsYY0bCNIe9AA1rNIDlLk7K9fn9HckQAW2LAq:BxoD3XtYrLsYY4iAUqDlLkOhtc+W28q
False
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 91.38 KB MD5: 8c496794864651bb1da5530e1f0acb5c
SHA1: c3773810179aed18d666c5eb4e471a58894c735b
SHA256: 56bb80b40cf22a0b4ee77fbf22666c6889e92d1a4df25845a269092612a371b6
SSDeep: 1536:BwScSV45aFv/UUcSZL/lCHHQm/9x4V61DGROnBe6tOHxPb3P5d///tYZmYytw7sq:jcQ3vHDd/OHj7+uGRUexLP59dG6w7sY3
False
C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 38.37 KB MD5: 8f38f3501407d230699c71a7015f708f
SHA1: 49f85fa01df47b0db7edd6f2fe8a0a37cdb5a66c
SHA256: 198aaad85fd678bf92f40264edb570c20ea8269599c57353fe777de265dd5f7d
SSDeep: 768:bhYtFy6E6crnRqDy+ktd8o1VbJrHUsv/t7PHszkruutA:6tFm6crnL+IlNTlL76
False
C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 38.37 KB MD5: 3efe988a525814b328c0ebb96406eed5
SHA1: 3c5477b3a67ed76e0600712a5fd6b9e96cc7216e
SHA256: c61b46e5932f6b621230cf21a46add930c81d324c677a816e149cc7ae163910d
SSDeep: 768:NbMSpRVFxYS3maxzxEJmh8JeDnttto5IT971WLqrnQmR0FQYuDy:ZLpRVFvjE8h8Jejho5I5xWLqrnQmR0FN
False
C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[idecryptyourdata@cock.li].bat 15.99 KB MD5: 662d7932e6193444aaf8213efd72fab9
SHA1: 31acc93bbac2c8f3fda060dc69fdf447e0bd99c4
SHA256: 772ab40438d696dba247b5b60c9c0fba66257c9e53d5806bf338f54b94271364
SSDeep: 384:V3lCJd5FRY+EsKXLeWp3B1ocdEvJ27B4HjtTRJBB4A:RlCJdlPgXaWBPwU76RJBBT
False
C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[idecryptyourdata@cock.li].bat 36.08 KB MD5: 11e5e5e4a66be55a884752073b325aa0
SHA1: 917dd14cc824daf7c1548852fdf3cb9b488c004e
SHA256: 99846728fdb70f7a3fe4313daca1194e01180560db4c51bec24012c4e86cb83f
SSDeep: 768:3DJVr6IjLlQVBmxOfPvvJx3uNq7pXrhXJD7li:1c+Q3mwHz3uKpbX7M
False
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.36 KB MD5: c2256941d7933e9b9403b814b2b57908
SHA1: d9fde4bd34616682651cba2fec08614791cc023c
SHA256: c1fcacac458b1fda083f5b54d564835915f7b5dc6341f6fe3918848fb7ee7f30
SSDeep: 24:ETXALkjtY3qfdxYZFT/WHs9yrD5U/gfRA9blGg9mwqVkdrNdy/I0NFXrjED+:QhtrbYnWHAyf5XO9wVkTwI81rIy
False
C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[idecryptyourdata@cock.li].bat 29.65 KB MD5: 99a9e9b767d6537c33207b07d863acc6
SHA1: 76c0a621ec6defe2bc6e04e40e56e59aa92f0fe4
SHA256: 2927ce8a95be96c6ad37b061af2557a8d04a98f852b325666e2b1462c0a8de24
SSDeep: 768:054U91yrULQnZYn9pRDKZtHsYBsOCScQ0Mv5/EhT3UpLWu5m:05l91GZQ9rD4tHs3/Q0M1AIpXk
False
C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[idecryptyourdata@cock.li].bat 10.13 KB MD5: 2b26c7612f3d0866f725b64f579e0b41
SHA1: bd724f8bc2baa62ce62bca8166820be5a0328322
SHA256: ca01458c21f27c2bd8f4b35ce8ff4bd2a26dd97363bbfcc79d6a8cd8faad5e84
SSDeep: 192:luRK+gRIEe7YjfpXWjtXBAcPf/o7D9dyLjjLpYD/HJvZBbb/X:0KRjaCxkACHoXjyxOxfbbv
False
C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 265.91 KB MD5: e26e7f84c459dbf0cc5d379ede0253ab
SHA1: ea62e8cc34b9cd92af47b67749bbd9cfd9e50825
SHA256: 828ddcebaa9cb313c1668f4a41b37817846027d897ea25c8f5f7c30bdfa9f97b
SSDeep: 6144:Z6emcK5EB4NHWBhuYeDVm4t/44FIiW0fWOSOAcCS:435E6cPeDI6ze2WOSOAq
False
C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[idecryptyourdata@cock.li].bat 40.36 KB MD5: 2d4e66b27a7dfbc5de1fa832d5783e32
SHA1: 0447c2bdd4175a9c9a3fc90d03b6687be04fa09c
SHA256: fe60b60d4afe5b24c5b0e61c8015ecbce76ed6825e3a48005a2822fd0b28909c
SSDeep: 768:Lfx2NqbRqSr40Y76qStWY7Cmzxw0TRK99jZJBiFZNvQq0lnZdp2ImqAN:Lfx2wbYCf0Y7TVroPzoFZlQFNZdp2F
False
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.36 KB MD5: d17f0fddbfbffa380d40fa4aab13aff3
SHA1: 55d39b8bcedb3908b33f35a5a9cd536553937825
SHA256: 834078199ae0f05c433567ef11720efec24cac9352f5da2b76345b089f074fc3
SSDeep: 24:i9KdF5vOQNEUAP462AzuCMvOplBUB0gwgvmPhL0rIxOn6Qiw2+z9i4/T6X36jwuv:i9KHtzKlPLPBMKUyFOmg4nQiezk4r6Xm
False
C:\588bce7c90097ed212\Strings.xml.id-B4197730.[idecryptyourdata@cock.li].bat 13.99 KB MD5: d539929b494500b13b0dc4e480882cb9
SHA1: 7ef2df0f7bca737b16732090d6d43a2d6e57dcc2
SHA256: 8258836431d8163fb4f16c9aded2cd67b5396b92048ae09a44d76a2d860a1f0e
SSDeep: 384:RZ2XSgikCInqoKJqKlBwCau7+tIqcTCn3guwB3IAdwpYwW+:RZ2fNCudKJP/3au7+tIlTCwLB3l2Yy
False
C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 38.23 KB MD5: 45e9d1e70116161bcd4eba6c6658c7a0
SHA1: 6e06404aff344014438a0741df60d438f6093f5f
SHA256: 22e42bd17d4a4656c614a2e2d22e901dfba0d417bbc5a3f2adc6ab22b360dd5e
SSDeep: 768:OPfyQKLiiNAwR/DEeAINUSnPth5SJdfxElJxYUMC72dvAe/fmdqSj:OPfyQ6AwDEeAINdPjkdfxcLqvLpSj
False
C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[idecryptyourdata@cock.li].bat 173.83 MB MD5: cc75e7bda8993fedfe1a6badcf08dce7
SHA1: 9f7920f930c3874402c2d3c14535e2bdd1fe4eed
SHA256: e104262286e666244be9b1244b073d074f316420ff783d93d664a93ea8c7c99c
SSDeep: 196608:GV04YyKSBXZ35w+KBK2KJKDcloT46ooP8ZNoz+hK12RP1O7lT:z4Y7qZ3CwFISoT46ooP8Zyz+hm6Mp
False
C:\588bce7c90097ed212\header.bmp.id-B4197730.[idecryptyourdata@cock.li].bat 3.77 KB MD5: db7cd03cbc189c48358693db52a3ab78
SHA1: 02d08c25689086931cd8259142d49be97679e3ec
SHA256: a62780fb776e4df4e099143f6a17ffeb8d0d7f1f14638910f69a56ada59e514f
SSDeep: 96:wmW128T/tKrObqSbUVtkvkY1LMleZSQuQJI08:wmW12853q6fvkYWleZSQhi08
False
C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat 1.11 MB MD5: 2db797bc9e7c395401d418d594866fb2
SHA1: 955da6f915f171c94299560c96f9fc58c20be7bf
SHA256: 1d45cf40a0242faec55d90c00c0a0ac50606ea68300c06ba1c561ffa66c9dd3c
SSDeep: 24576:G/ULu6dUmVHx/c4gm23v2C6UWs/FTzeyAi56wql+EamD:GcLu6ZR07m4v2C6k/ZC0ryD
False
C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[idecryptyourdata@cock.li].bat 101.87 KB MD5: baac54b5947ec479258907f872ce090c
SHA1: 5e2cabf025dbdcb14c9fd9f279cabfa139a8122e
SHA256: a93960a0b2826629ab6abd8d14a7ad4e23dfcee24ebea9d9997de5b41f921f60
SSDeep: 3072:rPQ5cdzviiWqHFovSB5D/sfJNTD+kWcDoqSlwy:UurBHyqB5wNTvW8ocy
False
C:\Boot\BOOTSTAT.DAT.id-B4197730.[idecryptyourdata@cock.li].bat 64.25 KB MD5: 02068f1cd61d523c20a8b0d2050785db
SHA1: 1954652ec1d5a19e3b392f45dae6543633537d5c
SHA256: 7b011ffa1849489bba48f7a3fc86e65d2284d70c2fc31e17cac9b0131c3f613b
SSDeep: 1536:VxLGoCkDhV2twNhubs8ulF0B5qHfkqwnhgajfpUaIZR5t:/3CuLJCbsJlFIEHfHnUUDZd
False
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[idecryptyourdata@cock.li].bat 4.30 KB MD5: c4185c1742acd2f072ec7403b91d9e68
SHA1: 66260a6847aa443b1005d850d717c919fcb7abca
SHA256: 4b5d73d093dec425380ac380863b6e21f9c4b70ff2d425f9ec5936721c994991
SSDeep: 96:hxNKuxHDuE9/vqRJDYvMbRsWGHylMg79dVsvM3rl0E:hXtZCE/vmJrOWGyF73VIO0E
False
C:\BOOTSECT.BAK.id-B4197730.[idecryptyourdata@cock.li].bat 8.25 KB MD5: 86ecc2c13cc1d08f48686ae9afe8792c
SHA1: 9201df9bb636cb08bf14d5436946c3f181afc5cb
SHA256: 7a3e3685f8ae9e6b9d815eac9f0fdeee6711a81b5a1abc236fa50164f07ab9d8
SSDeep: 192:EnuCYy5LjxqEuIj0/HRfstaw1em0Le4y9oOu0o:WuA1svw1/mr8o
False
C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat 4.62 KB MD5: d0e9ed67347391f5160584dc39eb8a02
SHA1: dd2847776d0db5fe705f9fce8698a00f07ae77f2
SHA256: 829e647ca2ab87fd26114c15aa7d705ea8b945b8139e173652dfd070a7003909
SSDeep: 96:Loaw6rqL1z0lmPg/c1qemYM7mJ3BklLgwhokoPPaQkjguR0c:Rw6A1zGKq7YOEKulkGPZkjx0c
False
C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat 4.93 KB MD5: 07d8df4642c1cdcd29edf8b291ec0401
SHA1: 43f198fe3baf73b1bc0232c823dc8590760f89b3
SHA256: 927576ea581b216e212906bac4be2d74f489b958300817986f6891ff65232067
SSDeep: 96:77P9GD5GlGSeS2j2qHrerK2WasIdJnDlOdUU9h1qNMF7LcbgZH0w:77kD5GgStqkLJRO6QAYku0w
False
C:\588bce7c90097ed212\netfx_Extended_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat 852.27 KB MD5: c07418d3876322945b7204296d88b3b9
SHA1: 1270c75d75e5dfbef2dbe3accda2ea06cd669940
SHA256: 8ed8ae2f302ea2b886b01c0ab2ff82a5bb0c83f64be8e3825386be1cc3f58d6f
SSDeep: 24576:iw66gZBrVPP6MmenmKjfCig2X9BcxN8icU:l+lPiNizLcxOicU
False
C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat 2.56 MB MD5: 1b15d476cd5e5da9666f24f2b0f6ee05
SHA1: 768d1d44ca1068f05c662d6ac20f1cb413fe5784
SHA256: 776a50f58e20393c490ec035ef6dbcb343e360bcf9c42e5ed25fe01166075ac6
SSDeep: 24576:nc+BQbPyxbs4rONS5voMfjhOGxy511DtbGJDXSsMBF5fuOSVUzQ704:ncxisfQxoML+5ZbGJ7Ssi5fuOQG4
False
C:\588bce7c90097ed212\netfx_Extended_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat 484.27 KB MD5: 9d81dae26ee92495576b31448316c75e
SHA1: 8d358254da4af299656d74bbcfc1a68bec5f932a
SHA256: a90fa5cc126809cdc1fdb6a6f1edeaed41404dc25c4bfe4e74dc6ac60156dea0
SSDeep: 12288:TckBpyc0WurOLv2fNzQe9pdFzIfxWS7ndM7b2I1g4H:T5vyBrOatf9pd+ZWB7G2
False
C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat 180.75 KB MD5: 059507f9c72450a89b7d1a4052d3b741
SHA1: 4d07c8c2df1b1281d457d17a0ac430823a017b22
SHA256: f03122195cdb24084b97088a397edd9e1677b4747e9b7db4f6cf866804172607
SSDeep: 3072:09L+QapwxlIDjG7uFbSCIe3tKM5UjdFscX9QxZ0BRXplb/xMg/G1D9TQycTNkLD3:IaUMG7uS1e3tLcX9QxkR7Ba9TQycWhv
False
C:\588bce7c90097ed212\Setup.exe.id-B4197730.[idecryptyourdata@cock.li].bat 76.55 KB MD5: 99fece5d5ad338cc980d49c53d2c88bd
SHA1: e901b50a64c961738a75c839d6453df205ffee2b
SHA256: 4cf06d09b2eff9af42abc0847dae73dc40b8dd86b2b7ccbab4a3bc1fce24e44c
SSDeep: 1536:befB9VFgDsfSU55F634Pt+XOnDWBo8WW4mJwtmARwBpUGo0sqRp/ti8d:ov7gQf7F6IQwWeW4X0BSusWpl/
False
C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[idecryptyourdata@cock.li].bat 788.58 KB MD5: 9644a2e7ad61e3c8e1a7aa07fa614090
SHA1: 11cec3ef26e1d7f80e267e4c220c7f1ef1325cf9
SHA256: 6baf7029cd9a3e8ee46d27d48ee1006a4688f642aa6e473789f4ac610152e365
SSDeep: 24576:ho7WpZnTkuqcLSjQgWGahZrmpz8DZkVyjR7+rPcTp:O7WpYcEgrhD+VKR7oUTp
False
C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat 92.75 KB MD5: bb71b4d0797295f4fb7e2405dc638495
SHA1: a97b6b66ca28a1fda9739cd7625b422130a35f01
SHA256: f68519e5b5e19ba81776c923a61df37696171a83bab3107054bf66ecfbcd018c
SSDeep: 1536:ltoeGs4ofm0PTyM1wHgFfvqJ0GXLoU3+tHzYLZFEU5yDvzXX9UVLPT+NP4m7f:ltOsHO0PungFHqXXLrxLZmUarH9UV2Nb
False
C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[idecryptyourdata@cock.li].bat 288.57 KB MD5: bd57223e4d6b6ce445cb6694e2483cea
SHA1: eeaa2b9f327dec2d48fc30a66218f18848c279fd
SHA256: 2c0fbdc404cf6baba258945d397326640da938c31cf7f6a69d03eb7194c4358a
SSDeep: 6144:l9Hx5ofz0JcEvyYKSDSg0V3Dck70X2YvcJFxnnNFPxxv1oBfz:l9R5oQzzKx3VTnomXFxnzJxvyBfz
False
C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat 890 bytes MD5: 04b0de182c1e54245d1f66f4ff1a9d1b
SHA1: d7730105ded16c147319fbe6f2372f35b9931733
SHA256: be3b77afaf6754c96af5b9d373c022ad1312f087f1600e69207f7423c66de2ba
SSDeep: 24:T6QhK/LSATgH2uWyMSub1bFtW5fCpXny3+:T/c/LSPH4jSupS5q1y3+
False
C:\Program Files\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat 410 bytes MD5: f32077b329cb1a1337913cd55d10514c
SHA1: 1ebbaf2b1a34df7bd2dd47b7341f7d248a8da6d8
SHA256: cbaea4c568eefc4dfbd536d196115eab35be54c0a4f17f44ebb7f8513bd95d95
SSDeep: 6:ofpPHmZrHaKkli25TVgPBguHCpvbuoZLwTEa46WC2EyySpdeXUPSgu1lw6QGyAEk:oZGZrhkwUTVgPBguHE4X8rGUKguXny3+
False
C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[idecryptyourdata@cock.li].bat 1.62 KB MD5: a725dfab531eda124bf03cb59f431ec2
SHA1: e2d1b16535feafc58b9bd2319b1595aa1fb6160b
SHA256: 195234682e75fbff6a4fd8f50d98e4ef968e26e82b63d130f60620650dc345f9
SSDeep: 24:jaog8DXZCY47GaZC2CYGacx0Y6CIpfDM03F2p7wcuh6VX9ZBkr2/6ey0kd7KXnyM:jpt94wYGacx6fISFe3uh6hlkrkJIey38
False
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.id-B4197730.[idecryptyourdata@cock.li].bat 15.15 KB MD5: 3b973b24eb5634d57ec8aecb16389e1e
SHA1: cb62932659cf38152a6bb27e9f975cc3f932077f
SHA256: 13b5a9fcd8dc298a867091088bdfac3df36a51a2b142b78990769d14882534ca
SSDeep: 384:h0Za1k0LE0oUpMH49gitknbKcd5nlVKCwDBI1q:h0A1ViUI9it45nlVc
False
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[idecryptyourdata@cock.li].bat 8.62 KB MD5: 50068f8a0c50c9a0644bd48ddeeae6fd
SHA1: 8a9ee73fad3c74795f9f421f625e22c731988314
SHA256: bde3fa65d5116bb58205357f8d197c46ccb4763b878ca924565db02607501961
SSDeep: 192:w6GAM5ebTkSCqdwvNZp8j+U4OSPjsz85O95SFaA++T3QkyWxQY1f08:FGaTkSZGNZFvF4IuSEM7QTWQl8
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 404 bytes MD5: e8eb324fb2c0d24ed000ebc46e0cb05e
SHA1: 990094bb4842aca635aec65e88b9e11b8310a32b
SHA256: 5484332261339adb51ad6cdcd941aafa8f97204ec8a67bd0b8f6ceeaf03757bb
SSDeep: 6:MsjEMMs2qWTQS+08frH5tbciMvnOClQEyyShqFWXUPSgu1lw6QGyAERAl:MTM9qNUj7MfArRUKguXny3Al
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 434 bytes MD5: 869fb6b70ce8064cccdc905c670081d8
SHA1: 409554cd6ad2358cce6c6f621861814b7ae67e85
SHA256: 89d985d77d216169f985629cd10d58831c0901ee246bf47fc1f9e1ae4addaf69
SSDeep: 12:Ypko0g/bXLquaSmdTVCbXa3OArMBcUKguXny3Gn:wkhcb7quaSmdTQ09Xny3G
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 422 bytes MD5: 20a5ab965d11f4b400f46220fb86f0ef
SHA1: 7e61c721cb2170b9b2d4df241e68ee3c5d86a02f
SHA256: 9a85091c11f7e5d545fa02f81841aedd15372f06974ee957f8a49e520b87cd9c
SSDeep: 12:C/zlvYANvBImp8ytaEd3H5Ar/BeUKguXny3Gl:CbpnIIg/BWXny3Gl
False
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.id-B4197730.[idecryptyourdata@cock.li].bat 14.06 KB MD5: 680f94e20a86d4e96141b9d2ef9eaf05
SHA1: 23d52d4c397b4bce99efe0005a7cfc6facd0fd91
SHA256: 1e32025b1a78978aa45692eaebec4e8862c9673863b257c5c11818daf9e99753
SSDeep: 384:8O+HJzc5Jg6gqLSXRFV+VnIIkNiGcEQz+:HIJQ5OF1QINiGz
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 422 bytes MD5: 5920776677517944ac72c9928101fe8b
SHA1: 83fbed6ce0ec21567757de7b307bfab33d521208
SHA256: 48129a2256312075a4ca0abf3b36dfaace282fd8bd7f6b9236503f8dbd6a0d2b
SSDeep: 6:rQ2EJCmkhFheU03nL8ap0sOVXp3CDb5nOClQEyySuDoXUPSgu1lw6QGyAERGl:NEJLkZeL8K0N530b5ArvUKguXny3Gl
False
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat 7.87 KB MD5: ff573fa6b538bd6ed28e696aa95db447
SHA1: 03a04b1d0512d08cbc95e26e4909eed779c40cf3
SHA256: e9758a082a2be1cd663c227f0aeaef1ad08f9d7d1799fb40c31cde03c1a4ad50
SSDeep: 192:Z2NUiICFuD9v3IzoFKvtvI9pzNkpajDpR4+nXO+yNLU0C:4UifF63ICKZMNY6DpR4++pNLbC
False
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat 12.21 KB MD5: ae1f68feecf68609d8f5b1e4b28edecd
SHA1: ffc5986ed6cec585b5dea5bba8bf876ca6436bf5
SHA256: 3048e8889152022e55ebdf1aecc2fe206162db83ac965289e1daa9d54cc6301f
SSDeep: 384:payk0URtfTF09On+qI9BvLgplZ6rHH4+4UWrBQGY:nk3TFLuBjKczH4TNQ5
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 418 bytes MD5: c7f41d6307170bc1f3c4f3bb9ea62d63
SHA1: 809703cc4405e3fccc99233e6af1c16d9e6539e6
SHA256: dbbac8d8bf80049311f6e9712f843a7be4c67a5d4b17d58b94c3d9669bc382c3
SSDeep: 12:zCHxRVGd+CaZ5UUgrh0/S3qArpUKguXny3Gn:uTVGd+CaZ5UUgd04/Xny3G
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 422 bytes MD5: 720eb913e755a9ef4f6a7bea70ae5c0b
SHA1: 6746043d362fa3b1e53eb145dd3290bec453cdc6
SHA256: 0953857a8f2184e350df3cec7db2ae5a5e2c53c22c32733f691365c0d44d3805
SSDeep: 12:ZES59uXlH9lS43vT5Ar9PailCJUKguXny3Gl:ZAfBghawKXny3Gl
False
C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[idecryptyourdata@cock.li].bat 280 bytes MD5: c20cc1c1950bfbffbb06405e490989c6
SHA1: c371c32b56e1233685a4837d143eea34d7ae1e4a
SHA256: 42e6a06c34c5a14c54dc370d22f4e84a3ea5294df71f6f3597f953183fe2ff51
SSDeep: 6:/CRhVpprfEyySmS0NWXUPSgu1lw6QGyAER8:6RhV3rr0sUKguXny38
False
C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[idecryptyourdata@cock.li].bat 103.25 KB MD5: c08aac48bffb590c351bcc342f2f452c
SHA1: 357d17b2a6a088642f335c5483dce47350f67be3
SHA256: 6a000ef3f44088fcc71237c48db676e3167f3e6e70c54fea4f4056d6268be343
SSDeep: 3072:x4JVHp8Znnm2L5w8b1js2DRqasaIKPF6UAP:4+mIxA2DsnsF6D
False
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[idecryptyourdata@cock.li].bat 62.71 KB MD5: eccecdd18e9f5ca296e14a700552c404
SHA1: 891166d6eafd6f4c5e083f71be5df46acc4607d7
SHA256: 8772356ba2afa437f826e6a44437149cfd832e54541beb79484a250aded4dc4a
SSDeep: 1536:MD7tLgRWbiwaSFj6oz2ZUHpwVAH6d+VSvEC9BKOPvsvnPYurF:MVLg4bJZ/zVHpwO0+2jTPuAurF
False
C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[idecryptyourdata@cock.li].bat 4.37 KB MD5: 954df46f9939bee962bf64ba933ed1ea
SHA1: 4884cc7ba1ec2002ed2bc6bbf79a7de6f48cebad
SHA256: bcb1947541ae5906394cbcf28edcd593d1f1665a298bcb7121d22ead3b88ed42
SSDeep: 96:6sbimiCbE3YdEPzve6YPGd2bLCbgheNMQH0KZl8sNhGFd0q:6smma3zPTePPe2bLsgwmQHxlxNC0q
False
C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[idecryptyourdata@cock.li].bat 1.17 KB MD5: 4ef37de16d57f9e2599542d4dc11e093
SHA1: 366664c569d9ba66ab0dfaa3a26ec67437029fde
SHA256: 4807bed8326609e5ab8a949e487273779459db0807ac4b1519824f0526361adb
SSDeep: 24:4wsHeYzFmOMnFJdj7MaNVLA2jiUKX4baOtJ1/j5ZCtU6qZLWPwJFoNpXny3o:4wweYzFmJFXjwfTX4RJ1L5H6qZtXyy3o
False
C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat 141.27 KB MD5: 4a747be0c8144c65e64d533a8009317b
SHA1: 8a45ebc6d50ff1f6281dedf8f72c0ebec99e6739
SHA256: 144abf1a3dcafbb12b971036d6ac5f4931a9e46ca637139d612c335d81496e6b
SSDeep: 3072:0Z9BBFL6q21K8XC4IaApC+9IPpz0H80ea0bvFN4xgvBNn2tP+/0s:0Z9Bo82C4GC+4hT0ex7FN4avDnMP+Z
False
C:\588bce7c90097ed212\SetupUtility.exe.id-B4197730.[idecryptyourdata@cock.li].bat 94.08 KB MD5: f2aecb4372e41735f0b95863f9d69e63
SHA1: 258c0820f3607120b39956d6b0b13b7ec45a75eb
SHA256: 7052cd71cd0c9d0a5443e450fafb98c72215749c52802108c1be46557611d0d6
SSDeep: 1536:6kU/vBr7lJ1W0hkwMM3JjZbI6y5yAQ4Qjr97ogoe43ljBoyfqkphVz+467+gGcHQ:UXlBW0OI5Q5Q4mqMyfHnVzDK+mw
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 434 bytes MD5: 0ae9a5a33ed6663f54c73bccb0a7a6a9
SHA1: 6bdd40785a601a13bc206a5ed174d70add187881
SHA256: aba5c4a26aff97479937940985c13d468fec51b7e4cf339e9f7ed6cc8426d6ce
SSDeep: 6:gvIp4e3mv9F+7fz4R6LI1L4dDJ99lip3CDXynOClQEyySRb6HvsfXUPSgu1lw6Qw:n4ey3+ACIil030aArhmHvcUKguXny3Gn
False
C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat 6.42 MB MD5: 644514b1f1b6c431e6b10ed2d3f8a3d4
SHA1: 5928c691a1060a10488698c28bba85be5a785b9a
SHA256: d767851c519437efe4ece80128a185f49177e6e8a8b38ecee4887f083f1d0e1c
SSDeep: 24576:54vzz1Y5Zj9Y6AOwaWVNWWHHzRu1k/L9chbUF/Tx7mWqn3gVtiBwGFwRusBwlNSa:5qk3NIX3NIIaMeAtJXXuHhmAms9HV
False
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[idecryptyourdata@cock.li].bat 142.04 KB MD5: b5d2fedce20bc1a2b371bed5f4060418
SHA1: 6dcb2fcde74fc6f0711e9faf26b2cfe0d305ab7a
SHA256: 808508f84a3bb3a507ae8eb248d72f88dd4e0921dfb12984bd6ac0893b8e7011
SSDeep: 3072:A2JfWyGmhj9lFr858pEjJXRnVwu/yARus5AiwO:AGWRU9lp82pEjPVwW55fD
False
C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[idecryptyourdata@cock.li].bat 544 bytes MD5: d6c7a9579302ede41c11166ccb6c851e
SHA1: de8df4f8b40e2164319ac51b053236562ac31be9
SHA256: 1552ed7f8da21855df92bdaf59524be1a0a97de7ad12ed88c10e5dad94f55b47
SSDeep: 12:3PILj/IzjpAOG7QrxyyPSPJdjc1jIRDrn4ilcUKguXny3sl:fOj+AJQlyyaPJKkFn4ilEXny3E
False
C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[idecryptyourdata@cock.li].bat 35.73 KB MD5: bc777333d16541408f29c4e5a47c8778
SHA1: 0803cb468c6ccec800d81a9a8ecce05894fbc6b8
SHA256: 225e1a3b733c6bcb77a3f808ea959066a4822a53a932ef97bfca22494dcb77c1
SSDeep: 768:ukmkmR4qkvOyMNd0g3czGtTITWIWj5evYuN8u7qEg:uk0KqkmN33HtTITlWj5ewuN8uO7
False
C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[idecryptyourdata@cock.li].bat 92.49 KB MD5: ffeb9808ae5b600479d87d753683fe6d
SHA1: d61114f0f0d21c2d4e4577d6868b81767c38b684
SHA256: e3128b092e24c21017d9e4c2e10421c8d141f6243cf573917d01d38d0c70ab13
SSDeep: 1536:zbXBN6EBsXLY/u2GdSn2n61NqByKJXxSh4jqqpxMqmAiUe9ehH+t9jGmvhpyRjxS:HfKXLY/uBRuIu892Oe9ehH+bychCbgD
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.81 KB MD5: c521af745b4627e718898b3c7bbc443d
SHA1: bb6b0a12330591523534639a89e1cfe332c9d821
SHA256: 15dc22441e3b683d2aebdb27da04724e19388bba6776a76e8309b6c1e7d36e0c
SSDeep: 48:OjmGY03Yr2OBqvEko2Zjr99AoKMH51L7Y6uFTXOZZy3a:qmOIrnqv/om92EZZYlDOZZ0a
False
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat 2.84 MB MD5: fef392ea657a35f5e392826a3a79b912
SHA1: 72e0ee6a46f9c977eb79a510c6e38f367718325f
SHA256: e43772dc7d9ee6b588706a5f24995519f7e0df1701df9957102a24adc7ec3b4a
SSDeep: 49152:WV4YaGoDumT1r7AdXZy9KU2KUYxs35DKZ3OIKUuwaGeeXvG4:WV4Yab1PAdXZzKUYxs3pKZnKUmGZl
False
C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[idecryptyourdata@cock.li].bat 170.68 KB MD5: 8a5d4fc648a90b05a9e9008bf2ce8fc4
SHA1: 928bec8b7a00026cbbe003c6fdcea0e7103446b0
SHA256: dbb50a9f6e3f6bf3c57cf497813dc6ec42838da91ee474f9337a7baef4911a8f
SSDeep: 3072:ERcooQm+T6ytZcNsgXWG7U2AccdzJrjUQL4Jw57ogOPbJQZNX3aD+2zk:ec7UT9tiNgGojccdzhFUJw5E1PEN4k
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 378.59 KB MD5: 622253340f0a3820a4767d5069a9cc4d
SHA1: d26a6853c85f491b03240e7272f081b844122175
SHA256: 93d535a59ec431f38be34b325218671067658c8fb5ed0c4089b3e8a15898f7db
SSDeep: 6144:IXGcIfxjrqgmV8zuzW3hRl1jPF8dfTrGwKPyEXxHjFkFLHw+kmH5zalRBV8VC2Rn:I2rfRGF8Sz+hRlZPifTCdaExh7+Xtale
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: c06191fdb04903f8caa668e206506401
SHA1: cb6c285be720fc4f8a3e1b5162e2ef3b4ed7eb46
SHA256: 9ee0a7b4c926c86342dc1f5bb4512ee5433819ea4380a5b530d6473e7568e0ba
SSDeep: 24:iJUbWK6tlQyXJkMP0QW8kc+mPkMzLbkrnh7c9vvORgjO9p0+iCGLPsvrYXny3a:iJUyTlma0+QZ+vqJp1iC8kyy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 782.42 KB MD5: 79019f1731b2974aee27e21bfeb6f7f1
SHA1: e6e8de0b3af5e2c1673fd42c4bbf48c77cae48aa
SHA256: 9f796f5d5de64262d3b2b85047b7bba4d1a368b03768b7f5a8dbc20058f30980
SSDeep: 24576:/6iA2v6GiSSvf62QpSFUE+ZqELWetTd757:/6dfSSvy2QpaUTb77t
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 485.20 KB MD5: f579ae9f228e58d9f5e4941ad519a065
SHA1: ced1e54df87535ca44292cd21498ed42910985c1
SHA256: 5658cd2dcf7f031c4222fa8af3b95e46c908cf98f5e29d083a60f6e53800a7af
SSDeep: 12288:IHkRAWxSN3xW5NPatG/ZbLxsk7LBSKuo2yQ1k8KDUoOn2:uNNednxrLIKuos1zo7
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 0acb04abf2c886c1ffcd94a26ccc1524
SHA1: 8bbaac7ad9045204f287b4cf21bb677765d248b7
SHA256: b5d7cab10f7714ad466883a14aa0f41bd311ed330e659ad1950328de43830806
SSDeep: 24:U93PfO7ThKpDZ6I/tW+4jxEr6L/D9n+1W6vG600vxJ5x2iXny3a:gXO7ThKd5/tl4d5/DVPK9x2Iy3a
False
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat 5.61 MB MD5: c4143c97f45d82b5de1471909b6f5e8b
SHA1: a49384e1252cf76587bb419a571c78676a65cb11
SHA256: 3de00d65e975895aec7102eceab1f3caaac968d76fec99fe416a1bdc587aac37
SSDeep: 98304:Ef0pKGBHTKYzKXH54UuFe1kBpHua/KUKcs3DKVDKurFNGAybmn9m:27GBHTK8KXZ4UuY1kB1iKFKurFNGAyU4
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 248.09 KB MD5: 005e364cebb5b51ca6c408831a4dac81
SHA1: 4b930c33acee053f959d1574f9d35c735bccbb60
SHA256: bfddf3b21c5c4c32778c5bee32ef1a9cb410be0420642479f5e30a0bd4a46852
SSDeep: 6144:3rr9K1Hcbp/XoiTI5J3YckMDIMICc1RuhiaMMMhAQv6:br9K1HwlMXYcvE91RWiJhuQC
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: a79c2e90d22f94c2bf695257598f5421
SHA1: 174970d94c77ff9c3ec084067217cbc1bbae2286
SHA256: dd88bb00f4268926d862f880671dc69595caba975b0202ffe19634ae26cf4e6e
SSDeep: 48:L6YR3WaJ9WRgEGTHQKRrShP/BKD5ftDElTy3a:mw3p9EyHhrsPKfqT0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 19.31 KB MD5: 76b3f099378f525730cd95a86c3d6bf6
SHA1: 9aff8a75754555a733d33198f581702619a907bc
SHA256: 0053461a694dbc26f5423569e7d0c3da351137bcaaeb02f4836910fd317f7bc0
SSDeep: 384:J53EmeKd5PqHNBLkR2AqMNsb17YAcAweHfj8R8kd1yf06A/zs17rlXa:J53Eme9faFqftYteLg841yDxpq
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 745.79 KB MD5: 070d3dfdeadf0654e04920c44443c8a4
SHA1: 301c3f935eec5d817e768bcc4ee6529563643f15
SHA256: 9af9ccaf5c54c23b02a544de26407cbe583cdd0d003a22ff9250ed5fbc151897
SSDeep: 12288:v/NwdSGlYzXYOJudEAZPASmsxyZ8V9vXySvgJ2FkKcIkbVSVgu78M6vKs3VtTaf+:9wshIOkEAJASmsYiXDvcbIkbQ+u78MTC
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 7e5542a18a4d21b96ca22e901b60c1fe
SHA1: f089cd7796ff09ef0b261e03c1f938f9436eb7c6
SHA256: f08625f1d013d104ca008415547216f95790b08358fffb5df8931212cd174fb9
SSDeep: 24:X6i4lDNBuhoTG7/2dpmbCBWCGg3qtPWnUU3SBKbS0QgagWS6rE8KcvH/Xny3a:XL4Zc2dpmbvCvaI5SsagPAEHQHfy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 54e7ba384580d34967c392a3d3cea502
SHA1: f4b11056de99410be01d84da5a582d757827d9e0
SHA256: dbf5ef7609d610589867b7d536623e0bf9025f2b3564e45e2e5d72cecda7df8f
SSDeep: 24:kUNHQs/T0NZrreItzengtQMJJR0iEou/pNmhe2Q9cOxip/V276KXny3a:nT8Zhz1JJWoCNmbQKOeyHy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 2.42 KB MD5: 2559f23aefea8a6ec09f69e65ad82bb4
SHA1: c1496e1247361340966cf788c2789d19401fcf67
SHA256: 67149ab7e597bbc1ed8397c720143146d6a6e37342f1832918475114f36b3807
SSDeep: 48:GvdCFKLrVzGyfHs7H4mFra6ahyHcYqUNrOGM+J+30WK3oqy3a:Gs+iyPfmFraAHHl/M+J+3LK4q0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.07 MB MD5: 23f5e350af65bf50d20e911fcab5b962
SHA1: 9e390c0868ba9c06553799164cfc0fe8e84020fe
SHA256: eb6c5e1415b66ab878dfa5a5460ad67acfc67be08d2ba2506cb63df6919f761c
SSDeep: 24576:Ud8ExwmURziPmyhs5hCjj5JKipprodlG97+hityDK:UsF5hyKu35Jj9ony+hityDK
False
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat 2.79 MB MD5: 3e2a5d4f0c1748687f80df23d0b70424
SHA1: 48271f461b62d2f1d34856a87c4eb30178239a51
SHA256: 15ee49873d76f0a62b27e42fb06dd375d8d85c29284f3545a4d8aec98e6dd009
SSDeep: 49152:oJ6tDuv7GuMRau8yuXQFKUYcs3HVKf3rhKM6rgQTd95HakjyXN5N0Yh:oJbGnRau84KUYcs31KfFKM6rhTnKNN
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 211.14 KB MD5: 57e1303b75012a73a8972a853029ec59
SHA1: b031026b935aac5703976dd2907e70b230d3053b
SHA256: 613d36a6dd8ed3ddef6dd67bf166a92c11b47c96d2b2e70ab1903bdfc777d1ac
SSDeep: 6144:PJ2XzOQEOmTTE2PAkPV6taZpr3J5a6hTimIYPSX:EXdEOgTvlgtaZP5hIYPSX
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: e46d140a2342afb6a972439b5a956802
SHA1: fc09cb5495322efcb6ee1549b7e1108578d7544c
SHA256: 16a55649d8e8361bb464fb435f3428520fef0ddfedd3004076ca71b3eb96b457
SSDeep: 24:IGhbWfr9OpG1r78Iwp5cfInCcC6dZHWi2rgaYkvmmT4+T2DLBxKXx2Xny3a:3h8r9vR8IwDcICcL4H+44+TuC8y3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: e616bcca2811430f959ec3bb5b52af1f
SHA1: 4e9b6e3ea17e35e0ea5414d73a5ca31630a17fac
SHA256: af3c67c555a6a430a5907b0b1c86e74270181261426a47402f2c528a414b6dbe
SSDeep: 48:LFS41SbBE/E1ckbT2OdxVbk3KzhuXgkGDFJPIlry3a:441SFvHbtVbSkhGGDFJPYr0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 335.61 KB MD5: cb06ec6d550d9e4ff229826d7fe3b65e
SHA1: aa5d73aa33d5b54cd2601582de118fcff0f505a3
SHA256: 145d20af135a3751a0180170916356d4ef9ceb24bcce7114a8e0b71667dbfa0e
SSDeep: 6144:llNErbhb59dn7KQU7xkdXgkkQuUuVFGjAsMEmw2jEU5Y/08v/x+UJnMCW/nYGfmG:3NErbhb5jnm+dQkhQU2j/u/0GggnMCDA
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 14.89 KB MD5: f03f9c2f615845976f8bd1f0214eb647
SHA1: c7a342705195a61b6998cb97c49f44666897f628
SHA256: f1d8328a8281feff746f0d89546e8a164b051c291d71389bcdea70115a2d07c5
SSDeep: 384:nWNUjZVoVERDtDQGJ/YTPYHOfzUNgJWvgCiJQ9qa:2SVoViDim0YczUJEqF
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 2.42 KB MD5: 6d5f78221fb1fdbb6b16c8a0137d9a0d
SHA1: f7886901eedf7957bc89a7a84a64b903374695b1
SHA256: 90f6a1cc14de4506a130f3b9bf6973abef8d8e0d434994f25d53a2ee1107e76c
SSDeep: 48:Z5sRuHTa/tYdYN4TIUXkw2d01yu1LQ1cTlNZ9y1hrVWky3a:+WTa/CTIUcdKz01Ky1hrUk0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 349.29 KB MD5: fc76856af4917fd3d10c71dc69fb1b87
SHA1: 250def7923d23cb5df7b787a7f15fc79eac68b83
SHA256: 7074703694cb4f977d3ae78773a83e41bc0b69fea34222555f6cf6b11d88029d
SSDeep: 6144:Mja2qVVm3p5VeYQLtyLXpYGnSA0LykYe4SPbrMKB0SHbsH+QDGlfOwVXQ:Wgap5lQJyLZYIAykH4SPbrMKBDseQIf0
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: c3704ad205af381bc88dc7c6a3c576f4
SHA1: bafcdd79209eaf58138462ec662b311c522fc5c3
SHA256: c47b1e9c31ae2c719822d2bd6e13bc7b8a2cb540465dec6d4b01a9d1b78b982d
SSDeep: 48:wKwfivZqJu3E3eNRgVJ9J1/SsmgMab9NlVNBy3a:iKh2u3E3KgP1/HbrZB0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 63.79 KB MD5: d7eff6cb4fe1283370e7b415c5c87d8c
SHA1: 3450b16f446d7f4a530cf3329739274caaac4ca8
SHA256: 064029ea35cbd619282146de1237f998195aea41a3850b97ed59b9206120ecf6
SSDeep: 1536:yJLR7LZKQEefFmsKfN8RWn6vciS04XCtENoPnBEGo:ghIMmfn8bthPBEGo
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 81652372cd3b697ddc0b209668098f4c
SHA1: 2f018744c8f4b633c4ab0a1326ce442afcd6e716
SHA256: 48108414e66841698f2f3d32c4941696f5b03067a119aea26bef2f2faf24fe3f
SSDeep: 24:GpcIMuhhXjn9M61RcIzBZEoGcdrlc74eLnHllhlMSHxeIxw2LlfEWXny3a:65hhznLWEWcZlM40z3FC28cy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: d03a0557da687258e61ea1972ec03d67
SHA1: 8e16ea24440615075f875915740ce4792902f4c0
SHA256: efdd4b3fef238e4b4f7fd79fdd334559586b50656142a44f93dd32da2afce67b
SSDeep: 24:J2H7hFbB/f+Mry10I5WsV3C/IKp6oNTZ7wjOdDKtG8IFIEdS3MnSl4Xny3a:4TBy135b3+/ptdxdDKU8aIEdS2SlSy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 9.33 KB MD5: 35cbaaebb95a413fbb30d41de9ee399a
SHA1: fbd5e5140b255e08d658d274e315b637fbc52576
SHA256: edabbc010643ad54376e417ff4840e326a7ee772677e682d83c0a0c2176a68f0
SSDeep: 192:sKcmXRC6ZihamHKwoTiVdo9SdjjXctYKO87YukmrYBFwdr0a:snqCpaqboTiLvjzyo87YirwwdYa
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: bf7ef6bbc44670458649c4401bb73344
SHA1: b55fdbdb535c2623dd825b1c3c32dc840feb2c65
SHA256: 1092f37886c1d81912f0aabc224a4079cd85d81504ca3bac495892856d00313b
SSDeep: 48:xvN+zYwu+9G8GvCN8cuV9KLF/elxQ6y3a:xwYa9GqhePQ60a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: b44aa5268cfe2db120e1252dcd2f8c40
SHA1: 455a7e3775b2f986b785f56fbe0e014744d5ce73
SHA256: a83f7fded1a68c3e8a78769465087d039f0d234ce6ada25aca021c6079ca97a8
SSDeep: 48:kcMa4T3aSsq8uaSdIU14+iN7yO7PipJiiLwy3a:sVDaSFYs/1kUO7PipIik0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.73 KB MD5: a9278a0b016dbffe6f79349906544fc1
SHA1: 6d7690ac2a8cce4b75a0cd3232a576d148a530f9
SHA256: b438a42291eed9da5043cacb542b17eaa39b5c36613ffa329cb822a4bdf6fea6
SSDeep: 48:0DeJmYMQa9qOqcd9Gb6q2SgLHD5dLOIvAUYugqZiT1i9wpPy3a:Ay9M1qOqc7zVdLOIQDuwx0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 3.98 KB MD5: 73f48dfee0ff814bca824c269ded74f9
SHA1: a4b56eb8db0e5911ca238e91c1aad256fb393af5
SHA256: 96f35df94d81f0b679236e62344a0ebb2c662a43fd88a0085c3f6e98d9f1b7dc
SSDeep: 96:p01ePa0HmWXn3gXUPHzQxjK6UBtFZEBouF9uWQ0a:O1CaB23gXryBtLECufuB0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 0c9a73bd516bc1199f4399944cd6a70a
SHA1: 0f690b85304c1cad34ce41857246a7f503763566
SHA256: 2a9beda20674d08e0ec8f1a2e7193df5b0809c22188fcff0cd6471f46cd8c9cf
SSDeep: 48:HaI5rh/sIbuKl906uhDJS99uFiznYQ4y3a:HaIxh/puKl9XuhwHPYx0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 5ea726f5a8b38275fe926c1257305570
SHA1: d8687d2037c58901e88f54339e78c25738cc8d10
SHA256: 685ee4c333e19d7734bdae0537fe16b35c74b3c29cc306783596acad7af4b814
SSDeep: 24:pN+FN7eHTYNF3A0NG8iydbc0Jwr4cRL0u8eVxOh4vQGsycR2gpaY9rxXny3a:pUFN7LNK0NmyJHGPBzfOWYF9rNy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 390.48 KB MD5: ec30cb2bb2ffc4331f03c4535e320e0b
SHA1: 45b3770828915655e997eeba59b43e9bcef96384
SHA256: fc34f249dcb71daa5bfa8fc310e0a9ca50c3d5048eebf57fce1c8fec4c2d13f0
SSDeep: 6144:tdUAYf7A/nqun9NmpJgf23gPZFxWo5ZuXqFTZQXWOFikjvIb+:tdUxf7Mquvmvgu3gPZ7XaXiCX5jvf
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 515.90 KB MD5: 5f98cec65121bb9760ab057c4d999db5
SHA1: 0bc7c46218f77909c3689cb9f04c96149a78e954
SHA256: 8274ae6b36c584ee9bfb8ea7c63f3207858c73997be7a9ee09164f70de23267d
SSDeep: 12288:t9+flBRp39M1l8ThMPHbrW5VD/kC1t4jsxe57Nx6S4Fp1joP4:PUlp39BgHnW5hku4pz0FpA4
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 3.61 KB MD5: 4b5cdaba6bd590fc5f6025f5d2ec2f2d
SHA1: 18f04c2459dbb7ea6e7b58688d55e762b841f440
SHA256: 86d3f86c375b57b12ca733eaadeab81240100e99a547e0cd0b5576205b5109be
SSDeep: 96:qx1Oyye7PGC/xUdz4YlM/MiACV//UR7ikpoVfxr0a:qxGdC/OdzhlfiACJcokpoD0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: a6a1f93e3bd9f20a14eb286c1f5690c7
SHA1: e7a1ad8d801efb84f2db8f954db54500e711b6a4
SHA256: 7ad939afae11a1f6f2f84fed213b3c94d2c96e5c950f87f553273367aa5dc528
SSDeep: 24:0ebfDC1zohXGTnxvKQqTG5n8qon+bQWpYjAr8fLgVuwtmOZYfXu7tvipgjOhcXnp:TDXhm4InPpCA+QtmOZYPu7ZYgMmy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat 9.87 KB MD5: 6484d8900fd9f45aa14f7847978d77c0
SHA1: 25419fef22d5c2bab0e93eaa19b35cda935488fc
SHA256: a71b67573ba8f7445ed27fab6d8d20cfb290013a4d02562fc89c9b9de7852040
SSDeep: 192:zstPOTrjdhD/GEtj50mZX528UUWB7d6Jbw9lQ83VQ6gc0y:zstP8rjdwEtj5H88UDB7ECgwZQy
False
C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[idecryptyourdata@cock.li].bat 640 bytes MD5: d53094988b64608a677c1312a9558387
SHA1: 2efb2e451089398e23eef79528da31d4d533cc5e
SHA256: 26db4f1a3afa001128337d4f8b58bfc7febd8f72c256fcb0ceb30c4acd51e17e
SSDeep: 12:MryAkX9o6TTggxMDSbycSU0TkIaDFSiYQxjLq6MDrwihUKguXny3sl:MG/i6fgiMuycZ04DzYMqxwyXny3E
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 9.06 KB MD5: 11486b274cde190ab70dbfcc64ebfa61
SHA1: e5356b5d018f3f2d6dea897b7ce1c4ea05493c97
SHA256: a1250761d0e9059ee4f4c217bce00e83fb6075e6a14158ba04b9fc75c83791e2
SSDeep: 192:i/qjcT2TP+rIsMo7dYbJGoHKy0daoV92lLozq0rj0o:JjcSar5ZdcJzqyUa89zz+o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 14.76 KB MD5: 691205c6bb6f3a4bca1e832db3b83ab9
SHA1: 1b9c2e44300a59a904541c50ab798f00b5909dc6
SHA256: 639e64f4890147801185121ac8dd730309e4177c4a933b0e9a62c4cdb361ddd0
SSDeep: 384:GP6SaO9kDn8Xhd9h8/IiX3U0l7YRrZJkn4FjCibWmoo:GJIsn9h83U0GtnrCibV
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 7.29 KB MD5: e47aa5baa9a3d45625247f40e606c229
SHA1: 45c3993d0a0504147fdf0f38fb5aa7faa06f394a
SHA256: 1e0e4a47d2b98057441a31608002b6d659cc687c92be85a8bbacbb865234d435
SSDeep: 192:0NKQYeOIAHQpfRvyb1qchrNULjypmNJohLBXvIyA95S3e0o:n/eOIHaqIOamzohL6Mlo
False
C:\BOOTNXT.id-B4197730.[idecryptyourdata@cock.li].bat 242 bytes MD5: 5097051fd1b1c9b0c5aa3f3d8337c161
SHA1: 1250157b6228e77181a57b294fd82ccac942c663
SHA256: 60751452cf3e32c8108d23f9d58af313fedf01b410a1479cc50c6414ad393543
SSDeep: 6:tLBclQcEyyS5t2t1XzINWrZMxNFV36if1GDrp5CP:tOPrj+1XkNKyXFd6if1GDrpE
False
C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[idecryptyourdata@cock.li].bat 41.88 MB MD5: b790da90d0c6c3db2d470430d72b0adf
SHA1: ba28aaf3de47f780fd99f939c6190d4a029b4166
SHA256: 9079e442aee573d221fa746a405405a2553f60de994e7db863d6eb28640df578
SSDeep: 49152:cpSdqU6tLnvVqSK5G22mDgBOOmeGGiU9Erqkbnt7QTr5+Oc2EI+8dd0ZwTse9QOH:CtZKH2mALErq2nt7rvfI+vZpfQ
False
C:\Logs\Application.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.25 KB MD5: 5ae29ceea644f74175e6988483aa37f9
SHA1: 185ccbbd4c0c52a8fa0211c9043fc5c09c207c6c
SHA256: 0e9824d8ea1aedf34637a6e90a50c66467bbe8466f0376af4d27ab8b72314e29
SSDeep: 1536:guq5IWDoqLg4b6lhUFZd0u4TBTpCqMPROavECXmzE9RZaTiVDFA9:gw2o4C+FZd0u4V8qCBvECXyENmID2
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 6.76 KB MD5: 79c2fcfe8789ec7a7556cff1014581ee
SHA1: ca78e8fb957735c78f4ca25327c57f52e7271bb1
SHA256: b92e6dc5fe7ed68929d8ebe23fe564587f0a1bdd028198264eed7f70096c97de
SSDeep: 96:tuJFZldV/v91APOS6LImmTDctqnTe9rJGzBQtW6dWX+f/1uM2xSysO2nA0o:MJxvr5pyW+eJJ+G1cX6/1uSzA0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 3.42 KB MD5: 62734d4a8c0e72d9cb0a13ef3fea9271
SHA1: 0889f92d60ebc8659af755ccd5b697011ad4fe06
SHA256: 34fac87ed699976ef52cae81588cd43d8c280ca0f6726e40b931dcb736a85364
SSDeep: 96:08drWlABYGMVNDmijWTDmkPMe4RrYWxzTtbAge+t0o:SlASGMVNqijWuk0/XpPv0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 7.75 KB MD5: 157519c65d7dc73970b7ed0abaed1b1d
SHA1: d132cc14b02f64cc449300c423dd67514ccaeb1e
SHA256: a0ff08cf56fbababe879008978dadca9a589d535a5ea3f57a5a8af9c7af321ea
SSDeep: 192:RPxlH92BAbL9Okwe2zUG/nXgTHcgs+VmoPDW81zeU0o:RPxld4CknNYGPXEcxiK81zebo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 8.15 KB MD5: 803af25aa1515106f6775c9e53fc63c7
SHA1: aa39f13c08752ecacf27d82b206a07edda463cd2
SHA256: e473984402b5822182e7318e8601eba226aeaa74b9d4c4fbdb1d5c1a3932a653
SSDeep: 192:hJOOVf3tD8X39M9mLNtfZuE/0oq5ErMNe+NJdUur/B+z0o:yYiX39M9SjfcToq5+MNLJdU4o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 764 bytes MD5: cdf64020483dea429e77d00b42abeeff
SHA1: b76433a55e089d7ceff35aad4264f9faf2471547
SHA256: 70b892c3cfa9e418dbaf52d7a7a9eb80855f15e774973bc037c4bd8c0f3ab6b7
SSDeep: 12:QDmBDuqB4zW85WWDZjhcOWxC2wtZOm57dA0H2XRBfaRcrQcUKguXny34l:QaBDuw4C85R5tYKdA0KisQEXny3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 748 bytes MD5: 4de7854e8d579c048e80d7fc2ff004ef
SHA1: 0e3be7b8c43eb3106a62ffc8dfa23edd39b5b038
SHA256: 2e24f1d21133c1f0661b1c787ffed71b205d6a831de60b94f980107da0bd81b0
SSDeep: 12:rGyXpctppRGHx737NKHcA1qWn1eGOQFPC9BYN8cZHHBDWlG+RcrIUKguXny34l:rwp/GR73E7MIeGHPoB8ZnBDJroXny3o
False
C:\Logs\Internet Explorer.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.27 KB MD5: aab5a7732f926b9fde09ce21fd741fec
SHA1: 25eb4cda5a61ab61c82433b112b6496f366f1c78
SHA256: 882b501be16b707a93497a367cc40889cbd6227f335d221e1a151fb225e2422f
SSDeep: 1536:ojwjJq+7muCWVV6XW3bzspdjkfsUiT4I7Ir4mT/t0D6gF65SzH:ojwFq+7m/98zgw7iT97/S2D6k65ST
False
C:\Logs\Key Management Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.28 KB MD5: 1f90268da240960f94dc259d81c3b321
SHA1: 2bcd3477bc0023d5bed0db000690106c655f105d
SHA256: 9863811af66e9693882296d9a52c73cc771372cc2699acb0564e287d7fe17a64
SSDeep: 1536:tpKP/VhlTUXR/6PrzU+ydS8HiDN8Qs5z9h1JuLwuC7SYV2AdRdNU:tAXVTTUXRSPrzsk8CRs190+zVRzo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 12.64 KB MD5: e5e5de20b03aac309683164830c562f2
SHA1: ba6760892d9af51ebfa8d1bb777c0a056d412fe1
SHA256: 1b97e83f4778022bdd21697d153c139af45059e1612e9e2f958daf5ce8d21a09
SSDeep: 384:8GLsotmTa5RzGXcLfR9iY6PGBuDhB1ZfHDrT0o:8OTGXcOPbFB1ZfnTv
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 11.86 KB MD5: 214260d3cd5c4d19f517d3f8ade28e2a
SHA1: b40455858c2b3bdd4151caebf00c6e30abdbcfd9
SHA256: 3377a63892534d443dfc97fa7b3a884a12d72b22e0461b0fa366a39deecce166
SSDeep: 192:+a8ZWX8cz+WmcHtkxSJYxMQz3i0fS96xCiMr3JgVL2dVf0833H0o:+fzczVmcHE0Wrm0fSfvS2dppUo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 12.43 KB MD5: de8303803d0fc829da4e97767b31be02
SHA1: f5d1e6e2bebb406fa403ddc8e016a7894966ff36
SHA256: 1b09b704fac90c1a404ea2b5b2edf3fb722b3ce728b2fc9c150315ce48180dbf
SSDeep: 192:TIT6IZkOl0g9GyVQXvXnQkZ7rb1w+mAOmuklcMi/1xkTeqspHrDH75w11h2uz+gX:ETDOOl0hXbrxw+9ucclwspvVyauzoo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.37 KB MD5: 225902b8b18f91cea5ae09c43c3c8d5b
SHA1: eb1cb569c533f326855516415ff02a0165a19557
SHA256: 0065e111a35ebea2591849fc92f362868ef885d618fe9880dec44794350ce637
SSDeep: 96:mY3Jlsjm/L9Qp+Yp8hcNdgL6gePBrbNfZsqNpXWirw8C6cIv9YTO0o:mY3jswKp+Yp8ugL6rBJDpU6cIWq0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 3.31 KB MD5: 64641ec3549244477ebe5d4bf3db9c01
SHA1: 3ae84510cc4779f0f20ccca8ae7aa30835ec9458
SHA256: 7e5e8f055875e686c9b13a71cd882442fce71f91cf1013882dd6b314c751fe31
SSDeep: 96:IuSak6LsKxrsjTXowk7dNlJM/zhElf8lkJ8aBl2IKe3Ny/3H0o:cak6ACr8Xoj7ZJM1hlkOaKIKedy/30o
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat 2.82 MB MD5: b9b017dfb4b794b96adab7e6201a4b8b
SHA1: 1a3b6bc4faf4bf1ef593ae798751310a2495f68a
SHA256: ef2f74e5e839016d3f4a4aa14e9e5b8a34f4d534138aee98d50881a9df2fb16c
SSDeep: 12288:dyZC1slqChJ+3VVomMAcwVWZzP80dHjAoybjbU3GZVO0qQI1/RzVxuvroD7+gJo+:4YCqlDMAcH8kIw3GZVbvI1/R/uvrC+qH
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 3.64 KB MD5: 4eb30e641fc5c731b18dceae872aaad8
SHA1: 9e6b690c21efc976496d748410288d329067865d
SHA256: cb788816596ff017c705ee946f7afc6702e3c78c937a95e770c2ed0fc92af8c1
SSDeep: 96:tJDGvJw3KUKt9VHpAtmarASu5NeejJpp/+WpWrvg8JZxh0o:t5GvJUM9VHCDMXlTp/vpL8JB0o
False
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.38 KB MD5: d5dd6bc15d581f767161b64c7094aa78
SHA1: 9542512681067e602e192952227424975eb23519
SHA256: 07d1146bdb2b101d77da753723e538f58231956866ee6453657ce3e2ca875174
SSDeep: 1536:2eDP5dVvRCOl+sc7KdT7erKvAL0zoQDnAlgXK0c7Q4hOfBffzc:2eP1MS+57i3RAooQDnAlgX2OFI
False
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 826dfe3981c7a9af3082ca86d7211b38
SHA1: 4dc71c7c2bd1d5012834ec301e32fafc8fe3d5a2
SHA256: 6148e774f80a1dcf49c0b96b2ed736558b9aaeff0bdcc204a434243c5badb87c
SSDeep: 768:xNCHxWKyA1+Ixrhach9apSM7u66VHzECjmxkN+Fji6GcYlUt8GJSti1VTGN6Fs/6:xmdl+CakSIqFol68oxVU6FwNs2fVrk
False
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 1167fee0f261c68581e505840fb1a14b
SHA1: 35dcbac6b0d1036564696f413311727983c01bf3
SHA256: 544ad61fed52e1c05d825cd56cf75b45390b336cbe7f00f85ceefe393b1b26fc
SSDeep: 1536:mSubEOmH3EZMJJrqrRolpLdwrqFOqyHYTaEqs:qbEFH0ZYgRkdw2FOq+YTpN
False
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: cb2eda3e7413b8f775e52517ea7fd7bc
SHA1: 52b8d5b279abbba9d091cc475669441bba94426e
SHA256: 737fb3d70ad72933453ecd61a4fbc44c8d8e52297945abe6418344f00aab9dca
SSDeep: 1536:fk9qb09kFrGlqxTB7f/myslnj8F7x1J7z8vVUB:7iC48F7x1Bz8CB
False
C:\Logs\HardwareEvents.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.26 KB MD5: 0e954c77ee741e7d719a04336d53c6f9
SHA1: 5f1ecfa2a7fb044f84821b17d3f8992e84fee4be
SHA256: 850bf7f51e530c45458044ce508f40cf446b0bc8a1c015356980c2fdc80c1e2c
SSDeep: 1536:LW8pNOw6JcQQLDcPwtY0hCkHUV4FrLkh1iWZeFIw7q:LW8TtLDRDRe4rLQZeWF
False
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: f10e6378e4290fbbace90c020ab7b12e
SHA1: fcfd94abb1a3c93b192c6b54d9d8afeee093b0cb
SHA256: 3d7ea20c897422d1780549d529a51c7a2ddc6d0c346d4d1cad961f2a530f1216
SSDeep: 1536:HqqxJcbFeW869j+19eL1GfeFjQ9L0B3mloBqSlrv:fx+bFeMKDyLjp7qmr
False
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 89be8fe9449ca8bc4004e5929c5478e9
SHA1: 25ef637edf715e5412f104fa38886d7794428a30
SHA256: 17b5359d25d9a4a3f3306928a0b750146bbcda0c576923bcf9adeaac5442abf7
SSDeep: 1536:O7XavAGmuEGi88dRYyNVT4c7uVYW7bjtSm7V5gQ:O1uE98QYeWXBD5gQ
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 2.78 KB MD5: 5667cd86a8cd1c85a4d69882a0dc16ce
SHA1: 6843d1807004ab4659ef97d62721876005228714
SHA256: 71b709ef7c2498ca2c880bdb0a76a9f049a821cd883cbc124047c6ea2bea8804
SSDeep: 48:a/d/n4E2tfTYfeu72KOMlLHXMZg3ULafQT14pJ+KslxuzSfpU6MVhCC+5u+fy3o:a/vdfe02+LQg3ULafI4pzsT7pmLCCUnn
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 15.18 KB MD5: efb28a0ae41718797de6cb461a68f2d4
SHA1: 2736232bd25ad1d3835e89829cda11ee56534a9e
SHA256: 6858eca0f5316f334bb39bcc81f0143d9fb2de5aa8f5d83f28f6566755d97460
SSDeep: 384:l03jUBxtG2sQxIOg69ri5n8ePUxhoGKO1NiPR6K28Ur2o:i3jUtWdd6Ni2UUoZOueD5
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 10.59 KB MD5: 842709c5d4aac46732f34431737f756c
SHA1: 26203c63c061952df184aa3060676b4cac6887e2
SHA256: 5b5dbd5116d2c6f629af6324458151a909b7c45c444871ed88e4145f5c3cb079
SSDeep: 192:F/KHBHiZEYfP1xu3fQ12V559vLUcfWnfuvzJhZWOIAnN4Y0gPKgDNP//es0o:FQCZE+P1xuPrn59dfWfxBAyY0mK2P/Co
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.43 KB MD5: d865189facf2d05d01a53a5591326422
SHA1: 5dbefe5e0a5647a431c7202341b532f220b63e4e
SHA256: c25a9a9e79191a7ee40cdcf01a637e7873d95143f87277df9de3b7dd317f7c2a
SSDeep: 96:gWkEImWuZwwWKVycggfu8uoptSUZJsDznu+sF9rQF9cGO3Def9IjpomO8JG0o:gP5mrwwDvgg/uozS0iznOYD3OG0o784v
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 1.36 KB MD5: 1250343d7940876e9cdebd51d82bd4eb
SHA1: eb3c327ff860830931779dd8436936ed8bd90610
SHA256: e0c2b6a8f666a1930cda5763924eccf99545e75419d8f12839bc914ee80bfb21
SSDeep: 24:l5F9A7um+uBIeus8OLRq077RQ4a3fPaH3EJqYx0Imo6D29z8DGxDbltso6Xny3o:L4KmhB3ubOLQUQO3QSZOVxvltsJy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.15 KB MD5: b5b0fcac9c66badbe5e1052d3cd8f301
SHA1: c1e70285e31a20db5c0a34a8cf00d5dd801abd7c
SHA256: e877e388ebe9c8d570766bfe33014079c47318c828cdc96cc18c6bb4feb061a4
SSDeep: 96:BV5Av4kjSe9CY/A8Hclbkop0j8/Cj28BIM+Xd7pXQ1hSgpp43VQ6wB0o:BVg9/Y8Hclbkrj8vMOd78Qz3VQ6W0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.07 KB MD5: 532c46925568c51073148ce5dcf68c63
SHA1: ce50535773beb6b66c2f3984fcfa7b506128bf7d
SHA256: 139404b66a95d771b16b12f8fe539a751bafb34190b97fca549bdfe6b336a0cf
SSDeep: 96:ChGX37GHB9sdTyQx4loreINrKR7SYTCmdf35rw0/4l3OMb9ei1z7ep2Ny5PE7KpV:ChGnIBKuloGR7NvBLE3OMbwuU2Y674cW
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 7.64 KB MD5: 6f550caad0b219c5690f011df19a6265
SHA1: 675399462c3e7df5a97cf0c5170a2391c870e0b3
SHA256: 2dd21bc0ba4584805f7fef210fb6e2c6414080ffae154bdd1cddb74a60c3ee60
SSDeep: 192:NT3D2y4ZSuWZ6/7CKBZDqLvQf6NI4yeSq30o:dX6ZDqLvpIQko
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 8.62 KB MD5: a4ffadcd424e12aa827c8bd336906a2a
SHA1: 5c3d451a0836c37513ca25ae3185ef7384c618d3
SHA256: eba5dabd75755dcb1767d0a47fb6a416366d8be25f24ebdb73a87d36c6cf0695
SSDeep: 192:gnuM6Ne0u4MD6Ko7G1FT7uKrRIMxdwZBVvH+972Ozqv1YbEDDBA0o:WmG1FPjRnz0Re2Ocq0Zo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 13.18 KB MD5: 842fac1b1cfc0bc0ab5f6122545f595a
SHA1: d0cac6418ca5f4f6640813fab5ba6662b73f21d4
SHA256: 313349e970984ffff94a4d246c8f68dd33eb801f165090565e050e5f1988b28f
SSDeep: 192:8E+3r3FJB/ac74PsDmniuFS0+aEvgJXyGS/a29ANNOJTRFR/Wzw+m2fWG4g0o:8ECSi4PdJFSdaEvr/9UEVFRczH4no
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 7.06 KB MD5: c05d172f355b9fbf48befb245c5f1c43
SHA1: c85c6f3449beeaa9df0c17c37a03c6214196cc2e
SHA256: 20864c23ec3e892a054c531d5f86072b24fdeb7b2bfb8c6bf7384b268709a5ae
SSDeep: 192:Ku7ybt7oLOh0QYguWYDlr8Lo2InXqwmUxcsfe43F5DSEh0o:+twg0B8o2IhwsmGOo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.01 KB MD5: 4664e04d7996352d13ecd97922b113e5
SHA1: 2c90c96918afa900bdb0782216ca49f6b7c20233
SHA256: f7b910a1425f39c2841179af145806bb0f635bbe4978f571f3bf7cc55a1924af
SSDeep: 96:/P6Q7Loi4+ns8hJoG8mMtWzyDSNV+bhh3jUNV8hG3vy25v0+zz5SXK98tl8Hx0o:foix8nM7NV+faVoEv0WSXK98tlQx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 9.28 KB MD5: c3b4ba06a00d39beb5b207f6de372b7e
SHA1: f58c001bf4d05b4f29805a3146d0a2a1999c3782
SHA256: 19012c74dbaae87ebd81e1b679544cda712ab2c2a3e86dae51880154479be597
SSDeep: 192:hEr7r0v1hErgLJfW3GIMq9Bs02g78S5Q/xrHYuanTqOt5ILx7wnJtU8I0o:hErXwh0gZbIb9B+gwS5QJbYuavtIxkPO
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.14 KB MD5: e1048434053c4b04d5a994a9b33ac8e7
SHA1: 1fb10e2ceecf48933cee1291b8361d3475f2a15a
SHA256: 8664841c3ec8d4dda0f9a148637eb85272b0422fc9b832aebb48e30b3749158c
SSDeep: 96:iiAnlDjKJMH6Z49m19G0gycyg0ERcAOFZwakEzpgADEVm8ujKk/5JrAu/0o:iDDjn819GcXV0EzNDEV7csu/0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.48 KB MD5: c3fdd195c3d972e5e901e69108e8d872
SHA1: eef332d783e8b98de86180c824ac9a1526cf2180
SHA256: f22c87a753f7da18626a586546be52fb8de6ef6f1d242f8692d261c97301c214
SSDeep: 96:QefetVP9z4ion7hkito6nOF74KpI2iYZq1i46wtUzLN6fYyAQzWQdB8cFyKQQBHe:Qe88NkSo6OF74Kp/3Zq846wqz56QGzTS
False
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 1.00 MB MD5: 98ec39ab775ceed1baab027f468e2c22
SHA1: 658673b55ab260e9e0c75b44f1d863f24e9ece31
SHA256: aef90096455f1ffd868d04f8b23851f6bccf5515fbffbb8104e95b6926db2085
SSDeep: 12288:wCebAfvOqULfEH6EMPN0YD7ZM07rtsEYns0Ia7/FviNxZf+kPBCnCmK0liu+gcni:9ekfvOBcNMmiXY4azFq9frO1s5nr6fb
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 4.11 KB MD5: 02270751dc9833b1ccd60df6272e3c6a
SHA1: 5f1fcc66b646fef3015bc8fde264c110e6aa6510
SHA256: 859f2ece1004149ba4d4cea8f4405be360a9058fe87fc8050ca232a4019ad5d7
SSDeep: 96:x4Nr4a7N86lfjpmYhUe8W1rrp+uMIcJfGE8sbx0zD4IA0o:x4xZpIoUA1U5JJfxjbg470o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 3.29 KB MD5: ed3ab07863c131e6143aabc871622279
SHA1: a2df191c5916cfa35cf8e12eee81d033b58f7324
SHA256: c518b2a76e202d32cb0209c0b6e24f4bb486743842e46dea54fb5f813dacc2a4
SSDeep: 96:hycM577UGbu0Xc/Vm6aTrutgCpecSbdHi3ex0o:QRly1aTSecyHi00o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.20 KB MD5: c85f3fa9737ccee8035bc362e78b743b
SHA1: 660cabc4854cf5eff399777e4a09debadc9fedc3
SHA256: c420c45e8d18c364195b092e047476a03f427f94136823d6ab4c2a407fdda676
SSDeep: 96:6mI3yw2Y3gMn9uhkWStSKfwpxFLZfNX6VmBToCrA10o:6byw2+twhA5kxHfV6+5r20o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 3.54 KB MD5: c8e427d86e2b9dcf9549c8a4822276b4
SHA1: 1e164606e31f8416aa755f275a8b162950cd9c51
SHA256: ffa2330aacabbaa2477dcc682106ed2d8d6e07384e7877202efaa376b917b4c6
SSDeep: 96:MDCHVYxAZRaJChsaf8OjkHMDVuz4FOQhfMtIE0o:MWVSAyJClDLeh0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.86 KB MD5: 249f2cc787300f0f53b105173d2f146e
SHA1: 3853a59b0c3c03129e5319092d930547c15a7f2b
SHA256: a1b016113a42faa887a948480c666ea1a63d5be3052c562ba9426c33014ecc38
SSDeep: 96:fC0QoqeFyiAumO1toIq53DmqwpkaOHSszWRnfY4lxvZ4XyCl5q0o:f7BRyVPO7JOzuSv/yn7vRCS0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.79 KB MD5: 5613a6ab91fd3908da25b35af9ff93f9
SHA1: 9ccc87acb9a0c63763c4bf8b4ce3ea86f3b44d21
SHA256: fce0f952f3b98733eaf32793ac7b88ab8244071190860c7b9d89ebee1ae18828
SSDeep: 96:ayEL8g36hLfLSD8+n4CyZJHmqMY1jIuBjnIs20+aK53UB8vEAx/t7crgHFb1rAyv:ayEL53yfuD8+n49GlsjxfyaK53UB8wgt
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 20.34 KB MD5: cdbb96cbf884171015431571c3ccb2fa
SHA1: cc5b48f88556f737a35007e8241be87c3cdbaf37
SHA256: 093e08fca493cf0854e9e952804ea4da8890d974108f3162c7f6e84a258bca4b
SSDeep: 384:T4OVSOe4dxyycesukA16np7C2YTizpKCQu5WaDChJi/8BKVRn7bBo:rVSmdxyHesukm6l1YTizppKP4Hbq
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.32 KB MD5: 1c4bd7c2cb3b26820e8a2a05cdec3478
SHA1: 307443228c9ff411eab5c13dea4b2f735db9a693
SHA256: bfe42163f0fd477351363c8cccdd5c2c6e4588efb5c26ddc640ed1e98670fa7f
SSDeep: 384:XszROHV6SFEDRjg9zBaCDsY3y5RN7mrvo:XszR6V/FEO91a0TuLSrg
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 10.82 KB MD5: 9860f6a1b27ad503120cf95c973fa99d
SHA1: eccaeb738d9ee7e5031f5998dfa5462c0386035f
SHA256: dbb4d2dde760cffc8ab926d68dd7d5dc247d21652135f9d41b81b3e73b1d0160
SSDeep: 192:8z/NL4bNRAdTGiewnhhPy8UVsK300jf+vP0A/UagUAQc4UOF+VCDifHl6Hde0o:MNLOjAdTBeI5kp30OEV/UagUNc4jkyi9
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.15 KB MD5: 8bfc07f94d104633f4352822902428cd
SHA1: 91c51f11448c812eca451bc074e7b0cab7551f8f
SHA256: 745b7f9c680c2a6e019e17fa02877d15bd58436e54aee3b0359494be1aabcb16
SSDeep: 192:ryEughM91uTOZF8RvbYARYs1hk4dqzodscjYp30o:u4UtZ+kARYs1hk441ao
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.03 KB MD5: 0c49b4a7d85cfd2ef30e80d086d4d06d
SHA1: 212407289ae0669c9d574147c6b9993c97e0edfb
SHA256: bdaef69c211844cb835c362c767777f8231cfd2897860d1b56ff8a4789821c59
SSDeep: 192:h7aaMpAATf6TQcyGUuoGZYflBnCkuYz+5iXMwTW064w0o:5aaMOATfKcvRnX+UXlTWUXo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.03 KB MD5: 46ed541b01ffd2b94e5ebc5c1b4fa690
SHA1: 3a063e7b06ba62ffbfa1130ef3157b00ee0e8bcb
SHA256: 49a6a6e42bdf40beca04dc9759eeee0ed483dcee7dc91eee511f473f8f7d82fb
SSDeep: 48:B178GyNWjB294y0xO8rRY8YsWFQZcaD0kU8Hc4ovQry3o:6NWjeaOlAWsc4uC0o
False
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: 51e5c5d29682b52edb4a322d4c7e8519
SHA1: 23bb554b191cea321d43f8fd4b2c6575a20acc2d
SHA256: 2182dc69c4de93ba8771a051475208bde32cb00597f844618b94a4d026db5944
SSDeep: 1536:7hka7TqEpVRLL3bnW9aGatMCi6i0DatlSad1EaEVwfCgv60tU+N:dkav9pffLnfGa+6LutPdybaVD
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.79 KB MD5: ef29ddfac258a42065131b6a4f2112e5
SHA1: 1d6803646dedcc847843f70795a21a6e76c578b2
SHA256: 174cb3d8ba080137756d9a14f58192609074eceb7f3c19d4ed8098357a295c07
SSDeep: 48:Jl/iFnBLyaMmv1Y1ZUWFOV16Hao81xjuMD51hcS4ly3o:rcnti91/e16Hal1xt1El0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.90 KB MD5: b7fbdcac10a9ea4f8dc1378bfa33d63c
SHA1: 9215968b281dbde817543f2c1485781c6c689c6e
SHA256: 34dc972f526792bd555ca97fc9740729eeaef40e91213187d3562f2d0a9aa535
SSDeep: 96:YkoGFG47R+pmbweNAMuHZm99OSJxAxSHDMVvuygVs0o:YTGMKVbweNAMUZm997znAVGygi0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 27.45 KB MD5: 46b227f39361a4cd3b7cafb00b89c93c
SHA1: ee28e20db2acdea799332b26df0c712ce2eeba76
SHA256: 4100dc32592b06ac75bc04cd61bf137b40b2c647363d12af009946e28279fe31
SSDeep: 768:Mp3Lsh6U2uqmpEGZtq8w4gXF/nw4876YlHbM5kllVeEuif8IEUP:Mp3LshwsZtqaPx79O5IlVemURUP
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 25.95 KB MD5: f1f714014e36f13e6639fe2342816dcf
SHA1: e47ff1bfb8bac8586775c36ed75d772600378926
SHA256: 12115312bb8c97318299b5f088c133ef9a00ec0dd95e1edfaf5a71f92ccbeeb6
SSDeep: 768:uWAGeWJvGXcwUgeJxsmhsYe0wSmeRC0Meq4KWzw+2W+:feWJvGXVUjzhReCmDT1Wzy
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.93 KB MD5: 281e55d02a8e7ab9eea484a4e56d2b7c
SHA1: 43438b8b0aafeedcc7e892db95ad1bd7ede399b4
SHA256: 7a3c49cb6140eff4d232cf0084b9f3606606bfc581409af4b972a695d6967057
SSDeep: 96:KFLYShbkQu0d9U6bnzy5JiZanrp9eJVsu38qlxw6SJLJSl9mPhULq/760a1QT50o:KFLYShIQum9vbz0QZarp2su386e/dSSH
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.18 KB MD5: 5fcfee9c608fd9d01ebbee7e17233063
SHA1: d3b8f7148f5c3d3bd1c733debc1ef5737fd568e5
SHA256: 40011f7c29dcfecd8bc090235d66dc200ec5c243fda5b38e9fc8139d8de6880c
SSDeep: 96:FK9V4en2XKJODyapF1YqZKkKmkl4kiH603D0o:FoomsF1YqtKmkKtz0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.43 KB MD5: f4bdd0728b16c3ce2287a4517305a69d
SHA1: af2e15f9c960d3603b4740bc43b4fae26012dd2e
SHA256: a4f9fe2515de80d989003010fa8c57e69b49ae31992343865cbae5a977972a3a
SSDeep: 192:4W22cNQj7EVYNqPZDebNqobmzlwaCUWrFPo2kA0o:4WhxjYVfPZDoNqWmzlwnUWre5Ho
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.61 KB MD5: a22922badd90e843c5461dcbab977307
SHA1: 07feb3be4a10ea3db09ed8d390f2265092a41167
SHA256: 5c7d9e5253ad0f91e489821c9e28653e3499aab3e20077e7e24ee4b727557f5c
SSDeep: 192:dclj49crwvnTxQv8R4khaU9eR4pW8TZ0o:ilM6c6vG4HsgKio
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.71 KB MD5: fc33bfb364f98f4fa17058f49623eae7
SHA1: 0b6f75c193e84159ca1685a2e6249b6d262feed9
SHA256: 767772f3f7c1cbab981a077e379098912392730bd93211c5f648c364f414df77
SSDeep: 192:mEzyLHDwTM4UqpdSM4dc/WTxbz3iRZ3k+UDgvxaLIb4yye0o:LkHDwTpd0eKxbY72gvxaLIM/lo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 9.26 KB MD5: 5c4373e0bbc6ad9a4ee589bff3d22bb5
SHA1: acb5732e402196c91f745eaec3cf542cb9778b77
SHA256: 66f4d8e20f83f29a4962545efa7653e50e84a5c29d7152838274b31002f2169b
SSDeep: 192:nFT9Vycj/Fz3U/s1K2S3TxbkmSxwKoC867/KAWQSj2Gllbdw0o:FT9Vyqtz3BhS39AXQ6TVWhSGfdXo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.29 KB MD5: 349a9d886c20be1ee3aba35a5da72f37
SHA1: 9424a96fede23efcee980b1e8f83c1e1642b22ab
SHA256: d53e13651c82a105843dca33473bcdd6be3ca3878698c030aeb552c673df944f
SSDeep: 48:iSbR3s8q2aiK6ALDr6Cm6PJIYhpe7GUkcvg3yle0nkujdojB6WmrnRGzy3o:iJLi7ALaTQS26kLiM8Fo0WmRGz0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.53 KB MD5: 7b3144956079aed2fed21d87ac60a1ea
SHA1: 9950e64492d2bca927839fe812a745453161bf39
SHA256: 9576158b7cee7c15be2cc00105b339fa09188256725cb2a3b2b63198605e14db
SSDeep: 48:0mY8x15bhHKkwYUjPdM5CNQlZ+XybVPFgxBeMkXioZnPafHy3o:dt151HKkw3jPS5aQlZ+XCpFeenioZPcP
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.15 KB MD5: 30199afdaf83b04e96adce829fb40b57
SHA1: 4c86cbfd479c34f424d10f210b450efb0d3d6e6c
SHA256: 6b0ea5ff269ee951b0eeca3ec9505dc89487154a08a2cf91dcffdb9d21e5cb4c
SSDeep: 192:GaF1oIYEbjWADDVDH4iShODBiWtk1kNL4e0o:GawIYEbiaDKxoliWm/lo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.71 KB MD5: a48992d4fd90444fb8920dfefd1f8bd2
SHA1: 69ca53d8965cd01920f4b9ec1662cad7b15266b5
SHA256: 94e93d8e6e4745ed3e2e6034605aeea19ae41cf75db716d3e60318991b2db93b
SSDeep: 192:BhagwVzA9OR1ZBEDc8/wpi/Efp3/N800O61Mu8vR80o:H/9O3EX/wpiY1m12vdo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.75 KB MD5: 2c355255182176230d879fb32f9c81e2
SHA1: 05ef8c59aa105d40427b3aacbbd3681e60f8f931
SHA256: ecbc949a26e54e8d249dbd3b0e0d0aeb794656c70198dea61d90c94b201d63d0
SSDeep: 96:VKL+l6P0L1vEikiQ9SM8NO1++qUWZpXzusgLjnNqqYroSNddZrxJyauxm5M0o:VKL+i0pkt9BO2FWZpXSDHnnOoIddyaup
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.81 KB MD5: ee5a52d70060ef8dd5b03d33d543e504
SHA1: 76443cc834fa75fa81d8c348052607f89ae6e5a5
SHA256: 806da6bf4fe3060210eefc7723fd02048887d52b6995888640bdd90a915740cd
SSDeep: 48:72AZuGzcFvsOFlhngS8SQIVrMAAt0VGK4zo+S+nAX+5sCVoqf4Cgc/dTWUyy3o:75ZuGIhFlhnglSQI6TtyazfjAX+WCaqg
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.57 KB MD5: 58e945983fdbb254bf88982ba00e2c9d
SHA1: 4a65c06584fb9536af6fc12506e6c1fcf78e5dc7
SHA256: fa4f484d737c29849a5a042c8f08b1803d222a08f630746d2270e0822b341e69
SSDeep: 96:uP5ni2/7CKXggEkMS0OKvUm43PJdKJlEQrbvg0gUeAKDJoZp7LbY/R0o:oV/ZwZv3WJdKJ7vg0O/DuZp7vW0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.53 KB MD5: 35976d4e6316a4d27fdba6371d63b779
SHA1: 6d94e3f3bc60b694abf3cbf3dc63820b47dbd372
SHA256: 3e76e59da5a60ff87fc979f28a9551c0592aa7c9fd402c1423334b75577079e2
SSDeep: 192:vWOEB9isRWYXAmbdyDAAhNygcRwPo4n8pP0xermx32Evh2/40o:u92MA8y8AjymQ92EM332/Po
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.73 KB MD5: 137c72ae0c927d32f18d7a70186c83c5
SHA1: 63d96615be93f8709398207fcaef83b18cc63cd6
SHA256: 2ea5173780fe113224f7b65abe36275b309ebe906bc3b8989d00e4caca42df64
SSDeep: 192:bJwPy1sTaRnBLFUOssxxYicGDfW1XOErpxJhIBhUbQXEpxaph9Ok0o:b2K6TaRnBpUTTxWW1XOE5hI3U7napbOk
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.31 KB MD5: 65da0108d37f743eb2d8de7a52ef744e
SHA1: c6d2f5886661d5f9fb4dade801ddba6c045f2255
SHA256: 889f749dfa3595a3f6caae9fc449f1b9f243365dd1293d2bba704c59c2cae1ba
SSDeep: 96:QX/tv6Bv38X34gcJVPGp0sBt/ojWNK9etbyKaTNXjnTsS0o:av6m3zcrOmsnQS+a1aTJAS0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.86 KB MD5: ef355be6b61ff5634ea564e82300ad28
SHA1: 69b8f409a879c03931af6ebeb32626fb379f1c6c
SHA256: fbfe1c94410d8825c03ee0ed4c1a12e206ddebf149096ba3b405cf42caaf5a7d
SSDeep: 192:HdfLGmCvbvEyfIxg4ens74JWi7zXTiiX0o:HgmCTvEyAxXecylEo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.86 KB MD5: 6a2e696076426f819544f8ab03310a62
SHA1: a532677a82353edd2afa96224934136047fa7aa2
SHA256: b37ed528f899e3af13254adbdbf5cb0ba285ca7bfd998ae0eef4893a5f2c304c
SSDeep: 192:bzzLaNkHbqBlUvaC4vIOMYQfxk1hfMlbko6WJWx0o:PzLaKHbqB4avvIORskqo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.21 KB MD5: 08a9ff2dc97728afa69f1cab26de7edc
SHA1: 5110dcd3dbc738dbe1fa579af38154cdccbdab85
SHA256: f7483b719da9a1eb437c0b6aca2a1c3d7c66b16e35a134fb2f65ff826fc16f5e
SSDeep: 48:gWpzfL0FSyB4nEWGtqBMbsBKiv9VDLapd5feRCy3o:gWpT4hi7yBeRC0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.67 KB MD5: 3ada0002c4996cabcb403f3114acc2bd
SHA1: aff4a79c2a03a07a062c9d3def6fec3e4f1807d4
SHA256: fe34cf26a0bd18e11f180ef7b94aff366b4066115db9ab39041f366861655601
SSDeep: 48:BPtvuSbO8/1yX4iSHVY2dFwQpHFa15kTl1kGRtdOp9yujqN+AbMOIN0cyj16bBVc:BPtmSt/cFCb7wc0aTRU9ydQAbMJ6cyes
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.51 KB MD5: 4fbb69fe4aa621afaa5bfe81de91302e
SHA1: 947c242353c222cc0c9465f023da7d61f32299fe
SHA256: cafc04fdd2cbf5ba36ffa7ec517d13b12d409dd528c912132406b5e14661a665
SSDeep: 96:H8MUcpPJKin4XaSI9SeONCB3qUIWo1PGfep3j8J9Tu0o:InxXBI9SeOg3Cwi0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.39 KB MD5: cc9a7b5e7ad3fc0c5c2a26ada176f108
SHA1: d062997397f82be2e967174dd37b373ca9b7939c
SHA256: ea009a7c00bd4f4d9916e8f4e3c4611c40295f4a4ae152513ca160be0b7c388a
SSDeep: 96:Lh1qoedbjP9jKZiXLzvikOo1ym/jUgtwQBExwYv3WRXA0o:LhUdbJKZc3vikv1f/jUgtw4ExwKG9A0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.12 KB MD5: cf378b381ead3f4224f3aff8e7e6a2fa
SHA1: a1ad7cab8cf74a9882c200c3722e72dc4da999c5
SHA256: b1e4608a0e6febbbccb508115a06f5a46520597d43cb1b267bfa911250ae581e
SSDeep: 96:ng+LCA7VXcXcR+rFRioL9hljPTMcbAUf/QcoXHs1a8arQV+nbIvubmcdJp0o:gBMeFsoL9nMcbAUfbo81a8assnbfv0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.12 KB MD5: a221b789c6e8a1161d424143c4343c8c
SHA1: 5704f4e97c35d41b1903a6dd0ba596f9c5f2ddb8
SHA256: a3e65ab4c5f6ba6bc0b7abd7844c3d7db784095c6bdb33282c461368aa1d89db
SSDeep: 96:+eDzg9PG4/4EzU144kpDF2L1Q3HZTlirBhMjMipvl+Zf/k10WWA92lom+gN0jA0o:+ensu4Rg1411Q1Q3HZTlKBKjV9+Zk10H
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.93 KB MD5: 5f5dcd93839858dad981c8543cd0e725
SHA1: b592eba0c86a343fbc4efe14e51629d96f3e891e
SHA256: b570f760083202b2409f7768b28ebc52fd6f6a744791dbc44834daeb309c703e
SSDeep: 96:/2nyzvXlE8/uB5IXtxmAjQRHZX63rgTK5A12nWahoaZl0o:MyzvXLiIXeTL6bWKaGWahoy0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 26.50 KB MD5: 668898c042b43e2ef2f51a6d5f7893d7
SHA1: 2db00beb22e18ecdf581dd4ffc312afab7370a2f
SHA256: 14200375edb66f6eab686d295fc7c1c5af1d6a3fb904aa8724fee78ec4d742e4
SSDeep: 384:oOkmEtgH0GiwwlGlJ3foZEFuGPZSHkaCDbPYzW+uaGzZg4xPtqtXhjWo:ZkttEVihGJ3AEFxPgHOrY3gzZBxPtwBZ
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 28.51 KB MD5: bf278e5bf4f8f37e218836892630296f
SHA1: ad58f3377f3dd29364acada074501fc56620b53e
SHA256: 5172dd2940f05cd92e541bf07f31b04af0d98762ce856cada0e83ba36f6ba997
SSDeep: 768:2iNx/RQ0fkyLZCFWqhhJuGyN3womfYJVPu9qp:2ii0SFWa3bd8VP2c
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 11.61 KB MD5: ca124e66300b9203ab8be710668369b1
SHA1: cdf556b3bba890e711cf4a609050702d1d05a8bb
SHA256: d54ef3392d1e2781f1b3a267319ad78c2123e47c616976ba2275e6c6806cc570
SSDeep: 192:K6iwPTQrQt6figjNaanq4ZPu+in6WR6mt//LV7HDlaFzst9L+GmtpnZW+G06ovvR:K6dt6qgj9PLin6Kt/LV7jlaxs9LZmtuE
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.00 KB MD5: 78a49b10fee2d6d91dbd399dc4f92a05
SHA1: 8c7c9de0fa5382b0268424ed27e68a8cc16ff9b4
SHA256: d45c8e5037d7111bd800841eb17ce17ea1fdcdbbd93a066e6b02a3ddd98f079c
SSDeep: 96:FeBRxenE/LdmDRmq0ZFlQSEmDIQDc8rJ/4yn9JcOmHs2tnjASfjy43G7UHojETrL:ARQnyLoT0ZFLEmDIH8rEs2N7NG7kojEz
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD05119_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 17.07 KB MD5: 803d545efa73496a084f390ec170e63a
SHA1: 533d8cc2827fa015e7e25b18cab4876054e3b394
SHA256: c70d7178e3520f2b89d464b353d189f5ca960d4d95a72144d84109cbf3a50af7
SSDeep: 384:ljKhOzyjTNTxKw3Qr5PHDcBw6L0vIWtMNlhRP6VFh4Eo:l+hOzy90w3whHDgZQ0/RPCh4/
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 16.53 KB MD5: e13bacb06d62a8840bb6d62ca9e2a118
SHA1: 76db8cd78ed89145774c1a48304d588a23c4a64a
SHA256: 296d88d4779df6ba8fb9345728ceddacd2a5c3e4bd27c8c11e085ac354254aab
SSDeep: 384:3EJ08g3c7FmeAin+NFWTwsF2KZgjnlNY70/r0yo:3n8rBm7Xe8HTgd
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 15.98 KB MD5: 401ea7e0f133f398d42416e9b89a0843
SHA1: 36c3d2bdf41133d45cac91306a74ac31bd910eef
SHA256: 18c3fd2b84c2b2f858e30dd3125b59e386d5a6de225117c74dad84a5460daaf7
SSDeep: 384:j3bIIjT03HBhpIIu3JP5MesvecxvckapYrdHYeYThIlFhb+c0sto:jLIIjT8XIIK1Wdecx0kaiEhIzT0h
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 26.36 KB MD5: cdd9d0d2dcf03dfff505e24bb4d2ba72
SHA1: a13a9bdc1dd75ab479a83e174e7461a2119691e5
SHA256: c374e01672cdd3eedfa4df00e688e15ad441fe004ecca572d844970ef63c2418
SSDeep: 384:HPlxQ1seW9yORnKi8NL0ZniEjTH/NhTEeVjPLLgXE+WHhdglZgtd9XwJpcjkhM9q:vlPXTnD7HX8nohjgQkO9bs6d8
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.04 KB MD5: 88b20b7867fc31b80a23f407e548765a
SHA1: 47abaaf567a8dba5f2cfa69164bfd458dc8bc312
SHA256: 1652339a0a78aae7c096b50952fb96c446f2a4d13460430a0f97c3cae16f6c64
SSDeep: 96:rv04/A2wWd3YYk4IyG48OYe+6EFSGpT3zmukAkyWRktymgEMvAs0o:bLd3YYmAYe+gGl3qBFNyMYs0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07831_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.21 KB MD5: e6c4b4affd2a3022bc0a53589a8e0d99
SHA1: 5d8c3750673a23ca89c2cfe82ff43a19d2f22b3b
SHA256: f7cb7af7ef8d3b862598b2de5b686104809b5fa44c59dad459562b3f45eca10c
SSDeep: 96:eJjg2RLmOrRVkHBWSNDbagzLtolJ+mgoxAk+EYj3V0J0o:Ag4iOrRWgSNhzhomSmHXk0o
False
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: c80a4fec9c04eb6e99fdc5001bf75254
SHA1: ec9e37aaa4accdcf9ccec7286ff04824cc7c7007
SHA256: 40a4e404ff69ddd94cd785752b53a06954e78bffbfc78d5b0de6d306c719747d
SSDeep: 1536:QxZUrKogxu6rqbo5ZDNg97/iUJijI9X7XDSH8pUuW4cj:gxuPbo7hE/l8ji7XD48pUuWdj
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08773_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 24.43 KB MD5: ee515102fea44b401c83e658150634a0
SHA1: eedd7843589f4c00b379f8785ac172cb7a9957f5
SHA256: 1617a9b0ca76f9160448ad474642e4a5cf4a65bb207d117b338d1875cabc9069
SSDeep: 384:lVPqG006Zq3KK2Sn7OI/sgFyOf4Z/q8XO6c60m+cpgwbPqK5k+eLD/LvqgSzGXZo:l5qGJX3rPS1gUP7OVmq0w+eLDLqgSyC
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 24.00 KB MD5: 35547d81c882de02946695c8ac0ace7f
SHA1: 670c8aa2611b774443fc367a87a8d32359c2d5e0
SHA256: 0b971347d62a7f31d5ed7d93e7d10b9c9bd6ad2bf8e853d3829fd9940f75f8a3
SSDeep: 384:znsQUK5ar27Ot1U4/rsZrr8JEHp4fiR+qekadqpo6P39GueYmhFeSxXQv0qZ5vRP:znsQB5l7K1U4IZv8Jop4qLekFaTRXQv3
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 47.11 KB MD5: c5bbc01bb39cf6bb5752cfbf068ef7af
SHA1: a834b605c60e801b4107ccb6d0fc68ac0d6d044c
SHA256: 3980f6d613c083c92818805a58e231ccc7d42a52001a6f993f398b1b17768fac
SSDeep: 768:f9rJCreysRPwt5UlgxgzEuO2czmxg+abAJG7TLJ9kHS3hjrBpoNq0fsaWIlw82k4:tUazwt5URXO1zJ+aUGn53B1poN5NWIlS
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 39.50 KB MD5: 45a46dba4f6b239ae01d6e11505cac53
SHA1: e9ebc07427e0689742f9e1c9597858294d1a68bb
SHA256: 7ea437dee63b3e906cdcaa09d7148c6ca3eff86c483a6496d3396dabb9c23515
SSDeep: 768:Vk3T9bcJ3tjInS0vqLjTqIGZm41ZFK6Zxj1ea4WbCBzlSbKh1c19DnWKDOb9jvVB:+3TqNSnOLjTiZm41LZDeJWbCZlwKh1lh
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 46.90 KB MD5: c5c58b002037647e8b7c47454847c0aa
SHA1: 81af9de1d25eb123e4ca15f0877f81140c9ac2be
SHA256: 0d97e5d8375f68562941204c3e6b11bfe17a6d10141028b2104041b66d35ce5f
SSDeep: 768:LogapygOJeDE1ZjLhSMB1OUyOAl3MF0B5n5I7Ki/cnWjh9osxntnCU2hd:lapycE1NLcMB1al8F0BbC/1osptnKhd
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.43 KB MD5: 24f2203f86104c5fae3a7864bff6b02a
SHA1: 4c72ec06060102491e6c96324db39991eecd9aaa
SHA256: d0e78615429a7b59f38d44b841e5855e728b07302bf2ff0886170b0d7518aeb2
SSDeep: 384:qyMyocJzKNSDk38Cj+rgW00OYI2gkUP5gNU6kIBix5yEm9lh13qFo:q3nsUTjwmYNaOmUsOLzaW
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 20.31 KB MD5: dbc20fbda3e98529a064533693a10cff
SHA1: c7c90027f37111eb87fa108dbcf9cfbccfcedb1a
SHA256: e1ce36cd1b8d36910a82df3ab18b64152c5352784bce4b5028a6f058240ad0ea
SSDeep: 384:22F5sGiM87gL5tazIFQ0MUritpuYFUQI6YNTRe1kG+7DDjLmMjhjJ9F6o:NXsjMYgLIyVLriPX+tDBRxKMN
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.01 KB MD5: 0eb720b3446b6a76183dc905faa9ba11
SHA1: 40da3aaf3a8f02cc1e6874dcbd70cc45d171b4e0
SHA256: 74b547ba83c2651ac3ae338724bdac0aab0f3cb1cd886d0f3a59f3ca07d2d728
SSDeep: 192:9SW1YjKIx0yP4l5SZt2GM8lHspKq6Tt5YaGBuCrfOFxFxFoyZcC8eIXYD0cTguhv:gW1YqyPKd8lHdp6BuqGF4DCNIIgyOo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 13.43 KB MD5: c969efc6c37d5ddfa1d7aebc69755880
SHA1: 82b1b75801baa7fdc630480c6c1a28297c6cefae
SHA256: 2c6c30237d22cb3ea1d65c6d85dda1e8fb22617d5b4944bd344f881660bbf9f6
SSDeep: 192:jktd4/AEVTPrKGqoKfJT9GwIknIV+XGE5pA0JXDLe8BiUubNi7tEO+/cMcXLw0o:jktuVuLT3IVpE5plJWuLqNirMQXo
False
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.30 KB MD5: 1a8061768d31bb0bb97b12f440c7d95f
SHA1: 206b7de7a5c61649d535fe5bf2170c7a5c3ac6a3
SHA256: 6636b97e2c2ddf4901c9d4ff08025cdad4acbe01442a24da4012db10c48d4531
SSDeep: 1536:ULDv/dk6gBApP9hXpo3/r1UzouW3SSOVOlDVGBftkz8arRPiJSYmGT3:UL766ScFNqUsbSStVOftIrRPioH+3
False
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: 40dc78a70afffc784eb070aa72c0edda
SHA1: 4c87d70249d04bd6c1517949c270dc77d7641ae1
SHA256: 226d8fd11d0d81f90dd899519702cf607c80979f01728481d7e73377f90b1351
SSDeep: 1536:J4r5XA/RBcezYno6jH3lnzN/DOzAoH3NR6b3MICs1DG:JgRijTzYno6jVB/D8JHdC8ICZ
False
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: a18f5a9609827174ab55341eae4eca7e
SHA1: d9dd49b390390b6e6dbe0342a08c684b1a7018c1
SHA256: 58119cf15364501a997ebd17cd3b0ec7115e2266fed685188f8690222ca25a34
SSDeep: 1536:iH/2AGTY4T/OFl50IWvcnDTVLnaYRV0AyBRSAVSJ:if2fY46T5/AcnXVLnakVCBvSJ
False
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.35 KB MD5: e9dd87579519bc88c95ccb55511f4a08
SHA1: 5218b30b1ff0a09922fa8052fa5d47a87dc17a3e
SHA256: 538797c91bad99750c9d423dcf8915bb8c289b2f9c3bef2223e1da0fdccab217
SSDeep: 1536:0lFboqIhogcBaz1ApuQyj0hl4ZddEF7JzXKmEulV3QY:cbo9ogcBazupO0h8dg7JzXbEEVAY
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 16.04 KB MD5: 3e07a1527ad5151d29aac5406c3efd87
SHA1: f9c397e0966061b150fd5282d5d6556c7a988f0a
SHA256: afede1344b52e95f59dcc38fecc50eda61fded80cc7e082ccbfea0329855f00c
SSDeep: 384:xNyQ/rs/oJ5pR3XJj9MN3rhhYM8x0YNlLViVXatRo:Hyh/c5TJs3VhBk0/VY6
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 20.21 KB MD5: bd6113266a64589513801573ad3020ea
SHA1: 79527468cd8c2b99565149812d7a7c45e60a6efd
SHA256: 415e22d905280c2b190b0ed0ee215071374ecc99376da6db836611661bf82628
SSDeep: 384:Fi7CQAiJAQByF/wGa+n+YIG1NznRwRaRyYj2/X6o:FiPF8N/prIAznKsj2N
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 15.61 KB MD5: d7363ec7aef6c1b15ae4fcba684b8760
SHA1: b9dced5a6b59656928a1ae4d786fd8e07fc9dbd9
SHA256: 92068ce79c3d2305fe262f0be64de7a5a4798181ed2294f294a12e017cbe32c6
SSDeep: 384:n0+VXZRhpMHn9LdnYJh3jeAs1SwAaK5VXdUyVMgcuBOEo:0+VXZRLSn9BY36KL5VXdjVMZuBO/
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.92 KB MD5: 01601cff6b4a2eb8a343817be2425b09
SHA1: 9449d3eab4a477383a4e23e537425d6fa32ac073
SHA256: 9a49606665af4373959ec986271495c541fc83d034b7bd4aee731c314fa73120
SSDeep: 384:/CGRJD/kCH/tTtodvhOE8wyTh4RlCrQIpgC6o:/9/XHodZOZwchHzbV
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.93 KB MD5: b764bd962f70e20ef4841bba2494aaef
SHA1: 8da8c4c50752fc1838f7466d8983348a25306668
SHA256: 4c229499b41736b676be87d0b8b8f952380564686e9431cf74a20ddaa5bf35db
SSDeep: 48:r5nClzowsYYTaAz8Rb5Q/5khzW/Mf/WbkXz1RBdHWFXbwl2y3o:Fnezo60aAz8nQRkh2atRQ10l20o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 9.71 KB MD5: bfb2b71ed24f116860f5f3756cb6ab89
SHA1: b537522153baca2d46fcbaff5db36e298494d5fb
SHA256: 135162e954f82e570d7ca12bd1a019d7083d89da67b591b89ccbc3623d21b0cd
SSDeep: 192:CNbxKYtAZBn29ko08sO+h2+bA8pLRMGV48B4rP9JFdSar1XQe0o:CJxSzhoB+h2AAKaGOO4rFJnb5XQlo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.81 KB MD5: 3dbbca4b246ba563189ad024163806a0
SHA1: 61e49cbad69ec55e6caa72d0a75d2123d6b594e4
SHA256: 8b0289f8324e6c0e214243ef965006a5b6d241191ccd66657d487b2d026e15a8
SSDeep: 192:B8vqErXtLLW7rV5MIz1PYrMbcFts8ol1OUnkqDJqe6tlKeOM41UcbtB28Inrh0o:avqErNq7pD5PYLsnOUn1DJq7XyUetcDt
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.39 KB MD5: f0b4cc1f580430aaacb025e8c2953a13
SHA1: c7f40027b2161305a5fb941a251f23f1cf74dd3d
SHA256: 848c2a5e70796de3f08216687bce351776e957b9190532edd099c79237b36cff
SSDeep: 384:UpZCV0xnlLtZDgnshITP/Kuv+GApfnmiutF7iwYgo:UpZfnFtZ8ska3PYtF7ix
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 19.95 KB MD5: 8b9cfb2209af3f12eb5826b76f8a088f
SHA1: 522952fd2978d8d89d992901a14ef7adbf30804d
SHA256: 5e0e9193865b0f51ed335ea46d575be5ec82546818288c49e44a8dafefb5d0fd
SSDeep: 384:vWqbKA6W1dh8oeIDi1DD8uWw64YJs0wama0PenTd7z1VjTgmLuWo:vaWPZ2r2VwC0yTpzbG
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.46 KB MD5: 06ed3781ec40182b6adc8451a974aa54
SHA1: d0627783bc12ee61e87c651ab518608bc49082bd
SHA256: e08724674a863ce4b25eff8a9959060f70101fe0c63e7599676995967184351a
SSDeep: 384:QXWwUt2oP6gPIZJsPbeXx1X9r4CIF3+5mo:QXW5PkZ2PbeXftECaMp
False
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 1.07 MB MD5: 17081d4d5ed97fbeb15d0f61168d320d
SHA1: fb9536ab93cbdc31b0c3d5917b4aee251cedc09f
SHA256: e175000eab0b3250532f46699ea84dd183b0cdff443daa3be792b42331f2a5e4
SSDeep: 24576:bETVtwV4aYMAsvngizo+QPMrwYL7cb4RaNjgzEnw:bETvwGVGzovwNU5gzt
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 18.12 KB MD5: c7ad4fe4d6eae83a92e303f9d7cc6939
SHA1: 94abcd8469478a62923b896d955aa935e58aeee6
SHA256: 480b31155640dacabfea72cdab88331eff32b4e81318110b1d11702bec209026
SSDeep: 384:pDquotA0uLTNDgT0+qt4AhCT5RmQqjHuE2uedZ1Jwnhgf6VWPLLFo:tqztrwTNkY+Ihe1qiueH14mSUPW
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 11.04 KB MD5: 8ef1c187d8bd56b280b1802fac9140e0
SHA1: 5ef39e084117ed2b8e5e6862e4eaff1c54e1ef12
SHA256: 311bc440d000f7236996422efa0cc0cc6c5aed498ec2bb66a96492b99b8c7923
SSDeep: 192:6yaiomUnJKbaImLEHGgu9ZNCBclv1tCCF82cZkCJuglmNLVyzs90o:6yaYUnCdpGCBcl9FdksLgo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.92 KB MD5: e9efb85c4c467d9b36941ea4b25ac5ec
SHA1: 78cd61c8cb19a153a41b05fa814ac75d7bf30e3a
SHA256: 7c98e4516762c4519d6714d4e25b0a2109cb2e51966b7ee70e42f889ab34430b
SSDeep: 96:cXuve48ElkZT3cyow4Xy8mRD8xXVr8xcDELd71VqoFCaV+2wDQ7wMIVG/r2oXuOM:gk8EM36wQySxXq/zF977t/rUeZCmi0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.23 KB MD5: 01c3f4951c8dccd6e49246f1ce092466
SHA1: 99c913956a45c424da8fc5d21943ed9b8350d27c
SHA256: 4c7e16a1d5c6d069b0b2a6c32baaed0273dfe957c6de6425cd31c45d502ad199
SSDeep: 24:86vHP8dWsn/djpWY1KPXCvakyppzXhnLelmFGr1HjpV8pHkN/Xny3o:7HP8R/YySzlelys1taEpy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.11 KB MD5: 180d06e388cf3f26e8eca180ec14f0d6
SHA1: ee524a26d349c21b0c9a2197dea70d1072445252
SHA256: de2696ed4b0a4d0d5af0de9666e3aa508b4380c02d6a6fec9e644455339bd3d1
SSDeep: 24:hEQyVZKXsFeY3DkGu6xA7C4smZ4skhLxaujWgFWG2q8vvCVXny3o:hEp709egSx2C4ulJxauSg9svCxy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.71 KB MD5: d01970867e705467f67ff216ea82db8f
SHA1: 0004b09d6240fb5833c5ce813c4e21d34e08d74a
SHA256: 0e8b7f4a1f13f058168b96faa5856e8c419c9575c00290b33262397e45d46e30
SSDeep: 48:5/bIb10pgphOjAgLlSRgkAS9OIEQtxy3o:5u0TjAMIgkAYT0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.14 KB MD5: fe43dda3f6f492a6bce7a39eb1a6bddc
SHA1: 9e6b4f1673cdd3dafa29c6c9b39599bc462836aa
SHA256: 990e974879fc1e63648ff8f5c6829220417c5c059bd332ca9c4aec3b0e186b58
SSDeep: 96:XX5aAITa+FiofK3PRy22zjy8SIuAowjcUxTkQp4a1nQcL0o:XgAI2+FieKfRyFjz23Urp4aT0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.90 KB MD5: 746d5dc71a088ea80419db7d547ec7a1
SHA1: ed44a21d29aae5eb1fad15689c339dd81e6cbd04
SHA256: 0f153c918c60bcc8a63500ee3ce728dc2a5d0a67b6279abedae8f9f2b91d6898
SSDeep: 48:5b7U6170waRjdx4zx8AlObZak0L20yPbeYT2xy3o:55d0ZRjmpObsX+T2x0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 9.32 KB MD5: fe527ba90211544267ebe20edd79ed70
SHA1: 8652a7b7640bf81ca5d5a61fb5ac84a786d1a807
SHA256: e06b3db107ea38342a1eca28a621a4f08f9fb97dcc31e00d7d86af6a7cbc4ec0
SSDeep: 192:q9iFL82y2CpqWiQpiRKxqEy3aMI6q6LMmhUFhFkxWcXkxB+SiQK0o:q9Ow2yREWbiN33I6q6LRhUa0xoS3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.12 KB MD5: f0e18d20b5a0bdaa87923c13569e7d58
SHA1: 39f61ecb891b3308bce059f012c74d20af156e16
SHA256: 9a70c29c169acc962acbf369005819e95437f762a339a031479bab92ac878f38
SSDeep: 192:3l+0283aX0MsWzqqqQw1glF+H1QT5hSxHMs5Fog7x0o:p5vMs+Jqb1uCQ9gVogSo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.17 KB MD5: a448f0b5d43c4185edb599a653ef6650
SHA1: 62b484261db52291c0e3352fa6fc0ff1973a1206
SHA256: d3f3db29c24ffcbcf24d72f5c69805544f9ec345ad9eca6b538c0283557e0404
SSDeep: 96:EID2g9JHvqXrJ5BDbtREjUhAEltf4HP7kli5Uby9L2zV4m0o:lBfHvqV5Zbim4v7qiWe2Sm0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00252_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.84 KB MD5: cada62ac142cd9f533009c62748d6aa7
SHA1: 67e83c319f48e76b498422d4788872aaf4f16c1e
SHA256: 343a33c3bda35e8a036f5be8abb76b1050bb2358bf1d4f64458f65b80ac94045
SSDeep: 96:v1gdEG6JAcR1+bxqmDb11BJ+9jz2qiy6r7t6/rfDcNpc+a/eFH0ax/s0o:v1gd16NR4lbFf2z2qEWr7cNpLrZxk0o
False
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 373f597bd5cb2981ef587958382bef1e
SHA1: b506c21a8bde021e268709f10a5406cc4a83feed
SHA256: 92ec21436df3291ae78b1d3243e9b9321798a3149c32715aef5641a10b176ce4
SSDeep: 1536:bdbzJfbXw/E/IgRgeacyRS/isoLcGY1gItGAfkZcpvc9x:bjbXw/mIgUcYNs9PttKcpvox
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00248_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.75 KB MD5: b7ab669541190fb093e1432f37a7dfd3
SHA1: 33914854f2b5dc37c6f41f4f9cca8192f0799396
SHA256: 64e005f4f8c896154f7324f10f8c0ca45be14a4d117727f52c91dff5e1bd0859
SSDeep: 48:BTaKlmpJAjgV1x+Vi+euExHV5pTxxD864nhLL1tby3o:NJkpKE1xaieE53pVCJnZL1tb0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.43 KB MD5: ed1821afb3ea17dd5993a4d6076f29e3
SHA1: b1276ddd005f44be7d6cc8498dc86fba2fab56ac
SHA256: 05e0402f54e3e2e6e4fd3d4f80f0847aabebc9555f9ac18be2ee4ead696fdb33
SSDeep: 192:VSbN8Ym4In5UGzyGxGV+uJIs3sQKxCO4cqpQgZV4oHCDgAjtmpjZqDndJvDMX0o:Ymy+RyGIF6qVV4oiDmFqDndjo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00254_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.93 KB MD5: f6e9c71ba1dfbefad47b650f32f7d5fc
SHA1: 520b0dab526f2bef276ef83e4dcabdf78d6f1163
SHA256: 7db6dfdb258df6dd94053be19c30b24d6ced69c60f6419b07ccb5955b7be2156
SSDeep: 48:U4SQLNa2vlGz0nb4r5fpT3zTQJE4sLpNZU0p4sufy3o:Uk9dbMlx3yxoU0pBuf0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.73 KB MD5: 856f8a7347ebaac05d844857eeb92f4d
SHA1: 1b30dbca1283ea7c12716e21ad34377f0ea7dbd5
SHA256: 9b616606eab10bfcf84a1487cc0d384412d17b0f14445ddef035408cf67d0e04
SSDeep: 48:VMoAxF7XeUkU0mYwmSsAWFnbbxkKZtQmb3mVtemejGF8yclM/V210vP3y3o:CoA53mxAQCKrPmfrejm8yuM/V2KvP30o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.39 KB MD5: c5026fc896cfe644e4aa76838990170b
SHA1: f4db9f07750be9af30e87650a6290f41a8bf3b32
SHA256: beb9602ebc48928b01e3d6ea7dc9b53ec84743f223ec0cee608cf9c38a12b51a
SSDeep: 96:QpjOJ2wDLp7DpDIXWPKaFBPUsYl7GS8tli4tP8N5qwyFXmbhYdyAEE0o:Qpk2wp726yxsFeQhZmt8j0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.18 KB MD5: 3224c10958fd1f783903cd9a230bc1d9
SHA1: 010d7645b611ad82a6f35f30fa3578e80764f30a
SHA256: 506a894972e47bfb5b2231be3d340639eb1c504ec6dab2cb5ce37e6cafab5514
SSDeep: 96:br2gMXRSw2HbxICL2uC1mzTQ4bQiYSlGBwHpBaX8vAm0o:XZMXRz2LhCwUSlZpMMvF0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00265_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.86 KB MD5: bb9a72a7df23173d4357defed1ce9a20
SHA1: caa22d67d0e8e0e572b0b58e823997fa0670b8da
SHA256: 0e03ac0043baf9064c2ef9824a471e5d52c15a74878c0b7ef3c93367ba2fdacc
SSDeep: 96:lQnh1KIkwNfwuTs2EKhupZ/+q7KOzkbM/v+iN4xpazeFY/IBW6B/glkNHwfBegGM:o1JkwRwuHxhe/+sKOAW+i+a6G/eW6Vgl
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.93 KB MD5: e665a4fcdf9f3dc45cc410666c402562
SHA1: e6b11304744f0c4fd8338ba60317eba319751cce
SHA256: efb65934790cb8aaae6c7f42e4907ffdfd14d23d3d84170652bd1ace9eca98f2
SSDeep: 96:+3V9dS/xOQwlUkRAyyoRVEmqxRtaRIlzgA0o:+3/4/x42QAyfVE1sI1z0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.82 KB MD5: 7be8c210f6d48e3ffde790d821d456ce
SHA1: 403805bcddcde468ae54f0cb97f503abbc4c57bb
SHA256: 3ee2f9be4e61eb4863e81c844a11ba711de987b3315aa32115f320f2098094be
SSDeep: 48:l4Qatdjchp/xrm7fo0/dgWetwdd3dA/9Wt3lo2yNxBtQ1um4+y3o:lHatdsxko0/m5wfaW1uxNxBd+0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.31 KB MD5: fccf6724ebc799c3ad4894aea9058010
SHA1: d74430f1fbf59e816ee531c290b1b60956bb3841
SHA256: d26482c8d90c39bdc80d011cf100247866e7ddec681f8a2dfb4798a34768028f
SSDeep: 96:O4iKqIY7WIntjhHDVdosUFMl2MtUtxR802s5O3FwAvpe0o:OF7VntVBCf9ss5O7E0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.03 KB MD5: f323c3efbde3bf77148dade71a0b935f
SHA1: c18413f74283118325b0a6c92469469697a6d3dd
SHA256: 7acccaa0907bc78d5e8e9fc4aba0fe3000041b6126e2987e3fa531171eee937c
SSDeep: 24:wyqKQ8gCyh6q2Iy17pTMy+w0bodukV6yJwR+b0lCVkzC0T8Xny3o:pe6JIy17ZNj0b2ukj+E0akzhTGy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00524_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.07 KB MD5: c635047c32ab6a567e64668e99a3f6a0
SHA1: 5c80dac7c92e3b4286940d553a8269535f91d7c8
SHA256: 14296ef2848cf23910a28fe715901aa3821ede0b27b8ef58293063806420f4a6
SSDeep: 192:ZoO/dkO1eOdJIV7Eju74nwoPM4y9FwFFL0o:tNpdJswaswMyoFF4o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00392_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 26.65 KB MD5: f384089e3032317072c7eaa5a5b22303
SHA1: e712e0624a17397411b858be3aff3cb9d8c0b1f6
SHA256: 4b9b8f86087f43c1534b5ff16a3f3378922d2696a2cb7cd040d5bc0112725863
SSDeep: 768:Kd3W+14+q1kfAMwCU6UFjNlgmhaMuLebJVu1xybiskLF:IWg+zFxKebCxybiF
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 13.03 KB MD5: 4d1901cc6aadc394e1b4abeab630a8b5
SHA1: fd40db8d89be86657193530faa3762c068a49590
SHA256: c5b4ec239979c4a150d514b3ee033c593f387534b5491c1d8026b6365f5bc932
SSDeep: 384:M8S6cqeS2rATfxS9TMpkLDOHLxUq9ff5au4o:M8S6MjATfxQM2LDgUqOur
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00648_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 11.46 KB MD5: 8e68c6977f64770c8f0c5c541bd0ee39
SHA1: 143249c5d0ac37a6f33544b0f6496824d4917b0f
SHA256: d7765705e822c121f678b0d3d4566588ea32c1046b21100ce2a948cbe7828b09
SSDeep: 192:ZIFa69ruJI9BYfG6m4I85yEqoNZGoVuMp8hQSdEV6I7x3Ep+3FsV5D0HH6OHZB+8:us698IMG6rr/nVxpQQx6Qa+3F6mfOTkl
False
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 2.82 MB MD5: b605a050cf385133bf3c6743ada30e26
SHA1: 467d14e38997f0cd17a2264b38be5971df57f05c
SHA256: 23dc8b24513962f02d7e94415630123de98b1bf59980c8f3b7b0a7bfe0482e5a
SSDeep: 24576:Y4N9QV/7bTbQW76BueI7QSkYhjQ07SADlOk:FN9QV/X/QT8eI7PkqVSm0k
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00921_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.54 KB MD5: 4179e9a67091088755ca844ad273a746
SHA1: 7b653e02363953eea488e672993fa2be1756d0de
SHA256: b4695735772a11cbe79439d2a88a72a9d7683c216e05e509ff359c95b66e0ce3
SSDeep: 96:0708TU0sBUD8L+4wHMvLBxOWrqUz3YTAbrbKVGKK0o:l8TlMX2Mz7OR+Nb3K60o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00247_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.34 KB MD5: a8788e054be0452b0386f73385998773
SHA1: e5ee2c580f4eccee1931dbbfa0f797255ec47648
SHA256: 6256745701ba8b02cf707b42599df48b838d45a2fc59694585d41f83588bb667
SSDeep: 384:cGBhuOwS+ohvSRcE8Rpsi4FCs2vBjEQhHjaiJvIko:cau1DohvWcE8TA2vBjdRjz4
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00923_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.36 KB MD5: 868062fb49112854dd0f06c025122bc7
SHA1: 98df948ce04a20887326fdee0f678a7478de7d0d
SHA256: 4958be20897db539cbc7fa3cd9a066b2c618ba9e2b9da91c763d222fef3fb656
SSDeep: 192:Qvb7ufEfe79eSywJHsHYnQbVV0F84okAPFWt33OaMEK0o:Qv+H78SywJsHnbVVsok+FWtukRo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 19.26 KB MD5: 4fc177c62c4590ea125c91a24bc376f8
SHA1: bd86258d84560155d68defbed39a4faa9d3d9484
SHA256: 44db61855648a752fd6089b9a64dc51ae2faf3efefaf1344241890a466b9eaf3
SSDeep: 384:SZKuk/TXLW/pyj+Rb+OwfXb3nwotZsKadExcEhjvYH+vzlgo:+Yyxyi6FfOducEh7C+bZ
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00985_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.92 KB MD5: c87b5f3c68ff7b2ef535fa239d8b299e
SHA1: 770b1042893a67353fe31c1ac6eca6912237118c
SHA256: bedd072e90b11bd49058fa8240e3853d5a54cdf989c17686945fa34e1452268e
SSDeep: 96:XUBYSi9/2HYiq053yMW4hbls3IoVa5JpJ/1Ar/P+/A0o:cU/+Y8C4da3IoVa5XZ1AL30o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00526_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 27.15 KB MD5: 378e8f5224828cff17dc94ecec8c392f
SHA1: 123bda99d77c75ad11af69a503198b2891a89c0f
SHA256: 52287fe5a37ff00bc8adff331d08434bf6145300d23071d9cde93962648900f8
SSDeep: 768:G2r9HTBRA9CnKpQwIvdBFtx1ps54BiueQG5O5x3B:G2r5Bag7wIT5EQG5O5v
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 473c6e220f5d1f793adc7c08d6841a3a
SHA1: 94c71479f250d9f19bbc222e9cf275120270f94d
SHA256: 5a24d9b974b7b8da9183e5ce8744891111767dc99d9cc76e361f86f979981792
SSDeep: 48:zk3sJDT9GM9Fxfw1+N7HHDHByZ1zTUy3o:csJDRGM9Fi27rByTzTU0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOATINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 28.56 KB MD5: ed05ff096347b145a724d5e272ee1d9e
SHA1: ee8751fb004177972e1a0e8593ff1d3cc2a770b1
SHA256: 6e0a3141421b016c11d8d46afa1e99b607ae989ff6ed20dfcaff2557228cbc01
SSDeep: 768:HROt9CAGjr1iU3vgG/pp4OeVR8bLDmUuMJK9EcyiVO:xw9CA+cDG/TBr3uiD
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOAT.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.50 KB MD5: f439d395d03a838df4cf1b5f771b666f
SHA1: 58ef8465f024c7a659030c48d68b61d1ab13e3b0
SHA256: 6198e294dd2b57392843770303d2aa434d3aeff7d3ee9c4db92f85c37a523fe3
SSDeep: 96:rI2hc0l7P7DRy+3Z4Q1VMpxMgBOmtMx82BjoBrn0Q:rIz4jDRrJrinBhyW2BA0Q
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00092_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.03 KB MD5: 8a6b00c70de3b800550ee48e05df5bd7
SHA1: 25f30eafcd8846765a5c467bcd314601d68894df
SHA256: 5cf8bb29c71a48d3b95d10cff433d267dd3eb9bca9bf07d63d286409d267abf3
SSDeep: 192:IdlMaM+2btfyRQnlYhbGh12akzDvT+L5jKiXHMUFg0o:uyNNtfflmZDLS9XHFno
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00100_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.56 KB MD5: 23ef4736c11f2019c58f0dd62da566c4
SHA1: 62b52cd3368f29953043b3399d06fb9e041bafed
SHA256: 9fc0eadaaa1eb830f35b4e0910edb3516fc01520bc883d6cbc1d0f86e26bb773
SSDeep: 48:P+3atYZ9227eW1GMY0d5ssAqS7eMrSKWNEQc26a9KThmQGl0VxancPVX2hr5iT4U:G366A9ZgsG5Z6akE0V8cAECglMAxx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00136_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.36 KB MD5: 6709df2c2826687b8f91c8ed0c65ce9a
SHA1: bf7bc7334b03d64fc88f5253058e8674fd5293c5
SHA256: 4ec40d87ceadba7d62fcf27a6f8c03f389bbe670b2db165653d61f22bcb4a621
SSDeep: 48:ClOO4c32cfFpfhPt/elCDO2ni8d0cwdtkkO9i1kDM66/M//482/oTJy3o:Cl94c32cjhIVGR7wdtklw10P9//482Ql
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00078_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.65 KB MD5: e9aec25dd3bdb82d01bc19dbb7f3a84a
SHA1: 39389a58cf58d7ba44495fdc21da2116de593e81
SHA256: b0eff086b78fe1e434205b1431c2a06beaeee05cd39a1b8a6bcb8f5159d96f8a
SSDeep: 48:cPQQ6vFHOxTuW266qdS/ZnP6RXFr1pvGJmbj7y3o:HQ6vNOR1X6ZSRXFfJj70o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00135_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.26 KB MD5: 3c9c3a28964497957e364add87231c4d
SHA1: 98fbab6366ab4dda91ac233751b5a2192320beac
SHA256: 6a8e4602232402600b1bb7d079af727de22f68fc4f0856a17ab074afd6ad949f
SSDeep: 24:Q2kkds4kWv7coxrPBbKR6f0KA3E/NTDQOFwMpLi+UYwMmmUysL1opfSXny3o:2irxraYrA0/ZMDMjUPyc1opf4y3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.92 KB MD5: ba72be501e2393d6034d634dff7907b7
SHA1: 5a28b48f0baef2aeb801ee2bef3b15bece5d2266
SHA256: 8fc1d6be0c9bd5a0ed6eb533f611e874d8abc29e95dd997e0e4e2a3b10e2b11f
SSDeep: 48:Bja72gUvzpD4yuQ8mDyLfTWJGv+5t6qWX3PQVvRdy3o:1gaeL9mDyL6OzqWX3k5d0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.11 KB MD5: e92e4ceeee7d208c20e13d9c574b0901
SHA1: 4522b70b55ca7aa712163527927e1cda6da667ff
SHA256: 22a7fb1d4677441b49620a6e88df6b71ccf5566eaa4fa73e9cbc2f92f7963712
SSDeep: 96:onr0kltYPryqCLLZ6dL8ye132W2CCmmm7aPM/bGlJP2gz7Z90qVeVV2DC90o:4IzLQkN8y232SmjMjiDZSSrDU0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00224_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.79 KB MD5: 673d26cc6577defbfbfc2cd71f797492
SHA1: 42865ef4ef6a86e08a7eadede827fbbe730d69af
SHA256: 0fb098c16304bc6aae4773355bd7f14ed1e47afd1202b1bb401ff9ee29202296
SSDeep: 48:/UZBU6bYkhtXVN4ma7e6bJkRnsT5rO/vne66aXyOOBey3o:/D6bphTWbJkRsTE3e33OO00o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.28 KB MD5: c497d6eba6901eb5b93f6370bc64967e
SHA1: 3924cd71cf763b5bb2215d98f2ff8a7853eb1017
SHA256: 591fdb9f3c37cfad6c1c175a6bb141e87d635c6ac36ca1b7aa6ae6b68061b874
SSDeep: 96:O/gqyWTOl8B5PcyRznIo/jSQA1bpsdNN2A90o:O/gqRTX/RzIqjwquO0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00186_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.73 KB MD5: d4428e2d978b1368449537abfe2dc17d
SHA1: 7a6543ecd83cebbd2dd41cb146da83661fc6cb01
SHA256: bcc5ae99bb33feb3fef280c0d78a0c8e60e17a8167f8b61207c5d02c239c903f
SSDeep: 384:koWIhNqDdArcu5t/fx4xJz+UZIOmcqkxo:v1ZcurimUZpmB
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.42 KB MD5: 9fd8695f03a78c00c313c49786b42175
SHA1: b7291059bbd3204d963d3399d632e1577f9695d5
SHA256: a352401df4fd304ce4b4ea0988e2547ec77a026dd9081ccf604456da4cff3e2e
SSDeep: 24:x+qRAduzLSmpdijdEA+j4cqc2xoPd4AlSX6hM5jXThyr/Cpfssl8k/5nFzXny3o:x+O1ze6ijZrcqcnBM5nk/CdjFBFzy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.25 KB MD5: d485f8bb622d60a9a58641bf6e3438d8
SHA1: fa4787cdfdd61e7841be261214f226751b478a58
SHA256: 58940fb2d367487dc14735e6b3ce6e88f3c75ec4be619d190659f4140ac2707f
SSDeep: 48:nAuw98JmJzMwuhwT9weYiEgoOUekqdnRcPrAL9rGui5Vsh0IrIy3o:nVUJzXkw+O/kqdn2CUUhrI0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.40 KB MD5: f263c4b7ec29c4bedfc8ca490dcedc7b
SHA1: 470ead4c42cf6c3165202e4500c9560975b7d617
SHA256: 08737d612c4fe315924ad98b64c7c2d8fdbd0732b643271581eb1825afa2ca02
SSDeep: 192:SbkTzRIEXMRNLG0tKnUioEILD44VOgG5kBFAHqRGx0o:OkTCEXMcUioEE44VOgrBSqo+o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00441_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.68 KB MD5: c225f3787ede2e923f3223ddd83c7d65
SHA1: 77aae719fc58f61a6ded6a80d1f175bf7cea4dd9
SHA256: 6a1ff1d4d9534956ff97019ff44c3c4dfca71bdda827dd63de9de9bcf9bf54a0
SSDeep: 48:zeYKkQQj2bzhxOofAKqAeeA3DocfdR1Y62Nq4Sb5m3HHZTChrwdLDwceza2iciAB:zGkvQOrhTld2NvStm3Z1dUOciN66hI0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00443_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.87 KB MD5: bc48c7524c8149387d112fead8fafaec
SHA1: 8220204a66ddd78b92a58df389cbe90ea4136b1b
SHA256: 3b4601a4826a5975e0144590ab2c01f693924df2dec55fef3c41a900efbbd790
SSDeep: 48:hT0iylNld3rwQMvL+EELg37f2tNbD3vGDWhby3o:F0ioDaQwjz2tNbD3veWhb0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.67 KB MD5: 1ebf6a32ff42819e0f71ca4bb7a2a6b3
SHA1: 7f010394bbd01e94df2f841e3cbae795ee8b3c0a
SHA256: 24f574a969a7b1c94ea03b82b9885414d73492b710ad0cef1dc137f6847285e5
SSDeep: 48:nKLkr789h0bT9l1bYCvuHGsoC0jdmErzJPifzm7+eiSF2q+viD9JLcHAy3o:nejvg9UC79t1zJPifSViSz+viD7cHA0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00444_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.04 KB MD5: ed8301c0402ea961c7188a5c47342b12
SHA1: af47bb33656e04a54dfca5e9042d5232984d690f
SHA256: 0a0b6f3ac5f49789823d491f0a1a47d431af8533761e63cf7d3e3750f26a2780
SSDeep: 96:Z3YNFKSDNrVIQMMWhhS2HJNqMQjtj1iNtL77d3JLZQ2H0o:JMFKwKrhS2HQj91iN577/LV0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00445_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.95 KB MD5: 96137fd94db4526f32a7549ba94f53a4
SHA1: ce591e3ad99a6e4326f57232d2211539c8a84a90
SHA256: 6a9ae8b91bdfae6f17c353e7e34807d80926293ebeeb0324a8397f88cd553a65
SSDeep: 96:tP+Q7oncUpKRAUJb4OvinhwCFkVst7SY0o:t77o/sRAjOWwPE7N0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00453_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.62 KB MD5: da00640d4df0e5b7c7c3f4482f0c9f39
SHA1: 7459608ea5eb639c2c11f82d082012d6b84bba8a
SHA256: 0838c924964f6545274121d584ab029c3d2eac5accad2106b3ddf9a339bc3b4d
SSDeep: 48:7I7yPgWRGiA+HErCN+8ote1kx67yy1Dr9b+RQkrIgq6DfneBZy3o:U7rnYACNoXgyg4Hq6LneBZ0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01080_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.90 KB MD5: a5feaace6b0f555e72732cff6df3b541
SHA1: 916d80a8be1452725717a975c6f121dc3fdd06ca
SHA256: f03772974796062ec65039b9804ac97a8bd201b4c6a861b864f47cc85c7a7abf
SSDeep: 48:98uCE5Hlq7GN2f9I0XmkAJ+BLTZWWNSjWKZAro9O0Y1c3yA0OTQVPc8AWy3o:euCaTN2qYRA+NsWYso9zF0O8VLAW0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01634_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.65 KB MD5: b16e893b9e173741220d8cdf40829a9e
SHA1: b46eac45bb262fc68edd2e82bc93b0d0c978d956
SHA256: 272b2a2835ae8a48804a2d917dc7facc9f62986d5ce4c7521af5f1bc0b6df15e
SSDeep: 96:B6iAsGntz7fZ/FaAWBWH0hpd3jOc0LctE9DKVm0o:wiADnf3c/tKP0o
False
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.35 KB MD5: bf7e41687167e86c7d386623f2581d72
SHA1: 43df2748621d9cec9e3dcd77f632e517c21cf527
SHA256: 45aae071890cacb10ef6c7a91939b3895e475af65d592d32e8527956939ec849
SSDeep: 1536:X6Kd5pkN6a6zlchiJ9eRailcy4sFtc2QzMNzZlbrvj33pmsJG/d:XFkR6zlchaS+sFK2/JZRjHBG/d
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01603_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.25 KB MD5: 0254725ed201399db6836337a91b379e
SHA1: b9bbb810c97fa15828c019ae186b603441e37ecf
SHA256: 3f827a8a36d84b0b40c525c58c9e830feee3e7671f0466bad9108a16bb12849d
SSDeep: 192:K1Xf2p/x0XXNnwhm004k7VNz5lS+RMad2ACjaEaSYhb0o:K1Op/x2qq4k7VUK4ACjtXo
False
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: 4d8edb0d05ac3962362f44cd6a6ce656
SHA1: e64f5878ca1c0f43176fac8de11cb824c056ef56
SHA256: 082dd45a2dad67af24de25c3a5657b59ffb7fd92887ef1e3edd8c3f3b79f1044
SSDeep: 1536:UiusVvw7CLnQJwjW52j5bQWoamoWj5rM5/IPhtocQDkc3EQy1I2:Ui078Uwj4OooP5/IJScQDkcnu
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01635_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.89 KB MD5: 1d5ad2c61e769c4ddefd6e00baaedfa5
SHA1: ea8cddc9f8e0a3ee53e16ed7b5c422ee61d43119
SHA256: 79dd6347cc8dc1b927a319951fb0cfa79a461c0fa6addbe4d0ffb8de63ef0015
SSDeep: 384:9AmybqkdqHLtjB9OTiilX335FAmLrjWTmdypeM+sEH/o:9ATqrVOTiM3JFXSJpepsEQ
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.07 KB MD5: 1de2983f6e6a1945fde071e53fb6efc5
SHA1: ff54b7b6d9868d99f80a205bc700f0d1312e2648
SHA256: f59accfe94b24519a0687ff89cace5114b54a390014a171bacd995fb926fed7b
SSDeep: 48:7Wn1Vzz9n77xlW2wrUXy6APahH+bPJEpPQTsubaT/+y3o:61BzRArUXSA+bPGeTsCaT20o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01638_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 10.53 KB MD5: 9d346c49f4775f1447222216dd34e0d3
SHA1: 790b7e5b532c8b632e625cba8c0bd7a3e38747d5
SHA256: 34b4e167a4186a24448940ab37af2d3a33e42c0151d8329b2a858a1d458164b8
SSDeep: 192:nEjpqakKK5pW49vrddVQafW6q5g+RHPLODqQXrtLicyjY+zRzA0o:Ejpqh5pW49v5dyYWNNRqDqQXpM8+RHo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.09 KB MD5: 03d465a9aa75c16180cf423d5059f866
SHA1: 554c3e88fcd8260efb55015a367def1194a8487e
SHA256: cc409d8689f45322fd852262fc17aaae7791bf76088032129a46d473440f4c7b
SSDeep: 96:89fely9EcRqVqRjQcUvgDhDtXzk1Rny5uG2tcUFT0o:K9xqVYU4Ka250o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CG1606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.71 KB MD5: 9669892146782d0eebc63c0a9d998246
SHA1: d262984e6a58c94bfa54a57da44378a143c3d96a
SHA256: 6ba318030644820fe5288874902e9d54027d37a2da29e9c1adb1a796ab20685c
SSDeep: 48:0Xtc9JKVhfpkXNSTvhIKna8fFDOLLmqM/5HZ4RVhqIo6H+mm5c98QSfm6iPwdclF:0XixXNSTv3NKOR5UcIdH+je8QBqd2B08
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.37 KB MD5: eaef9bd76bbc408fa7a364b0fe8b7145
SHA1: b26c6d96774d4d5cbd27e49ae51e541a41b39198
SHA256: acaa2ad8221fa3e1802ae028fbcd1b655a8eb160d43bad4638219045bb4998b4
SSDeep: 96:WeF8PImhcAA/K5DOw3FiLMdSgUT1QB5mwaVUhOsoy4xToU0o:WeIh1AC45wE73VUAFx30o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC1.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.61 KB MD5: 31dc6b5a0152ed8fe2fbc7303579038c
SHA1: f2f03f53b9a09a21c54a20d278feab66d580a796
SHA256: 7d47bbb35be9bbee88440f4af1aafe7c5ea9f1e2f7eb011493c3b6cae36dee49
SSDeep: 48:1FVChAMqm5xp8HYppMZBFQkfNdgo+TffKGcXDGWwmWrjuf3BL4whMy3o:5S757dmRr1dgo+TqRSmLaeM0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANE.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.38 KB MD5: 26e19734540e50ea45ffca081b1a1758
SHA1: 79c6335ea9c44940cf2c135dc28925b83db58afc
SHA256: 69e93bb4b5afa671c93a723a522aa033bb1b809a1dc7e54838c97b7e13dbb5a3
SSDeep: 96:S4ly1Oe9k8ogCqpCyxXxvrI2DkIbYRy+WT73e05nwJwxKF90ml:mHG8NCqpCyVxvrIgkIbY8+Kh5wt0S
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 48.62 KB MD5: 7ad59bb08aca29dc5e239cbf925e8791
SHA1: 3147bb004d386d895bd1851085caa30f1bde7be5
SHA256: 01cb525f3be1421e49af62f9d40561c7a587c2e2b54660fce37ed2ba0d86052f
SSDeep: 768:0cV0nPGHoqnNT8tGZWoJWnYrIPWdkZRQbloUr3YJtDOv+y212qSqeYJ7Kw:f6uIq9+YrIfS5O/8zqeYJ+w
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.13 KB MD5: c1ccd2f08811e1e1af3e096b624a68cc
SHA1: a5b7ba0fa04d93884ca6e1b1696543f238c1f17a
SHA256: 8cee54ca3653e05948260278b6bd6c3426c83421cddb5592a8b12f70f922cd0a
SSDeep: 96:9gw8MGWDjb3Ck4NDXF4IjjA99v5PtBrkMArm0m:WKjP3MJ4UjgjtxkMR0m
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUPINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 10.32 KB MD5: e46921c99c03f6d17255eaeba15756be
SHA1: e729875d8509619414ee7244546b24520d7bd9fe
SHA256: 22d06ddc69c0922ef9c3c9f763f5b87ed5b510e21c2336683a9534ba31105a88
SSDeep: 192:2Fwp6JA4KMbw0D0uKb/2ytWjEqHr8o0bQAgfV7w1/u6ncY7jeAYiD0+:2QDGAuA/2Hjwjgfa1/u61Dg+
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC2.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.45 KB MD5: 3f51f7aecec6595c4bf4f462e88534d9
SHA1: 5414f6af68e3b587222b2db0d5cda0eb3fab713e
SHA256: 5d210dffa6dfb0cc0620e8170f24e48a3e26d3c40b4b44f194cf9e6055be7248
SSDeep: 48:9RyMq37m643houfXh09gqpGBHaFiYn0WpPj3Ayg/s5H4TKzTgXey3o:9J8SF/K9g8GBmf0iPD2DTw4e0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.44 KB MD5: 22fd4697b86b958af5d0030a97e2f4c7
SHA1: 1ed1367c71af813c22287a8932dd7d527f1b7357
SHA256: a61e116d7c4ca2ca8dd80a62fece64705b61a74d544b7495c9bafe7b81b6be62
SSDeep: 48:yGJlGj5MJBEMUaQY/tmAF7PraTqak98RuPtnYb3vBMQqBVaoPO0xaFw7y3Q:yxUfUxYLprqqHr1ncMpTd2MEq0Q
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.31 KB MD5: 0f63e232105c56bee7769e0493257f24
SHA1: 4e83587640aba0e34058a92ea3e48c2c74124fa1
SHA256: 1601953cf065fc3270d0d86847f8baef1f9b7cc47138894323fdbd1f393ca783
SSDeep: 192:iUPBH8m7dIeL95thrjGKJagw+HU/sKUmyEpHjp/VTte0o:tPh8m7dIeLTrjGKYgdc7zxpHjdlo
False
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: 7147d7d0cecc38134f6c43875a116810
SHA1: 87820125ac9814d64e886240c9ffe0fd3b67c5c6
SHA256: af033f6f1887161245e74d9a43282fedb05222e4aa69ca764989f4f553e63618
SSDeep: 1536:1lo9RAUSjmQNM2q5uH5Qj5ULmfZZkG5nSYXeIjTQGXZ9LP:cR1xQNzqaQyLwPkNYuIVXP
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00256_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.01 KB MD5: 0ddcc59e4a03d39639b3c0dba8842744
SHA1: 8a54276886bc565831d81240fd84df790901ac7a
SHA256: cdbc247a7ded12802444b05385ae141ad53fcb4049003ba5ab5a5420d802822d
SSDeep: 96:VSxCPqOib9sk1hsohezRaodnKj7z6NHVTt0o:VSxNs4/hegO1BVJ0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.87 KB MD5: 159ef4e0c4b6db58ff8a5c0fcf2062be
SHA1: 0e55692bfa885ca43a756a5ac3e2df97a85b42e5
SHA256: e92030df909e23db9ef13a8e1c39bc24e30764871933b8560bfc37deb28c5c44
SSDeep: 48:5uNEJmNOC2TpzDTE6O+Fj62bmBOdFvlXA1zW2TCDK3bO/YBhcO9NOAWUZTLmnFZJ:Bmn+Nn1dxiQdj+7TCDKO/ClT5WwLmFRt
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 29.17 KB MD5: 6526110ac4c49d20da4a36a436889805
SHA1: a7233e8a614cb931539265116745e6e5cc881dfd
SHA256: 45a4efa115015c29d873b109bb48a566645694797b827ff5ffdbd6263e2619e1
SSDeep: 384:DVQ1MpdotMgDcJqWdNorJL2AExN1ldAPkVpWpXkay8zUUiVeapzWymQPl0VMG5JT:+1MgMJ0VvqN1ld2Tkjghin9mSo5tYQV
False
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: 44768500fbf2e8aa30c9d80d2e891e97
SHA1: 62a32d57c812a2a891ee5b2da10388275c8bb368
SHA256: 1cdeb16113eda4fc1a72444bd1833ee88d3d2da98e0c5c92e3e434a24ef21a6a
SSDeep: 1536:rMLFDCVAPFwhTG1BUgKMvvV1FQqFq1M2FVkCNM6rRaxASgOk:r8OmFwx8KgKgtFq1NLZM6dkA/Ok
False
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: 224f43ca3fdc4bc5e3265c7ebc1e8698
SHA1: 8516d64b5cf044d0eea2f431f65178863715abb3
SHA256: fef5db19729e1ef1433de559fe9ea27a6d5e9fe77ea058d1ac3d041257de16bb
SSDeep: 1536:aZJRbJFCCCbWV7WoTI5gjOwAZSEbtdXu3PwLxN5FxJFriakTs0rmcP6HHon:4bJFCCuqatbtdXu3oLr5FxLrzk4ymcPP
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 37.32 KB MD5: f708795a4c26b35b4a2f3d838cc2c963
SHA1: e9e4c27662b30ee31f9805d32d98e1fd9f084af4
SHA256: 9eb1098dd80952d4353a09bb8efbc35c2e42a4de7e6ac45d18f4136ce4280082
SSDeep: 768:4/osEjCZv/TG81at0e5kFQQ4URbOza/rg3t9DHfuuAvRylDO58h+rc:4Jv/KRt0gkFQQTga/i3Apok8n
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 39.32 KB MD5: 52e3da590b83ff80143b01dfc34b9cea
SHA1: bb79585c50b35cf74f045ec487313c96f4843ba2
SHA256: 117969adc830d0a61b933e50d7a3082cb6fd29b5f46c6aad91c0a579f06dda98
SSDeep: 768:bc8QqfH/K5xfIwzA3AAET1Kw6Mna8QBGM3Kr429v5:bc9qf/Pw0QAET1Z9bQBVe5
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00405_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 17.42 KB MD5: 34a1c7d49ef7c5bd610a48fe549b89c6
SHA1: a94327133b636a62127249c911eb21364f7c0611
SHA256: ab41f2c8bd2288a50013a977e5eda8ad63253618a98a713dcc03cbf3ff55a359
SSDeep: 384:LK6ckO4IUb1TBCBjPp2d3SF+smzspekXfal315fRAgq19w/KNio:h3O4HhNCxAzsAkyl33fRsmm
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00414_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 42.14 KB MD5: 5c8c545c72d21fb8d5dce01e4d114b8b
SHA1: 28ba2ab6055684c1ea7b95c69a4abeff718b11f1
SHA256: d15d91b79344c980765c76cef23052f2dc17c5ce87535eab2649f6975ccf2cb0
SSDeep: 768:iezlZaJnL1Rs+LiGxKntmRZ38mH6CeJBYD+t9GSzCbKmz/hvCoJE5:FZZqnL1RsCiJnA/iej5bK8/5BJE5
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00419_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 956 bytes MD5: eb17b7e57293cdf7f3dc2bc55e704b9e
SHA1: b296ed5e9ede4ebd1f54ed349420b2fd901262f0
SHA256: 84e691476ab08ba4c6361f083aab56dab84d53f0e64b3e935c80ee204c36b8f9
SSDeep: 24:1CaW5ZeTuaC+98FuMZFbSKJtIIRTfWIKL6y2Y8qfXny3o:1ibeE+KAutX9AgY8Iy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00413_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 42.23 KB MD5: 057c6bd5442738d8d3838c2f6fb4d3e9
SHA1: 460e21ce81ed20787d43ac46c37fab597d3b12d5
SHA256: 33372702786cad113a310dd403bd7d0cfb81e51e8d36af3c879d9dadaaf89e7c
SSDeep: 768:feZj6ERFA4B9HT877KyUM7WF9hy+Vin6TH86ZYPlKrXzCve4tSvLMZJKpjYQWaGU:fsj33A4zHYNUhhpEmH86ZYkrXuve4tSf
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00407_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.89 KB MD5: 19a5011a3ddfb217899d0fc33f68bc96
SHA1: b7dcd0d4c6ae8731d2dd21d6601ba870e46ab08e
SHA256: b225e00054d5a5afd4e210f84d95fd9e601c074255f93f4a9644f5ac681127bc
SSDeep: 192:jvF6aFGBOQPfn/zYuJELoa5AyGGn+3m0en1DtLJxM0o:jN5iX/Euq5Ayx+GnNlJNo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00448_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.12 KB MD5: a35887ca45db3e6022e209b55ce05d14
SHA1: 1ce925ecad3551793314202d9bb1e18d1b4c4001
SHA256: 8dc37503b3759bb0350c17d873b9512ecdf33e81b25c6627e5790690ea1a5d7b
SSDeep: 96:0mdYdpXdYR6aIFQZTc29cln8zEpaiymuh/sjNpH5W0o:0mdYjXuRJD76ln8zEdkh/szE0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00449_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 10.00 KB MD5: 4bf4044afd5e0035e883c9446dab427b
SHA1: 4da5f0778e3d15370b32c9a7ac83fa0afa575a11
SHA256: 620ac3b1267ab5e5fe69708be14f7634f70974cb2eea644e34957408e161567b
SSDeep: 192:8e/nKDPELNLLvqrMgnqlHxqpayj6Y3y3ugMb7tjicoIhiartienbe0o:8ecPEx/vqT7mY3yegMbhjiYigi0Jo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00687_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 20.54 KB MD5: e5366127be286c9007694d75b42e49d3
SHA1: f4a2b419626a6d8fc9fbe4501d4244cba3b44e62
SHA256: d555345265eeffa318c63f193cd5797e736522492ba7686a1d957c70b5ab1ed2
SSDeep: 384:ElyGaQZ6SYj+VFREG3g/OGylB7VjsxYFJH3ZZWtYodOyhcNnOkfO40o:oyGaG6SYj2FRVCOGiB7dUYzjFodpmv
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00705_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 24.25 KB MD5: 93ff78bf5a5050760bb1dd1a04529b36
SHA1: c7bce3ce8da75a4a920d407e89d8b0ec80bef05e
SHA256: cc59291ac8005a1135bc38cdde0141f644936e2afe242935447cc24915abc8fb
SSDeep: 384:AgmISqEbbp0QBA1fFZam8LDFR6RsBdoYS5nRKylpVunWp1lGBGJN9tTCIjxLZpwS:OFvppBAV18lR6eBdoYS5sjIjxdpP
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.42 KB MD5: 248d21c45582c30229c8393e9ac7c258
SHA1: 1610b25ec4625450ed7f7762fe39bc41843a658c
SHA256: 2ef65d267e0ad03c7c1e07ef4142a35527df6b6a6afd5faa34e0118be31beb62
SSDeep: 48:jsIZ4gQk/RASzPmChoYAP7yCMSWkxLo34HZXA7j2VLrh47QEy0dy3o:fZ4gQk/jmCRA7WkxLooHZO17Qz0d0o
False
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.30 KB MD5: e7400931a6ba08c16a877b84c163b381
SHA1: 370d348ac54ee2b79bc3d0fd47cd03d537c24b40
SHA256: 6a1c3a3b9ed792bef45804eb14cdcaa7bd83a64ee37663191e60803e33c9a052
SSDeep: 1536:cD+9lIiVhaDgRWCUoPfUtKVfdn/99Q093F0YnXMi5i2DF6ZCHZ:y+9lV4D+DBnUt8Vx910YXMiQPw5
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01138_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.84 KB MD5: 9f6534854b4b67d12158429d276460a3
SHA1: 7f1f8fccd28b69f6d70ca5818636142050f5bdd5
SHA256: a1988cc3615489244ffc2c686c184b5dd2995a7827c04991b30ef9a226e6c588
SSDeep: 96:HXnWVXuN9c3SzDEQWC9GnwH/jyZ9nHsIsklbmwb0o:3ZN9cQE3C9XqnHtplLb0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.71 KB MD5: 0f005eea01fafbfe899c9751da6d4056
SHA1: a1dafe647dafca111a67cc589751204e5eb36b6a
SHA256: b8cd02b269a2cf78be3eeff66b51e591ce62fcd1f83ce37cbd0d57d168924b0c
SSDeep: 384:HV0cyu4gtkWOREIh8QF5a5iQMu2H6jal/ATXdClo:Ccldz0Exs5qiQJ2H6k/ARX
False
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: b4d76f37f07e03515f767f2e6ff05090
SHA1: cb189d04238de887a822b7e8986719f8dbea95a4
SHA256: 9c970f1ad88be3ed80085cb5bea88628de44144e86ef35848bb683604dd30578
SSDeep: 1536:vbhm2px0NoMW7QmIgnKzFnGr29gCorS0BEvW8z6rBMA45:jbdMW7ognKzNG0gCorS0BEe8zcMA45
False
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: ddb7af877d44228eabf34a52275ffbe0
SHA1: 314e1781fb503088f16477f889331bb36c076915
SHA256: 5c47a77d4ca4ae56f20dd664375bc46269f6551b27e2521fedf112f4f8d8a70a
SSDeep: 1536:lAS39Gsm/cN3IKo0+2dV3D7I4lFWFkX0RLUQTq1Nw/:+S39PYcuh0DT7vPWS051Tqjw/
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01140_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.78 KB MD5: c90ede24cc6423a7f505e1d236669321
SHA1: 7188f57514dbf72c2ad7ec4ca0950ce63bd0c4fe
SHA256: 08d455d609575611861f5c58449b77281336deb1ee4a864dbfebf64431baff76
SSDeep: 48:rWRMK/Or8XtfLh39jtfhwYF1oTZo+pJIXJrBxLhKcfzMiQxZCinrzywkn8H/B/A9:CGKWO9h3lc61opStKsiZCirPq8fJA10o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01143_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.32 KB MD5: 8619538b04b47a5486166ce4693a99f0
SHA1: 036423e21dacc76334410f52d52478f239002233
SHA256: 682fd1adc7b786f5983e24c135e5c693889fb8834729ea6bebe9553ed97d909f
SSDeep: 48:4cYcCC9iZd3Yk0i3uUMDN2Z7VCiYutdtoipLKb8nUi+rh1SqOmy3o:HYcClZxY3i3uUo2x7X2QLLI6qOm0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.95 KB MD5: 4558fb594b8f844af726074c9ab710b4
SHA1: 63ef5cc99f40c72c918e53796e8bb9dd866a4302
SHA256: eb85fb9ef72baedc2b42d7e50e751ec303efab56481e1c6eb7faa6ab97953bf3
SSDeep: 48:/bsbjPbml66tGkQH7WzTZ8i43AK713o6LGG5/3x/Y6GWJ850sJFbOMGgTW2qVkav:8bmI6tGkpBu13oiT5/VY67OJEMG8WBkq
False
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 1.00 MB MD5: cbeab9daa958bfc7847a95a294478a81
SHA1: 7b2aee0653a0518060eaa619867391c6e1b24999
SHA256: 93ad9ece12588585bb54676284d856f86548b042462ca47067bb85b74aa53a49
SSDeep: 24576:y5XnZmGhl9iQIwmagd2iYgrEnT++6Myz9la+7yL8Vps+:y5XEgiQIwmatiY+ST+Rla+OQzs+
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.96 KB MD5: 8eb8dc75b5113562b141bbcba219e5ca
SHA1: f7fbfccf979798cce68260b46bf1bfd02d54f2cb
SHA256: b7366b6954ed1f8ec8e04f64f0387892df620944e56a12418403477d8332af25
SSDeep: 48:rSTLyqqOtTECwvoimLXPF6wla9mrfcix/XJ6vqWlganwLbep/RQDEBc/+W/muQoe:eTLvpTECwAxt6Z9sfcM56qWymp/RNWmt
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 30.64 KB MD5: 142aa757739c886599dff7a6f87ded0f
SHA1: 0849ab923aeb11b76ad202400e8062ca61339fa1
SHA256: 12f2e3506e8d9d1500e621999abc7a5043f4445ef6a8731a16e22c375f143808
SSDeep: 768:9JuPl6KUWrOv1UW4Cxlxd6hsg7au+n/1k0m+Me:X0ZUWrOv8Od6Swd+dkHo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01151_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.14 KB MD5: 359cb8169d70ae0145372dc7528facee
SHA1: a8d425ee5d744e141eae5f3b1c71041020e2d2e2
SHA256: 0de4ac02ddd1ba10abc1ad8af6c8cabc04edce008a9e1fc0ef64d3f8722de321
SSDeep: 48:VU425IWlxqw4vgU400kOLB614WQsR5ex8JAiNL1gggTWw6VpH+Uj0BDYIy3o:VbCPKJZOLB9sR5LmWPTSBZ0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01157_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.75 KB MD5: f5fa5d5de2349b4fe39932bcc39cff0e
SHA1: e3f8d763fff974857e47fe670c98634cb09535f3
SHA256: aada06ee45ea376518e8b37be4af54b2cba27a536822ed2403142133ead1b382
SSDeep: 48:JZICAW8Kvej+jPbGDoPdfrE62SOKm46x0TyEb86Fy6egJy3UICSKi69sIRS69GX8:JZyweCjPy2BEQ6eTxHfNsI0qGOzfX0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.14 KB MD5: c6492ae532535a0283559c30e143f4da
SHA1: d89369bb6a9f5c725fd3fbf7f55d57087e7b2416
SHA256: 5e45958cfe85fec4100b4188baf64f8d670cec754621b199329ac9d09797d13f
SSDeep: 48:i1pGpK5qNLR9S2GXhMe095mgYuDCkfaHy26JG2YVKhUaL/K64t8C1aEDdy3o:4stuPhZcmgmkHMuUaJ4qC1aEx0o
False
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 01fe382ce342626bf617dd0e3966ec05
SHA1: f5178d5dbea12fd3b689ce740fac210957672b22
SHA256: 0697e76fbdb5455563dde67b73d4279e19b5f16b85816d5b10aa3bacb8b171d5
SSDeep: 1536:PgqxIbQl0S++ax3vppusnIKgZpFaiFtYOGO2y44luAVNtj90n:PVeXi7aIv/tb5cAVrj9S
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.42 KB MD5: adaefa4e21e3260fdde01d603f8bbb41
SHA1: 89017253bedf32e3c3109ed2bb1be007cbc403da
SHA256: bc2712a80f779d4f46098b62562f4a813aa26c2f6241fe9a39ad5e40bd24fc0e
SSDeep: 48:lxDly6SMjtqTI7qC7vLCznuXvuQ/pnW8oqPu2ZkXba+B+cmA4htIQhfAly3o:lx46SM3qC7G62evu2ZQG2f74xtAl0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01162_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.48 KB MD5: f3d12a16fe2570c94205738841ee487a
SHA1: cd0cdba4c2b3ce06dcada5962849f447b3c1e957
SHA256: 7fb677680be333ccbb96a734bc5b18ac221a8f756ce2413ff1c6f3c14b8db170
SSDeep: 48:oNhLX63bP6n1NTqSh76ZK/cePcAY8qLGbGBjGpnxt7Mdh7/cCy3o:o+3bP61kE5TP5G0j9oh7/cC0o
False
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: d7762b926022ac7c4953fccc40116de8
SHA1: c70907cbf760f79eb254c6ab815a4e92b9cf2775
SHA256: 7b7e0d946836ff5c87b8060142b3e9dcb0f61c8922af5291a0b13d9b3f1e010b
SSDeep: 1536:g5kzGpLEmIaSIxz3yW+MktSLzrM57sMZULgYfBYmP7VTcdha:Ekzcfxz3yFMour47sMeJZYmVAdg
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.28 KB MD5: cc57e50e90b2b041454b402fc52c5fff
SHA1: 13f9cc16e16d2b69122094192d738f967ab32b71
SHA256: bb3ab1dd948bd9ee52fc42d2085fadac7b3d0a3333b5053a28bd3441f5c53c9f
SSDeep: 48:aQmDiR1nnTieHgbLl5gy2vxamuGILJ4AgyYMhIfb2utMT7QTxy3o:aQmDK1nTiZfIvxamuGgJ4CNob2SJTx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00437_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.12 KB MD5: d53a6a8167c84bd830aeaa8e2f1751ac
SHA1: ab89682e4f2d0a127147b5d80915df857a04651f
SHA256: 2b0f572da63cac0c0303323d2a764d8bd0a737acbbac75943edd0f4028ed9e36
SSDeep: 48:V0u99TQ8RqC187a+Qp1lCKE0LvS8O5my0lYdp1jtknG4tSapy3o:CuvTQJC18+++nbE0PTy4eunG4hp0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01167_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.28 KB MD5: 7e1f1d7569c2337d8c8f405d6d822249
SHA1: 8814799505abb0fcdcc4840f9e2fe0dfced38324
SHA256: 8e1126f109c975b07ce2fe5e47fb407a2c5ce52217561666d7201b02efbc2fc6
SSDeep: 48:HQfgx3kxiWa4Qpt71anpM0n94auSluGDIPz7ynnTFTEeaPmrQX5AQy3o:HQYhkxKD8pM06a7sz+nTEPmo5AQ0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01168_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.20 KB MD5: 4a5ba913a45b20a930402d198cbe3a99
SHA1: 15dd4943504e5ff290112d48e83bb29e102566a3
SHA256: 6f2b84fd2b8ce29c497269070c52553c2df9d1930522ac326a909e59808741b1
SSDeep: 48:3acO9AVBPkcZ81QnfbrUfpL74dAwuZW0k6KbGxPf3A9y3o:3axuZZ8qfbrcL8rWlRKK/A90o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01169_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.21 KB MD5: 256b96ff84a89517d632c7123eb2acef
SHA1: cc934f19147c5b1e746ff898480693f730d4a578
SHA256: 32a097c7e68193863fb1348daad7f0f01ac53c5ad0c1dbbf83e569c6977ee53f
SSDeep: 48:A+UJH4M2eD6OM0jPufxhujJpUy4IyjzkoXI4QZbdnRTfmZKy3o:hUqrejrjPQxhazukoXI4QxdnJmQ0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01170_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.59 KB MD5: 432eaa9b842f2055f9be421ace612e20
SHA1: 6da66797a41f5f515f4767f55559442c6646195b
SHA256: dfcbfda25643ed879d2f186400015442fef0142999ef9a91678050d1186f0d6a
SSDeep: 48:7vbwmpE34s+cIa7SY+tG1uW6ofXdU6UrGsu1fec2BBYTdFEU8LpXJmAqy3o:7TfpE3+XKf+tMua1vU6ncBYTzEU8LZ4R
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01171_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.25 KB MD5: 5fcc67e8066d3619e0760a54cf9db1e1
SHA1: f916702a6c32874cecc2ec6cd327f46d5f04ab9c
SHA256: 0d0a08563c89df4776d9fef5f04188a31ba714f57f3cc13927ad46bb7432ec91
SSDeep: 48:r8iZcunnQkYu7LBVeZ43tgSaG5Jmg07TdEe/nWd0ydVeBBy3o:QiHnnQkl6Z49SGL07BEefWdSBB0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01139_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.79 KB MD5: 1d370c2584d90cc082e5fb9c48bd023b
SHA1: 06819731714c3606d8321977bbf9b7964bf96e55
SHA256: d93a809b95d1055aa7bef580881bdf9fd3d2bf6d47ab5c50184e8128bfe66fd2
SSDeep: 96:4fPzq43q1ratJESxhTtbUNtn99rew9U8wTBKW15ZcM3s0o:wPV61ratJB0nPqew5Zls0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.42 KB MD5: 307e7132bffe94382c953012d3f63b28
SHA1: b97c500406507f6958de96437a23cda4c358aa0f
SHA256: 312861dd7b785382bd9423e6eb9078f3a4c83931160175f2b09c5097d23b70c9
SSDeep: 48:MtY81ods6comZpCFXhFw2zdLoxu4aCytiPBGIb4cG+8vlP83Zxy3o:pGXjp604LlChGIb4fZlk3Zx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.00 KB MD5: 764352caadf8ddf44c1ab2b8ee646753
SHA1: aa72b374fe428ffe5f9b00d2357587aa018f6def
SHA256: 0625e72269b003facfc6206eb4414e1cfcfa6e0db65eb1d00f34e36045ad04c6
SSDeep: 48:sBv4fdAtTBB38V+ANP+Tc6JPijmgVHtHYSj700Nuy3o:cv4l0L4sc6Rfg+0Nu0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01176_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.09 KB MD5: e1a1f9b90fbe1b8c02477d571d251fe9
SHA1: 9705844db844d33aaef25df3efee33da7a5ef32e
SHA256: fa0d263b2fa5f7497baa3b4dc406b372f54390e6077b08176094abcf9027503f
SSDeep: 48:N+QmcmgkfSSpsXu1aq+w04VxrO9j5mKuoSTprfy3o:NbmjL2Xq+IVQEmSTx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01178_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.95 KB MD5: d15dededdcdf92141d118088b0c3d035
SHA1: be52b4c282451417c13975fac756e6f7b3f932a5
SHA256: 04e043c0e2e631aaf9d78670d15c3f88dfcfe4beb610a8bcdaa1a00f38defc0c
SSDeep: 96:pfDCx7usJGqITx85v+vJ/b2SbUXS2eV5HoFmgApd/gc5gJHRCqv4LKX50o:dDCJVGLTx85mL52e/IF2d/gMg2w0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01181_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.65 KB MD5: 0d15b2debdba400fa96ecc978cee9c70
SHA1: ce93c481179fc5abc387d33561c838289f63ee0a
SHA256: 3f9fa72702a579faf69f27f20b0534372e73c5f8a01837408a4ba3d9e8ebb283
SSDeep: 48:yme6dDDJfNWkvnA9rdBxL8QSFRODKDy7k+vty3o:xeSfNWkvnArdBxL89FR3+7k+vt0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01182_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.17 KB MD5: 6f9bcdc869fa9befe01fbc55a97eb126
SHA1: 06fb692f3b9d26e1bce749cce41518de6b26c3a3
SHA256: e4eca2479a9898d9f9160a561852ad7e564bfaa76ac2e375ffca93492755bfa8
SSDeep: 48:00KWpIYkgDtkEmhpzdYR24laBcmNF72YeGG3wr1OoBcr8T6XrK6KhVuOt/PLGxy4:0eIoaEmc24lkrJGAwSSXrgyO9Ts0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01179_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.21 KB MD5: bc48a13ebb7cde8a0d730cb413cd91dc
SHA1: c2e919914ad8cb6d74955d9caf01bfd90c6790c6
SHA256: ffb29e744cde556c494b1e8738dbf0ea74ef0184cb2c465410f3cf1092c4c7a8
SSDeep: 48:8bVJfVjxth94MTkSNXBRwIoVnNLFSL4NRWzk6gec9oriksEy3o:8Jt7tvpdNXoIoVaLAWxgec9o+E0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01183_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.48 KB MD5: 1a0b4b24b259f87995eb9e91efd12c42
SHA1: a25aeaca94da64fb8061b35fd032102b4f9f2348
SHA256: f1c5e3d3855b65082f97f04ee3055182b5a3dec6f6065b5a8ceadf1e91bce83b
SSDeep: 48:thHb+ExNiszwixjGqBhjj5qGUi1/9q9Tt4h7g9IP8kDEszxZQL95fDv4txy3o:7b+ETi6hjG8hjj5qdiyRt4wI0kQLXfDA
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01186_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.61 KB MD5: a7006253c9b4df26a74a06ed1ba1dc21
SHA1: 68c6d1b6dca3cdc5678cd6c9ad066ac4045c49f5
SHA256: 49d30921ebae79778fe1edf80319832b39f2e2af2bc959916762e94b7a925273
SSDeep: 192:dWmrmaOibv8mGx7mYMjc/Hjs868tYYeSrjQb0o:dxCiAmRYMjSO6lpjQoo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01366_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.96 KB MD5: 8d3786903616d259417443e370f27da1
SHA1: 6f3bea4137ab3db510209457c58873368b70e312
SHA256: aa912008664c988005b9f623d307747a127f2192444ce260d416675a43bbb219
SSDeep: 48:2erJ07odkygi5TVL8ovGF7tEXCv5+2EqITIqy3o:3Rdkg5BL8ouEk+2zITIq0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01163_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.48 KB MD5: 104f33bf12235b4ba18aa8a953a89f68
SHA1: 523c233dae94aa5ccb7d1908d6a73d6fd47cbe2f
SHA256: 3534c1579ced180612da3eb2612fc3f888d40d6cb6ba92074fc04f3eef55ba58
SSDeep: 48:s0B3KcKJP735TLEPj4AUk/v8mV6OzDLbGNRTm54Le5R9Wl3pbhuRKitzCxy3o:jMhdO4y/vwiPERTm54V3OXzCx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01585_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.70 KB MD5: 1ddfb85ebb5c6e7204f26dfd62bd0f95
SHA1: e2fac1c328751b278696a7f5e47345c545256b33
SHA256: cdd4542118f830abe702032f9b098c9731106b3021a1ce370e2885659ea2f0da
SSDeep: 48:+eNxeXAiQxhRiGVwFYnraz9DQJuzGRoKLLr2WOP5EJ5HKHWZStgS0F6Vb4wWv0iR:bXnzRi8yFSLLLr2NPW5Hd6v048v0I0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01434_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.12 KB MD5: d32e35d4fb27ab8e0f5133c00a586058
SHA1: 09c90090198876c0746a9fb2f85580ab73f5727c
SHA256: abebd863ca833d2ac6ff8e02e480fbd52ff5259c077bcbf77d5f2e72712f304e
SSDeep: 24:BjVbGMIUCZjkFBqXbNKpiFwg+iPeZio59mzdsA7AqS5FYcpFXny3o:BRIUCK2bNKpn7Kdsdlphy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 828 bytes MD5: 46b6e0163841e43737d8ec4da62478a5
SHA1: 74f20aec7df21743dc2234947e65d01a40b3b58f
SHA256: 168a76e7a50080b8b77f6e4b552b336accdbc4bcd15120cf8a86b5f42dec19cf
SSDeep: 24:v1P951m8Jc3XdcunFdE/hYAmIcGrFXny3o:v1j1mojuFdUPbrhy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01631_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 796 bytes MD5: c70c6d547f290630cbc44bf7b9da3b2b
SHA1: d44292fd10b4c9965e8ef307796baef193fee9bd
SHA256: 7325cbd9f5ab8df9ea385d7c01010dbb9e98c570993ded57a4399f52d1989a31
SSDeep: 12:eORx73eqJFWaH+bunHSZJLm3RhbnBZXPszG2xutFWH1Inbs+1rmUKguXny34l:B3reqJ0ai3Ebn3k/xutgGsu+Xny3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01630_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 540 bytes MD5: 84c41671202be6c4a344c37aca6dcdc5
SHA1: 44ffdd1ab5ba9a80cfd149f7c71e77988cde8b36
SHA256: d5edd7f1b7bb0673ef3c244046d67484d4a7ed203a46c8b2509ab1300d326f70
SSDeep: 12:HH/V+DedgiWWSIW9yyDUouk6+4u+rjnYUKguXny34l:HfVGghJuAEXny3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 18.86 KB MD5: 0bbbd77e4de121b97c9bd2f46bc74458
SHA1: 05c7299662e6d83ab1ca250e09d3b35352cf5fbd
SHA256: a87772654897bfd4a3b34673f4c9b5cb15f4aa0a9afd434648b746de9fecc13b
SSDeep: 384:WI89REoCU7gAhJvADntDGKU9W5ILUxTaO0gYmhrscLerW5io:N89RENSvcHU45XcmPBscLUW3
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.29 KB MD5: 8e3b98608ee0f126299c90def6a7484e
SHA1: f88aa829b1b2c21a9ed2a6aa0177844b3c6e2412
SHA256: 41c41cffd43c8375cb8df394b25e4644069aa48ddc504a4ca3dc5d854d8c2240
SSDeep: 96:w6p8wRAIv0nJ8eHfITh7Ax5zTcGHGu/pnWIJe953DDCavl5DnV5MSRIT8HW0o:Np8wRJ0iBTGHHGuVzerOavHDnwSRIT8O
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01793_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.42 KB MD5: fde92f16c6a69d0f532ada533b511cf2
SHA1: ef4e00ea453768ee51d82c0d4abb31c89f7f3386
SHA256: a469ff1d863b7d476dcf9a4d6c7fa0ed09d31e2a360191e648412e775481f2d8
SSDeep: 96:JouAB8o3C7wrltmChUHJfPXVPagi0h5kEU9wnT8GW0o:GuAXr3aJfPX5aX0hNbTq0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.59 KB MD5: ae99fce1b27ea04c56d414a07bbe793b
SHA1: 06fc9350c9327312eb7059399b01a56374d94ec5
SHA256: 7cada96f77a37b2f50a5dbebd3aefc5056eb7c69446b1467ac6e194a2f1c1312
SSDeep: 48:4RNsFLFI+3fJEnp66a6iFWpWUd+voScfAohy3o:4RGLFI0fJmp642WsUd+sfAoh0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01772_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.48 KB MD5: f4989ef76f40dfa7e040cfedebf71e97
SHA1: 5b33e739f9729c0a55146b6971beecbec70fb2a0
SHA256: cbecbd627c041c56892804545664560801005ede34a2d2e8ff3d16ac8886c0e1
SSDeep: 48:vQvgKXjZ+s/wjCLk3YshdOFIQPs7kN+gjenqgoD46QD/Cy3o:MzTVoj9IshEOQ07kN+goqvCD/C0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00019_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.98 KB MD5: 541b6ded8fb91adc012af967909aeb60
SHA1: 15cc10ae5663b1d62e8c17868f8c66263048e156
SHA256: 06092cbb250c98ad1ccd6145d20d1fc45a2eba2982133a751aa3313ead6f2e2e
SSDeep: 384:SOS+v+Ygqca8pcLvByDE5XKRvlZK7TKvjo:IuEtaC6ByP5I
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.87 KB MD5: a8bf1f4ae5b70a8c44bbf15728860c88
SHA1: da89067783e69bacfec75f3c12fd8859e9643498
SHA256: 1f913391272149719a8c441963cbc2335204320acf64ecf700270888aa812189
SSDeep: 48:lCkSwIbV9787jEz8jkexRlqvq92RBF/bXRsON7CTh3VvJt1DBgAbEFQAPcqQYUxv:lCkSw8a7jU84eobFTXRsON7qhVJtkAcU
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.03 KB MD5: c07c54ab3ce0cd255fe37d51b6935efd
SHA1: ba5f56fc5790d652c6081220e28b36245d202ca0
SHA256: 57c3a27a10cb4662e9916ad228e442a5a50ea2a4c952f0addea04f6799615463
SSDeep: 192:ehTSmSBAjiVwrx+T+E01BQGDwBmjIzM6gvq40o:aiVwrYT+E012c0Y6giPo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00006_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 13.86 KB MD5: 5f782f907703c5566c178f34293b06f4
SHA1: 321a6b545d9d5a9c3abea55dca01b315c4bb5c04
SHA256: e858e9dfc9b3857fe82a9810ae7cba55ae7376b2f2cc3c061a01757cda60f4ec
SSDeep: 384:Du78TipzosalC6tvUZJ2naeqwl7lGwxTQBq4xZWo:i78TipkblCSvVaeqwVNxckMn
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.86 KB MD5: 117a4d9567913ae031f1cb3193139e99
SHA1: 0074cb898141e04a091a15107dad1ab017bd0063
SHA256: 4d7e4ddb61ba5c05118941e4a07ffb87dc1e5eb14a4f922efab196e3a988c5ae
SSDeep: 192:T178M4njG+wLMyQFtZyX5LetTp+de6jo4cXwzhyOW1Me0o:Tt4njG+wLMjFtZmqtCe6AXktW1Mlo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00319_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.46 KB MD5: a562175da00853ae481a66d63065557c
SHA1: b33c0ea28162802723f6114a1ba24c8ec951165d
SHA256: c32fe7314365c2252f5c1ef388102fa3f0a9e3f3eebd8fbbbf8394c4c2ca7979
SSDeep: 48:E8DfrmaHSrOuAaql/CvqwXcZCs+Dx0QF/wYYjXmPgXMOy3o:EY6ViuAaAURMsJCe47jX+O0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00320_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 988 bytes MD5: a257a72175304b6d264e7db860a12a17
SHA1: 0f9e388197ce244732d0826b987004f44d1d76e5
SHA256: db61ef275acadabd7b2cdf9ef0bebcaeefff6c6c925379c9404b96b364a888b8
SSDeep: 24:xwBGkdotslxo75irFi9YdffDO9hYIpF6eOiabAwXny3o:xwBGkdotjVir/1DOU0UbAay3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00397_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 17.14 KB MD5: 139bb2edcca5cce66f0b8cc2de7b4beb
SHA1: c9452f4dfb31dfabc46edbee64516923c8cbd15f
SHA256: d8cdc82f203a92bd0fb05d72360ad0903fb3462f62d6a03c495e1d762fd0e824
SSDeep: 384:E7Izl+UqKjzyvcjHx5wUgmxlyDq9wxKb6cgfl90gxTyKo:EAQzI5wmyO9wxKex992
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01180_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.28 KB MD5: c1e0745ff099403d28946f4f6a47a926
SHA1: b2a81ee5e5eed2791bb645a1703ae02f3b7cb722
SHA256: 9abef66300f2e3a69bacb40b76c465d713e5718596b789d5665f3f56b7c05818
SSDeep: 48:dgGXhGDoETUjvkMBXqE1V+ptQsnhDk64c/aRltwZoXnlTjXS06Aky3o:OGXhGsEYjsMvA0Uk4iRXMOnJSJAk0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00902_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.00 KB MD5: 71429652f9a5e24991a4c0f7dfea7a8c
SHA1: ded80be899fa419a08fbc1bcb75a98aac992c270
SHA256: a44fe3294cb8a451ec98b6e078b062e2c523b709370fb60eef49fd9f0ce849b3
SSDeep: 192:otsDCX+SWO4naNnF6iWcGLYGwArrzH+R7w2FdzVwLZ0o:qht4naNnFTWcGsGwAr3H+R7vFdgWo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00074_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 17.67 KB MD5: 2b133f4499815a1703cc07a3ee26e4f6
SHA1: dd273ab1a0c61be17c713954e454a580dce9877d
SHA256: 1c4609e8d1fc2932f7c74b240f3fa4e4bebaee8cd1e4801b78b12fe8f841f40d
SSDeep: 384:SCDA3nKqF6IEvlQmcp2Iy5eufEhBDcKlQ1AI3eeEYHKS/PXkNm3gM2OwUMo:SBnXtEU0p+ccAALeEm/MNLMhw2
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00077_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 29.78 KB MD5: 6ff68ecde7637c362013bf4314a75a37
SHA1: 4342f8f27d8ed6a1e767330599ccfa2aba846079
SHA256: bd8039d0a5b2986a77b6b2b4b072948866ce05357314d5d2de515551967038c5
SSDeep: 768:49KYKDmpONj/zGVyWwpRn2PVyXwBbVupDYzHc99lNp5bhAnFjN7:4YiqkpPVySV+DWcbR51aFj9
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00086_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 28.76 KB MD5: 59859b90e83e9011b046d878a98dc91a
SHA1: 2ea0a437a7c7bb7b380d4bfa2215d3621abb671c
SHA256: 0aeace9789c74bc99444e84315d1ab856ae2f712afef9825693648135038a642
SSDeep: 768:ATPjVHt037fZBTPD2/J7NXQ2J07RYEl8onL:+Sr+XQ2X08+
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 11.95 KB MD5: 403691ddd8a7f01949e5d71a04561b01
SHA1: bb05c3ff45491acd598a79f1e622fb3a31e09aa3
SHA256: 38bdaad4c3bd113da49113317599f16d764554d5963c0d492621249fd242fc0e
SSDeep: 192:QTHx++yt7RxSM4tCbRdOvjcwKwSDvYhx3m9dICM5yznEWqd7Ph+drbx7sQpPlPav:rHxsCFXvYD3m9dYEEjd7Pybx7rpPlPBo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00096_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 36.75 KB MD5: 73f0bd2e413eccce8b3d63a6acb42cb8
SHA1: 068ef65631753354ccd1a6273cc1b3eb184c3182
SHA256: 9776389a3f26608ce21b410345151afd88707ae879d7a6d602914f5cab5c0c3f
SSDeep: 768:DS6/Ly8++IQ7vM69zykgQBhldIhcM+r2ZDyHC4ax3PqqgYxjs:DS6/Ll7vjNtvbJreD2CVWYNs
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00202_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.01 KB MD5: 3400d661ee7b0554ca8d2736071e15fd
SHA1: 1ca5bee8c5a06c24a10993fa17a979d6dee5ed95
SHA256: 037b09273d28eb00e88d351b9c7859e6bf2e6941c75cc9f1e0229efe447af73e
SSDeep: 192:En/UNIZFDUZqGwBrFFNValUoWMVc5qow30o:En/DbUZqG4d4pUwko
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00222_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.31 KB MD5: a81874b75309b22a6b755639262ee1a5
SHA1: 907bacd255938f833e42751e625ff3ac0825ee25
SHA256: 7d002b6eee15982a7c79d97351ac02cf9567aefaf7b6abf4568e815b6b6ffa2b
SSDeep: 192:iRK3TDobiCYK1NV0+PSBGc1enkzv962Jb7svIFIvdVv2ypTYnN9Q/7ioLEIz7Yt3:iRK3TDoXe+8/e8JMwO52ruGoLHXVo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 15.73 KB MD5: 064cc899079e1a26845dd4a78a2a1bbd
SHA1: 107d208a20a1d1b9ddf0a6189a789b57a081a4b0
SHA256: d9b1214e666f50081aa3e81318ef0966aa44e4c6e8562150d794a6f66a7b4980
SSDeep: 384:oaXtn3emDi7qElt2ocLrC4AptPBDXTym9EkrTZBZ4208m9Tmd5go:oktbm55Oe4KPBD+m9/D+p9qr
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 18.01 KB MD5: 21d970e3875dbdaabe8999c41cad1b0b
SHA1: 8b4d0c1926865ec6c9e3cc632f293713e7ae165e
SHA256: 3109f20207e96092b4e0bfe76b1eb89ac4e30d38371fd960f290e329ee186309
SSDeep: 384:39Gp2niGDPUYb4cj/cKw4p7OePS11/WUPPhNiv3l/9gW57VVo:N25EPb9FzKee/hPhN4hZ70
False
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: c882e6e41122c23dcc820e7170ef0067
SHA1: 30daabd74437482602a78154d47de4446accc1f8
SHA256: ee9f96e3cc8002b2495844e3c5683219d8003aa6ebf54b3137cb37b5abc4a74b
SSDeep: 1536:ElVGVmxuzMJ0ApW+mkGBzB+tGaO/b4vXjWhgAOmLYgfg1sFM:UG5zMCAYkGn8zgsYCAze
False
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.34 KB MD5: 634aaa83dcea85cd4f57eeaa9efe87f4
SHA1: e3ee7fe95cfdb6d092ddbb66e5f7a3f4871dfa1a
SHA256: 80a76f8a0bdd7629146bd218bc8ab471b26472c475086380d386e1d981e6c132
SSDeep: 1536:25nbYOb5Hw5s5itDTmpoMDYCzi+wJI8NjSiI770eT/YKwA/Xrhdk:4bYgyK5AqoMDYCWVSD6K7k
False
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 11bf722770f6a560c4bd91046508bfab
SHA1: 1b2bf2ee570d55b9a8f4ddd5bc4c00b09fe2e406
SHA256: 560eacc674e8665bc3ac13afeb3bc21acbbcdfb0bd19deecb5cf637f4a380cef
SSDeep: 1536:VSy7EyqQTkg+7SLDUQeDdLTY0SQZqC2WJHoGmJ:8yEyVs7SvU15LTYMICLHoGmJ
False
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: d29c7111cc035b7fdc7a77f30d0ca3c5
SHA1: 2abd2b01110fdcb3c4243dd34bc75cc10a54aa44
SHA256: d706d012389c909c7059ceafc3953bc9ec724ed2a72fbc11ed59fe30e37b2e3a
SSDeep: 1536:2DyfzhWi74Miy7JECu0Cl1aLMz5n6MRI8Bpd:2Dy7h/TJUlgG5PIApd
False
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: 7ab23323549ec7cd986e31f619a1f4ae
SHA1: ea143c876fbde0c2c00fad5ff83080182ccf02c3
SHA256: ec3360f2f9178604972b89fceba05515c0e7358cbea9c12e410facf6d5714b2d
SSDeep: 1536:Iz55nTUU9cjCoFTL5xf+xkPe1bAtHt2MoCIyN7Zco:Sf59cGoFjf+xkPe1it2MOdo
False
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: ab44c7521b82aceaf4c225965d88ee25
SHA1: edd71c326db8849e478cf6d4592d6e377d1b8774
SHA256: e81db3cfcfd0284a446e8d50681683fab9dd9a96435f3f90323dba69c45acd83
SSDeep: 1536:9wHmwdT4owJvBYKbn0lUP3OUulJscg2I5QUY7StpvE:9whT1+baUP3sRg2o87GdE
False
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: bee9641b620652f3186cb2621e0ac3c9
SHA1: 60cd43d6fd7111f6accc88350642f705dbda65bb
SHA256: 522cd737362be6510a438f4eba2e3cf10d3128991b43753f53bfee5b65409060
SSDeep: 1536:MLywo3qN12Upf2WDek5WNanjuyA6dlVzExHHKiAg:Mw6N12UpuAJ5/nOfnAg
False
C:\Logs\Microsoft-Windows-International%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: d83db986c2ffeae9f9a72e67173c74b9
SHA1: 0e28e545d2b4e5610b6fe2eed80c42926adfcb0c
SHA256: 29aae65f832ca0c0a680db0ffa1794522da7b72897f0ff0444418c2832d5e8af
SSDeep: 1536:ExhhN+dVI/CaTyQDLSJ36BOZ2lMpGlMEKxpMMXCKag6bk:+YdVIKa2kE3e+UlQPHXn/
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00361_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.21 KB MD5: 3119b57b6f4d6aafea1b2c424eea05cc
SHA1: 058d48d0a4b71bed0115f9b760214b1df50872d1
SHA256: e5b625a2fe5165d59a0b35676f9a8d928279d0c7cf913ba9b09ff427ea821512
SSDeep: 96:B1x9GNTknUCn3pKzRThYbBpFZC1nCxXb9N/IFVsmM+7abZmC1rxdJ0o:Tx9uTLCn5KzY1wnCxJoV3abZmmJ0o
False
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.30 KB MD5: fa3c0dfaaaa177fb07341513485b74ec
SHA1: e33b647a179b66c64468709520ea718df02056ab
SHA256: d6152ef807bdb0765a70ed04a184fe8eb7c0d5f1536c84944988b3544cf89520
SSDeep: 1536:tRwt2RzKTsENyS+j7A+8AptTRWIC1MF0bsgKD266PSo:tRwcRzG6jp/Ri1MFysgKD2TSo
False
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: e34bb8630b3538440252d1bacc331e16
SHA1: 68dec7bcb2123c38620359ebc63a3efb4c62b5f1
SHA256: 0a88f37986afc5d14a61aebbf4482df95e14e71c92f0678a9a25d6815890d887
SSDeep: 1536:51GMb5D5N95taeexkp/XEtokKkVIe8p2bFrxJL+NdPnz:3GMbx5jaeexkVUykKnENXML
False
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: 3e131a00c5483c4cc5320961c24c1ecb
SHA1: d1a31986493130ebd023c3d63d90820e0cfe77f9
SHA256: f1198b23ea9f977bf60555f7066d84a5805b87b3885bdf944eba6fd17605442f
SSDeep: 1536:SEPJrHits817AYLXzfT+OTzD4WkuMP/ZNSt7qAtqLiuODS:HPJ7itiRxvPPSZqXL5ODS
False
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.29 KB MD5: 7099fa271a697de7c93b173cf408adaa
SHA1: e6dd9325faf070a45d25aa394318d3e42d578e88
SHA256: 0b794100ebbe59f3461feb14e0ac15b43dbe4c25411ed24e875474482c8d566c
SSDeep: 1536:pEy9mLeLpBKiRlF2pKxR3Id0e5ZPhfWJ1xMJCRjN+:iLKpBVRWKH4d0e5ZRoxXRc
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.59 KB MD5: c20c43fd2021cf7550d084c7810e31f3
SHA1: 890f65528f22a8a95ff347a53db02629b441fea8
SHA256: 344bfd598b3b17a7a85f26f32c9815a8e38834620f3e43b7e5b37e6a31776794
SSDeep: 192:m6U4rL++YrVqoDhSKuGILJdSgzy6P0sMCewOOCkWD54j2iWTl0o:7L+rVTpurL3FVcsDOOCkoOj2iUio
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00336_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.17 KB MD5: 4dab8ec9c7a00f046ce9bedf3b15860e
SHA1: 7605f3213495b5314d2f3efb85e0ea3e6ca864c7
SHA256: a606cd509874f0352dac389cadee66a53ae5ae63227e9ff156ba2ecc2662f19d
SSDeep: 192:QqK9bx9uYcxebz/ys+lRCHeJHNOBbBlmUHGH0o:Zod9u/xQzKs+njOVHm3Uo
False
Host Behavior
File (5114)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Users\FD1HVy\Desktop\hgaibc.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\WINDOWS\System32\hgaibc.exe desired_access = GENERIC_WRITE True 1
Fn
Create C:\Users\FD1HVy\Desktop\hgaibc.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 2
Fn
Create C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe desired_access = GENERIC_WRITE True 1
Fn
Create C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe desired_access = GENERIC_WRITE True 1
Fn
Create C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\GetCurrentRollback.ini desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\preoobe.cmd desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\SetupComplete.cmd desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\SetupComplete.cmd desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\$WINRE_BACKUP_PARTITION.MARKER desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1025\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1028\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\GetCurrentRollback.ini desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1025\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\$Recycle.Bin\S-1-5-18\desktop.ini desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1028\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1028\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\$Recycle.Bin\S-1-5-18\desktop.ini desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1025\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1025\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1029\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1029\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1030\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1030\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\preoobe.cmd desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1031\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1031\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1032\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1032\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1033\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1033\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1035\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1035\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1025\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1025\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1028\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1028\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1028\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1028\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1029\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1029\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1029\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1030\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1030\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1030\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1030\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1031\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1031\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1029\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1031\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1031\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1032\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1032\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1032\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1032\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1036\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1036\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1037\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1037\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1038\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1038\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1040\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1041\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1041\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1042\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1042\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1033\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1043\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1033\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1033\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1033\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1035\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1035\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1035\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1035\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1036\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1036\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1044\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1044\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1045\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1045\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1046\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1046\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1046\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1036\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1036\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1037\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1037\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1037\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1038\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1038\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1037\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1049\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1049\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1053\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1053\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1055\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1055\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1038\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1038\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1040\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1040\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1040\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1040\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1041\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1041\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1040\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2052\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2052\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2070\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2070\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3076\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3076\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1041\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1041\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1042\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1042\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1042\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1042\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1043\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1043\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1043\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1043\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1043\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3082\SetupResources.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3082\SetupResources.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1044\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1044\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\DisplayIcon.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\DisplayIcon.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Print.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1044\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1044\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1045\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1045\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1045\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1045\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1046\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1046\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1049\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1046\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1049\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate1.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate1.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate2.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate2.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate3.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate3.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Print.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate4.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1049\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1049\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1053\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1053\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate4.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate5.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate5.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate6.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate6.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1053\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1053\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1055\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1055\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1055\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1055\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1046\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2052\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2052\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate7.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate7.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate8.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2052\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2052\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate8.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Rotate8.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2070\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2070\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Save.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Save.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Setup.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Setup.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2070\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2070\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3076\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3076\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3076\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3076\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3082\eula.rtf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3082\eula.rtf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3082\LocalizedData.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3082\LocalizedData.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\stop.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Client\Parameterinfo.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Client\Parameterinfo.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\SysReqMet.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Client\UiInfo.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\DHtmlHeader.html desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Client\UiInfo.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\DHtmlHeader.html desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Extended\Parameterinfo.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Extended\Parameterinfo.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Extended\UiInfo.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Extended\UiInfo.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\stop.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\header.bmp desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\ParameterInfo.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupUi.xsd desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SplashScreen.bmp desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SplashScreen.bmp desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\ParameterInfo.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\header.bmp desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\header.bmp.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupUi.xsd desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\warn.ico desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\warn.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Core.mzz desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\588bce7c90097ed212\Graphics\SysReqMet.ico desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Core_x64.msi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\588bce7c90097ed212\Strings.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Strings.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Strings.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Core_x86.msi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Core_x86.msi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\UiInfo.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\UiInfo.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\watermark.bmp desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\watermark.bmp desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Extended.mzz desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\Boot\BCD.LOG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\BOOTSTAT.DAT desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\updaterevokesipolicy.p7b desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\BOOTSECT.BAK desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\BOOTSECT.BAK desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\BOOTSECT.BAK.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Extended_x64.msi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\updaterevokesipolicy.p7b desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Boot\BOOTSTAT.DAT desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\BOOTSTAT.DAT.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Content.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Content.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\delete.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\delete.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\join.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\split.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\join.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\FlickAnimation.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad\auxbase.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Extended_x64.msi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Extended_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad\auxbase.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert\insertbase.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert\insertbase.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\split.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Extended_x86.msi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Extended_x86.msi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\netfx_Extended_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\588bce7c90097ed212\RGB9RAST_x64.msi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\RGB9RAST_x64.msi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\RGB9Rast_x86.msi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\RGB9Rast_x86.msi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsdeu.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Setup.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Setup.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Setup.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupEngine.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupEngine.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsdeu.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsfin.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsfin.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipssrl.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupUi.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupUi.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipssrl.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Garden.htm desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupUtility.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupUtility.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\SetupUtility.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Garden.htm desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\GreenBubbles.jpg desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\GreenBubbles.jpg desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\HandPrints.jpg desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\HandPrints.jpg desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Peacock.htm desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Peacock.htm desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Roses.htm desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Roses.htm desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Roses.jpg desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Roses.jpg desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\ShadesOfBlue.jpg desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\ShadesOfBlue.jpg desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\README.txt desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\README.txt desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\Welcome.html desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\Welcome.html desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\AppXManifest.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\588bce7c90097ed212\sqmapi.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\sqmapi.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\Program Files\Microsoft Office\FileSystemMetadata.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\FileSystemMetadata.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\Office16\OSPP.HTM desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\Office16\OSPP.HTM desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\Program Files\Microsoft Office\Office16\OSPP.VBS desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\Office16\SLERROR.XML desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\Office16\SLERROR.XML desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\Office16\OSPP.VBS desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Boot\BCD desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\BCD.LOG1 desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\BCD.LOG2 desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bg-BG\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bg-BG\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\bootspaces.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bootspaces.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\bootvhd.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bootvhd.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\bootmgr desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\BOOTNXT.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\hiberfil.sys desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Logs\Application.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Application.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Application.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\HardwareEvents.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Internet Explorer.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Internet Explorer.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Internet Explorer.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Key Management Service.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Key Management Service.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Key Management Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\HardwareEvents.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\HardwareEvents.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD05119_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07831_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08773_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00248_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00252_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00254_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Read C:\$Recycle.Bin\S-1-5-18\desktop.ini size = 1048560, size_out = 129 True 1
Fn
Data
Read C:\$Recycle.Bin\S-1-5-18\desktop.ini size = 1048560, size_out = 0 True 1
Fn
Read C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini size = 1048560, size_out = 129 True 1
Fn
Data
Read C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini size = 1048560, size_out = 0 True 1
Fn
Write C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat size = 144 True 1
Fn
Data
Write C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat size = 144 True 1
Fn
Data
Write C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini size = 14176 True 1
Fn
Data
Write C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini size = 248 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 4144 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 256 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 4784 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 260 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 8208 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi size = 4464 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi size = 264 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat size = 656 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat size = 176 True 1
Fn
Data
Write C:\Program Files\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[idecryptyourdata@cock.li].bat size = 1424 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 15280 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 8592 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 160 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 244 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 176 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 258 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 160 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 262 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.id-B4197730.[idecryptyourdata@cock.li].bat size = 14160 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 160 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 262 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 7808 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 246 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 12256 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 252 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 160 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 262 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 160 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 258 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[idecryptyourdata@cock.li].bat size = 48 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[idecryptyourdata@cock.li].bat size = 105504 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[idecryptyourdata@cock.li].bat size = 63936 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[idecryptyourdata@cock.li].bat size = 280 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[idecryptyourdata@cock.li].bat size = 4240 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[idecryptyourdata@cock.li].bat size = 960 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 786700 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 176 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat size = 258 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 288 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 256 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 262144 True 3
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[idecryptyourdata@cock.li].bat size = 145184 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[idecryptyourdata@cock.li].bat size = 266 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[idecryptyourdata@cock.li].bat size = 36352 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[idecryptyourdata@cock.li].bat size = 94480 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1536 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[idecryptyourdata@cock.li].bat size = 174544 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 387360 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml size = 800880 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 496528 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 253728 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1048560 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 19456 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 763376 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 2160 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 76384 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 215888 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 343344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 14928 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 2160 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 357360 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 65008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 9232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1456 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 3760 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 399536 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 527968 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 3376 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 1264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 318 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 384 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 256 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 9840 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 262 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9040 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14880 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 786714 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat size = 262144 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6688 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7696 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8112 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 528 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 512 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12704 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11904 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12496 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3152 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3488 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2608 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15312 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10608 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5328 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1152 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5040 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4960 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7584 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8592 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6992 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4896 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5376 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4400 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3968 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3136 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3040 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3392 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4736 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5696 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20592 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14432 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10848 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7088 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3360 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7984 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1840 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1600 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3760 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 27872 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 26336 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5840 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2768 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7376 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7552 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6640 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9248 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2112 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2352 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6064 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6640 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4624 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2640 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3424 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8496 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7680 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3152 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7808 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7808 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2032 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2496 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3360 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4304 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4816 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 26896 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 28960 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11648 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4880 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 22528 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD05119_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17248 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD05119_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16688 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16128 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 26752 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4928 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07831_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4080 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07831_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08773_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 24784 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08773_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 24336 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 48000 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 40208 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 47792 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14544 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20560 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7968 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13520 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16192 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20464 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15744 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12992 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9712 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8784 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14496 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20192 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12528 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9824 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 18320 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11072 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7872 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 896 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10160 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1472 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1520 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4000 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1712 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9312 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8080 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4032 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00252_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4720 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00252_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00248_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1552 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00248_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12496 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00254_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1744 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00254_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2560 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5280 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00265_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5760 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00265_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3792 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2656 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4176 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 816 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00524_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00524_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00392_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 27056 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00392_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13104 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00648_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11504 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00648_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00921_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4416 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00921_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00247_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14448 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00247_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00525_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9600 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00525_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00923_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6272 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00923_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 19488 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00985_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3776 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00985_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00526_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 27568 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00526_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOATINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 29008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOATINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOAT.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3360 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOAT.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00092_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7984 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00092_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00100_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2384 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00100_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00078_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1456 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00136_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2176 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00136_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00078_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00135_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1056 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00135_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1728 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8368 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4992 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00224_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1600 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00224_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3120 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12800 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1216 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 2
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2064 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5584 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00441_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3536 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00441_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00443_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1680 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00443_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2496 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00444_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3904 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00444_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00445_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3808 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00445_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00453_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2448 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00453_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01080_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2736 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01080_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01634_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3504 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01634_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01603_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7184 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01603_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01635_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01635_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1888 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01638_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10544 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01638_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3952 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CG1606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3568 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CG1606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC1.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2432 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC1.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANE.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5280 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANE.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 230 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 49552 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2976 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUPINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10336 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUPINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC2.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2272 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC2.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2272 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8272 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00256_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2848 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00256_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2704 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 29632 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 37984 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00372_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 800 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00372_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 40032 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00405_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17600 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00405_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00414_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 42912 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00414_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00419_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 720 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00419_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00413_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 43008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00413_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00407_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7840 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00407_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00448_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2960 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00448_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00449_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10000 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00449_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00687_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20800 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00687_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00705_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 24592 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00705_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01138_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3696 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01138_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14832 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01140_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3632 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01140_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01143_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2144 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01143_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2784 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 31136 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2800 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01151_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2976 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01151_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01157_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3600 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01157_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2976 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01162_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2304 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01162_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2096 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00437_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1936 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00437_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01167_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2096 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01167_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01139_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3648 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01139_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01168_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2016 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01168_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01169_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2032 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01169_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01170_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2416 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01170_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01171_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2064 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01171_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1808 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01176_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1904 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01176_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01178_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3808 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01178_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01180_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2096 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01181_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1456 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01181_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01182_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01182_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01179_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2032 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01179_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01183_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2304 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01183_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01186_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8576 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01186_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01366_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1776 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01366_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01163_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2304 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01163_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2336 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01585_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2528 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01585_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01434_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 912 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01434_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 592 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01630_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 304 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01630_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01631_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 560 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01631_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 19072 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4160 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01793_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01793_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1392 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01772_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2304 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01772_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00019_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13056 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00019_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2704 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6960 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00006_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13952 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00006_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6784 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00319_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2288 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00319_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00320_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 752 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00320_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00397_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17312 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00397_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01180_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00902_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7952 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00902_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00074_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17856 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00074_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00077_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 30256 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00077_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00086_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 29216 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00086_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12000 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00096_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 37392 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00096_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00202_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6944 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00202_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00222_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12368 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00222_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15872 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 18208 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Delete C:\588bce7c90097ed212\1049\LocalizedData.xml - True 1
Fn
For performance reasons, the remaining 3796 entries are omitted.
The remaining entries can be found in glog.xml.
Registry (8)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders value_name = Startup, data = 83, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders value_name = Startup, data = %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders value_name = Common Startup, data = %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Write Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run value_name = hgaibc.exe, data = C:\WINDOWS\System32\hgaibc.exe, size = 60, type = REG_SZ True 1
Fn
Process (1650)
»
Operation Process Additional Information Success Count Logfile
Create C:\WINDOWS\system32\cmd.exe os_pid = 0xf8c, startup_flags = STARTF_USESHOWWINDOW, STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
Enumerate Processes - - True 1628
Fn
Enumerate Processes - - False 21
Fn
Module (135)
»
Operation Module Additional Information Success Count Logfile
Load kernel32.dll base_address = 0x75e90000 True 1
Fn
Load advapi32.dll base_address = 0x761b0000 True 1
Fn
Load user32.dll base_address = 0x74b70000 True 1
Fn
Load Shell32.dll base_address = 0x76480000 True 1
Fn
Load ntdll.dll base_address = 0x77bb0000 True 1
Fn
Load mpr.dll base_address = 0x74500000 True 1
Fn
Load ws2_32.dll base_address = 0x746a0000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x75e90000 True 16
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hgaibc.exe, file_name_orig = C:\Users\FD1HVy\Desktop\hgaibc.exe, size = 32767 True 3
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetProcAddress, address_out = 0x75ea51b0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetModuleHandleW, address_out = 0x75ea50d0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindNextFileW, address_out = 0x75efee40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindClose, address_out = 0x75efed70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = MoveFileW, address_out = 0x75ede500 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetFileSizeEx, address_out = 0x75efef40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetModuleFileNameW, address_out = 0x75ea5090 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetFileAttributesW, address_out = 0x75efef10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ExitProcess, address_out = 0x75ea3cb0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCommandLineW, address_out = 0x75ea4cc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetComputerNameW, address_out = 0x75ed32c0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetComputerNameA, address_out = 0x75ed3780 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateMutexW, address_out = 0x75efeb70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrlenW, address_out = 0x75ea6c70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrlenA, address_out = 0x75ea6c50 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCurrentProcess, address_out = 0x75efea10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WaitForSingleObject, address_out = 0x75efeca0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetLogicalDrives, address_out = 0x75ea0d20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetTickCount, address_out = 0x75efdd50 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DeleteFileW, address_out = 0x75efed40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WideCharToMultiByte, address_out = 0x75ea6b10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = InitializeCriticalSectionAndSpinCount, address_out = 0x75efebb0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Sleep, address_out = 0x75ea6760 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = LeaveCriticalSection, address_out = 0x77bfb250 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ReadFile, address_out = 0x75eff090 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateFileW, address_out = 0x75efed10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = OpenMutexW, address_out = 0x75efebf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = EnterCriticalSection, address_out = 0x77bfb2d0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WaitForMultipleObjects, address_out = 0x75efec80 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrcmpiW, address_out = 0x75ea6bf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrcmpiA, address_out = 0x75ea6bd0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DeleteCriticalSection, address_out = 0x77bdfb90 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ReleaseMutex, address_out = 0x75efec20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CloseHandle, address_out = 0x75efeab0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetVersion, address_out = 0x75ea56c0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateThread, address_out = 0x75ea46b0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ExpandEnvironmentStringsW, address_out = 0x75ea4a40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = QueryPerformanceCounter, address_out = 0x75ea5da0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = QueryPerformanceFrequency, address_out = 0x75ea5dc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCurrentProcessId, address_out = 0x75efea20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetFileAttributesW, address_out = 0x75eff100 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetVolumeInformationW, address_out = 0x75eff020 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WriteFile, address_out = 0x75eff180 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetFilePointerEx, address_out = 0x75eff130 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetEndOfFile, address_out = 0x75eff0e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindFirstFileW, address_out = 0x75efedf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetProcessHeap, address_out = 0x75ea51f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapReAlloc, address_out = 0x77bef630 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapAlloc, address_out = 0x77bf2dc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapFree, address_out = 0x75ea57f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreatePipe, address_out = 0x75ea4590 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetHandleInformation, address_out = 0x75efeae0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateProcessW, address_out = 0x75ea4610 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CompareStringW, address_out = 0x75ea4430 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CompareStringA, address_out = 0x75ea4410 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = OpenProcess, address_out = 0x75ea5cc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = TerminateProcess, address_out = 0x75ea67e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetSystemTime, address_out = 0x75ea54e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SystemTimeToFileTime, address_out = 0x75ea67a0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetLastError, address_out = 0x75ea5010 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateToolhelp32Snapshot, address_out = 0x75ededc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Process32NextW, address_out = 0x75edf8f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Process32FirstW, address_out = 0x75edf750 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegOpenKeyExW, address_out = 0x761ce580 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegQueryValueExW, address_out = 0x761ce5a0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegSetValueExW, address_out = 0x761cf530 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegCloseKey, address_out = 0x761ced60 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenProcessToken, address_out = 0x761cefb0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = GetTokenInformation, address_out = 0x761cee90 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenSCManagerW, address_out = 0x761d0540 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenServiceW, address_out = 0x761cfa20 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CloseServiceHandle, address_out = 0x761cfc00 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = ControlService, address_out = 0x761e26d0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = QueryServiceStatus, address_out = 0x761d2380 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = EnumDependentServicesW, address_out = 0x761e2f70 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = EnumServicesStatusExW, address_out = 0x761cfc80 True 1
Fn
Get Address c:\windows\syswow64\user32.dll function = SystemParametersInfoW, address_out = 0x74b9f210 True 1
Fn
Get Address c:\windows\syswow64\shell32.dll function = ShellExecuteExW, address_out = 0x765e4730 True 1
Fn
Get Address c:\windows\syswow64\ntdll.dll function = NtQuerySystemInformation, address_out = 0x77c22070 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetCloseEnum, address_out = 0x74502640 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetOpenEnumW, address_out = 0x74502790 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetEnumResourceW, address_out = 0x74502410 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = WSAStartup, address_out = 0x746a5b40 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = socket, address_out = 0x746b4510 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = send, address_out = 0x746a5030 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = recv, address_out = 0x746b0c50 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = connect, address_out = 0x746a5410 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = closesocket, address_out = 0x746b0910 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = gethostbyname, address_out = 0x746d6cb0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = inet_addr, address_out = 0x746b9160 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = ntohl, address_out = 0x746a49d0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = htonl, address_out = 0x746a49d0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = htons, address_out = 0x746b8ff0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 16
Fn
Service (63)
»
Operation Additional Information Success Count Logfile
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 3
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 3
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 2
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 5
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 5
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 4
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 4
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 2
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 3
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 5
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 4
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
System (243)
»
Operation Additional Information Success Count Logfile
Get Computer Name result_out = NQDPDE True 1
Fn
Sleep duration = -1 (infinite) False 1
Fn
Sleep duration = 500 milliseconds (0.500 seconds) True 20
Fn
Sleep duration = 100 milliseconds (0.100 seconds) True 13
Fn
Get Time type = Performance Ctr, time = 13390446661 True 1
Fn
Get Time type = Ticks, time = 133875 True 3
Fn
Get Time type = Ticks, time = 134781 True 2
Fn
Get Time type = Ticks, time = 135000 True 2
Fn
Get Time type = Ticks, time = 136343 True 4
Fn
Get Time type = Ticks, time = 136546 True 2
Fn
Get Time type = Ticks, time = 136937 True 2
Fn
Get Time type = Ticks, time = 137062 True 2
Fn
Get Time type = Ticks, time = 137937 True 2
Fn
Get Time type = Ticks, time = 137953 True 2
Fn
Get Time type = Ticks, time = 138671 True 2
Fn
Get Time type = Ticks, time = 139218 True 4
Fn
Get Time type = Ticks, time = 139562 True 2
Fn
Get Time type = Ticks, time = 140953 True 4
Fn
Get Time type = Ticks, time = 141234 True 2
Fn
Get Time type = Ticks, time = 142265 True 4
Fn
Get Time type = Ticks, time = 142437 True 2
Fn
Get Time type = Ticks, time = 142546 True 2
Fn
Get Time type = Ticks, time = 142656 True 2
Fn
Get Time type = Ticks, time = 142765 True 2
Fn
Get Time type = Ticks, time = 142875 True 2
Fn
Get Time type = Ticks, time = 143000 True 2
Fn
Get Time type = Ticks, time = 143109 True 2
Fn
Get Time type = Ticks, time = 143218 True 2
Fn
Get Time type = Ticks, time = 143328 True 4
Fn
Get Time type = Ticks, time = 143437 True 2
Fn
Get Time type = Ticks, time = 143546 True 2
Fn
Get Time type = Ticks, time = 143656 True 2
Fn
Get Time type = Ticks, time = 143828 True 2
Fn
Get Time type = Ticks, time = 143937 True 2
Fn
Get Time type = Ticks, time = 144046 True 2
Fn
Get Time type = Ticks, time = 144171 True 2
Fn
Get Time type = Ticks, time = 144281 True 2
Fn
Get Time type = Ticks, time = 144390 True 4
Fn
Get Time type = Ticks, time = 144500 True 2
Fn
Get Time type = Ticks, time = 144609 True 2
Fn
Get Time type = Ticks, time = 144750 True 2
Fn
Get Time type = Ticks, time = 144859 True 2
Fn
Get Time type = Ticks, time = 144968 True 2
Fn
Get Time type = Ticks, time = 145078 True 2
Fn
Get Time type = Ticks, time = 145187 True 2
Fn
Get Time type = Ticks, time = 145328 True 2
Fn
Get Time type = Ticks, time = 145437 True 4
Fn
Get Time type = Ticks, time = 145546 True 2
Fn
Get Time type = Ticks, time = 145671 True 2
Fn
Get Time type = Ticks, time = 145781 True 2
Fn
Get Time type = Ticks, time = 145890 True 2
Fn
Get Time type = Ticks, time = 146000 True 2
Fn
Get Time type = Ticks, time = 146109 True 2
Fn
Get Time type = Ticks, time = 146218 True 2
Fn
Get Time type = Ticks, time = 146328 True 2
Fn
Get Time type = Ticks, time = 147015 True 4
Fn
Get Time type = Ticks, time = 147468 True 2
Fn
Get Time type = Ticks, time = 147796 True 1
Fn
Get Time type = Ticks, time = 147843 True 1
Fn
Get Time type = Ticks, time = 148546 True 4
Fn
Get Time type = Ticks, time = 149328 True 2
Fn
Get Time type = Ticks, time = 149921 True 4
Fn
Get Time type = Ticks, time = 150375 True 2
Fn
Get Time type = Ticks, time = 151343 True 4
Fn
Get Time type = Ticks, time = 152031 True 2
Fn
Get Time type = Ticks, time = 152562 True 4
Fn
Get Time type = Ticks, time = 153421 True 2
Fn
Get Time type = Ticks, time = 154203 True 4
Fn
Get Time type = Ticks, time = 154765 True 2
Fn
Get Time type = Ticks, time = 155234 True 4
Fn
Get Time type = Ticks, time = 156093 True 2
Fn
Get Time type = Ticks, time = 156703 True 4
Fn
Get Time type = Ticks, time = 157109 True 2
Fn
Get Time type = Ticks, time = 157562 True 2
Fn
Get Time type = Ticks, time = 158609 True 4
Fn
Get Time type = Ticks, time = 159328 True 2
Fn
Get Time type = Ticks, time = 160390 True 4
Fn
Get Time type = Ticks, time = 161046 True 2
Fn
Get Time type = Ticks, time = 161703 True 4
Fn
Get Time type = Ticks, time = 162171 True 2
Fn
Get Time type = Ticks, time = 162312 True 2
Fn
Get Time type = Ticks, time = 162703 True 2
Fn
Get Time type = Ticks, time = 162890 True 4
Fn
Get Time type = Ticks, time = 163031 True 2
Fn
Get Time type = Ticks, time = 163281 True 2
Fn
Get Time type = Ticks, time = 163390 True 2
Fn
Get Time type = Ticks, time = 163515 True 2
Fn
Get Time type = Ticks, time = 163640 True 2
Fn
Get Time type = Ticks, time = 163750 True 2
Fn
Get Info type = Operating System True 2
Fn
Mutex (4)
»
Operation Additional Information Success Count Logfile
Create mutex_name = Global\syncronize_1TPBM0A True 1
Fn
Create mutex_name = Global\syncronize_1TPBM0U True 1
Fn
Open mutex_name = Global\syncronize_1TPBM0A, desired_access = SYNCHRONIZE False 1
Fn
Open mutex_name = Global\syncronize_1TPBM0U, desired_access = SYNCHRONIZE False 1
Fn
Process #2: cmd.exe
143 0
»
Information Value
ID #2
File Name c:\windows\system32\cmd.exe
Command Line "C:\WINDOWS\system32\cmd.exe"
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:42, Reason: Child Process
Unmonitor End Time: 00:01:14, Reason: Self Terminated
Monitor Duration 00:00:31
OS Process Information
»
Information Value
PID 0xf8c
Parent PID 0xe0c (c:\users\fd1hvy\desktop\hgaibc.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x F64
0x 4D0
0x 2AC
Host Behavior
File (94)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Users\FD1HVy\Desktop type = file_attributes True 2
Fn
Get Info STD_OUTPUT_HANDLE type = file_type True 8
Fn
Get Info STD_INPUT_HANDLE type = file_type True 3
Fn
Open STD_OUTPUT_HANDLE - True 19
Fn
Open STD_INPUT_HANDLE - True 31
Fn
Read STD_INPUT_HANDLE size = 1, size_out = 1 True 24
Fn
Data
Write STD_OUTPUT_HANDLE size = 38 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 2 True 3
Fn
Data
Write STD_OUTPUT_HANDLE size = 52 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 24 True 2
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 4, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (2)
»
Operation Process Additional Information Success Count Logfile
Create C:\WINDOWS\system32\mode.com os_pid = 0x83c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Get Info C:\WINDOWS\system32\mode.com type = PROCESS_BASIC_INFORMATION True 1
Fn
Memory (1)
»
Operation Process Additional Information Success Count Logfile
Read C:\WINDOWS\system32\mode.com address = 947687292928, size = 1952 True 1
Fn
Data
Module (10)
»
Operation Module Additional Information Success Count Logfile
Load NTDLL.DLL base_address = 0x7ff931f40000 True 1
Fn
Get Handle c:\windows\system32\cmd.exe base_address = 0x7ff6b42a0000 True 1
Fn
Get Handle c:\windows\system32\kernel32.dll base_address = 0x7ff92fdd0000 True 2
Fn
Get Filename - process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\WINDOWS\system32\cmd.exe, size = 32743 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetThreadUILanguage, address_out = 0x7ff92fdea990 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = CopyFileExW, address_out = 0x7ff92fdee830 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = IsDebuggerPresent, address_out = 0x7ff92fdee300 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x7ff92f1b0a40 True 1
Fn
Get Address c:\windows\system32\ntdll.dll function = NtQueryInformationProcess, address_out = 0x7ff931fe56b0 True 1
Fn
System (1)
»
Operation Additional Information Success Count Logfile
Get Info type = Operating System True 1
Fn
Environment (16)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 5
Fn
Data
Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 2
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 2
Fn
Get Environment String name = PROMPT False 1
Fn
Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Set Environment String name = PROMPT, value = $P$G True 1
Fn
Set Environment String name = =C:, value = C:\Users\FD1HVy\Desktop True 1
Fn
Set Environment String name = COPYCMD True 1
Fn
Process #4: mode.com
0 0
»
Information Value
ID #4
File Name c:\windows\system32\mode.com
Command Line mode con cp select=1251
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:01:11, Reason: Child Process
Unmonitor End Time: 00:03:22, Reason: Terminated by Timeout
Monitor Duration 00:02:10
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0x83c
Parent PID 0xf8c (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A70
0x A80
0x AEC
Process #5: hgaibc.exe
13731 0
»
Information Value
ID #5
File Name c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe
Command Line "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:29, Reason: Autostart
Unmonitor End Time: 00:03:04, Reason: Self Terminated
Monitor Duration 00:00:34
OS Process Information
»
Information Value
PID 0xe24
Parent PID 0x9d4 (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x E28
0x E2C
0x E48
0x E4C
0x E50
0x E54
0x E58
0x E60
0x E74
0x E78
0x E7C
0x E80
0x E84
0x E88
0x E8C
0x E90
0x E94
0x E98
0x EB4
0x EBC
0x EC4
0x ECC
0x ED0
0x ED4
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points AV YARA Actions
hgaibc.exe 0x00400000 0x00418FFF Relevant Image - 32-bit - False False
hgaibc.exe 0x00400000 0x00418FFF Process Termination - 32-bit - False False
Host Behavior
File (1520)
»
Operation Filename Additional Information Success Count Logfile
Create C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 2
Fn
Create C:\WINDOWS\System32\hgaibc.exe desired_access = GENERIC_WRITE False 1
Fn
Create C:\Users\FD1HVy\AppData\Roaming\hgaibc.exe desired_access = GENERIC_WRITE True 1
Fn
Create C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 2
Fn
Create C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe desired_access = GENERIC_WRITE False 1
Fn
Create C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe desired_access = GENERIC_WRITE False 1
Fn
Create C:\$WINRE_BACKUP_PARTITION.MARKER desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\BCD desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\BCD.LOG1 desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\BCD.LOG2 desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bg-BG\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bootspaces.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bootvhd.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\cs-CZ\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bg-BG\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\cs-CZ\memtest.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\cs-CZ\memtest.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\da-DK\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\da-DK\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\da-DK\memtest.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\da-DK\memtest.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\de-DE\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\de-DE\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\de-DE\memtest.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\de-DE\memtest.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\cs-CZ\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\el-GR\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\el-GR\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\el-GR\memtest.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\el-GR\memtest.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\en-GB\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\en-GB\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\en-US\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\en-US\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\en-US\memtest.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\en-US\memtest.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\es-ES\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\es-ES\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\es-ES\memtest.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\es-ES\memtest.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\es-MX\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\es-MX\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\et-EE\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\et-EE\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\fi-FI\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\fi-FI\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\bootvhd.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\Fonts\jpn_boot.ttf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\Fonts\kor_boot.ttf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\Fonts\malgunn_boot.ttf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\Fonts\malgunn_boot.ttf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\Fonts\malgun_boot.ttf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\Fonts\malgun_boot.ttf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\Fonts\meiryon_boot.ttf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\Fonts\meiryon_boot.ttf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\Fonts\meiryo_boot.ttf desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\Fonts\meiryo_boot.ttf desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\bootmgr desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\bootspaces.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\BCD.LOG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\updaterevokesipolicy.p7b desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\updaterevokesipolicy.p7b desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\tabskb.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\tabskb.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\TipRes.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\TipRes.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\tipresx.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\tipresx.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\es-ES\tipresx.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\es-ES\tipresx.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Content.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Content.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\ado\msader15.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\msader15.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\ado\msado15.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\msado15.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\baseAltGr_rtl.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\baseAltGr_rtl.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_altgr.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_altgr.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_heb.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_heb.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_jpn.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_jpn.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_kor.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_kor.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\glass.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\glass.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\Services\verisign.bmp desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\Services\verisign.bmp desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\ado\adojavas.inc desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\adojavas.inc desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\ado\adovbs.inc desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\adovbs.inc desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\msadc\adcjavas.inc desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\msadc\adcjavas.inc desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\msadc\adcvbs.inc desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\msadc\adcvbs.inc desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\COPYRIGHT.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\classlist.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\currency.data.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_pt_BR.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_sv.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_CN.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_HK.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_TW.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\ext\access-bridge-64.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\ext\dnsns.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\ext\jaccess.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\ext\meta-index.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\ext\sunec.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\ext\sunmscapi.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\ext\sunpkcs11.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\ext\zipfs.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\flavormap.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.bfc.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.properties.src.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiBold.ttf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiItalic.ttf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightItalic.ttf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightRegular.ttf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaSansDemiBold.ttf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaSansRegular.ttf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaTypewriterBold.ttf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaTypewriterRegular.ttf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\hijrah-config-umalqura.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\cursors.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\javafx.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\ext\sunjce_provider.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\jfr\default.jfc.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\jfr\profile.jfc.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\jfr.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\jfxswt.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\jsse.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\logging.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\management\jmxremote.access.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\management\jmxremote.password.template.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\management\management.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\management\snmp.acl.template.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\management-agent.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\meta-index.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\net.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\psfont.properties.ja.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\psfontj2d.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\security\blacklist.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\security\blacklisted.certs.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\security\cacerts.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\javaws.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\security\java.policy.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\security\java.security.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\security\javaws.policy.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\security\local_policy.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\security\US_export_policy.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\sound.properties.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\tzmappings.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\LICENSE.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\release.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105292.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\lib\jce.jar.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105306.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105336.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105298.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105974.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106124.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107132.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107264.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107266.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107280.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107282.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107288.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BABY_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CARBN_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CMNTY_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EAST_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EXPLR_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FALL_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FINCL_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FINCL_02.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\GRDEN_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\GRID_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HTECH_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\INDST_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\JNGLE_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NBOOK_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\OCEAN_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\OUTDR_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PAPER_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_02.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_03.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_04.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_05.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_06.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_07.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_08.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_09.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_10.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ROAD_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SAFRI_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SCHOL_02.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SHOW_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SPACE_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SPRNG_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SUMER_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\MUSIC_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\URBAN_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\VCTRN_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WNTER_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Banded Edge.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Extreme Shadow.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Frosted Glass.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Glossy.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Glow Edge.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Grunge Texture.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Inset.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Milk Glass.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Office 2007 - 2010.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Reflection.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Riblet.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Smokey Glass.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Subtle Solids.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Top Shadow.eftx.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\JAVA_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Flattener\AppVOpcServices.dll.manifest.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107138.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Integration\Windows6.1-KB2999226-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Integration\Windows6.1-KB2999226-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Integration\Windows8-RT-KB2999226-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Integration\Windows8-RT-KB2999226-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Integration\Windows8.1-KB2999226-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Integration\Windows8.1-KB2999226-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Flattener\AppVPackaging.dll.manifest.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SWEST_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107134.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-bridge-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-root-bridge-test.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-root.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-stil.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107426.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107446.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107450.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107658.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107728.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107742.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107746.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0136865.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0144773.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145373.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145707.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145879.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145904.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0146142.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149018.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151055.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151063.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151073.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152432.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152436.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152556.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152560.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152568.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152594.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152602.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152608.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152610.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152622.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152626.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152628.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152688.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152690.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152694.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152696.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152698.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152876.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151041.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152882.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152884.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152892.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153087.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153091.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153093.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153095.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153265.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153305.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153313.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153518.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp2-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp3-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp4-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail2-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail3-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152878.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157167.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157177.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157191.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157831.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158071.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158477.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0160590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0164153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0168644.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0156537.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174952.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175428.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177257.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177806.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178348.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178459.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178932.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172035.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182689.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182888.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182902.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182946.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183172.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183174.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183198.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183574.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185670.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185774.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185776.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185778.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185780.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185786.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_KMS_Automation-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_KMS_Automation-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_KMS_Automation-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145168.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185790.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185798.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteFreeR_Bypass-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteFreeR_Bypass-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteFreeR_Bypass-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185796.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185818.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185828.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185834.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185842.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186346.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186362.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187647.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187815.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187817.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187819.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187825.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187829.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187835.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187837.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187839.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187849.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187851.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187859.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187863.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187881.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187883.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ul-oob.xrm-ms desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ul-oob.xrm-ms desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\pkeyconfig-office.xrm-ms desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\pkeyconfig-office.xrm-ms desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\pkeyconfig-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ppd.xrm-ms desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ppd.xrm-ms desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ul-oob.xrm-ms desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ul-oob.xrm-ms desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-pl.xrm-ms desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-pl.xrm-ms desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ppd.xrm-ms desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ppd.xrm-ms desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE False 1
Fn
For performance reasons, the remaining 518 entries are omitted.
The remaining entries can be found in glog.xml.
Registry (10)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders value_name = Startup, data = 83, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders value_name = Startup, data = %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders value_name = Common Startup, data = %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Write Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run value_name = hgaibc.exe, data = 7237488, size = 84, type = REG_SZ False 1
Fn
Write Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run value_name = hgaibc.exe, data = C:\Users\FD1HVy\AppData\Roaming\hgaibc.exe, size = 84, type = REG_SZ True 1
Fn
Process (1160)
»
Operation Process Additional Information Success Count Logfile
Create C:\WINDOWS\system32\cmd.exe os_pid = 0xe40, startup_flags = STARTF_USESHOWWINDOW, STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
Create C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe show_window = SW_SHOWNORMAL True 1
Fn
Create C:\WINDOWS\system32\cmd.exe os_pid = 0xbb0, startup_flags = STARTF_USESHOWWINDOW, STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
Enumerate Processes - - True 1131
Fn
Enumerate Processes - - False 26
Fn
Module (164)
»
Operation Module Additional Information Success Count Logfile
Load kernel32.dll base_address = 0x77050000 True 1
Fn
Load advapi32.dll base_address = 0x75b90000 True 1
Fn
Load user32.dll base_address = 0x774c0000 True 1
Fn
Load Shell32.dll base_address = 0x744f0000 True 1
Fn
Load ntdll.dll base_address = 0x77850000 True 1
Fn
Load mpr.dll base_address = 0x74250000 True 1
Fn
Load ws2_32.dll base_address = 0x76f10000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x77050000 True 30
Fn
Get Filename - process_name = c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe, file_name_orig = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 32767 True 4
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetProcAddress, address_out = 0x770651b0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetModuleHandleW, address_out = 0x770650d0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindNextFileW, address_out = 0x770bee40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindClose, address_out = 0x770bed70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = MoveFileW, address_out = 0x7709e500 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetFileSizeEx, address_out = 0x770bef40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetModuleFileNameW, address_out = 0x77065090 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetFileAttributesW, address_out = 0x770bef10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ExitProcess, address_out = 0x77063cb0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCommandLineW, address_out = 0x77064cc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetComputerNameW, address_out = 0x770932c0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetComputerNameA, address_out = 0x77093780 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateMutexW, address_out = 0x770beb70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrlenW, address_out = 0x77066c70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrlenA, address_out = 0x77066c50 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCurrentProcess, address_out = 0x770bea10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WaitForSingleObject, address_out = 0x770beca0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetLogicalDrives, address_out = 0x77060d20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetTickCount, address_out = 0x770bdd50 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DeleteFileW, address_out = 0x770bed40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WideCharToMultiByte, address_out = 0x77066b10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = InitializeCriticalSectionAndSpinCount, address_out = 0x770bebb0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Sleep, address_out = 0x77066760 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = LeaveCriticalSection, address_out = 0x7789b250 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ReadFile, address_out = 0x770bf090 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateFileW, address_out = 0x770bed10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = OpenMutexW, address_out = 0x770bebf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = EnterCriticalSection, address_out = 0x7789b2d0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WaitForMultipleObjects, address_out = 0x770bec80 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrcmpiW, address_out = 0x77066bf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrcmpiA, address_out = 0x77066bd0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DeleteCriticalSection, address_out = 0x7787fb90 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ReleaseMutex, address_out = 0x770bec20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CloseHandle, address_out = 0x770beab0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetVersion, address_out = 0x770656c0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateThread, address_out = 0x770646b0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ExpandEnvironmentStringsW, address_out = 0x77064a40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = QueryPerformanceCounter, address_out = 0x77065da0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = QueryPerformanceFrequency, address_out = 0x77065dc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCurrentProcessId, address_out = 0x770bea20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetFileAttributesW, address_out = 0x770bf100 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetVolumeInformationW, address_out = 0x770bf020 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WriteFile, address_out = 0x770bf180 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetFilePointerEx, address_out = 0x770bf130 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetEndOfFile, address_out = 0x770bf0e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindFirstFileW, address_out = 0x770bedf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetProcessHeap, address_out = 0x770651f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapReAlloc, address_out = 0x7788f630 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapAlloc, address_out = 0x77892dc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapFree, address_out = 0x770657f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreatePipe, address_out = 0x77064590 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetHandleInformation, address_out = 0x770beae0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateProcessW, address_out = 0x77064610 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CompareStringW, address_out = 0x77064430 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CompareStringA, address_out = 0x77064410 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = OpenProcess, address_out = 0x77065cc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = TerminateProcess, address_out = 0x770667e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetSystemTime, address_out = 0x770654e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SystemTimeToFileTime, address_out = 0x770667a0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetLastError, address_out = 0x77065010 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateToolhelp32Snapshot, address_out = 0x7709edc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Process32NextW, address_out = 0x7709f8f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Process32FirstW, address_out = 0x7709f750 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegOpenKeyExW, address_out = 0x75bae580 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegQueryValueExW, address_out = 0x75bae5a0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegSetValueExW, address_out = 0x75baf530 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegCloseKey, address_out = 0x75baed60 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenProcessToken, address_out = 0x75baefb0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = GetTokenInformation, address_out = 0x75baee90 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenSCManagerW, address_out = 0x75bb0540 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenServiceW, address_out = 0x75bafa20 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CloseServiceHandle, address_out = 0x75bafc00 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = ControlService, address_out = 0x75bc26d0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = QueryServiceStatus, address_out = 0x75bb2380 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = EnumDependentServicesW, address_out = 0x75bc2f70 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = EnumServicesStatusExW, address_out = 0x75bafc80 True 1
Fn
Get Address c:\windows\syswow64\user32.dll function = SystemParametersInfoW, address_out = 0x774ef210 True 1
Fn
Get Address c:\windows\syswow64\shell32.dll function = ShellExecuteExW, address_out = 0x74654730 True 1
Fn
Get Address c:\windows\syswow64\ntdll.dll function = NtQuerySystemInformation, address_out = 0x778c2070 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetCloseEnum, address_out = 0x74252640 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetOpenEnumW, address_out = 0x74252790 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetEnumResourceW, address_out = 0x74252410 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = WSAStartup, address_out = 0x76f15b40 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = socket, address_out = 0x76f24510 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = send, address_out = 0x76f15030 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = recv, address_out = 0x76f20c50 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = connect, address_out = 0x76f15410 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = closesocket, address_out = 0x76f20910 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = gethostbyname, address_out = 0x76f46cb0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = inet_addr, address_out = 0x76f29160 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = ntohl, address_out = 0x76f149d0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = htonl, address_out = 0x76f149d0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = htons, address_out = 0x76f28ff0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 30
Fn
Service (81)
»
Operation Additional Information Success Count Logfile
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 5
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 5
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 4
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 4
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 5
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 5
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 3
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 3
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 5
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 4
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 5
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 3
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
System (310)
»
Operation Additional Information Success Count Logfile
Get Computer Name result_out = NQDPDE True 1
Fn
Sleep duration = -1 (infinite) True 3
Fn
Sleep duration = 500 milliseconds (0.500 seconds) True 26
Fn
Sleep duration = 100 milliseconds (0.100 seconds) True 79
Fn
Get Time type = Performance Ctr, time = 7330864441 True 1
Fn
Get Time type = Ticks, time = 73265 True 3
Fn
Get Time type = Ticks, time = 75500 True 1
Fn
Get Time type = Ticks, time = 75531 True 1
Fn
Get Time type = Ticks, time = 75703 True 2
Fn
Get Time type = Ticks, time = 76078 True 2
Fn
Get Time type = Ticks, time = 76671 True 4
Fn
Get Time type = Ticks, time = 77343 True 2
Fn
Get Time type = Ticks, time = 77734 True 4
Fn
Get Time type = Ticks, time = 77953 True 2
Fn
Get Time type = Ticks, time = 78406 True 1
Fn
Get Time type = Ticks, time = 78421 True 1
Fn
Get Time type = Ticks, time = 78828 True 4
Fn
Get Time type = Ticks, time = 79078 True 2
Fn
Get Time type = Ticks, time = 79406 True 2
Fn
Get Time type = Ticks, time = 79781 True 2
Fn
Get Time type = Ticks, time = 80109 True 4
Fn
Get Time type = Ticks, time = 80656 True 2
Fn
Get Time type = Ticks, time = 80984 True 2
Fn
Get Time type = Ticks, time = 81296 True 4
Fn
Get Time type = Ticks, time = 81546 True 1
Fn
Get Time type = Ticks, time = 81562 True 1
Fn
Get Time type = Ticks, time = 81812 True 2
Fn
Get Time type = Ticks, time = 81968 True 2
Fn
Get Time type = Ticks, time = 82218 True 2
Fn
Get Time type = Ticks, time = 82468 True 4
Fn
Get Time type = Ticks, time = 82734 True 2
Fn
Get Time type = Ticks, time = 82937 True 2
Fn
Get Time type = Ticks, time = 83250 True 2
Fn
Get Time type = Ticks, time = 83515 True 4
Fn
Get Time type = Ticks, time = 83937 True 2
Fn
Get Time type = Ticks, time = 84265 True 2
Fn
Get Time type = Ticks, time = 84656 True 4
Fn
Get Time type = Ticks, time = 85125 True 2
Fn
Get Time type = Ticks, time = 85390 True 2
Fn
Get Time type = Ticks, time = 85562 True 2
Fn
Get Time type = Ticks, time = 85828 True 4
Fn
Get Time type = Ticks, time = 86203 True 2
Fn
Get Time type = Ticks, time = 86500 True 2
Fn
Get Time type = Ticks, time = 86734 True 2
Fn
Get Time type = Ticks, time = 87234 True 4
Fn
Get Time type = Ticks, time = 87531 True 2
Fn
Get Time type = Ticks, time = 87718 True 2
Fn
Get Time type = Ticks, time = 88062 True 2
Fn
Get Time type = Ticks, time = 88265 True 4
Fn
Get Time type = Ticks, time = 88437 True 2
Fn
Get Time type = Ticks, time = 88750 True 2
Fn
Get Time type = Ticks, time = 89328 True 4
Fn
Get Time type = Ticks, time = 90078 True 2
Fn
Get Time type = Ticks, time = 90515 True 4
Fn
Get Time type = Ticks, time = 90781 True 2
Fn
Get Time type = Ticks, time = 91078 True 2
Fn
Get Time type = Ticks, time = 91343 True 2
Fn
Get Time type = Ticks, time = 91593 True 4
Fn
Get Time type = Ticks, time = 91734 True 2
Fn
Get Time type = Ticks, time = 91937 True 2
Fn
Get Time type = Ticks, time = 92203 True 2
Fn
Get Time type = Ticks, time = 92656 True 4
Fn
Get Time type = Ticks, time = 92875 True 2
Fn
Get Time type = Ticks, time = 93093 True 2
Fn
Get Time type = Ticks, time = 93296 True 2
Fn
Get Time type = Ticks, time = 93562 True 2
Fn
Get Time type = Ticks, time = 93765 True 4
Fn
Get Time type = Ticks, time = 93937 True 2
Fn
Get Time type = Ticks, time = 94390 True 2
Fn
Get Time type = Ticks, time = 94765 True 2
Fn
Get Time type = Ticks, time = 95265 True 4
Fn
Get Time type = Ticks, time = 95609 True 2
Fn
Get Time type = Ticks, time = 95968 True 2
Fn
Get Time type = Ticks, time = 96125 True 2
Fn
Get Time type = Ticks, time = 96250 True 2
Fn
Get Time type = Ticks, time = 96437 True 4
Fn
Get Time type = Ticks, time = 96546 True 2
Fn
Get Time type = Ticks, time = 96765 True 2
Fn
Get Time type = Ticks, time = 96921 True 2
Fn
Get Time type = Ticks, time = 97187 True 2
Fn
Get Time type = Ticks, time = 97437 True 2
Fn
Get Time type = Ticks, time = 97656 True 4
Fn
Get Time type = Ticks, time = 97796 True 2
Fn
Get Time type = Ticks, time = 97953 True 2
Fn
Get Time type = Ticks, time = 98109 True 2
Fn
Get Time type = Ticks, time = 98265 True 2
Fn
Get Time type = Ticks, time = 98453 True 1
Fn
Get Time type = Ticks, time = 98734 True 2
Fn
Get Info type = Operating System True 2
Fn
Mutex (5)
»
Operation Additional Information Success Count Logfile
Create mutex_name = Global\syncronize_1TPBM0A True 1
Fn
Create mutex_name = Global\syncronize_1TPBM0U True 1
Fn
Open mutex_name = Global\syncronize_1TPBM0A, desired_access = SYNCHRONIZE False 1
Fn
Open mutex_name = Global\syncronize_1TPBM0U, desired_access = SYNCHRONIZE False 1
Fn
Release mutex_name = Global\syncronize_1TPBM0A True 1
Fn
Process #6: hgaibc.exe
111 0
»
Information Value
ID #6
File Name c:\users\fd1hvy\appdata\roaming\microsoft\windows\start menu\programs\startup\hgaibc.exe
Command Line "C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:32, Reason: Autostart
Unmonitor End Time: 00:02:36, Reason: Self Terminated
Monitor Duration 00:00:03
OS Process Information
»
Information Value
PID 0xe34
Parent PID 0x9d4 (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x E38
0x E3C
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points AV YARA Actions
hgaibc.exe 0x00400000 0x00418FFF Process Termination - 32-bit - False False
Host Behavior
Module (100)
»
Operation Module Additional Information Success Count Logfile
Load kernel32.dll base_address = 0x77050000 True 1
Fn
Load advapi32.dll base_address = 0x75b90000 True 1
Fn
Load user32.dll base_address = 0x774c0000 True 1
Fn
Load Shell32.dll base_address = 0x744f0000 True 1
Fn
Load ntdll.dll base_address = 0x77850000 True 1
Fn
Load mpr.dll base_address = 0x74250000 True 1
Fn
Load ws2_32.dll base_address = 0x76f10000 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetProcAddress, address_out = 0x770651b0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetModuleHandleW, address_out = 0x770650d0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindNextFileW, address_out = 0x770bee40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindClose, address_out = 0x770bed70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = MoveFileW, address_out = 0x7709e500 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetFileSizeEx, address_out = 0x770bef40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetModuleFileNameW, address_out = 0x77065090 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetFileAttributesW, address_out = 0x770bef10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ExitProcess, address_out = 0x77063cb0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCommandLineW, address_out = 0x77064cc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetComputerNameW, address_out = 0x770932c0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetComputerNameA, address_out = 0x77093780 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateMutexW, address_out = 0x770beb70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrlenW, address_out = 0x77066c70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrlenA, address_out = 0x77066c50 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCurrentProcess, address_out = 0x770bea10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WaitForSingleObject, address_out = 0x770beca0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetLogicalDrives, address_out = 0x77060d20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetTickCount, address_out = 0x770bdd50 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DeleteFileW, address_out = 0x770bed40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WideCharToMultiByte, address_out = 0x77066b10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = InitializeCriticalSectionAndSpinCount, address_out = 0x770bebb0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Sleep, address_out = 0x77066760 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = LeaveCriticalSection, address_out = 0x7789b250 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ReadFile, address_out = 0x770bf090 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateFileW, address_out = 0x770bed10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = OpenMutexW, address_out = 0x770bebf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = EnterCriticalSection, address_out = 0x7789b2d0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WaitForMultipleObjects, address_out = 0x770bec80 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrcmpiW, address_out = 0x77066bf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrcmpiA, address_out = 0x77066bd0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DeleteCriticalSection, address_out = 0x7787fb90 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ReleaseMutex, address_out = 0x770bec20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CloseHandle, address_out = 0x770beab0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetVersion, address_out = 0x770656c0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateThread, address_out = 0x770646b0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ExpandEnvironmentStringsW, address_out = 0x77064a40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = QueryPerformanceCounter, address_out = 0x77065da0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = QueryPerformanceFrequency, address_out = 0x77065dc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCurrentProcessId, address_out = 0x770bea20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetFileAttributesW, address_out = 0x770bf100 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetVolumeInformationW, address_out = 0x770bf020 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WriteFile, address_out = 0x770bf180 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetFilePointerEx, address_out = 0x770bf130 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetEndOfFile, address_out = 0x770bf0e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindFirstFileW, address_out = 0x770bedf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetProcessHeap, address_out = 0x770651f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapReAlloc, address_out = 0x7788f630 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapAlloc, address_out = 0x77892dc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapFree, address_out = 0x770657f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreatePipe, address_out = 0x77064590 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetHandleInformation, address_out = 0x770beae0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateProcessW, address_out = 0x77064610 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CompareStringW, address_out = 0x77064430 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CompareStringA, address_out = 0x77064410 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = OpenProcess, address_out = 0x77065cc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = TerminateProcess, address_out = 0x770667e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetSystemTime, address_out = 0x770654e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SystemTimeToFileTime, address_out = 0x770667a0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetLastError, address_out = 0x77065010 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateToolhelp32Snapshot, address_out = 0x7709edc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Process32NextW, address_out = 0x7709f8f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Process32FirstW, address_out = 0x7709f750 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegOpenKeyExW, address_out = 0x75bae580 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegQueryValueExW, address_out = 0x75bae5a0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegSetValueExW, address_out = 0x75baf530 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegCloseKey, address_out = 0x75baed60 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenProcessToken, address_out = 0x75baefb0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = GetTokenInformation, address_out = 0x75baee90 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenSCManagerW, address_out = 0x75bb0540 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenServiceW, address_out = 0x75bafa20 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CloseServiceHandle, address_out = 0x75bafc00 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = ControlService, address_out = 0x75bc26d0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = QueryServiceStatus, address_out = 0x75bb2380 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = EnumDependentServicesW, address_out = 0x75bc2f70 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = EnumServicesStatusExW, address_out = 0x75bafc80 True 1
Fn
Get Address c:\windows\syswow64\user32.dll function = SystemParametersInfoW, address_out = 0x774ef210 True 1
Fn
Get Address c:\windows\syswow64\shell32.dll function = ShellExecuteExW, address_out = 0x74654730 True 1
Fn
Get Address c:\windows\syswow64\ntdll.dll function = NtQuerySystemInformation, address_out = 0x778c2070 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetCloseEnum, address_out = 0x74252640 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetOpenEnumW, address_out = 0x74252790 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetEnumResourceW, address_out = 0x74252410 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = WSAStartup, address_out = 0x76f15b40 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = socket, address_out = 0x76f24510 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = send, address_out = 0x76f15030 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = recv, address_out = 0x76f20c50 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = connect, address_out = 0x76f15410 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = closesocket, address_out = 0x76f20910 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = gethostbyname, address_out = 0x76f46cb0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = inet_addr, address_out = 0x76f29160 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = ntohl, address_out = 0x76f149d0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = htonl, address_out = 0x76f149d0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = htons, address_out = 0x76f28ff0 True 1
Fn
System (6)
»
Operation Additional Information Success Count Logfile
Get Time type = Performance Ctr, time = 7423771604 True 1
Fn
Get Time type = Ticks, time = 74203 True 3
Fn
Get Info type = Operating System True 2
Fn
Mutex (2)
»
Operation Additional Information Success Count Logfile
Open mutex_name = Global\syncronize_1TPBM0A, desired_access = SYNCHRONIZE True 1
Fn
Open mutex_name = Global\syncronize_1TPBM0U, desired_access = SYNCHRONIZE True 1
Fn
Process #7: cmd.exe
284 0
»
Information Value
ID #7
File Name c:\windows\system32\cmd.exe
Command Line "C:\WINDOWS\system32\cmd.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:33, Reason: Child Process
Unmonitor End Time: 00:02:58, Reason: Self Terminated
Monitor Duration 00:00:25
OS Process Information
»
Information Value
PID 0xe40
Parent PID 0xe24 (c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x E44
0x EC0
Host Behavior
File (218)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\WINDOWS\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_OUTPUT_HANDLE type = file_type True 14
Fn
Get Info STD_INPUT_HANDLE type = file_type True 7
Fn
Open STD_OUTPUT_HANDLE - True 36
Fn
Open STD_INPUT_HANDLE - True 81
Fn
Read STD_INPUT_HANDLE size = 1, size_out = 1 True 65
Fn
Data
Write STD_OUTPUT_HANDLE size = 38 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 2 True 5
Fn
Data
Write STD_OUTPUT_HANDLE size = 52 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 20 True 3
Fn
Data
Write STD_OUTPUT_HANDLE size = 24 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 36 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 5 True 1
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 4, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (4)
»
Operation Process Additional Information Success Count Logfile
Create C:\WINDOWS\system32\mode.com os_pid = 0xed8, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Create C:\WINDOWS\system32\vssadmin.exe os_pid = 0xf98, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Get Info C:\WINDOWS\system32\mode.com type = PROCESS_BASIC_INFORMATION True 1
Fn
Get Info C:\WINDOWS\system32\vssadmin.exe type = PROCESS_BASIC_INFORMATION True 1
Fn
Memory (2)
»
Operation Process Additional Information Success Count Logfile
Read C:\WINDOWS\system32\mode.com address = 1083334918144, size = 1952 True 1
Fn
Data
Read C:\WINDOWS\system32\vssadmin.exe address = 476233924608, size = 1952 True 1
Fn
Data
Module (10)
»
Operation Module Additional Information Success Count Logfile
Load NTDLL.DLL base_address = 0x7ff8c85b0000 True 1
Fn
Get Handle c:\windows\system32\cmd.exe base_address = 0x7ff695310000 True 1
Fn
Get Handle c:\windows\system32\kernel32.dll base_address = 0x7ff8c81c0000 True 2
Fn
Get Filename - process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\WINDOWS\system32\cmd.exe, size = 32743 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetThreadUILanguage, address_out = 0x7ff8c81da990 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = CopyFileExW, address_out = 0x7ff8c81de830 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = IsDebuggerPresent, address_out = 0x7ff8c81de300 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x7ff8c5880a40 True 1
Fn
Get Address c:\windows\system32\ntdll.dll function = NtQueryInformationProcess, address_out = 0x7ff8c86556b0 True 1
Fn
System (1)
»
Operation Additional Information Success Count Logfile
Get Info type = Operating System True 1
Fn
Environment (30)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 10
Fn
Data
Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps; True 3
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 3
Fn
Get Environment String name = PROMPT False 1
Fn
Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Get Environment String name = PROMPT, result_out = $P$G True 3
Fn
Set Environment String name = PROMPT, value = $P$G True 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 2
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 2
Fn
Set Environment String name = =ExitCode, value = 00000002 True 1
Fn
Process #10: mode.com
0 0
»
Information Value
ID #10
File Name c:\windows\system32\mode.com
Command Line mode con cp select=1251
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:41, Reason: Child Process
Unmonitor End Time: 00:02:49, Reason: Self Terminated
Monitor Duration 00:00:07
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xed8
Parent PID 0xe40 (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x EDC
0x EE0
Process #11: vssadmin.exe
0 0
»
Information Value
ID #11
File Name c:\windows\system32\vssadmin.exe
Command Line vssadmin delete shadows /all /quiet
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:51, Reason: Child Process
Unmonitor End Time: 00:02:57, Reason: Self Terminated
Monitor Duration 00:00:05
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xf98
Parent PID 0xe40 (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x F9C
0x FB8
0x FC4
0x FD0
0x FD4
Process #12: hgaibc.exe
29163 0
»
Information Value
ID #12
File Name c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe
Command Line "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe" -a
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:57, Reason: Child Process
Unmonitor End Time: 00:03:22, Reason: Terminated by Timeout
Monitor Duration 00:00:25
OS Process Information
»
Information Value
PID 0x2a8
Parent PID 0xe24 (c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x C24
0x 380
0x C5C
0x 8BC
0x C68
0x 998
0x 638
0x C84
0x 970
0x 964
0x A94
0x 908
0x A8C
0x A90
0x C4C
0x 90C
0x 904
0x 4F4
Host Behavior
File (4652)
»
Operation Filename Additional Information Success Count Logfile
Create C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\WINDOWS\System32\hgaibc.exe desired_access = GENERIC_WRITE True 1
Fn
Create C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 2
Fn
Create C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe desired_access = GENERIC_WRITE True 1
Fn
Create C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe desired_access = GENERIC_WRITE False 1
Fn
Create C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\$WINRE_BACKUP_PARTITION.MARKER desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\BCD.LOG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\updaterevokesipolicy.p7b desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\updaterevokesipolicy.p7b desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\BCD desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\BCD.LOG1 desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\BCD.LOG2 desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bg-BG\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bg-BG\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\bootspaces.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bootspaces.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\bootvhd.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\bootvhd.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\cs-CZ\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\cs-CZ\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\fr-FR\memtest.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\fr-FR\memtest.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\hr-HR\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\hr-HR\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\hu-HU\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\hu-HU\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\hu-HU\memtest.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\hu-HU\memtest.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\it-IT\bootmgr.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\it-IT\bootmgr.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Boot\it-IT\memtest.exe.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Boot\it-IT\memtest.exe.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\bootmgr desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-time-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Content.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Content.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\ApiClient.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\ApiClient.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVCatalog.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVCatalog.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\hwrcommonlm.dat desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\hwrcommonlm.dat desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\hwrenclm.dat desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\hwrenclm.dat desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\hwrlatinlm.dat desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\hwrlatinlm.dat desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipscat.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipscat.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsnor.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsnor.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsplk.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsplk.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsptb.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsptb.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsptg.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsptg.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsrom.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsrom.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsrus.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsrus.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipssrb.xml desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipssrb.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\msadc\adcvbs.inc desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\msadc\adcvbs.inc desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\oledbjvs.inc desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\oledbjvs.inc desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\oledbvbs.inc desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\oledbvbs.inc desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVFileSystemMetadata.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVFileSystemMetadata.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvApi.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvApi.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream64.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream64.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvStreamingManager.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvStreamingManager.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystemController.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystemController.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvVirtualization.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvVirtualization.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVManifest.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVManifest.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVOrchestration.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVOrchestration.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVPolicy.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVPolicy.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ipsnld.xml desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\msadc\adcjavas.inc desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\msadc\adcjavas.inc desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105298.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105306.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105336.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp120.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp120.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp140.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp140.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcr120.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcr120.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\StreamServer.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\StreamServer.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ar-SA\tipresx.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\bg-BG\tipresx.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\bg-BG\tipresx.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\cs-CZ\tipresx.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\cs-CZ\tipresx.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\da-DK\tipresx.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\da-DK\tipresx.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\de-DE\tipresx.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\de-DE\tipresx.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\el-GR\tipresx.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\el-GR\tipresx.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-GB\tipresx.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\en-GB\tipresx.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Microsoft.Ink.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105974.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106124.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\ar-SA\tipresx.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\mip.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\mraut.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\Microsoft.Ink.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\mshwgst.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107132.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107134.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107138.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\mip.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\OFFICE16\LICLUA.EXE.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\ink\mshwgst.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107264.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107266.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107280.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107282.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107288.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VGX\VGX.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VGX\VGX.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107426.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107446.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107450.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\ado\msader15.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\msader15.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\ado\msado15.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\msado15.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\ado\msado20.tlb desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\msado20.tlb desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\ado\msado21.tlb desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\msado21.tlb desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\ado\msado25.tlb desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\ado\msado25.tlb desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107658.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\en-US\oledb32r.dll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\en-US\oledb32r.dll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\en-US\sqloledb.rll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\en-US\sqloledb.rll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\en-US\sqlxmlx.rll.mui desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\en-US\sqlxmlx.rll.mui desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\msdaosp.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\msdaosp.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\msdaps.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\msdaps.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\msdasql.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Common Files\System\Ole DB\msdasql.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Internet Explorer\SIGNUP\install.ins.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Internet Explorer\spray-roman.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Internet Explorer\sqmapi.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Internet Explorer\sqmapi.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\awt.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\awt.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\awt.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107728.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107742.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107746.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0136865.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0144773.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145168.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145373.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145707.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\bci.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\bci.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\bci.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145879.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145904.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0146142.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149018.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151041.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\eula.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\eula.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\eula.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151055.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151063.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151073.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152432.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152436.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152556.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152560.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152568.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152594.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\glass.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\glass.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\glass.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152602.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152610.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152622.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152626.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152628.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152688.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152690.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152694.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152696.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152698.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152608.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152876.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152878.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152882.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152884.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152892.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153087.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153091.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153093.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153095.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153265.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153305.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153313.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153518.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0156537.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157167.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157177.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157191.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157831.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158071.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158477.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0160590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0164153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0168644.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172035.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174952.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jli.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jli.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jli.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175428.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177257.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177806.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178348.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178459.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\klist.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\klist.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\klist.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178932.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0179963.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182689.JPG.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182888.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\management.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\management.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\management.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182902.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182946.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183172.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183174.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183198.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183574.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185670.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185774.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185776.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185778.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185780.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185786.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185790.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185796.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185798.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185800.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\net.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\net.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\net.dll.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185806.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185818.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185828.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185834.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185842.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186346.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186362.WMF.id-B4197730.[idecryptyourdata@cock.li].bat desired_access = GENERIC_WRITE True 1
Fn
Create C:\Program Files\Java\jre1.8.0_144\bin\nio.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 27856 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 272 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 26832 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 282 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 70864 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 278 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 19664 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 278 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 24784 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 274 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-time-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 21200 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-time-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 272 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 19152 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 278 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 23248 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 278 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 19152 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 276 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 24784 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 276 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 786714 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 396976 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 250 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 786698 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 262144 True 3
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 263904 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 244 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 820432 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 230 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 262144 True 3
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash.id-B4197730.[idecryptyourdata@cock.li].bat size = 112 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash.id-B4197730.[idecryptyourdata@cock.li].bat size = 230 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash.id-B4197730.[idecryptyourdata@cock.li].bat size = 112 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105298.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6336 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105298.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 512224 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 246 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 332976 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 902336 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105306.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4336 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105306.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2032 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 358624 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 242 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10512 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8000 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105336.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2912 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105336.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 61040 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 250 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11600 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8864 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12384 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17072 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 1048560 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 242 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4640 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4976 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 786706 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 262144 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8256 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5888 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5984 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 996576 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 244 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4976 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4960 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20448 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9408 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6256 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5168 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5488 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 390336 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 242 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4160 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 31824 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7392 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 982736 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 44704 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 252 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8688 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10368 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13824 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 18736 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11728 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105974.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4624 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105974.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10064 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2928 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 23552 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11904 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 21552 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2160 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8256 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7648 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9056 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106124.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5824 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106124.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14144 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 27088 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107132.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 48384 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107132.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107134.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 48400 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107134.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 19616 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20144 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13472 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13792 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 22304 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 24912 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16112 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\OFFICE16\LICLUA.EXE.id-B4197730.[idecryptyourdata@cock.li].bat size = 363744 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\OFFICE16\LICLUA.EXE.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 1048560 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9984 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20224 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8560 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8000 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107138.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17216 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107138.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107264.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5280 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107264.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107266.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5872 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107266.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107280.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11120 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107280.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107282.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14144 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107282.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 22544 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12320 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2464 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4144 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4544 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10864 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11296 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6544 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE.id-B4197730.[idecryptyourdata@cock.li].bat size = 244304 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat size = 590528 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat size = 260 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 18640 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 260 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5088 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 23680 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7968 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107288.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13440 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107288.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16592 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 12464 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 250 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107426.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11504 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107426.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107446.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 30352 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107446.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15904 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 21232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3728 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4256 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9616 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6032 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4992 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 20624 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 244 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 855392 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 426608 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8016 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16480 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6864 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 990048 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107450.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4928 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107450.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 367232 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8880 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3584 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3056 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4208 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11408 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12208 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6432 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7952 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6800 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 168080 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb.id-B4197730.[idecryptyourdata@cock.li].bat size = 17056 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10848 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 100496 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 246 True 1
Fn
Data
Write C:\Program Files\Internet Explorer\spray-roman.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 75792 True 1
Fn
Data
Write C:\Program Files\Internet Explorer\spray-roman.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 242 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107658.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7088 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107658.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4816 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3808 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14016 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4640 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8272 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107728.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5504 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107728.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3152 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107742.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3648 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107742.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 26784 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4720 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0136865.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16720 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0136865.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0144773.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 40240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0144773.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\awt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 1048560 True 1
Fn
Data
Write C:\Program Files\Internet Explorer\SIGNUP\install.ins.id-B4197730.[idecryptyourdata@cock.li].bat size = 464 True 1
Fn
Data
Write C:\Program Files\Internet Explorer\SIGNUP\install.ins.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3072 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 61648 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 49248 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107746.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4800 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107746.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145168.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 33664 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145168.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\awt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 468064 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\awt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb.id-B4197730.[idecryptyourdata@cock.li].bat size = 22688 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 48880 True 1
Fn
Data
Write C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 258 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 21136 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145373.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 17872 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145373.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145879.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 35424 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 31856 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145707.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 36832 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145707.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145904.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 39552 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145904.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 36800 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 43680 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 33968 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0146142.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 46512 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0146142.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 38240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149018.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 27408 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149018.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145879.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 67552 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 64816 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 46416 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 86096 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 240 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 159824 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\bci.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 16976 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\bci.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll size = 587856 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll size = 232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8496 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151041.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4368 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15472 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 18512 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 29776 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 24656 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151041.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151063.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10640 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151063.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6768 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151055.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14640 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151055.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13216 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 1026128 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 274512 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 1048560 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\eula.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 136272 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 24848 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10768 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151073.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14144 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151073.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152432.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16496 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152432.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152436.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152436.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16064 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152556.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16448 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152556.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152560.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10896 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152560.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152568.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3712 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152568.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3376 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10944 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 108128 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 246 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 242 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 242 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152594.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6352 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 186960 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 619600 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 248 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 455760 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152594.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\eula.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9776 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152602.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6288 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152602.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16640 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 123472 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152610.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5968 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152610.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152622.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9616 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152622.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152626.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 26256 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152626.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\glass.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 265808 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\glass.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 230 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152628.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 30816 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152628.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152690.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1280 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152690.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152694.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1360 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152694.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152696.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7328 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152696.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1216 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1664 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4912 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 19024 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 63568 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 15952 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152608.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12448 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152608.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152876.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7888 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152876.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152878.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14896 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152878.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 21072 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 34384 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152882.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9088 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152882.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152688.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 34688 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152698.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1216 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4592 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152688.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 158288 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 230 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1952 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152892.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10672 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152892.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11360 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4512 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 33072 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153087.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1920 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153087.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152884.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6960 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152884.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152698.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7856 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153091.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8144 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153091.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153093.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8896 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153093.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153095.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3712 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153095.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153265.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3024 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153265.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 159824 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20112 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 80464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\java.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 206928 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\java.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl.id-B4197730.[idecryptyourdata@cock.li].bat size = 187408 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 142416 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 258 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 69200 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 242 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 538192 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 206928 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 230 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 128080 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 30816 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153305.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 38496 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153305.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15456 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17520 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 34272 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12768 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153518.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12544 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153518.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0156537.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 1392 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0156537.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157167.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 46704 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157167.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157177.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 21728 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157177.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 36624 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157831.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11408 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157831.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158071.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 18656 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158071.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158477.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17968 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158477.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0160590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 29408 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0160590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 319568 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 250 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 14416 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153313.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16960 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153313.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0168644.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20912 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0168644.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14480 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6896 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172035.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7456 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172035.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7440 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12704 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5872 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9744 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157191.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17920 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157191.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 201808 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 139856 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 29776 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 246 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 26704 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174952.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 24992 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174952.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 15440 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 258 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 46464 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175428.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 14560 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175428.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0164153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 46496 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 15952 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 296016 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jli.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 174672 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jli.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 112208 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 242 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 20048 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 235600 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0164153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7040 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177806.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 55568 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177806.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 185936 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178348.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 36992 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178348.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 35408 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178459.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 29216 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178459.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5104 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177257.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 45360 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177257.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 26544 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 220752 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 31312 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 24048 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 16464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 23344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178932.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 35344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178932.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0179963.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 32112 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0179963.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182689.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 16624 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182689.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 18512 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\klist.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 16464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\klist.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 230 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 16464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 230 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 16464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 233552 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\management.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 36944 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\management.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 240 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 786694 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15152 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182902.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7824 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182902.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 829280 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182946.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16096 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182946.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183172.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 29792 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183172.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183174.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 28640 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183174.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183198.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 24432 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183198.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183574.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 19280 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183574.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185670.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7312 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185670.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 32048 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185776.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 27104 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185776.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185778.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 25328 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185778.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185780.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 59744 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185780.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182888.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 24400 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182888.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185790.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20672 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185790.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185796.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 25872 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185796.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185798.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 33840 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185798.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 262144 True 3
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185806.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 30528 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185806.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185818.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 35728 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185818.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185828.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7808 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185828.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185834.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8592 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185834.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185774.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20048 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185774.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185842.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 14320 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185842.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186346.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8672 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186346.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 33856 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 660144 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\net.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 96848 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\net.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 963248 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 653904 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185786.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 39344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185786.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 18224 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\nio.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 60496 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\nio.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187647.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6608 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187647.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 16464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187815.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5392 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187815.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\npt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 19024 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\npt.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187817.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11648 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187817.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 16464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 234 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 829280 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185800.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 24240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185800.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187825.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7504 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187825.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187829.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12368 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187829.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187835.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9360 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187835.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187837.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16368 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187837.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187839.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5376 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187839.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 234576 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 230 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 16464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186362.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17664 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186362.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187819.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10368 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187819.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7120 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 57424 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 244 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187849.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7584 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187849.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187851.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8736 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187851.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187859.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2736 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187859.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9120 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187881.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4704 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187881.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187883.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2112 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187883.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187893.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5632 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187893.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187895.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3488 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187895.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187921.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187921.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188511.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10720 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188511.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188513.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12304 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188513.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188519.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5840 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188519.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188587.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15200 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188587.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188667.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16032 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188667.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187863.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10832 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187863.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 130640 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 97872 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188669.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 29616 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188669.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\resource.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 15440 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\resource.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195248.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195248.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4544 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195260.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8320 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195260.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 29440 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 21344 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195772.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3696 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195772.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 15952 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 228 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195788.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195788.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196060.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 4752 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196060.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196110.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5328 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196110.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196142.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3840 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196142.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188679.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13168 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188679.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6928 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5712 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197979.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 40240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197979.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198016.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 33952 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198016.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 23728 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 16464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 242 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198021.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 34928 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198021.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa.id-B4197730.[idecryptyourdata@cock.li].bat size = 786690 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198022.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 26160 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198022.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195428.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 18624 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195428.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196354.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13712 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196354.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197983.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 26256 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197983.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa.id-B4197730.[idecryptyourdata@cock.li].bat size = 262144 True 3
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 16464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198113.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 42288 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198113.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198025.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 15568 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198025.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198102.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 54976 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198102.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198226.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 41920 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198226.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 70224 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198234.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 42656 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198234.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 786682 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 262144 True 3
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198372.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 28576 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198372.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 40304 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 571984 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 57728 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 44560 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198447.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 49680 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198447.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 29008 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 31824 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199429.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 16688 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199429.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 50048 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199423.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 26160 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199423.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199303.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 31824 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199303.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 255056 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 226 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 204880 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 244 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199465.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5072 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199465.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199469.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13760 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199469.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199475.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5264 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199475.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199473.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10784 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199473.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 135760 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 230 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199483.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10176 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199483.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200163.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7184 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200163.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200183.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5328 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200183.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200151.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8208 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200151.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199609.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 12336 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199609.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 31312 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200289.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 41152 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 19472 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200189.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8064 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200189.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 20240 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200289.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200467.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 13936 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200467.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200521.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 10048 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200521.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200383.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 21408 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200383.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0211981.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 28288 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0211981.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0202045.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 42256 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0202045.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212601.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9680 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212601.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6160 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212953.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 7504 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212953.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200611.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3904 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200611.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213449.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 3856 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213449.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214934.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 31936 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214934.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 197200 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\verify.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 49232 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\verify.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214948.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 44800 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214948.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 16464 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe.id-B4197730.[idecryptyourdata@cock.li].bat size = 238 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 6560 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212751.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 2064 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212751.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 79952 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215070.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 11632 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215070.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215076.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 8032 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215076.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215210.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 33232 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215210.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 17840 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215709.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 9296 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215709.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 5632 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 21632 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216112.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 42896 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216112.JPG.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216540.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 42128 True 1
Fn
Data
Write C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216540.WMF.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 192592 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 236 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 110160 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat size = 264 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties.id-B4197730.[idecryptyourdata@cock.li].bat size = 160 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties.id-B4197730.[idecryptyourdata@cock.li].bat size = 260 True 1
Fn
Data
Write C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg.id-B4197730.[idecryptyourdata@cock.li].bat size = 640 True 1
Fn
Data
For performance reasons, the remaining 3383 entries are omitted.
The remaining entries can be found in glog.xml.
Registry (8)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders value_name = Startup, data = 83, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders value_name = Startup, data = %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders value_name = Common Startup, data = %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Write Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run value_name = hgaibc.exe, data = C:\WINDOWS\System32\hgaibc.exe, size = 60, type = REG_SZ True 1
Fn
Process (1109)
»
Operation Process Additional Information Success Count Logfile
Create C:\WINDOWS\system32\cmd.exe os_pid = 0xc40, startup_flags = STARTF_USESHOWWINDOW, STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
Enumerate Processes - - True 1082
Fn
Enumerate Processes - - False 26
Fn
Module (135)
»
Operation Module Additional Information Success Count Logfile
Load kernel32.dll base_address = 0x77050000 True 1
Fn
Load advapi32.dll base_address = 0x75b90000 True 1
Fn
Load user32.dll base_address = 0x774c0000 True 1
Fn
Load Shell32.dll base_address = 0x744f0000 True 1
Fn
Load ntdll.dll base_address = 0x77850000 True 1
Fn
Load mpr.dll base_address = 0x74250000 True 1
Fn
Load ws2_32.dll base_address = 0x76f10000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x77050000 True 16
Fn
Get Filename - process_name = c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe, file_name_orig = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 32767 True 3
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetProcAddress, address_out = 0x770651b0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetModuleHandleW, address_out = 0x770650d0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindNextFileW, address_out = 0x770bee40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindClose, address_out = 0x770bed70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = MoveFileW, address_out = 0x7709e500 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetFileSizeEx, address_out = 0x770bef40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetModuleFileNameW, address_out = 0x77065090 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetFileAttributesW, address_out = 0x770bef10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ExitProcess, address_out = 0x77063cb0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCommandLineW, address_out = 0x77064cc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetComputerNameW, address_out = 0x770932c0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetComputerNameA, address_out = 0x77093780 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateMutexW, address_out = 0x770beb70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrlenW, address_out = 0x77066c70 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrlenA, address_out = 0x77066c50 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCurrentProcess, address_out = 0x770bea10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WaitForSingleObject, address_out = 0x770beca0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetLogicalDrives, address_out = 0x77060d20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetTickCount, address_out = 0x770bdd50 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DeleteFileW, address_out = 0x770bed40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WideCharToMultiByte, address_out = 0x77066b10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = InitializeCriticalSectionAndSpinCount, address_out = 0x770bebb0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Sleep, address_out = 0x77066760 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = LeaveCriticalSection, address_out = 0x7789b250 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ReadFile, address_out = 0x770bf090 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateFileW, address_out = 0x770bed10 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = OpenMutexW, address_out = 0x770bebf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = EnterCriticalSection, address_out = 0x7789b2d0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WaitForMultipleObjects, address_out = 0x770bec80 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrcmpiW, address_out = 0x77066bf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = lstrcmpiA, address_out = 0x77066bd0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DeleteCriticalSection, address_out = 0x7787fb90 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ReleaseMutex, address_out = 0x770bec20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CloseHandle, address_out = 0x770beab0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetVersion, address_out = 0x770656c0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateThread, address_out = 0x770646b0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ExpandEnvironmentStringsW, address_out = 0x77064a40 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = QueryPerformanceCounter, address_out = 0x77065da0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = QueryPerformanceFrequency, address_out = 0x77065dc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetCurrentProcessId, address_out = 0x770bea20 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetFileAttributesW, address_out = 0x770bf100 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetVolumeInformationW, address_out = 0x770bf020 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WriteFile, address_out = 0x770bf180 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetFilePointerEx, address_out = 0x770bf130 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetEndOfFile, address_out = 0x770bf0e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FindFirstFileW, address_out = 0x770bedf0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetProcessHeap, address_out = 0x770651f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapReAlloc, address_out = 0x7788f630 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapAlloc, address_out = 0x77892dc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = HeapFree, address_out = 0x770657f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreatePipe, address_out = 0x77064590 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SetHandleInformation, address_out = 0x770beae0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateProcessW, address_out = 0x77064610 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CompareStringW, address_out = 0x77064430 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CompareStringA, address_out = 0x77064410 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = OpenProcess, address_out = 0x77065cc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = TerminateProcess, address_out = 0x770667e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetSystemTime, address_out = 0x770654e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = SystemTimeToFileTime, address_out = 0x770667a0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetLastError, address_out = 0x77065010 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = CreateToolhelp32Snapshot, address_out = 0x7709edc0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Process32NextW, address_out = 0x7709f8f0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Process32FirstW, address_out = 0x7709f750 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegOpenKeyExW, address_out = 0x75bae580 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegQueryValueExW, address_out = 0x75bae5a0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegSetValueExW, address_out = 0x75baf530 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RegCloseKey, address_out = 0x75baed60 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenProcessToken, address_out = 0x75baefb0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = GetTokenInformation, address_out = 0x75baee90 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenSCManagerW, address_out = 0x75bb0540 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenServiceW, address_out = 0x75bafa20 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CloseServiceHandle, address_out = 0x75bafc00 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = ControlService, address_out = 0x75bc26d0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = QueryServiceStatus, address_out = 0x75bb2380 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = EnumDependentServicesW, address_out = 0x75bc2f70 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = EnumServicesStatusExW, address_out = 0x75bafc80 True 1
Fn
Get Address c:\windows\syswow64\user32.dll function = SystemParametersInfoW, address_out = 0x774ef210 True 1
Fn
Get Address c:\windows\syswow64\shell32.dll function = ShellExecuteExW, address_out = 0x74654730 True 1
Fn
Get Address c:\windows\syswow64\ntdll.dll function = NtQuerySystemInformation, address_out = 0x778c2070 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetCloseEnum, address_out = 0x74252640 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetOpenEnumW, address_out = 0x74252790 True 1
Fn
Get Address c:\windows\syswow64\mpr.dll function = WNetEnumResourceW, address_out = 0x74252410 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = WSAStartup, address_out = 0x76f15b40 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = socket, address_out = 0x76f24510 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = send, address_out = 0x76f15030 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = recv, address_out = 0x76f20c50 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = connect, address_out = 0x76f15410 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = closesocket, address_out = 0x76f20910 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = gethostbyname, address_out = 0x76f46cb0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = inet_addr, address_out = 0x76f29160 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = ntohl, address_out = 0x76f149d0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = htonl, address_out = 0x76f149d0 True 1
Fn
Get Address c:\windows\syswow64\ws2_32.dll function = htons, address_out = 0x76f28ff0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 16
Fn
Service (78)
»
Operation Additional Information Success Count Logfile
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 2
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 3
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 3
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 3
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 3
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 2
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 5
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 5
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 3
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 3
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 2
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE False 2
Fn
Enumerate database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 3
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 3
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 5
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 3
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
Open Manager database_name = SERVICES_ACTIVE_DATABASE True 2
Fn
System (313)
»
Operation Additional Information Success Count Logfile
Get Computer Name result_out = NQDPDE True 1
Fn
Sleep duration = -1 (infinite) False 1
Fn
Sleep duration = 100 milliseconds (0.100 seconds) True 54
Fn
Sleep duration = 500 milliseconds (0.500 seconds) True 25
Fn
Get Time type = Performance Ctr, time = 9800944433 True 1
Fn
Get Time type = Ticks, time = 97968 True 3
Fn
Get Time type = Ticks, time = 98421 True 2
Fn
Get Time type = Ticks, time = 98671 True 2
Fn
Get Time type = Ticks, time = 98937 True 2
Fn
Get Time type = Ticks, time = 99312 True 2
Fn
Get Time type = Ticks, time = 99875 True 4
Fn
Get Time type = Ticks, time = 100171 True 2
Fn
Get Time type = Ticks, time = 100468 True 2
Fn
Get Time type = Ticks, time = 102046 True 4
Fn
Get Time type = Ticks, time = 102843 True 2
Fn
Get Time type = Ticks, time = 103265 True 4
Fn
Get Time type = Ticks, time = 103734 True 2
Fn
Get Time type = Ticks, time = 104734 True 4
Fn
Get Time type = Ticks, time = 105156 True 2
Fn
Get Time type = Ticks, time = 105593 True 2
Fn
Get Time type = Ticks, time = 105890 True 4
Fn
Get Time type = Ticks, time = 106078 True 2
Fn
Get Time type = Ticks, time = 106203 True 2
Fn
Get Time type = Ticks, time = 106375 True 2
Fn
Get Time type = Ticks, time = 106562 True 2
Fn
Get Time type = Ticks, time = 106953 True 4
Fn
Get Time type = Ticks, time = 107156 True 2
Fn
Get Time type = Ticks, time = 107343 True 2
Fn
Get Time type = Ticks, time = 107468 True 2
Fn
Get Time type = Ticks, time = 107609 True 2
Fn
Get Time type = Ticks, time = 107765 True 2
Fn
Get Time type = Ticks, time = 107875 True 2
Fn
Get Time type = Ticks, time = 107984 True 4
Fn
Get Time type = Ticks, time = 108093 True 2
Fn
Get Time type = Ticks, time = 108203 True 2
Fn
Get Time type = Ticks, time = 108312 True 2
Fn
Get Time type = Ticks, time = 108421 True 2
Fn
Get Time type = Ticks, time = 108718 True 2
Fn
Get Time type = Ticks, time = 108828 True 2
Fn
Get Time type = Ticks, time = 108968 True 2
Fn
Get Time type = Ticks, time = 109078 True 4
Fn
Get Time type = Ticks, time = 109218 True 2
Fn
Get Time type = Ticks, time = 109328 True 2
Fn
Get Time type = Ticks, time = 109437 True 2
Fn
Get Time type = Ticks, time = 109546 True 2
Fn
Get Time type = Ticks, time = 109656 True 2
Fn
Get Time type = Ticks, time = 109765 True 2
Fn
Get Time type = Ticks, time = 109875 True 2
Fn
Get Time type = Ticks, time = 110000 True 2
Fn
Get Time type = Ticks, time = 110109 True 4
Fn
Get Time type = Ticks, time = 110218 True 2
Fn
Get Time type = Ticks, time = 110328 True 2
Fn
Get Time type = Ticks, time = 110437 True 2
Fn
Get Time type = Ticks, time = 110546 True 2
Fn
Get Time type = Ticks, time = 110656 True 2
Fn
Get Time type = Ticks, time = 110765 True 2
Fn
Get Time type = Ticks, time = 110875 True 2
Fn
Get Time type = Ticks, time = 110984 True 2
Fn
Get Time type = Ticks, time = 111093 True 2
Fn
Get Time type = Ticks, time = 111265 True 4
Fn
Get Time type = Ticks, time = 111390 True 2
Fn
Get Time type = Ticks, time = 111500 True 2
Fn
Get Time type = Ticks, time = 111703 True 2
Fn
Get Time type = Ticks, time = 111828 True 2
Fn
Get Time type = Ticks, time = 111937 True 2
Fn
Get Time type = Ticks, time = 112046 True 2
Fn
Get Time type = Ticks, time = 112156 True 2
Fn
Get Time type = Ticks, time = 112265 True 2
Fn
Get Time type = Ticks, time = 112375 True 4
Fn
Get Time type = Ticks, time = 112500 True 2
Fn
Get Time type = Ticks, time = 114937 True 4
Fn
Get Time type = Ticks, time = 115078 True 2
Fn
Get Time type = Ticks, time = 115187 True 2
Fn
Get Time type = Ticks, time = 115296 True 2
Fn
Get Time type = Ticks, time = 115406 True 2
Fn
Get Time type = Ticks, time = 115531 True 2
Fn
Get Time type = Ticks, time = 115640 True 2
Fn
Get Time type = Ticks, time = 115750 True 2
Fn
Get Time type = Ticks, time = 115875 True 2
Fn
Get Time type = Ticks, time = 115984 True 4
Fn
Get Time type = Ticks, time = 116093 True 2
Fn
Get Time type = Ticks, time = 116359 True 2
Fn
Get Time type = Ticks, time = 116468 True 2
Fn
Get Time type = Ticks, time = 116593 True 2
Fn
Get Time type = Ticks, time = 117000 True 4
Fn
Get Time type = Ticks, time = 117140 True 2
Fn
Get Time type = Ticks, time = 117250 True 2
Fn
Get Time type = Ticks, time = 117656 True 2
Fn
Get Time type = Ticks, time = 118062 True 4
Fn
Get Time type = Ticks, time = 118546 True 2
Fn
Get Time type = Ticks, time = 119062 True 2
Fn
Get Time type = Ticks, time = 119296 True 4
Fn
Get Time type = Ticks, time = 119437 True 2
Fn
Get Time type = Ticks, time = 119687 True 2
Fn
Get Time type = Ticks, time = 119953 True 2
Fn
Get Time type = Ticks, time = 120062 True 2
Fn
Get Time type = Ticks, time = 120671 True 4
Fn
Get Time type = Ticks, time = 121000 True 2
Fn
Get Time type = Ticks, time = 121187 True 2
Fn
Get Time type = Ticks, time = 122250 True 4
Fn
Get Time type = Ticks, time = 122609 True 2
Fn
Get Info type = Operating System True 2
Fn
Mutex (2)
»
Operation Additional Information Success Count Logfile
Open mutex_name = Global\syncronize_1TPBM0A, desired_access = SYNCHRONIZE True 1
Fn
Open mutex_name = Global\syncronize_1TPBM0U, desired_access = SYNCHRONIZE True 1
Fn
Process #13: cmd.exe
284 0
»
Information Value
ID #13
File Name c:\windows\system32\cmd.exe
Command Line "C:\WINDOWS\system32\cmd.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:57, Reason: Child Process
Unmonitor End Time: 00:03:08, Reason: Self Terminated
Monitor Duration 00:00:10
OS Process Information
»
Information Value
PID 0xc40
Parent PID 0x2a8 (c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x C48
0x 4CC
Host Behavior
File (218)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\WINDOWS\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_OUTPUT_HANDLE type = file_type True 14
Fn
Get Info STD_INPUT_HANDLE type = file_type True 7
Fn
Open STD_OUTPUT_HANDLE - True 36
Fn
Open STD_INPUT_HANDLE - True 81
Fn
Read STD_INPUT_HANDLE size = 1, size_out = 1 True 65
Fn
Data
Write STD_OUTPUT_HANDLE size = 38 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 2 True 5
Fn
Data
Write STD_OUTPUT_HANDLE size = 52 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 20 True 3
Fn
Data
Write STD_OUTPUT_HANDLE size = 24 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 36 True 1
Fn
Data
Write STD_OUTPUT_HANDLE size = 5 True 1
Fn
Data
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 4, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Process (4)
»
Operation Process Additional Information Success Count Logfile
Create C:\WINDOWS\system32\mode.com os_pid = 0x500, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Create C:\WINDOWS\system32\vssadmin.exe os_pid = 0x4a0, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Get Info C:\WINDOWS\system32\mode.com type = PROCESS_BASIC_INFORMATION True 1
Fn
Get Info C:\WINDOWS\system32\vssadmin.exe type = PROCESS_BASIC_INFORMATION True 1
Fn
Memory (2)
»
Operation Process Additional Information Success Count Logfile
Read C:\WINDOWS\system32\mode.com address = 357413429248, size = 1952 True 1
Fn
Data
Read C:\WINDOWS\system32\vssadmin.exe address = 1062815592448, size = 1952 True 1
Fn
Data
Module (10)
»
Operation Module Additional Information Success Count Logfile
Load NTDLL.DLL base_address = 0x7ff8c85b0000 True 1
Fn
Get Handle c:\windows\system32\cmd.exe base_address = 0x7ff695310000 True 1
Fn
Get Handle c:\windows\system32\kernel32.dll base_address = 0x7ff8c81c0000 True 2
Fn
Get Filename - process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\WINDOWS\system32\cmd.exe, size = 32743 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetThreadUILanguage, address_out = 0x7ff8c81da990 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = CopyFileExW, address_out = 0x7ff8c81de830 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = IsDebuggerPresent, address_out = 0x7ff8c81de300 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetConsoleInputExeNameW, address_out = 0x7ff8c5880a40 True 1
Fn
Get Address c:\windows\system32\ntdll.dll function = NtQueryInformationProcess, address_out = 0x7ff8c86556b0 True 1
Fn
System (1)
»
Operation Additional Information Success Count Logfile
Get Info type = Operating System True 1
Fn
Environment (30)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 10
Fn
Data
Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 3
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 3
Fn
Get Environment String name = PROMPT False 1
Fn
Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Get Environment String name = PROMPT, result_out = $P$G True 3
Fn
Set Environment String name = PROMPT, value = $P$G True 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Set Environment String name = COPYCMD True 2
Fn
Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Set Environment String name = =ExitCodeAscii True 2
Fn
Set Environment String name = =ExitCode, value = 00000002 True 1
Fn
Process #15: cmd.exe
60 0
»
Information Value
ID #15
File Name c:\windows\system32\cmd.exe
Command Line "C:\WINDOWS\system32\cmd.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:59, Reason: Child Process
Unmonitor End Time: 00:03:06, Reason: Self Terminated
Monitor Duration 00:00:07
OS Process Information
»
Information Value
PID 0xbb0
Parent PID 0xe24 (c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 9C8
0x 4F8
Host Behavior
File (25)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\WINDOWS\system32 type = file_attributes True 1
Fn
Get Info C:\Windows\System32 type = file_attributes True 1
Fn
Get Info STD_OUTPUT_HANDLE type = file_type True 5
Fn
Get Info STD_ERROR_HANDLE type = file_type True 1
Fn
Open STD_OUTPUT_HANDLE - True 10
Fn
Open STD_INPUT_HANDLE - True 2
Fn
Open STD_ERROR_HANDLE - True 2
Fn
Write STD_OUTPUT_HANDLE size = 38 False 1
Fn
Write STD_OUTPUT_HANDLE size = 2 False 1
Fn
Write STD_ERROR_HANDLE size = 51 False 1
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Command Processor - True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 4, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module (4)
»
Operation Module Additional Information Success Count Logfile
Get Handle c:\windows\system32\cmd.exe base_address = 0x7ff695310000 True 1
Fn
Get Handle c:\windows\system32\kernel32.dll base_address = 0x7ff8c81c0000 True 1
Fn
Get Filename - process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\WINDOWS\system32\cmd.exe, size = 32743 True 1
Fn
Get Address c:\windows\system32\kernel32.dll function = SetThreadUILanguage, address_out = 0x7ff8c81da990 True 1
Fn
System (1)
»
Operation Additional Information Success Count Logfile
Get Info type = Operating System True 1
Fn
Environment (11)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 4
Fn
Data
Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps; True 1
Fn
Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Get Environment String name = PROMPT False 1
Fn
Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Get Environment String name = KEYS False 1
Fn
Set Environment String name = PROMPT, value = $P$G True 1
Fn
Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Process #17: mode.com
0 0
»
Information Value
ID #17
File Name c:\windows\system32\mode.com
Command Line mode con cp select=1251
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:03:06, Reason: Child Process
Unmonitor End Time: 00:03:08, Reason: Self Terminated
Monitor Duration 00:00:01
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0x500
Parent PID 0xc40 (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 4A4
0x CF8
Process #18: vssadmin.exe
0 0
»
Information Value
ID #18
File Name c:\windows\system32\vssadmin.exe
Command Line vssadmin delete shadows /all /quiet
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:03:07, Reason: Child Process
Unmonitor End Time: 00:03:08, Reason: Self Terminated
Monitor Duration 00:00:01
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0x4a0
Parent PID 0xc40 (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 36C
0x 3A4
0x 478
0x 47C
0x 4C8
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image